The customer has these simple rules to assign licenses to users in AD groups which have been working without issue for years and no recent upgrade has been done on their system.
Many users suddenly did not have licenses out of the blue today and the administrator said they did not remove anyone's license. Then while I was looking into it I was saw many users get their license applied back and again the admin said they did not apply any license changes. So we could run an Audit report to see who was doing this and it is NT AUTHORITY\NETWORK SERVICE.
It has actually been playing with user licenses on random intervals all day and night. I can find so many User - SetLicense actions in just a single day for any user.
What is going on here?