Virtual Machine CPU: Recurring 100% Usage at Noon — Investigation and Troubleshooting Guidance

Jim-2564 0 Reputation points
2026-10-07T17:53:11.67+00:00

Problem description

I am experiencing a recurring issue with my Azure virtual machine running Windows in the Central US region. For the past two days, around 12 pm Central Time, the VM's CPU usage spikes to 100%, causing it to become unresponsive. The high CPU usage persists during these periods, and I observe that Windows Defender seems to be the abnormal process consuming the most CPU. The VM is hosting Remote Desktop Services and SQL Server. Despite efforts, I am unable to determine the exact trigger for these spikes and want guidance on troubleshooting and resolving the issue.

Environment

Azure Windows virtual machine in Central US, hosting Remote Desktop Services and SQL Server.

What I've already tried

I have used monitoring tools to confirm the high CPU condition, checked the responsible process (Windows Defender), reviewed health notifications and logs, and noted a VM restart on 2026-10-05. I attempted to run diagnostic scripts inside the VM, but the server's slow performance prevents effective execution. I have not made any configuration changes or applied exclusions yet.

Current status

I am seeking assistance to identify the root cause of the recurring CPU spikes around noon, verify if Windows Defender or other processes are involved, and receive recommended troubleshooting steps to resolve the issue.

Azure Virtual Machines
Azure Virtual Machines

An Azure service that is used to provision Windows and Linux virtual machines.


1 answer

Sort by: Most helpful
  1. Atif Naseem Ahmed 160 Reputation points
    2026-10-07T22:52:32.42+00:00

    Hi Jim,

    A spike at the same time every day, with Windows Defender as the top process, usually means a scheduled Defender scan is running across a busy SQL Server and RDS host with no exclusions. Here's how to confirm it and fix it.

    1. Run commands without RDP

    Because the VM is unresponsive during the spike, use Run command > RunPowerShellScript on the VM in the Azure portal (or the Serial Console) for the checks below.

    2. Confirm the scan schedule

    Get-TimeZone
    Get-MpPreference | Select-Object ScanScheduleDay, ScanScheduleTime, ScanScheduleQuickScanTime, ScanParameters, ScanAvgCPULoadFactor, RandomizeScheduleTaskTimes
    Get-MpComputerStatus | Select-Object QuickScanStartTime, FullScanStartTime
    

    Azure VMs use UTC by default, so 12 PM Central would show as 17:00 in the VM's clock. You can also open Event Viewer at Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational and look for event 1000 (scan started) and 1001 (scan finished) around that time.

    3. Move the scan to off-hours

    Set-MpPreference -ScanScheduleDay Everyday -ScanScheduleTime 02:00:00 -ScanParameters 1
    

    ScanParameters 1 makes it a quick scan instead of a full scan. If Defender is managed by Intune, Group Policy, or Microsoft Defender for Endpoint, change the schedule there, because local settings will be overwritten.

    4. Add the recommended SQL Server exclusions

    Scanning live database and backup files is a very common cause of high CPU. Microsoft's guidance is in Configure antivirus software to work with SQL Server. For example:

    Add-MpPreference -ExclusionExtension ".mdf", ".ndf", ".ldf", ".bak", ".trn"
    Add-MpPreference -ExclusionProcess "C:\Program Files\Microsoft SQL Server\MSSQL16.MSSQLSERVER\MSSQL\Binn\sqlservr.exe"
    

    Change the path to match your SQL Server version and instance name. If you use FSLogix profile containers for RDS, exclude those .vhd/.vhdx files too.

    5. Limit how much CPU scans can use

    Set-MpPreference -ScanAvgCPULoadFactor 30 -EnableLowCpuPriority $true
    

    This applies to scheduled scans only, not real-time protection.

    6. Check the VM size

    If it's a B-series (burstable) VM, check the CPU Credits Remaining metric in the portal. If credits run out, the VM is throttled and a daily scan can push it over the edge. Running RDS and SQL Server on the same VM is also heavy, so consider a larger size if CPU stays high after the changes above.

    If the spike continues after moving the scan, share the output from step 2 and the Defender events from that time window, and we can dig further.

    If this answer helps, please click "Accept Answer" so others with the same issue can find it.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.