Sylv3r Posted April 29, 2014 Posted April 29, 2014 We've got an issue at the moment where at the start of each lesson, when users are logging onto our workstations the DC runs at 100% with lsass.exe running high basically killing our box. It is taken users up to 3 minutes to logon, eventually after about 5 minutes once everybody gets logged on the load drops again to 4% and continues fine. The network isn't slow or anything and the users experience isn't affected once they finally get logged onto to the network. I have been tinkering with things over the last few days and can't for the live of me work out why it is doing it. We've restarted the servers and the AV across the school is fully up-to-date. Nothing out of the ordinary appears in the event viewer. It's just basically seems that AD can't cope with the number of requests at the same time. If anybody has any idea, what could be up or any pointers that would be great. I've trawled the internet looking for possible causes and lots of people seem to have the issue, but nobody really knows how to fix it. The DC is Windows 2008 R2 and all the clients are running Windows 7 SP1. Cheers
Gaz Posted April 29, 2014 Posted April 29, 2014 I wonder if its worth trying process monitor to find out exactly what the process is doing. Process Monitor Monitor the lsass.exe process during the busy period and see if you can decipher what its doing exactly.
Sylv3r Posted April 30, 2014 Author Posted April 30, 2014 Thanks Gaz I had already tried that the other day, but had planned to give it another shot. Nothing out of the ordinary appeared to show up - but no harm in trying again Cheers
bdmichalski Posted May 2, 2014 Posted May 2, 2014 I personally have never seen the problem you are describing, but if all this box is doing is AD, it is pretty easy to spin up a new DC and migrate the roles over. Something might just be fluky with this DC and migrating everything to a fresh install could be your quickest fix.
xenonive Posted May 2, 2014 Posted May 2, 2014 I had this with a corrupt active directory object mostly caused by hard power off at some point . Might be worth running check for corruptions in active directory else look group policy corruptions .
psydii Posted May 2, 2014 Posted May 2, 2014 Enterprise hotfix rollup installed? Also try this one for the latest LSASS.exe available in the Windows Catalog: Description of an update rollup that resolves interoperation issues in Windows Server 2008 SP2, Windows 7 SP1, and Windows Server 2008 R2 SP1 and Large version store size causes high CPU usage on a computer that is running Windows Server 2008 R2
psydii Posted May 2, 2014 Posted May 2, 2014 For reference: How many DCs do you have and how many clients?
xenonive Posted May 3, 2014 Posted May 3, 2014 For reference: How many DCs do you have and how many clients? That is a good point could just be too many client requests for one DC
Sylv3r Posted May 3, 2014 Author Posted May 3, 2014 Thanks for the pointers guys. Will take a look at some of the hot fixes posted here. We've got 4 DC's for around 1,200 clients. Everything has worked fine for 3+ years with a similar number of clients. Obvioussly all clients aren't logging in at the same time as some may have already logged in earlier or standing alone at the logon screen.
psydii Posted May 4, 2014 Posted May 4, 2014 (edited) That should be fine. Following on from @xenonive and a little more research... since hotfix builds of specific files are cumulative, perhaps actually your should also install " http://support.microsoft.com/kb/2878563/en-us " to get the latest esent.dll and then follow the advice in " http://support.microsoft.com/kb/2566592/en-us " to check and repair any damage to the AD database. Edited May 4, 2014 by psydii
free780 Posted May 4, 2014 Posted May 4, 2014 Have you got the antivirus exception s configured as per ms recommendations.
Winner Posted January 27, 2016 Posted January 27, 2016 We've got an issue at the moment where at the start of each lesson, when users are logging onto our workstations the DC runs at 100% with lsass.exe running high basically killing our box. It is taken users up to 3 minutes to logon, eventually after about 5 minutes once everybody gets logged on the load drops again to 4% and continues fine. The network isn't slow or anything and the users experience isn't affected once they finally get logged onto to the network. I have been tinkering with things over the last few days and can't for the live of me work out why it is doing it. We've restarted the servers and the AV across the school is fully up-to-date. Nothing out of the ordinary appears in the event viewer. It's just basically seems that AD can't cope with the number of requests at the same time. If anybody has any idea, what could be up or any pointers that would be great. I've trawled the internet looking for possible causes and lots of people seem to have the issue, but nobody really knows how to fix it. The DC is Windows 2008 R2 and all the clients are running Windows 7 SP1. Cheers Hi Sylv3r, did you ever resolve this? We are having the same issue with lsass.exe running at 100% when clients startup/wake from sleep. We have 5 2012 R2 DC's for 2000 Win7 clients so they should be able to cope.
Davit2005 Posted January 27, 2016 Posted January 27, 2016 (edited) Hi Sylv3r, did you ever resolve this? We are having the same issue with lsass.exe running at 100% when clients startup/wake from sleep. We have 5 2012 R2 DC's for 2000 Win7 clients so they should be able to cope. Are the DC's virtual or Physical and if Virtual how many CPU's are allocated and how much RAM. We found specifically our Virtual DC's had the issues and so we upped the vCPU count from 1 to 2. 1600 workstations and 3 DC's running 2008 R2 both VM's 8GB Ram (2 DC's Virtual and 1 Physical). Since upping the vCPU's we haven't noticed any further problems. Also I'd thought 5 DC's would mean more replication traffic. Edited January 27, 2016 by Davit2005
Winner Posted January 27, 2016 Posted January 27, 2016 3 DCs are virtual, 2 vCPU with 16GB RAM. Two are for our primary site, and the other services a different site. We then have two other physical DC's for some smaller satellite sites.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now