About domain Controller CPU Spikes from Unauthenticated LDAP Queries

Fited Zaheen 20 Reputation points
2026-09-30T06:10:37.2+00:00

Hello hope you could help.

The domain controller CPU usage spikes to 100% when unauthenticated LDAP queries scan the directory tree. This excessive directory search activity is causing high CPU utilization and impacting domain controller performance. I would like to enforce LDAP channel binding and signing to prevent insecure LDAP queries. What is the recommended approach and which settings should be reviewed before applying these changes?

Windows for business | Windows Server | Devices and deployment | Configure application groups
0 comments No comments

2 answers

Sort by: Most helpful
  1. Domic Vo 34,165 Reputation points Independent Advisor
    2026-09-30T07:23:58.27+00:00

    Hello,

    Since UDP 1812 is used for RADIUS authentication, the first step is to verify whether the VPN gateway is actually sending Access-Request packets and whether they reach the RADIUS server. Enable RADIUS debugging on the VPN device and capture traffic on both the VPN gateway and RADIUS server.

    If the requests leave the VPN appliance but never appear on the RADIUS server, the firewall or network path is blocking UDP/1812. Review firewall policies, NAT rules, and session logs for both UDP/1812 and UDP/1813 if RADIUS accounting is enabled.

    If you are using Microsoft NPS, check Event Viewer under Applications and Services Logs\Microsoft\Windows\NetworkPolicyandAccessServices and the Security log. If no authentication events are recorded during a login attempt, the requests are not reaching NPS.

    If NPS receives the request but rejects it, verify the RADIUS client definition, source IP address, and shared secret configuration. An incorrect shared secret or unregistered client will generate NPS authentication errors.

    A packet capture is usually the fastest way to identify the exact failure point. Trace the packet path and determine whether the Access-Request reaches the RADIUS server and whether the Access-Accept or Access-Reject response returns successfully to the VPN gateway.

    I hope you've found something useful here. If it helps you get more insight into the issue, it's appreciated to accept the answer. Should you have more questions, feel free to leave a message. Have a nice day!

    Domic Vo.

    Was this answer helpful?

    0 comments No comments

  2. AI answer

    2026-09-30T06:10:56.16+00:00

    The recommended approach is to harden the domain controllers by enforcing LDAP signing and reviewing LDAP channel binding before moving to stricter enforcement.

    1. Review the current hardening state on the domain controllers.
      • Check Domain controller: LDAP server signing requirements.
      • Check Domain controller: LDAP server channel binding token requirements.
      • Microsoft states that the March 10, 2020 updates and later updates do not automatically change the default LDAP signing or LDAP channel binding policies on new or existing domain controllers.
    2. Audit before enforcing.
      • Review Directory Service event log entries for LDAP signing:
        • 2886: server is not enforcing LDAP signing.
        • 2887: unprotected binds were accepted.
        • 2888: unprotected binds were rejected after Require Signing is enabled.
        • 2889: identifies clients that do not use signing on port 389 when higher logging is enabled.
      • Review LDAP channel binding audit events:
        • 3039, 3040, 3041 for CBT-related activity.
        • On Windows Server 2022, the August 8, 2023 update also added audit events 3074 and 3075 for clients that cannot use LDAP channel binding tokens.
    3. Start with a compatibility-focused channel binding configuration.
      • If using the LdapEnforceChannelBinding registry entry, Microsoft recommends value 1 to maximize compatibility with older operating system versions.
      • Value 0 explicitly disables the setting.
      • The LDAP server responds dynamically to changes to this registry entry, so a restart is not required after applying the registry change.
      • Risk: on Windows Server 2008 and older systems, required prerequisite protection must be installed first; otherwise LDAPS connections can fail with LDAP error 81 - LDAP_SERVER_DOWN.
    4. Identify and reduce the LDAP workload that is driving CPU spikes.
      • Run Active Directory Diagnostics in Performance Monitor while the issue is occurring:
        • Open Server Manager or run Perfmon.msc.
        • Go to Diagnostics > Reliability and Performance > Data Collector Sets > System.
        • Start Active Directory Diagnostics.
        • After collection and report compilation, review Reports > System > Active Directory Diagnostics.
      • In the report, check:
        • Diagnostic Results for general performance concerns.
        • Active Directory for what the domain controller is busy doing, including LDAP queries affecting performance.
        • Network to identify remote clients communicating most with the domain controller.
    5. Review query behavior before assuming policy enforcement alone will solve the CPU issue.
      • Focus on top calling clients and identify the source of excessive LDAP workload.
      • Verify clients are using site-optimal domain controllers.
      • Work with application owners to reduce query frequency and use caching.
      • Optimize LDAP query syntax, reduce returned attributes, and narrow the search base.
      • Add Active Directory attribute indexes only when required, noting that this increases database size and can temporarily delay replication during index build.

    In practice, the safest sequence is:

    • audit current unsigned and CBT-incompatible clients,
    • identify the systems generating excessive LDAP searches,
    • remediate or reconfigure those clients and applications,
    • then enforce LDAP server signing requirements and tighten LDAP server channel binding token requirements.

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.