Re: Network Services/NT Authority



The first two events both related to the network service logon and are
normal. I was referring to the one an hour later that did not indicate it
had anything to do with network service. You actually do have a network if
you have a network adapter of any kind installed in your computer and
network service a normal special low privileged identity on your operating
system compared to system. If you use services.msc to view your services you
will see that some services such as DNS client and Remote Procedure Call use
the network service identity. --- Steve


"Magsowner" <Magsowner@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:4296D292-3E45-4F5C-9E09-06E402E11A20@xxxxxxxxxxxxxxxx
Well, that creates another question in my mind:
1. Do you mean that we cannot rely on the time shown on the event log?
The
two events that occured together show the same exact time, but the time
shown
for the next event indicates an hour had passed.
2. I'm still confused about this "Network Services - NT Authority thing
since I don't have a "network". What Network would it refer to??

"Steven L Umbach" wrote:

Well the two events may be in order in the security log but timewise they
do
not relate as an hour is a long time between events. It is not unusual to
see the logon events for Network Services and the Group Policy event
probably is just informational and nothing to worry about. --- Steve


"Magsowner" <Magsowner@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5D3696DD-358F-4B5F-929A-35755A34BBA2@xxxxxxxxxxxxxxxx
Steve: Thanks for your response: I don't really know how to tell if
my
firewall settings have been changed or not, I'm not that technical in
that
area. There were 2 events that occured one right after the other:
1st was event ID # 528, successful logon by the Network Service,
Domain:-
NT
Authority: then #576 which assigned special privledges to the new log
on.
Then about an hour later there were two events ID # 858 to apply
Windows
Firewall Group Settings.

"Steven L Umbach" wrote:

Are you finding that your firewall settings are being changed?? If you
can
post the Event ID that refers to Windows Firewall Group Policy here in
a
reply. --- Steve


"Magsowner" <Magsowner@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:DDDF7FE6-7EC5-4F4E-8BAB-AD694BC7D13B@xxxxxxxxxxxxxxxx
:-I see entries in my Security Event Viewer indicating that
User: Network Services
Domain: NT Authority
is accessing my system in the wee hours of the morning with Special
Privledges assigned and then immediately followed by changes in my
Firewall
Group policy. I do not have a network, unless it is referring to my
cable
internet connection. What is Network Services and What is NT
Authority?
Should I be concerned about this?








.


Quantcast