News

Windows Bug Falsely Reports Microsoft Defender Antivirus Is Turned Off

6 min read Editorial

Microsoft confirmed Friday that a glitch is making Windows falsely report that Microsoft Defender Antivirus is turned off — even when the antivirus is running normally and every setting shows it as active. The vendor says it is working on a fix, but security experts warn that the advisory attached to the bug could do more harm than the glitch itself.

Status at a glance

  • Issue: Windows displays a false ‘Microsoft Defender Antivirus is turned off’ notification while the antivirus is actually functioning.
  • Status: Investigating. Microsoft says it is working to release a resolution in a future Microsoft Defender Antivirus update.
  • Affected versions: Windows 11 (version 26H1), Windows Server 2025, Windows 10 Enterprise LTSC 2016, and Windows Server 2012.
  • KB / error code: None published yet.

According to the Microsoft release health dashboard, the false alert shows up after the latest Defender Antivirus updates are installed. The notification can appear when Windows starts and then pop up intermittently afterward, and it keeps showing even if you turn off your notification settings. Microsoft notes it can be observed in any version of Windows or Windows Server running Defender Antivirus with the latest updates.

A close-up of a computer monitor showing the Windows Security app window with the Microsoft Defender Antivirus protectio
The Windows Security app still shows Defender protection as active despite the false popup.

What Microsoft says

The vendor’s status page is straightforward about the current state of play. After describing the false ‘turned off’ message, Microsoft wrote that it is ‘working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.’ In other words, there is no patch today, and no firm date for one.

Advertisement

The affected list is unusually broad. Microsoft says the glitch can hit everything from the newest Windows 11, version 26H1, and Windows Server 2025 all the way back to Windows 10 Enterprise LTSC 2016 and Windows Server 2012 — a span of roughly fourteen years of operating systems sharing one code path.

Why security experts are alarmed

The immediate technical annoyance is small. The bigger worry, according to consultants, is what this trains people to do: ignore a critical signal.

‘Microsoft has just published guidance telling enterprises to ignore the exact signal that precedes a large share of ransomware detonations,’ said Aman Mahapatra, chief strategy officer at technology consulting firm Tribeca Softtech. He pointed out that disabling endpoint protection is standard tradecraft in nearly every ransomware affiliate playbook over the past five years.

‘The alert Microsoft is telling people to disregard is the same alert an operator triggers minutes before encryption starts,’ Mahapatra said. ‘That is a genuine security regression created by a bug advisory and the open-ended timeline on a fix makes it worse.’

He also expects the problem to compound inside enterprise security teams. ‘When a signal fires constantly and is known to be false, human response degrades in days, not weeks,’ he said, predicting that many security operations centers (SOCs) will write suppression rules within a week to stop the alert noise — and those rules will outlive the bug by months.

A security operations center with multiple monitors displaying red alerts and dashboards, the silhouette of an analyst w
SOC teams may add suppression rules for the false alerts, risking longer-term blind spots.

The degradation of trust problem

Lane Thames, team lead for cybersecurity R&D at Fortra, said IT leaders need to be deliberate about how they communicate this to users, and they need to do it fast.

‘The message cannot simply be, “If Windows says Defender is turned off, ignore it,”‘ Thames said. ‘That is exactly the behavior we spend years teaching users not to adopt.’ He suggested a better framing: Microsoft is aware of a known notification issue, but users should keep reporting security warnings through the normal help desk or security channel, and IT should verify Defender’s actual state itself.

Thames warned that false warnings erode the trust that security controls depend on. ‘Security notifications only work when users believe them,’ he said. ‘If Windows repeatedly tells someone that their antivirus is disabled when IT tells them that it isn’t, eventually one of those sources loses credibility, if not both.’

Tom Kellermann, VP of AI security and threat research at TrendAI, a division of TrendMicro, added that in attacks his team has analyzed, roughly 67% involve tampering with or disabling security software — usually a precursor to a broader, more intrusive campaign. He called Microsoft’s advisory wording ‘a poor example of crisis communications’ and urged people to verify rather than blindly follow the ‘ignore it’ guidance, involving threat hunting teams who can examine XDR telemetry.

Preserve evidence before it’s too late

Noah Kenney, principal consultant at Digital 520, advised CISOs and CIOs to start saving records now, in case a breach claim later hinges on whether Defender was actually running.

‘Six months from now, an insurer looking at a breached server won’t accept “Microsoft said there was a bug” as proof that Defender was running,’ he said. ‘The popup says off. Microsoft says on. The company’s own telemetry has to break the tie.’ He recommended time-stamped sensor check-in records, Defender versions, and any reporting gaps. The eventual patch will make the warning disappear, but it won’t recreate evidence a company failed to retain.

Kenney also flagged the breadth of the affected list as a structural risk. ‘Windows 11 26H1 and Windows Server 2012 are fourteen years apart, and Microsoft says this bug can hit both,’ he said, noting that companies typically separate desktops, servers, legacy systems, and critical infrastructure into different patch rings — yet Defender runs through all of them. A bad update, he warned, can produce the same wrong security signal everywhere at once.

What this means for you

For most home users, the practical takeaway is simple: if you see a ‘Microsoft Defender Antivirus is turned off’ popup, don’t panic and don’t act on it. Your protection is almost certainly still active. But do not let this become a habit of ignoring security warnings altogether.

The real risk shows up on shared or work machines. If an attacker ever calls your help desk claiming the alert is ‘the known Microsoft bug,’ treat that as a red flag rather than a free pass — the public advisory gives a pretext, but it doesn’t prove anything about your specific machine.

How to check and what to do

Until Microsoft ships a fix, here’s how to keep yourself informed without being misled:

  • Open the Windows Security app and check the Antivirus section directly. If Defender shows as active and protection is on, your real state is fine regardless of any popup.
  • Don’t disable or reconfigure Defender based on the false alert — that would leave you genuinely exposed.
  • Enterprises and IT teams should verify Defender’s actual state from the management side (Intune, Group Policy, or your EDR/XDR tooling) rather than asking end users to judge it.
  • SOC teams should be cautious about adding suppression rules, and if you do, set a reminder to remove them once Microsoft’s resolution lands.
  • Consider retaining Defender telemetry and check-in records now, especially if you carry cyber insurance that may question a future claim.

Microsoft says it will update the release health dashboard when more information is available. Until then, the safest posture is to trust the Windows Security app over the popup — and to keep teaching yourself and your teams to treat security warnings as worth a second look, not a shrug.

Source: Computerworld

Over to you: If you saw the ‘Defender is turned off’ popup on your machine, would you trust the Windows Security app over it — or dig into your Defender settings first?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement