April 17, 2009
3:12 am | Last updated: April 17, 2009 at: 6:49 am

The problem has to do with LSASS consuming a lot of CPU time on your Domain Controllers (DC's). The cause of this high CPU turns out to be Conficker infected computers throwing bad passwords against the DC's. The rate of bad passwords can be as high as 10,000 per minute from multiple clients.As you can imagine, this high CPU usage affects other workflows which are AD dependent – including Exchange/SharePoint/Authentication etc. If you temporarily pull the network cable from the DC and wait a few minutes, LSASS drops back down to ~1% or whatever value is normal in your setup.

Full Article

Loading

Contextual Related Posts:

No followup yet

Leave a Response

Comment Preview
« Microsoft Approach to Enterprise SecurityWindows Live Video Messages Updates; joins Wave 3 family »
Feed Icon

Subscribe via RSS or email: