Ureader.com  
Microsoft software help and Community
   home   |   control panel login   |   archive   |  
 
platform
active.directory
adsi
adsi.iis-admin
base
com_ole
complus_mts
component_svcs
database
directx
gdi
graphics_mm
internet.client
internet.server
internet.server.isapi-dev
localization
mapi
messaging
msi
mslayerforunicode
multimedia
networking
networking.ipv6
sdk_install
security
shell
telephony.tapi_2
telephony.tapi_3
telephony.tsp
telephony.wte
tools
ui
ui_shell
win_base_svcs
win16
  
 
date: Thu, 17 Apr 2008 07:04:00 -0700,    group: microsoft.public.platformsdk.security        back       


Logon session for DOMAIN\COMPUTER$   
Hello, 
 
I have been using the logonsessions utility (Sysinternal's one) on a domain 
controller (Windows 2003).
I see several logon sessions where the account name is: <DOMAIN>\<COMPUTER>$ 
and the SID is S-1-5-18.
(Alternatively I use LsaEnumerateLogonSessions and LsaGetLogonSessionData 
with same results).
 
My questions are:
A. I know the Sid of this account is different and the SID is representing 
the NT AUTHORITY\SYSTEM account. Is there anyone who can explain the conflict?
B. Where are those session are coming from? Which component initiates these?
 
Thanks in advance,
Ahaz
date: Thu, 17 Apr 2008 07:04:00 -0700   author:   Ahaz Israeli

Google
 
Web ureader.com


    COPYRIGHT 2007, YARDI TECHNOLOGY LIMITED, ALL RIGHT RESERVE  |   contact us