Event ID/Source search
Keyword searchExample: Windows cannot unload your registry file
Event ID: 514 Source: Security
|Type: Success Audit|
An authentication package has been loaded by the Local Security Authority.
This authentication package will be used to authenticate logon attempts.
Authentication Package Name: <authentication package name>
|English: Request a translation of the event description in plain English.|
|Concepts to understand:|
What is the LSA?
What is an authentication protocol?
As per Microsoft: "This event record indicates that the Local Security Authority (LSA) has loaded an authentication package used for authenticating logon requests.Authentication packages are responsible for validating user identification and authentication information collected by logon processes during log on. A single system can simultaneously support multiple authentication packages". See MSW2KDB for additional information about this event.
Windows can use different authentication packages, depending on how it was configured. Loading multiple authentication packages permits the LSA (Local Security Authority) to support multiple logon processes and multiple security protocols.
Depending on what type of resource is accessed and from where, these packages are loaded accordingly. 514 just records this process. Of course, one may build custom auth. packages and they will be recorded accordingly.
See the link to Windows Authentication Packages for information about the <authentication package> field.
|Private comment: Subscribers only. See example of private comment|
|Links: ME174074, Windows Authentication Packages, Online Analysis of Security Event Log, MSW2KDB|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
Send comments or solutions
- Notify me when updated