{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
        "slug": "dse-20260908-246-interpret-remote-access-historical-reports-as-sessions",
        "url": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/"
        },
        "title": "Interpret Remote Access historical reports as sessions",
        "summary": "Why should a Remote Access report not be read as a count of distinct people?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-08T18:13:05+00:00",
        "modified_at": "2026-09-08T18:29:34+00:00",
        "reviewed_on": "2026-09-08",
        "reading_minutes": 2,
        "word_count": 234,
        "potentially_affected": "Operators reviewing historical Remote Access usage reports after accounting is enabled.",
        "dse_recommendation": "Write the reporting question and time range before exporting results.",
        "primary_source": {
            "name": "Generate a usage report for remote clients using historical data",
            "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft requires Remote Access accounting to be configured before historical usage reports can be generated. The reporting view supports a selected time period and presents user activity and load statistics. Remote Access accounting identifies a session by the combination of the remote client address and user name, rather than treating it simply as a connection. <a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use the report for the interval and accounting configuration that actually produced it. State whether the question concerns session activity, client addresses, identities, or business users. Avoid silently substituting one of those populations for another in an operational summary.</p>\n<h2>DSE recommendation</h2>\n<p>Write the reporting question and time range before exporting results. Have the Remote Access owner explain how session records will be grouped for that question and how machine and user activity will be distinguished where relevant. Restrict access to the identity and address data. Include the report filters and interpretation rules with the output so recipients do not mistake a raw session total for a personnel measure.</p>\n<h2>Verification</h2>\n<p>Compare a small, authorized sample of known activity with the corresponding session records. Check the interval boundaries, identity values, and remote addresses used in the comparison. Note missing accounting coverage or ambiguous identity grouping in the report, and resolve those limitations before making a capacity or usage conclusion.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Generate a usage report for remote clients using historical data</a>. Source reviewed September 8, 2026.</p>",
        "content_text": "Source facts\nMicrosoft requires Remote Access accounting to be configured before historical usage reports can be generated. The reporting view supports a selected time period and presents user activity and load statistics. Remote Access accounting identifies a session by the combination of the remote client address and user name, rather than treating it simply as a connection. Microsoft Learn.\nApplicability\nUse the report for the interval and accounting configuration that actually produced it. State whether the question concerns session activity, client addresses, identities, or business users. Avoid silently substituting one of those populations for another in an operational summary.\nDSE recommendation\nWrite the reporting question and time range before exporting results. Have the Remote Access owner explain how session records will be grouped for that question and how machine and user activity will be distinguished where relevant. Restrict access to the identity and address data. Include the report filters and interpretation rules with the output so recipients do not mistake a raw session total for a personnel measure.\nVerification\nCompare a small, authorized sample of known activity with the corresponding session records. Check the interval boundaries, identity values, and remote addresses used in the comparison. Note missing accounting coverage or ambiguous identity grouping in the report, and resolve those limitations before making a capacity or usage conclusion.\nOfficial references\nMicrosoft Learn: Generate a usage report for remote clients using historical data. Source reviewed September 8, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft requires Remote Access accounting to be configured before historical usage reports can be generated. The reporting view supports a selected time period and presents user activity and load statistics. Remote Access accounting identifies a session by the combination of the remote client address and user name, rather than treating it simply as a connection. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data).\n\n## Applicability\n\nUse the report for the interval and accounting configuration that actually produced it. State whether the question concerns session activity, client addresses, identities, or business users. Avoid silently substituting one of those populations for another in an operational summary.\n\n## DSE recommendation\n\nWrite the reporting question and time range before exporting results. Have the Remote Access owner explain how session records will be grouped for that question and how machine and user activity will be distinguished where relevant. Restrict access to the identity and address data. Include the report filters and interpretation rules with the output so recipients do not mistake a raw session total for a personnel measure.\n\n## Verification\n\nCompare a small, authorized sample of known activity with the corresponding session records. Check the interval boundaries, identity values, and remote addresses used in the comparison. Note missing accounting coverage or ambiguous identity grouping in the report, and resolve those limitations before making a capacity or usage conclusion.\n\n## Official references\n\n[Microsoft Learn: Generate a usage report for remote clients using historical data](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data). Source reviewed September 8, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-08"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Interpret Remote Access historical reports as sessions",
                        "item": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
                "url": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/",
                "headline": "Interpret Remote Access historical reports as sessions",
                "description": "Why should a Remote Access report not be read as a count of distinct people?",
                "abstract": "Why should a Remote Access report not be read as a count of distinct people?",
                "articleBody": "Source facts\nMicrosoft requires Remote Access accounting to be configured before historical usage reports can be generated. The reporting view supports a selected time period and presents user activity and load statistics. Remote Access accounting identifies a session by the combination of the remote client address and user name, rather than treating it simply as a connection. Microsoft Learn.\nApplicability\nUse the report for the interval and accounting configuration that actually produced it. State whether the question concerns session activity, client addresses, identities, or business users. Avoid silently substituting one of those populations for another in an operational summary.\nDSE recommendation\nWrite the reporting question and time range before exporting results. Have the Remote Access owner explain how session records will be grouped for that question and how machine and user activity will be distinguished where relevant. Restrict access to the identity and address data. Include the report filters and interpretation rules with the output so recipients do not mistake a raw session total for a personnel measure.\nVerification\nCompare a small, authorized sample of known activity with the corresponding session records. Check the interval boundaries, identity values, and remote addresses used in the comparison. Note missing accounting coverage or ambiguous identity grouping in the report, and resolve those limitations before making a capacity or usage conclusion.\nOfficial references\nMicrosoft Learn: Generate a usage report for remote clients using historical data. Source reviewed September 8, 2026.",
                "datePublished": "2026-09-08T18:13:05+00:00",
                "dateModified": "2026-09-08T18:29:34+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Interpret Remote Access historical reports as sessions"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 234,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Generate a usage report for remote clients using historical data",
                    "url": "https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data"
                }
            }
        ]
    }
}