LATEST
Mon, Aug 31, 2026
Loading weather...
Technology

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off
Source: Computerworld

Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it will train users to ignore critical alerts, which makes them far more susceptible to attacks. The Microsoft release health dashboard update on the issue reported: “After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is functioning correctly and all settings show it as active. These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off. This issue can be observed in any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.” The post added: “We are working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.” It then listed the various Windows client and server versions impacted: everything from the current Windows 11, version 26H1 and Windows Server 2025 back to Windows 10 Enterprise LTSC 2016 and Windows Server 2012. Bad guidance Industry observers said the suggestion that users ignore these alerts is concerning. “Microsoft has just published guidance telling enterprises to ignore the exact signal that precedes a large share of ransomware detonations,” said Aman Mahapatra, chief strategy officer for technology consulting firm Tribeca Softtech, pointing out that disabling endpoint protection is standard tradecraft across virtually every ransomware affiliate playbook over the last five years. “The alert Microsoft is telling people to disregard is the same alert an operator triggers minutes before encryption starts,” he said. “That is a genuine security regression created by a bug advisory and the open-ended timeline on a fix makes it worse.” More disturbingly, he expects many security operations centers (SOCs) will create rules to suppress these alerts, which will make the problem even more severe. “When a signal fires constantly and is known to be false, human response degrades in days, not weeks,” Mahapatra said. “A SOC seeing hundreds of these across a Windows fleet will write a suppression rule by next week, because the alternative is drowning [in false alerts], and that rule will outlive the bug by months. Nobody goes back to remove filters that are keeping the queue clean.” Mahapatra also predicted that attackers will quickly leverage the bug to help in social engineering attacks.  “An attacker calling a help desk with ‘You’ll see Defender alerts on my machine, Microsoft says it’s the known bug, ignore it’ now has a corroborating vendor advisory backing the pretext,” Mahapatra said. “Help desks have been primed for exactly this issue. That is a working pretext with public documentation behind it, and it will get used.” Lane Thames, team lead for cybersecurity R&D at Fortra, amplified Mahapatra’s concerns. “IT teams need to be very careful about how they communicate this problem to users, and that communication should happen immediately,” Thames advised. “The message cannot simply be, ‘If Windows says Defender is turned off, ignore it.’ That is exactly the behavior we spend years teaching users not to adopt.” “The better message is that Microsoft is currently experiencing a known notification issue with Microsoft Defender, but users should continue reporting security warnings through the normal help desk or security channel,” he said. “IT should verify Defender’s actual state rather than asking users to make that determination, otherwise, when the next warning is real, users may have already been trained to ignore it.” This Microsoft alert “creates a perfect opportunity for a real attack to hide in the noise,” he added. Degradation of trust But Thames stressed that there is a bigger potential issue: degradation of trust. “Security notifications only work when users believe them. If Windows repeatedly tells someone that their antivirus is disabled when IT tells them that it isn’t, eventually one of those sources loses credibility, if not both,” he said. “Microsoft needs to resolve this quickly, because false security warnings have a large consequence: they degrade the trust that security controls depend on.” Tom Kellermann, VP of AI security and threat research at TrendAI, a division of TrendMicro, added that in the attacks his team has analyzed, roughly 67% leverage tampering with and disabling security software, something that is is usually a precursor to “a more systemic and intrusive campaign.” The Microsoft advisory’s wording “is a poor example of crisis communications” and is “ridiculous,” he said. “Do not trust that advice [to ignore the alert]. Verify if it’s accurate and involve your threat hunting teams,” who can examine XDR telemetry. Preserve the evidence Noah Kenney, principal consultant at Digital 520, advised CISOs and CIOs to save evidence of this situation to prove insurance claims that will likely initially be denied.  “Six months from now, an insurer looking at a breached server won’t accept ‘Microsoft said there was a bug’ as proof that Defender was running. The popup says off. Microsoft says on. The company’s own telemetry has to break the tie,” he said. “That means time-stamped records of sensor check-ins, Defender versions, and any gaps in reporting. CISOs should save those records now. The patch will make the warning disappear, but it will not recreate evidence if the company failed to retain it.” He noted that his greatest concern about the Microsoft alert is its wide impact on many Windows versions. “Windows 11 26H1 and Windows Server 2012 are fourteen years apart, and Microsoft says this bug can hit both,” he said. “Companies separate desktops, servers, legacy systems, and critical infrastructure into different patch rings, but Defender runs through all of them. The popup will get patched, but that shared failure path through the Windows estate will still be there, and a bad update can produce the same wrong security signal everywhere at once.”

Original reporting: ComputerworldRead original report →
Have feedback on this article?Report error or suggestion

Read More from Technology

I used AI to build Home Assistant automations I was too intimidated to write myself, and it worked

AI does a surprisingly good job at writing YAML.......

Read Article »

I tested iFi’s new DAC/amp and it’s a masterpiece, with impressive portable power, stellar sound quality, a fountain of features, and an intuitive OLED display

I tested iFi’s new iDSD GR 2 portable DAC/amp, and it's a phenomenal sequel, wit...

Read Article »

Cronos blockchain restarts after $74 million Tectonic exploit

The Cronos blockchain network has resumed trading activity after a price-manipul...

Read Article »
Return to Front Page

5 minutes. The news that matters.

Get the most important stories of the day, without having to browse hundreds of articles.