Updated: October 2026
The fan is loud, the laptop is slow, and Task Manager shows the CPU pinned at 100%. Ending the top process makes the ticket go away until tomorrow. Here's how to lower CPU usage in a way that sticks: find the process, fix the cause, then set the policy that stops it coming back.
Find the Process Before You Fix Anything
A short spike is normal. Opening an app, installing an update or starting a scan pushes the CPU up for a few seconds. Microsoft's own troubleshooting guidance draws the line at usage that stays at 80% or higher for extended periods. Below that, you're looking at a busy PC, not a broken one.
Start with Task Manager. Sort the Processes tab by the CPU column and note the top name. Then open Resource Monitor (resmon), go to the CPU tab and sort by Average CPU. Task Manager shows the current moment. Resource Monitor's average shows what has been busy for the last minute, and that's the number worth acting on.
When the top line is a container, like System or svchost.exe, reach for Process Explorer from Sysinternals. Open the process properties, go to the Threads tab and look at which thread is busy and what it's running. That's how you tell a driver from a service from a scan.
On a remote PC, PowerShell gets you the top five without a session:
powershellGet-Counter '\Process(*)\% Processor Time' -SampleInterval 5 -MaxSamples 3 | ForEach-Object { $_.CounterSamples | Where-Object InstanceName -notin '_total','idle' | Sort-Object CookedValue -Descending | Select-Object -First 5 InstanceName, @{n='CPU%';e={[math]::Round($_.CookedValue / $env:NUMBER_OF_PROCESSORS, 1)}} }
The per-process counter adds up across cores, so one process on an 8-core machine can read 400%. Dividing by the core count puts it back on roughly the same scale as Task Manager.
Darien's Tips walks through Process Explorer, the Sysinternals tool Microsoft points to for this job.
The Usual Culprits and the Fix for Each
Once you have a name, the fix depends on what owns it. Each row pairs the fix for today with the policy that stops the repeat.
| Process | What it is | Fix today | Policy so it doesn't return |
|---|---|---|---|
| MsMpEng.exe (Antimalware Service Executable) | Microsoft Defender scanning | Let the scan finish, check what it's scanning | Cap scan CPU, schedule scans off-hours, add tested exclusions |
| TiWorker.exe (Windows Modules Installer Worker) | Windows Update installing | Let it finish, then reboot | Active hours and a patch window outside the workday |
| SearchIndexer.exe | Windows Search building its index | Pause indexing or rebuild a corrupt index | Classic indexing instead of Enhanced |
| chrome.exe, msedge.exe | Tabs and extensions | Find the heavy tab with the browser's own task manager (Shift+Esc) | Extension allowlist, sleeping tabs |
| svchost.exe | A group of Windows services | Split the group to find the service | Fix or disable that service |
| System interrupts | Hardware interrupts and drivers | Update the driver, unplug devices one at a time | Driver and firmware baseline |
| Unknown name at 100% on every core | Possibly a cryptominer | Isolate the device and scan it | Application allowlisting |
For svchost, Microsoft's method is to break each service into its own process with sc config <service> type= own, then watch which one stays busy. Our svchost.exe guide walks through it, including how to spot a fake one.
For browsers, one runaway tab can hold a core by itself. The Chrome memory guide covers the fleet-side settings, and they help CPU as much as RAM.
Windows Search has two modes under Settings, Privacy & security, Search. Microsoft describes Enhanced as indexing the entire PC, which "may use more system resources". Classic covers Documents, Pictures, Music and the desktop, and that's enough for a typical office user.
Defender: Cap the Scan, Then Check for a Loop
Defender's scheduled scans already have a limit. The ScanAvgCPULoadFactor setting defaults to 50, so a scan aims to average no more than half the CPU. Microsoft calls it guidance for the engine, not a hard limit. By default it applies to scheduled scans only, so a custom scan started from a console runs without it. On older hardware, lower the cap and run scans at low priority:
powershellSet-MpPreference -ScanAvgCPULoadFactor 30 -EnableLowCpuPriority $true
When Defender stays busy outside a scan, that's a different problem. In this r/sysadmin thread from October 2024, MsMpEng used 30-60% CPU on IIS servers for weeks. Microsoft's product group eventually traced it to network inspection activity.
To see what Defender is spending its time on, record it. Run New-MpPerformanceRecording -RecordTo C:\temp\defender.etl, reproduce the slowdown, press Enter, then run Get-MpPerformanceReport -Path C:\temp\defender.etl -TopFiles 10. The report lists the files, paths and processes that cost the most scan time. Exclude only what you've confirmed is safe.
When It's Heat or Power, Not a Process
Sometimes nothing is misbehaving. The CPU is running slow, so ordinary work fills it. Open Task Manager's Performance tab, select CPU and compare Speed with Base speed while the machine is busy. A CPU that sits far below its base speed under load is being held back by heat or a power limit.
That's what one admin found in April 2025 after moving Lenovo laptops to Windows 11 24H2. A power plan pushed through Intune or GPO left Lenovo's thermal service without the Windows 11 power setting it reads. The laptops capped themselves at about 10 W and 500-700 MHz, and removing the policy fixed it.
The lesson carries past Lenovo: test a power plan policy on each hardware model before you push it. Run powercfg /getactivescheme to see which plan is live. Then check the physical side. Blocked vents, a failing fan or dried thermal paste all end in the same throttled clock.
Stop It Coming Back With Fleet Monitoring
The hardest version of this ticket is the one you can't reproduce. The user says the PC sat at 100% all afternoon. You connect, and it's idle.
Monitoring fixes that, as long as it alerts on the right thing. Alert on sustained load, not spikes, with Microsoft's 80% line as the floor. A workable starting point for endpoints:
- Trigger at 90% or more for 15 minutes, not on a single sample.
- Capture the top five processes when the alert fires, so the ticket arrives with a name in it.
- Auto-close the alert if usage drops back, and keep the record.
- Review the devices that trip it every week. A repeat offender is either a policy gap or an upgrade conversation.
Then roll the fixes out as policy, not one PC at a time: Defender scan limits, update windows, Classic indexing, a browser extension allowlist and a trimmed startup list. Our guide to debloating Windows 11 covers the startup and preinstalled-app side.
OpenFrame can run the Get-Counter snapshot above as a script across a client's devices and collect the output, so "it was slow yesterday" comes with a list of process names.
The Short Version
To lower CPU usage, find the process first: Task Manager for the name, Resource Monitor for the average, Process Explorer when the name is a container. Fix the cause, whether it's a scan, an update, the indexer, a browser, a service or a driver. If nothing is misbehaving, compare the clock speed with the base speed to catch heat and power limits. Then turn the fix into policy and alert on sustained load, so the next one arrives with the process name attached.
If the busy process turns out to be svchost.exe, the svchost guide linked above is the next read.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
