# Interpret Remote Access historical reports as sessions

> Why should a Remote Access report not be read as a count of distinct people?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-08T18:13:05+00:00
- Modified: 2026-09-08T18:29:34+00:00
- Last reviewed by DSE: 2026-09-08
- Resource type: Guide
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why should a Remote Access report not be read as a count of distinct people?

## Potentially affected

Operators reviewing historical Remote Access usage reports after accounting is enabled.

## DSE recommendation

Write the reporting question and time range before exporting results.

## Article

## Source facts

Microsoft requires Remote Access accounting to be configured before historical usage reports can be generated. The reporting view supports a selected time period and presents user activity and load statistics. Remote Access accounting identifies a session by the combination of the remote client address and user name, rather than treating it simply as a connection. [Microsoft Learn](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data).

## Applicability

Use the report for the interval and accounting configuration that actually produced it. State whether the question concerns session activity, client addresses, identities, or business users. Avoid silently substituting one of those populations for another in an operational summary.

## DSE recommendation

Write the reporting question and time range before exporting results. Have the Remote Access owner explain how session records will be grouped for that question and how machine and user activity will be distinguished where relevant. Restrict access to the identity and address data. Include the report filters and interpretation rules with the output so recipients do not mistake a raw session total for a personnel measure.

## Verification

Compare a small, authorized sample of known activity with the corresponding session records. Check the interval boundaries, identity values, and remote addresses used in the comparison. Note missing accounting coverage or ambiguous identity grouping in the report, and resolve those limitations before making a capacity or usage conclusion.

## Official references

[Microsoft Learn: Generate a usage report for remote clients using historical data](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data). Source reviewed September 8, 2026.

## Primary reference

- Name: Generate a usage report for remote clients using historical data
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/windows-server/remote/remote-access/ras/monitoring-and-accounting/Generate-a-usage-report-for-remote-clients-using-historical-data
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Interpret Remote Access historical reports as sessions,” DSE Security, https://update.dsesecurity.com/updates/dse-20260908-246-interpret-remote-access-historical-reports-as-sessions/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
