Choose the session event
One scenario is to request a lock when a remote session disconnects. Another is to request a power response to a connection event while the session is already locked. These are reactions to Windows session notifications, not a firewall or remote-access approval system.
- Open Triggers and find Remote session connected and Remote session disconnected.
- Choose the required action for each. For an initial disconnect scenario, use Remote session disconnected → Lock Windows and leave connection at Do nothing.
- If you need different behavior while locked, enable Windows locked → Monitor while Windows is locked and configure its corresponding rows separately.
- Save and review the rest of the profile, especially input triggers that could act during a remote interaction.
Run a controlled test
Use a spare, authorized Remote Desktop session and a whole-app Test monitoring.cmd launch. Have a way to reach the computer locally. Connect and disconnect as you normally would, then inspect Event history for the exact connection, unlock and profile transitions.
A verified Windows unlock ends normal monitoring and takes precedence when the connection also unlocks the session. Consequently, “connected → restart” is not a guarantee of a restart on every successful remote sign-in. Validate the sequence for the actual Windows session you intend to monitor.
Coverage and limits
These events concern Remote Desktop/remote-terminal session changes. Third-party remote-control applications may not generate them, and the app does not identify the remote person, inspect network traffic or evaluate their authorization. Other sessions on the machine are not a substitute for the app's own monitored session.
Keep a real restart or shutdown response disabled until you understand the observed order; it can interrupt remote work and leave you needing local access. See the testing checklist and independent locked-session behavior.