Defender For Endpoint consuming a lot of CPU

Bombbe 1,621 Reputation points
2022-06-21T11:32:32.693+00:00

Hi,
we are testing Azure Virtual Desktop with to vm host pool and we are noticing that Defender For Endpoint (old ATP) are consuming a lot of cpu usage all the time, around 50%. This makes our VDI's very slow to even do basic task like opening powershell or Excel because cpu is spking 100% all the time.

213401-image.png

and even when not a single user are connected to host it is still under 60% cpu usage (spike is when i connected to host).
213240-image.png

host details (Microsoft Windows 10 Enterprise for Virtual Desktops) and the VM sku is Standard D2s v3 (2 vcpus, 8 GiB memory)

213376-image.png

What are they ways so start to investigate the issue? What to look / do first?

Azure Virtual Desktop
Azure Virtual Desktop
A Microsoft desktop and app virtualization service that runs on Azure. Previously known as Windows Virtual Desktop.
1,451 questions
0 comments No comments
{count} votes

Accepted answer
  1. Carlos Solís Salazar 17,791 Reputation points MVP
    2022-06-21T22:39:43.747+00:00

    Hi @Bombbe

    Thank you for asking this question on the **Microsoft Q&A Platform. **

    When the first boot is usually the antimalware solutions require more resources,

    Did you leave the host active for a while?

    Also, you are running with the minimum hardware requirement (Cores)

    Cores: 2 minimum, 4 preferred Memory: 1 GB minimum, 4 preferred

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/minimum-requirements?view=o365-worldwide

    So, I would recommend you use a VM SKU with more resources os run your test without windows defender

    Hope this helps,
    Carlos Solís Salazar


    Accept Answer and Upvote, if any of the above helped, this thread can help others in the community looking for remediation for similar issues.
    NOTE: To answer you as quickly as possible, please mention me in your reply.



1 additional answer

Sort by: Most helpful
  1. deherman-MSFT 35,636 Reputation points Microsoft Employee
    2022-06-21T17:34:46.21+00:00

    @Bombbe
    You can follow our page here to diagnose the issue. I have sent you a private message so we can work with you directly to resolve this.

    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-performance-issues?view=o365-worldwide