Mine is set to manual and as far as I know has never been started and I don't worry about it at all.
My sense is that it is the client / agent side of a larger feature set that one might use in a larger organization consisting of perhaps an active directory domain or at the very least a real server running Windows Server 2k8 or later consisting of a network policy server with network health polices proscribed ( windows updates, virus signatures, firewall configuration, etc.,).
Read more about it here.....
http://en.wikipedia.org/wiki/Network_Access_Protection