Microsoft Defender falsely warns that antivirus protection is turned off
Microsoft is asking customers to ignore a false Windows Security warning claiming that Microsoft Defender Antivirus is turned off after installing the latest Defender update.
The issue has affected users in the Windows Insider program, including systems running builds from the Release Preview Channel. Reports of the problem have been circulating since June, although Microsoft only recently acknowledged it.
The false notification appears in the Windows Security app and asks users to “tap or click to turn on Microsoft Defender Antivirus,” even though Defender is enabled and protecting the device.
According to Microsoft, the known issue affects all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025.
“After you install the latest updates for Microsoft Defender Antivirus, you may receive a notification that says ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is working properly and is enabled in all settings,” Microsoft explains in an update to its Windows release health dashboard.
“These notifications may appear when Windows starts and intermittently thereafter. They will continue to appear even if your notification settings are turned off.”
Microsoft says it is working on a fix that will be delivered through a future Microsoft Defender Antivirus update. Until then, users can safely disregard the warning if Microsoft Defender is enabled in the Windows Security app.
This is not the first time Microsoft has asked customers to ignore inaccurate security alerts or error messages caused by Windows updates.
In April, Microsoft identified and fixed a bug that generated an invalid 0x80070643 error after users installed the April 2025 Windows Recovery Environment (WinRE) update. The company also addressed false BitLocker Drive Encryption errors affecting Windows 10 and Windows 11 devices.
In July 2025, Microsoft asked users to ignore false Windows Firewall warnings that appeared after rebooting systems with the June 2025 Preview Update installed.
A month later, Microsoft confirmed that the July 2025 Preview Update and the subsequent Windows 11 24H2 update were generating false CertificateServicesClient (CertEnroll) errors.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




