> Source: [sk95888](https://support.checkpoint.com/results/sk/sk95888)

# sk95888 - lsass.exe consumes high CPU on AD Domain Controllers 

| Property | Value |
|----------|-------|
| Solution ID | sk95888 |
| Date Created | 2013-10-25 |
| Last Modified | 2020-10-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- lsass.exe process (Local Security Authentication Subsystem) consumes high CPU on Active Directory (AD) Domain Controllers.

## Cause

The lsass process is responsible for:

* Validating login credentials (i.e. username/password pairs) for local logins (that is, logins to your workstation in a workgroup environment)
* Passing login credentials to your domain controller and getting responses for domain logins
* Enforcing some aspects of local security policy (which accounts and groups have which rights, which accounts and groups can login at what times and via what means, etc.)
* Running the "protected storage" service

LDAP groups updates feature, introduced in R77, uses extended WMI query (to the already existing one, for ADQuery) to receive security events for groups membership changes.

This extended WMI query may cause high CPU usage by lsass.exe

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
