An Azure service that is used to provision Windows and Linux virtual machines.
Hi Jim,
A spike at the same time every day, with Windows Defender as the top process, usually means a scheduled Defender scan is running across a busy SQL Server and RDS host with no exclusions. Here's how to confirm it and fix it.
1. Run commands without RDP
Because the VM is unresponsive during the spike, use Run command > RunPowerShellScript on the VM in the Azure portal (or the Serial Console) for the checks below.
2. Confirm the scan schedule
Get-TimeZone
Get-MpPreference | Select-Object ScanScheduleDay, ScanScheduleTime, ScanScheduleQuickScanTime, ScanParameters, ScanAvgCPULoadFactor, RandomizeScheduleTaskTimes
Get-MpComputerStatus | Select-Object QuickScanStartTime, FullScanStartTime
Azure VMs use UTC by default, so 12 PM Central would show as 17:00 in the VM's clock. You can also open Event Viewer at Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational and look for event 1000 (scan started) and 1001 (scan finished) around that time.
3. Move the scan to off-hours
Set-MpPreference -ScanScheduleDay Everyday -ScanScheduleTime 02:00:00 -ScanParameters 1
ScanParameters 1 makes it a quick scan instead of a full scan. If Defender is managed by Intune, Group Policy, or Microsoft Defender for Endpoint, change the schedule there, because local settings will be overwritten.
4. Add the recommended SQL Server exclusions
Scanning live database and backup files is a very common cause of high CPU. Microsoft's guidance is in Configure antivirus software to work with SQL Server. For example:
Add-MpPreference -ExclusionExtension ".mdf", ".ndf", ".ldf", ".bak", ".trn"
Add-MpPreference -ExclusionProcess "C:\Program Files\Microsoft SQL Server\MSSQL16.MSSQLSERVER\MSSQL\Binn\sqlservr.exe"
Change the path to match your SQL Server version and instance name. If you use FSLogix profile containers for RDS, exclude those .vhd/.vhdx files too.
5. Limit how much CPU scans can use
Set-MpPreference -ScanAvgCPULoadFactor 30 -EnableLowCpuPriority $true
This applies to scheduled scans only, not real-time protection.
6. Check the VM size
If it's a B-series (burstable) VM, check the CPU Credits Remaining metric in the portal. If credits run out, the VM is throttled and a daily scan can push it over the edge. Running RDS and SQL Server on the same VM is also heavy, so consider a larger size if CPU stays high after the changes above.
If the spike continues after moving the scan, share the output from step 2 and the Defender events from that time window, and we can dig further.
If this answer helps, please click "Accept Answer" so others with the same issue can find it.