SOLVED

Updating to Windows 10 Multi user 21H2 - MSSENSE.EXE constantly using 25% cpu on new session hosts

%3CLINGO-SUB%20id%3D%22lingo-sub-3263512%22%20slang%3D%22en-US%22%3EUpdating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hosts%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3263512%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20have%20updated%20golden%20image%20VM%20to%20Windows%2010%20Multi%20User%20version%2021H2%20with%20latest%20KB%20updates%20and%20latest%20FsLogix%20version.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20creating%20new%20machines%20the%20mssense.exe%20process%20(some%20new%20EDR%20sensor%20process%20with%20defender%3F)%20is%20using%2025%25%20cpu.%20We%20have%20Defender%20exclusions%20for%20VDI%20and%20FsLogix%20in%20the%20environment%20and%20also%20best%20practice%20VDI%20defender%20GPO%20applied.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDisabling%20windows%20defender%20does%20not%20help%20aswell.%20Still%20mssense.exe%20is%20using%2025%25%20cpu.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20is%20this%20process%20and%20what%20can%20we%20do%20to%20disable%20or%20remedy%20this%20cpu%20usage%20on%20it%3F%20Or%20figure%20out%20WHAT%20is%20is%20spending%20time%20doing%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20Regards%26nbsp%3B%3C%2FP%3E%3CP%3EAT%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3301297%22%20slang%3D%22en-US%22%3ERe%3A%20Updating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hos%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3301297%22%20slang%3D%22en-US%22%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F823248%22%20target%3D%22_blank%22%3E%40ATWVD%3C%2FA%3E%20Yes%2C%20I%20actually%20have.%20The%20issue%20ended%20up%20being%20related%20to%20the%20customer%20enabling%20an%20Azure%20Policy%20that%20installed%20Defender%20for%20servers%20on%20the%20master%20image%20(The%20ASC%20Policy%20got%20activated%20from%20the%20root%20management%20group).%20This%20caused%20for%20corruption%20on%20Defender%20for%20endpoint%20on%20the%20session%20host%20because%20we%20auto%20register%20the%20session%20hosts%20using%20a%20GPO%20the%20senseGuid%20was%20no%20longer%20unique.%3CBR%20%2F%3E%3CBR%20%2F%3EA%20simple%20test%20to%20see%20if%20you%20run%20into%20the%20same%20issue%20is%20to%20perform%20off%20boarding%20for%20Defender%20using%20the%20offboarding%20script%20on%20one%20of%20the%20session%20host%2C%20reboot%20and%20then%20onboard%20the%20session%20host%20again.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20the%20CPU%20usage%20does%20not%20go%20back%20to%2025%25%20usage%20constantly%2C%20it%20is%20fixed.%20I%20recommend%20monitoring%20it%20for%2024hrs.%3CBR%20%2F%3E%3CBR%20%2F%3EThe%20final%20step%20would%20be%20to%20perform%20offboarding%20on%20the%20master%20image%20and%20make%20sure%20a%20policy%20is%20not%20installing%20defender%20onto%20the%20master%20image%20again.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3301279%22%20slang%3D%22en-US%22%3ERe%3A%20Updating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hos%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3301279%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1367174%22%20target%3D%22_blank%22%3E%40RinoPROITS%3C%2FA%3E%26nbsp%3Bhave%20you%20had%20any%20progress%20with%20MS%20support%20or%20a%26nbsp%3B%3CSPAN%3Eepiphany%20on%20this%20case%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3289194%22%20slang%3D%22en-US%22%3ERe%3A%20Updating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hos%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3289194%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1367174%22%20target%3D%22_blank%22%3E%40RinoPROITS%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EWe%20have%20an%20ongoing%20Azure%20Support%20case%20on%20this.%20Latest%20reply%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%22I%C2%B4m%20still%20reviewing%20the%20situation%20with%20the%20Defender.%20I%C2%B4m%20not%20completely%20sure%20but%20I%C2%B4m%20suspecting%20that%20the%20Defender%20Database%20may%20have%20something%20to%20do%20since%20the%20Procmon%20is%20populated%20with%20checking%E2%80%99s%20on%20this%20path%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22ATWVD_0-1650374709680.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F365234i92AFE249226F1C76%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22ATWVD_0-1650374709680.png%22%20alt%3D%22ATWVD_0-1650374709680.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20they%20all%20show%20up%20as%20a%20SUCCESS%20so%20it%20seems%20that%20is%20not%20an%20error%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22ATWVD_1-1650374709682.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F365233i33EBB7CAA534F711%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22ATWVD_1-1650374709682.png%22%20alt%3D%22ATWVD_1-1650374709682.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20is%20something%20that%20I%20have%20to%20consult%20since%20I%C2%B4ve%20found%20some%20similar%20issues%20on%20third%20party%20sites%20googling%20this%20path%20although%20nothing%20from%20Microsoft%20end%20from%20the%20time%20being%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Feur01.safelinks.protection.outlook.com%2F%3Furl%3Dhttps%253A%252F%252Fforum.restic.net%252Ft%252Fwindows-defender-causes-10x-slowdown%252F925%26amp%3Bdata%3D05%257C01%257Casbjorn.thom%2540soprasteria.com%257C291b88e794e44468001008da214509bb%257C8b87af7d86474dc78df45f69a2011bb5%257C0%257C0%257C637858877684460465%257CUnknown%257CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%253D%257C3000%257C%257C%257C%26amp%3Bsdata%3DQgzYFjcbuY6XIVZG38PgxBJPg5I96mMjitKNasTMwRg%253D%26amp%3Breserved%3D0%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fforum.restic.net%2Ft%2Fwindows-defender-causes-10x-slowdown%2F925%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%C2%B4ve%20found%20some%20sites%20saying%20that%20you%20could%20delete%20this%20entries%20but%20I%C2%B4m%20not%20confident%20on%20doing%20that%20since%20compromising%20how%20defender%20works.%20I%20will%20take%20a%20look%20into%20it%20and%20confirming%20once%20I%20have%20some%20deeper%20insights%20on%20this.%22%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3289112%22%20slang%3D%22en-US%22%3ERe%3A%20Updating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hos%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3289112%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F823248%22%20target%3D%22_blank%22%3E%40ATWVD%3C%2FA%3E%26nbsp%3BI%20am%20seeing%20similar%20issues%20on%20our%20hosts.%20Currently%20have%20a%20ticket%20open%20with%20MS%20but%20so%20far%20no%20luck.%20Were%20you%20able%20to%20fix%20the%20issue%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3350405%22%20slang%3D%22en-US%22%3ERe%3A%20Updating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hos%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3350405%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EThank%20you!%20Got%20time%20to%20test%20this%20today%2C%20and%20it%20is%20exactly%20the%20same%20issue%20here.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3350605%22%20slang%3D%22en-US%22%3ERe%3A%20Updating%20to%20Windows%2010%20Multi%20user%2021H2%20-%20MSSENSE.EXE%20constantly%20using%2025%25%20cpu%20on%20new%20session%20hos%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3350605%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F823248%22%20target%3D%22_blank%22%3E%40ATWVD%3C%2FA%3E%26nbsp%3BPerfect%2C%20glad%20to%20hear%20the%20issue%20is%20resolved%20for%20you%20as%20well.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

We have updated golden image VM to Windows 10 Multi User version 21H2 with latest KB updates and latest FsLogix version.

 

When creating new machines the mssense.exe process (some new EDR sensor process with defender?) is using 25% cpu. We have Defender exclusions for VDI and FsLogix in the environment and also best practice VDI defender GPO applied.

 

Disabling windows defender does not help aswell. Still mssense.exe is using 25% cpu.

 

What is this process and what can we do to disable or remedy this cpu usage on it? Or figure out WHAT is is spending time doing?

 

Best Regards 

AT

6 Replies

@ATWVD I am seeing similar issues on our hosts. Currently have a ticket open with MS but so far no luck. Were you able to fix the issue?

@RinoPROITS 

We have an ongoing Azure Support case on this. Latest reply:

"I´m still reviewing the situation with the Defender. I´m not completely sure but I´m suspecting that the Defender Database may have something to do since the Procmon is populated with checking’s on this path:

 

ATWVD_0-1650374709680.png

 

 

However they all show up as a SUCCESS so it seems that is not an error:

 

ATWVD_1-1650374709682.png

 

 

It is something that I have to consult since I´ve found some similar issues on third party sites googling this path although nothing from Microsoft end from the time being:

 

https://forum.restic.net/t/windows-defender-causes-10x-slowdown/925

 

I´ve found some sites saying that you could delete this entries but I´m not confident on doing that since compromising how defender works. I will take a look into it and confirming once I have some deeper insights on this."

@RinoPROITS have you had any progress with MS support or a epiphany on this case?

best response confirmed by ATWVD (Occasional Contributor)
Solution
@ATWVD Yes, I actually have. The issue ended up being related to the customer enabling an Azure Policy that installed Defender for servers on the master image (The ASC Policy got activated from the root management group). This caused for corruption on Defender for endpoint on the session host because we auto register the session hosts using a GPO the senseGuid was no longer unique.

A simple test to see if you run into the same issue is to perform off boarding for Defender using the offboarding script on one of the session host, reboot and then onboard the session host again.

If the CPU usage does not go back to 25% usage constantly, it is fixed. I recommend monitoring it for 24hrs.

The final step would be to perform offboarding on the master image and make sure a policy is not installing defender onto the master image again.
Hi,

Thank you! Got time to test this today, and it is exactly the same issue here.

@ATWVD Perfect, glad to hear the issue is resolved for you as well.