.png)
A laptop comes back damaged, but no one knows what happened. A loaner disappears, possibly forever. Or a tablet suddenly shows up under the wrong student’s name.
For IT teams, the first question is an easy one: “Who last used this device?”
But the answer isn’t always as easy as the question. Finding out the answer quickly and easily varies by operating system and, just as importantly, how the device is managed. For multi-platform device fleets, it can get complex. Windows records logins locally. Google Admin can report on recent Chromebook users, and macOS maintains local login history. iPads and Android devices can be trickier, especially when they are assigned to a single user or set up without separate device-level user accounts.
In this guide, we’ll walk you through how to identify the last logged-in user across the most common devices, with practical steps for Windows, Chromebook, Mac, iPad, and Android.
Login is the general term for accessing an account or device. Logon is the more technical term commonly used by Windows for starting a user session. Throughout this guide, we use "login" generally and "logon" when referring specifically to Windows terminology.
Knowing who was last logged in to a device can help your team:
Knowing when the device was used is as important as knowing who used it. A username gives you a starting point: a timestamp helps you determine whether that user’s activity lines up with the incident.
The good news is that the information is often waiting for you. You just need to know where to look. Let’s get started:
Windows records successful logons in its Security event log. To review them:
According to Microsoft’s documentation for Event ID 4624, the event is created whenever Windows starts a successful login session.
Windows records several login types, including network connections, services, unlocks, and remote sessions.
For a standard login where someone entered their credentials directly on the computer, look for Logon Type 2, which Microsoft classifies as an interactive logon. Other common types include:
If the device is managed through Microsoft Intune, you can also check its Primary user under Devices → Select a device → Overview.
Microsoft explains that Intune normally assigns the Primary user during or shortly after enrollment. On a shared or reassigned laptop, that association may not reflect the person who most recently used it.
For managed Chromebooks, recent-user information is available through Google Admin.
Google Admin shows which accounts recently used the device, when the activity occurred, and how long the Chromebook was used. According to Google’s ChromeOS device documentation, the activity report covers the previous 30 days and retains up to 100 recent users when reporting is enabled.
If you have access to the Mac, you can check its recorded login sessions through Terminal.
Open Terminal and run:
last
The command lists recorded sessions in reverse chronological order, including the username and the beginning and end of each session.
To review the history for one user, add the username:
last alex
Apple provides instructions for opening Terminal and running command-line tools. You can also enter man last in Terminal to open the documentation for the command directly on the Mac.
This method works when you can access the computer, but it is less practical when you need to investigate devices remotely.
A standard iPad does not use the same multi-user login system as Windows or macOS.
Apple supports Shared iPad, which allows multiple people to sign in using Managed Apple Accounts. The device must be organization-owned, supervised, and connected to a device-management service.
Check the user and session information available through your MDM; the amount of historical activity you can review depends on that platform.
On Android, the process varies depending on the enrollment method and whether user sign-in happens at the device or app level.
Some managed Android devices are connected to a specific employee or student. Others are intentionally configured as shared or userless devices: Google’s Android Management API documentation confirms that dedicated Android devices can be provisioned with an anonymous, userless account.
In these setups, users may sign in to individual apps without signing in to Android itself. That means there’s no single Android page that reliably shows who last used the device.
Depending on your configuration, you may need to review:
Tracking down who last used a device can mean jumping between different tools, systems, and platforms, depending on the operating system. On Windows, you might be digging through the Event Viewer. For Chromebooks, you’ll need to check Google Admin. On a Mac, you’ll be running
Terminal commands, while iPads and Android devices may require you wading through a mess of several systems.
Senturo makes identifying who last used a device easy by showing the last logged-in user and timestamp directly on the device record.
The username tells you who signed in, while the timestamp answers when: which tells you whether that login lines up with the incident you are investigating.
You can compare that information alongside:
This gives your IT people a complete timeline without having to check a different system for every piece of information.
In a real-world example, Euclid City Schools used last-user data and location history to help attendance and school staff resolve device mix-ups faster.
No. Being the last person to log in does not prove that they damaged, lost, or misused a device. Another person could have handled it without signing in.
The username and timestamp are just part of the investigation, not an accusation. To reach a reasonable conclusion, compare them with location history, network activity, assignment records, check-in data, and any other relevant information you can find on Senturo.
Open Event Viewer → Windows Logs → Security and filter for Event ID 4624. For a direct login on the computer, look for Logon Type 2 and review the account listed under New Logon.
Yes, if it’s a managed Chromebook and recent-user reporting is enabled. In Google Admin, select the device and open Systems and activity → Recent users and activity.
Open Terminal and run last. The command displays recorded user sessions in reverse chronological order. To check one account, run last username.
It depends on the configuration. Standard iPads do not provide traditional multi-user login history. A shared iPad supports multiple Managed Apple Accounts, with user information managed through an organization’s MDM.
Not through a single Android screen. The information available depends on how the device was enrolled and whether users sign in to Android itself or to individual apps.
Not necessarily. An assigned or primary user shows who the management system associates with the device. That person may not be the one who used it most recently.
A username tells you who signed in. The timestamp indicates when that login happened, making the information more useful when investigating a missing, damaged, shared, or unreturned device.