u/Altruistic_Use820

Im having this issue: I have since last year that my windows server 2025 DC keeps crashing/reboot after 2-5 days. I have a windows server 2019 dc and has no problem with it. The LSASS is causing this crash. When I check the handle count on both servers at the same time I get this for example server 2025 6.500.000 handles and growing around 3.700 per minute. And the 2019 windows server around 4.400 handles and barely moves.

Windows server has the update KB5091157 installed. OS built 26100.32698 DC, Global catalog and dns. Domain/forest functional level is win server 2016. Server is fully patched.

What has been tested and eliminated: Windows Server Backup disabled→ no change Windows Admin Center → not running -

PAM: NOT active (EnabledScopes empty) - 32k Pages feature: NOT active - Global Catalog: YES on Server 2025 - FSMO roles: PDC Emulator on Server 2019

What causes the crash: LSASS handle count grows continuously at ~3,700-4,200 handles/minute during the day. No specific workflow triggers it, it is a continuous steady leak from the moment the server starts.
Crash occurs when handle count reaches approximately 16,000,000 handles. Fresh after reboot: ~3,400 handles. Typical time to crash: 2-5 days
When fresh reboot the Server 2025 it starts around 3400 handle. I have done some testing and the handle growth continues at roughtly the same rate no matter what I try. Has anyone else running server 2025 as a domain controller seen continuous lsass handle growth like this or has a fix?

reddit.com
u/Altruistic_Use820 — 8 days ago

Im having this issue: I have since last year that my windows server 2025 DC keeps crashing/reboot after 2-5 days. I have a windows server 2019 dc and has no problem with it. The LSASS is causing this crash. When I check the handle count on both servers at the same time I get this: server 2025 6.500.000 handles and growing around 3.700 per minute. And the 2019 around 4.400 handles and barely moves.
Windows server has the update KB5091157 installed. OS built 26100 DC, Global catalog and dns. Domain/forest functional level is win server 2016

Crash patern: LSASS crash: 0xC0000005 access violation, Event ID: 1015, Crashes every 2–5 days, Started after july 2025, Before crash: Kerberos 0xc000009a errors Before crash: TLS Event ID 36871
When fresh reboot the Server 2025 it starts around 3400 handle., during work hours 3700-4200 handles per minute. I have done some testing and the handle growth continues at roughtly the same rate no matter what I try. Has anyone els running server 2025 as a domain controller seen continuous lsass handle growth like this or has a fix?

reddit.com
u/Altruistic_Use820 — 8 days ago