Jul 09 2020 02:44 AM - edited Jul 09 2020 02:46 AM
I have the problem that our Clients use too much CPU during a FullScan. Actually, the usage is limited to 20%, but the setting seems to have no effect. Whether I set it via Configuration Manager or GPO, the result is the same.
Does anyone have a similar problem or even better... a solution?
Jul 11 2020 12:37 AM - edited Feb 20 2024 04:54 AM
Hello @philippwree,
Refer this guide:
https://www.kapilarya.com/limit-cpu-usage-during-a-windows-defender-scan
Let us know if this helps!
Note: Included link in this reply refers to blog post by a trusted Microsoft MVP.
*This reply was updated to make sure it is valid.
Jul 14 2020 08:58 AM
Have the same problem as @philippwree!
In the Configuration Manager, we defined a CPU load of 30% for our windows servers in the default defender policy. The setting has also been correctly transmitted to the agents.
Checked local via powershell "Get-MpPreference" and in the registry "HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows Defender \ Scan \ AvgCPULoadFactor". The values are correctly limited to 30%.
Despite the throttling, the process "MsMpEng.exe" uses up to 100% CPU for scheduled and manual defender scans (full and quick).
Possibly a bug in a microsoft defender update?
Aug 31 2020 03:08 AM
Did you find any solution for the Windows Defender problem @philippwree?
We are currently distributing the load on our host by running the scans of the VMs at different times. However, we still have the problem with the load on the CPU.
Oct 14 2020 01:12 AM
@philippwree We have the same issue, CPU limit is completely ignored. Is there a solution anywhere? iv been searching but cant find anything usefull
Oct 14 2020 05:44 AM - edited Oct 14 2020 06:06 AM
@Daniel_Larsson In your antimalware policy under “Scheduled Scans”, switch the option “Start a scheduled scan only when the computer is idle” to no. That solved the problem for us.
It seems that the check by Microsoft is flawed. If Endpoint thinks the system is idle, he ignores the CPU limit.
Jan 15 2021 04:51 AM
Changing the following setting to NO doesn't make any difference for us - "Start a scheduled scan only when the computer is idle” / "“ScanOnlyIfIdle” doesn't make any difference for us.
I tried setting "AvgCPULoadFactor"n in the registry to 1% and it would still hit up to 68%.
Apr 13 2021 05:14 AM - edited Apr 13 2021 05:15 AM
Hey,
based on the docs article for Set-MpPreference, its not a hard limit, see text below.
Set-MpPreference (Defender) | Microsoft Docs
Specifies the maximum percentage CPU usage for a scan. The acceptable values for this parameter are: integers from 5 through 100, and the value 0, which disables CPU throttling. Windows Defender does not exceed the percentage of CPU usage that you specify. The default value is 50.
Note: This is not a hard limit but rather a guidance for the scanning engine to not exceed this maximum on average.
Apr 13 2021 05:51 AM
@Salbert89 Thanks, yes. There were two microsoft docs related to this setting. One said it was a hard limit and one said it was not. I contributed to both docs about the difference and they changed the one that said it was a hard limit to say it wasn't.
Apr 13 2021 06:15 AM
@Salbert89 It really should be a hard limit though...
I have a bunch of HP computers that completely ignores it and becomes useless everytime they run a fullscan. It's not model specific, OS specific or anything else from what we can tell, its like 1 in 50 machines just does not give a ****. We can tell they have all the settings, but it just goes to 99% CPU and stays there... leaving the users to get angry and restarts the computers to be able to continue working.
I have looked all over the internet for a solution to this, and tried them all, Nothing works.
May 05 2021 12:35 PM
May 05 2021 01:05 PM
@MAlv68 I had a ticket open with Microsoft support for months about this but didn't get anywhere. The one useful comment was that a manually run scan will ignore any CPU limits like ScanAvgCPULoadFactor.
May 05 2021 01:23 PM
Thanks Andrew! I was wondering about "manual" scans vs. "Scheduled" scans. I appreciate your information. Seems kind of strange that there would be a difference but I understand it. Thanks again!
May 05 2021 01:56 PM
Aug 07 2021 04:56 AM
Feb 19 2024 10:37 AM
Hello is there any fix for the windows server 2016 , high cpu utilization as we are still facing the issue. antimalware service executable is taking more than 80 % for our production environment
Feb 20 2024 02:11 AM
Feb 20 2024 09:38 AM