What does BSOD 71 (REF_UNKNOWN_LOGON_SESSION) mean?

 
Could be also:
ConstantTypeOS
ERROR_REQ_NOT_ACCEPWin32 errorWindows
EPROTOerrnoLinux
EREMOTEerrnoMac
EPROTOerrnoSolaris
Previous Next
DEREF_UNKNOWN_LOGON_SESSION CANCEL_STATE_IN_COMPLETED_IRP

REF_UNKNOWN_LOGON_SESSION

Unknown logon-session reference for REF_UNKNOWN_LOGON_SESSION

REF_UNKNOWN_LOGON_SESSION is bug check code 0x00000047. This is the reference-side partner of DEthis result. It indicates that the kernel attempted to acquire a reference on a logon-session object that was not valid in the current security bookkeeping.

How to read it in a dump

  • Check whether the crash occurred during logon, logout, token creation, impersonation, or audit processing.
  • The relevant evidence is the token/logon-session object, not the user name alone.
  • A stale pointer or object lifetime bug can present as an unknown session.

What to check

  • Review security and authentication filters, EDR/AV products, and token-manipulation code.
  • Compare reference and dereference crashes if both occur.
  • Look for pool corruption around security objects.

References

Dump evidence

Preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “this result”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.

Analysis order

  • Run WinDbg !analyze -v, then inspect the documented meaning of each parameter instead of relying only on the probably-caused-by line.
  • find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with ref / unknown / logon / session.
  • keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.

Do not repeatedly reboot a machine affected by this result before collecting the dump and event logs. Recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.


Looking for a different code? Search another status or error code.