I am performing an AD account/group audit for our production domain against a newly created sandbox domain. Both domains are at the Server 2016 level, but the production domain has been in service since roughly the year 2000.
In both production and sandbox domains, I have a built-in group called IIS_IUSRS. In the production domain, it has one user: NETWORK SERVICE which appears to be a placeholder account. In the sandbox domain, the group has one user:IUSR. It is also a placeholder account. These placeholder accounts are different between production & sandbox, yet both are Server 2016 domains.
My questions:
- Should I be concerned that these do not match?
- If NETWORK SERVICE an artifact of a legacy system, how can I configure them to match to avoid confusion going forward?
- What is a placeholder account for? What is the purpose?