Microsoft Fixes False Windows Defender Antivirus Warnings After Recent Updates
Microsoft has fixed a known issue that caused Windows users to receive false warnings claiming that Microsoft Defender Antivirus was turned off after installing recent updates.
The fix is included in Microsoft Defender Antivirus version 4.18.26080.4, released on September 17, according to a Thursday update to Microsoft’s Windows Release Health Dashboard.
False Microsoft Defender warnings appeared even when protection was enabled
Microsoft acknowledged the bug in late August after users, including those in the Windows Insider Release Preview channel, reported seeing the alerts. Related reports indicated that the issue had been appearing in the Windows Insider program since at least June.
The problem affected all supported Windows client and server versions, including the latest Windows 11 26H1 and Windows Server 2025 releases. It triggered a false “Tap or click to turn on Microsoft Defender Antivirus” warning in the Windows Security app.
“After you install the latest updates for Microsoft Defender Antivirus, you may receive a notification that says ‘Microsoft Defender Antivirus is turned off’ even though the antivirus is working properly and is enabled in all settings,” Microsoft explained.
“These notifications may appear when Windows starts and intermittently thereafter. They will continue to appear even if your notification settings are turned off.”
Microsoft has fixed similar false Windows warnings before
This is not the first time Microsoft has asked customers to ignore false errors and warnings that appeared after installing a Windows update.
In April 2025, Microsoft addressed an issue that caused false BitLocker Drive Encryption errors on Windows 10 and Windows 11 devices. The company also fixed a bug that generated an invalid 0x80070643 failure error after users installed Windows Recovery Environment (WinRE) updates.
In July 2025, users were asked to ignore false Windows Firewall warnings that appeared after restarting their devices following installation of the June 2025 Preview Update.
A month later, Microsoft warned that the July 2025 Preview Update and the subsequent Windows 11 24H2 update were causing spurious CertificateServicesClient (CertEnroll) errors.
This week, Microsoft also released an emergency Windows update to fix issues affecting Remote Desktop Services, Hyper-V, and USB audio after installation of the September 2026 security update.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



