Microsoft is telling customers to sit tight and ignore Defender Antivirus false alerts that incorrectly report the antivirus has been switched off, following the installation of recent Defender updates. The alerts are wrong: the antivirus is running fine. Microsoft says a fix is coming, but hasn’t said when.

The erroneous notifications surface in the Windows Security app and prompt users to ‘Tap or click to turn on Microsoft Defender Antivirus.’ According to Microsoft’s Friday release health dashboard update, the alerts can appear when Windows starts and may recur intermittently throughout a session. They persist even when notification settings are turned off, which makes them particularly awkward to manage.

‘After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that “Microsoft Defender Antivirus is turned off,” even though the antivirus is functioning correctly and all settings show it as active,’ Microsoft explained in the dashboard post.

Who is affected by the Defender Antivirus false alerts

The known issue covers all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025. That is a broad scope: this is not a niche preview build problem. The issue has, in fact, been affecting users in the Release Preview Channel of the Windows Insider programme since June, though Microsoft appears not to have caught it until now.

Microsoft says it is working on a resolution and will push it out in a future Microsoft Defender Antivirus update. No timeline has been given.

The suppression rule problem that could make things worse

Here is where it gets more involved. Computerworld reports that security experts predict security operations centres (SOCs) will respond to the noise by creating rules to suppress these alerts altogether. The concern is that once those suppression rules are in place, a genuine Defender outage could go unnoticed, buried under the same rule that was set up to quiet the false positives. It is a well-worn pattern in security operations: a noisy false alarm trains teams to mute the alarm class, and the real event then slips through.

Microsoft’s advice to end users is simply to ignore the prompts for now. That is reasonable guidance for a home user who knows the context. For a managed enterprise environment, though, the calculus is different, and the suppression-rule concern is a practical one worth considering before any SOC automation is adjusted.

A recurring pattern of post-update false errors

This is not the first time Microsoft has been in the position of asking users to disregard alerts that its own updates caused. The pattern has become familiar enough over 2025 to merit a brief recap.

In April, Microsoft confirmed and subsequently fixed a bug that produced invalid 0x80070643 failure errors after installation of the April 2025 Windows Recovery Environment (WinRE) updates. Around the same time, an issue was generating incorrect BitLocker drive encryption errors on Windows 10 and Windows 11 devices.

July 2025 brought another round, when users were asked to disregard erroneous Windows Firewall alerts appearing after reboots following the June 2025 preview update. Then, a month later, Microsoft flagged that the July 2025 preview update and subsequent Windows 11 24H2 updates were triggering incorrect CertificateServicesClient (CertEnroll) errors.

None of those incidents involved a genuine security failure, but each required Microsoft to issue public guidance telling users to stand down. The cumulative effect is a degree of alert fatigue that is, to put it mildly, not ideal for a security product.

Microsoft has not confirmed a specific release date for the Defender fix. Until it arrives, Windows Security app warnings about Defender being off can be treated as a known issue, with the caveat that any SOC rules drafted in response to this episode should be scoped carefully and reviewed once the patch lands.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version