I see log entry’s where it’s clear ‘user A’ added ‘user B’ to ‘group C’…. however I also see entries where instead of it being a user that is doing the adding to the group, it is ‘nt authority\system’, the computername$ account. What would make that happen? The only thing I can think of is a process running in the context of ‘system’ performed the action… but I don’t know why that would be happening…. Is it normal?