I am using windows server 2012 R2. This server hosts role of RODC, DNS, DHCP and NPS. As I checked in server performance report, lsass.exe is utilizing high bandwidth so I suspect something related to AD service. However, we cannot ignore other roles hosted on this server so checking possible cause at DNS, DCHP and NPS level.
- I have verified AD sites and services, subnet is added well.
- Replication time is set to 30 minutes as other DCs have
We have one AD group, member of that group do local cache of credential for RODC authentication so I added all computers in that group. Also, I captured some information from Wireshark and Network Mon tool, it shows some service accounts are sending too many Kerberos ticket this may also cause a bandwidth utilization. So those service accounts are added in a group so the credential will be added locally at computer.
I have asked local IT team to observe the status. so far now they have not reported any problem. I will wait for few more days and update you guys.