关于机器账户以UMFD身份交互式登录的正常性及适用场景咨询
Great question! Let’s break this down clearly based on the event data you shared and standard Windows system behavior:
First off, this is completely normal behavior—no need to flag this as a security concern. Here’s the breakdown:
What are UMFD accounts?
UMFD stands for User Mode Driver Framework accounts. These are system-managed virtual accounts (confirmed by VirtualAccount: %%1842 in your event data) created specifically to isolate font driver processes. The TargetDomainName: Font Driver Host and TargetUserSid: S-1-5-96-0-3 further confirm this is a font-related UMFD account.
Why is the machine account (server2$) logging in interactively as UMFD-3?
The interactive logon type (LogonType: 2) might seem unexpected at first, but it’s tied to the winlogon.exe process (Windows Logon Manager) initializing a secure session for the font driver host. This typically happens in these scenarios:
- System startup: When your server boots up, it initializes core services including font driver hosts, which require an isolated session to operate securely.
- User logon: When a user signs into the server, the system spins up a UMFD account to handle font rendering for that user’s session—this limits the impact of any potential font driver issues to just that session.
- Font/driver updates: If you install new fonts or update font drivers, the system restarts the font host process, triggering this logon event.
Key event details that confirm normality:
SubjectUserSid: S-1-5-18is the Local System account, acting through the machine accountserver2$—this is the system itself initiating the action, not an external user.LogonProcessName: Advapiindicates this is an API-driven logon for a system service, not a human-initiated login.ElevatedToken: %%1843means the token isn’t elevated, which aligns with UMFD’s purpose of limiting privilege exposure for isolated driver processes.
When should you worry?
Only if you see an unusual surge in these events, or if they’re paired with other suspicious activity (like unknown processes triggering UMFD logons, or failed logon attempts for UMFD accounts). On its own, this event is just Windows doing its job to keep font processing secure.
备注:内容来源于stack exchange,提问作者Nina G

