Hello,
Thanks for the suggestions. Basically, I'm finding my DC's occasionally
hanging LSASS at 99% and investigation has found that there are developers
using my AD for their security, but their LDAP queries are inefficient and
therefore causing the LSASS spike. It was taking down one of our workhorse
DC's on a regular basis until it was isolated. The problem is, we can't
just turn off access to LDAP, we have to see how we can prevent this from
happening. I just found another one a week ago, not as severe. I cranked
up the LDAP logging and found out who it was, and asked them to recode their
query, but I can't stop him from running it, and it's still happening every
night when his script runs.
I'm going to look into chaning the LDAP query timeouts or better yet,
recreate a new OU structure with access restrictions for object viewing, and
then all the developers will start coming out of the woodwork.
Again, thanks for the advice.