Windows Security Log Event ID 514

Operating Systems Windows Server 2000
Windows 2003 and XP
CategorySystem
Type Success
Corresponding events
in Windows 2008
and Vista
4610  
Discussions on Event ID 514
Info required on windows security event [ ref:00D799ma.5007CCNuV:ref ]
14 - An authentication package has been...

514: An authentication package has been loaded by the Local Security Authority

On this page

Event 514 is logged once at startup for each authentication package on the system.

An authentication package is a DLL that encapsulates a given form of authentication, such as NTLM or Kerberos. The Local Security Authority calls into the appropriate authentication package during the logon process to find out if the user is authentic.

Although a third party can develop an authentication package, few do so. The standard packages that come with Windows Server 2003 are as follows: 

  • Microsoft Authentication Package V1_0
  • Wdigest
  • Microsoft Unified Security Protocol Provider
  • Schannel
  • NTLM
  • Kerberos
  • Negotiate

The security implication of event 514, realistically, is low. Although a rogue package could cause great harm by stealing credentials at the time of logon, the effort required in developing and installing a rogue authentication package is significant.

Free Security Log Resources by Randy

Description Fields in 514

  • Authentication Package Name: The full path of the dll and the package name

Supercharger Free Edition

 

Examples of 514

An authentication package has been loaded by the Local Security Authority. This authentication package will be used to authenticate logon attempts. 
Authentication Package Name: C:\WINDOWS\system32\kerberos.dll : Kerberos.

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources