Could another user be connected to the computer?¶
Yes. Servers, shared workstations and virtual environments can hold several user sessions at once, including sessions with no desktop currently visible on the monitor.
The useful distinction is between the screen in front of you and the set of sessions running on the system. They are not always the same thing.
What several sessions can look like¶
A Windows Remote Desktop Session Host, for example, can list a console session alongside active, disconnected or listening remote sessions. A representative display might look like this:
console local.user ID 1 activerdp-tcp#4 ops.user ID 6 activerdp-tcp#2 admin.user ID 4 discThat view may establish that three labelled sessions existed and describe their technical state. It does not show that the named account holder personally controlled each one at the relevant time.
Current Microsoft session-command behaviour - checked 27 September 2026
Microsoft documents that query session displays sessions on a Remote Desktop Session Host server, including session name, username, ID and state where available. Microsoft also documents that logoff ends the selected session's processes and deletes that session. The exact fields and states available depend on the server, permissions and session state.
Preserve each session as a separate relationship¶
Where the information is already displayed, record:
- session name and identifier;
- username or service account;
- active, idle or disconnected state;
- logon, connection or last-active time;
- source device or address where shown;
- local, remote, administrative or virtual context; and
- applications or processes associated with that session.
A disconnected session may still retain running applications and unsaved work. An active service account may represent software rather than a person. A visible remote desktop may itself contain another remote or virtual session.
Do not switch or terminate sessions just to identify them¶
Changing user, sending a message or logging somebody out creates new activity and may close processes, lose unsaved data or alert a remote party. If unfamiliar sessions create a live risk, preserve the most important identifiers first where delay is safe and obtain system-administration, incident-response or forensic support.
Use session details to join authentication, endpoint and network records. Then test who controlled the account and device. Login-session evidence explains why technical continuity and user continuity are separate questions.