High CPU usage in domain controllers after you perform a schema update in a Windows Server 2008 R2-based Active Directory forest

Gjelder: Windows Server 2008 R2 EnterpriseWindows Server 2008 R2 DatacenterWindows Server 2008 R2 Foundation


Assume that you perform a schema update in a Windows Server 2008 R2-based Active Directory forest. The size of the Active Directory databases in the forest is large, such as 100 gigabytes (GB). In this situation, all the domain controllers in the forest may update all schema cache at the same time. Therefore, the domain controllers experience high CPU usage. Especially, the Lsass.exe process uses the most of the CPU usage. This results in a degradation of the responsiveness of the domain controllers.

Note Most operations on the domain controllers are affected by this behavior.


Hotfix information

To resolve the issue, install this hotfix on all domain controllers in the forest.

This hotfix introduces a new capability that lets forest administrators to postpone index creation to a point in time that they decide. By default, domain controllers create indexes when they receive the appropriate schema change through replication. After you apply this hotfix, you can defer the index creation by using a new attribute, dSHeuristics. The details of this attribute are as follows:
  • Set the nineteenth byte of the dSHeuristics attribute to 1 until the following occurs:
    • The domain controller receives the UpdateSchemaNow rootDSE mod. This triggers a rebuild of the schema cache.
    • The domain controller is restarted. This requires that the schema cache be rebuilt and, in turn, the deferred indexes are rebuilt.
    For more information about the dSHeuristics attribute, go to the following Microsoft website:
  • Any attribute that is in a deferred index state is logged in the event log every 24 hours. More specifically, the following events are logged accordingly:
    • 2944: Index deferred (logged one time)
      The event message resembles the following:
      Any index changes that are associated with a schema change are being deferred.
    • 2945: Index still pending (logged every 24 hours)
      The event message resembles the following:
      Index changes associated with a previous schema change are still pending. This is because the forest-wide ds-heuristic flag fDisableAutoIndexingOnSchemaUpdate is set. This flag, when set, disables automatic indexing of existing attributes on schema update. To ensure optimal performance from this DC, force an index creation by performing a rootDSE attribute modification on schemaUpdateNow and set it to 1. This behavior can also be turned off by resetting dsHeuristic fDisableAutoIndexingOnSchemaUpdate to 0, then DCs running Windows Server 2008 R2 SP1 or later will automatically rebuild indices as they receive this change.
    • 1137: Index created (logged one time)
      Note This is not a new event.
A supported hotfix is available from Microsoft. However, this hotfix is intended to correct only the problem that is described in this article. Apply this hotfix only to systems that are experiencing the problem described in this article. This hotfix might receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next software update that contains this hotfix.

If the hotfix is available for download, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, visit the following Microsoft website:
Note The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.


To apply this hotfix, you must be running Windows Server 2008 R2 Service Pack 1 (SP1).

For more information about how to obtain a Windows 7 or Windows Server 2008 R2 service pack, click the following article number to view the article in the Microsoft Knowledge Base:

976932 Information about Service Pack 1 for Windows 7 and for Windows Server 2008 R2

Registry information

To apply this hotfix, you do not have to make any changes to the registry.

Restart requirement

You must restart the computer after you apply this hotfix.

Hotfix replacement information

This hotfix does not replace a previously released hotfix.


Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

More Information

For more information about deferred index creation in Windows Server 2012, go to the following Microsoft sites:For more information about software update terminology, click the following article number to view the article in the Microsoft Knowledge Base:

824684 Description of the standard terminology that is used to describe Microsoft software updates