| Previous | Next |
| INSUFFICIENT_SYSTEM_MAP_REGS | REF_UNKNOWN_LOGON_SESSION |
DEREF_UNKNOWN_LOGON_SESSION
Unknown logon-session dereference for DEREF_UNKNOWN_LOGON_SESSION
DEREF_UNKNOWN_LOGON_SESSION is bug check code 0x00000046. Logon sessions are security-accounting objects. This bug check means reference tracking around a logon-session object failed during dereference, suggesting corruption, stale references, or incorrect security callback behavior.
How to read it in a dump
- The failing path should be interpreted with security subsystem, token, LSA/logon, and object-reference state in mind.
- Do not treat it as a bad password or normal authentication failure; it is kernel bookkeeping.
- Look for endpoint, audit, authentication, or file-system/security filter drivers.
What to check
- Inspect token and logon-session references in the dump.
- Check security products and kernel callbacks around logon/session lifecycle.
- Use verifier for drivers that retain token, process, or security object references.
References
Dump evidence
Preserve the complete dump, the four bug-check parameters, the exact Windows build, loaded-module list, and the event timeline immediately before the stop. AllStat summarizes the condition as “this result”; that sentence identifies the failure class, while the parameters and stack determine which object, driver, processor, or subsystem instance was involved.
Analysis order
- Run WinDbg
!analyze -v, then inspect the documented meaning of each parameter instead of relying only on the probably-caused-by line. - find the earliest abnormal event: driver update, firmware change, device reset, storage error, verifier report, resource exhaustion, or application hang connected with deref / unknown / logon / session.
- keep third-party filter, security, storage, graphics, and virtualization drivers in the module inventory; removing evidence before dump analysis can obscure the responsible path.
Do not repeatedly reboot a machine affected by this result before collecting the dump and event logs. Recovery actions should follow the component identified by the stack and parameters, not merely the symbolic stop-code name.
Looking for a different code? Search another status or error code.
