| Login | Type | Disabled | Last Access | Days Since | Source | Confidence | Active Sessions | Note |
|---|---|---|---|---|---|---|---|---|
| app_svc | SQL_LOGIN | No | 2026-07-19 08:41 | 0 | Live | Exact | 3 | |
| etl_svc | SQL_LOGIN | No | 2026-07-19 03:00 | 0 | ErrorLog | Exact | 0 | |
| CONTOSO\dba_team | WINDOWS_GROUP | No | - | - | None | Unknown | 0 | Windows group login - members connect with their own AD account, not this group's identity. |
| report_ro | SQL_LOGIN | No | 2026-06-02 07:15 | 47 | ErrorLog | Exact | 0 | |
| legacy_app | SQL_LOGIN | No | - | - | None | Unknown | 0 | No session and no ErrorLog entry found in the retained window - default AuditLevel only records failed logins. |
| old_migration_svc | SQL_LOGIN | Yes | 2025-11-08 14:02 | 254 | ErrorLog | Exact | 0 | Login disabled - retained for audit history. |
SQL Server does not persist a true "last login" timestamp - this combines live sessions (sys.dm_exec_sessions) with successful-login entries still present in the SQL Server error log.