Microsoft has confirmed a widespread Windows issue that is causing users to receive alarming notifications claiming that Microsoft Defender Antivirus has been turned off, even though the security software remains active and continues protecting the system normally.
The problem appeared after recent Microsoft Defender Antivirus updates and affects a broad range of Windows client and server releases. Microsoft says the notifications are incorrect and that users whose Defender settings continue to show the antivirus as active can disregard the warning while the company prepares a permanent fix.
Defender remains active despite the warningAffected users may see Windows Security display a notification telling them that Microsoft Defender Antivirus is disabled and prompting them to turn it back on. The alert can appear during Windows startup and then return intermittently while the computer is running.
More confusingly, disabling notifications does not necessarily stop the message from appearing.
Microsoft’s investigation has determined that this is a notification problem rather than an actual antivirus shutdown. Defender continues operating correctly, and its settings report that protection remains enabled. Microsoft therefore is not advising users to reinstall Defender, modify security policies or attempt complicated workarounds.
The issue had reportedly been affecting systems in the Windows Insider Release Preview Channel since June, but Microsoft formally acknowledged the broader problem at the end of August.
The bug affects Windows 10, Windows 11 and Windows ServerThis is not limited to a particular Windows 11 release. Microsoft says the incorrect notification can occur on any supported Windows or Windows Server installation running Microsoft Defender Antivirus with the latest Defender updates.
The affected client platforms include Windows 11 versions 26H1, 25H2, 24H2 and 23H2, as well as Windows 10 22H2, 21H2 and Enterprise LTSC releases. Windows Server versions from Server 2012 through Server 2025 are also listed as affected.
That broad scope makes sense because Defender’s security intelligence and platform components receive updates independently of the larger Windows cumulative update cycle. A problem introduced through Defender’s update mechanism can therefore propagate across multiple generations of Windows.
False security warnings create their own security problemTechnically, this appears to be a relatively minor software defect: the antivirus works, but Windows incorrectly reports that it does not.
Operationally, however, false security warnings can be surprisingly damaging.
Security notifications are deliberately designed to attract attention. When Windows tells someone that antivirus protection has been disabled, the expected response is immediate concern. If users repeatedly receive warnings that turn out to be meaningless, they may gradually become accustomed to ignoring them.
That creates an alert-fatigue problem. A future warning indicating that Defender genuinely has stopped working could receive less attention because users have learned that similar notifications cannot necessarily be trusted.
For corporate IT teams, the issue can also generate unnecessary support requests. Employees receiving an antivirus warning may contact the help desk, while administrators have to determine whether each report represents an actual endpoint protection failure or merely Microsoft’s known notification bug.
Microsoft has dealt with similar false alarms beforeThe Defender incident is not the first recent example of Windows displaying misleading warnings following an update.
In April 2025, Microsoft addressed incorrect0x80070643failure messages associated with Windows Recovery Environment updates and also dealt with erroneous BitLocker encryption warnings. Later that year, Windows users were told to disregard incorrect Windows Firewall alerts appearing after certain updates, followed by erroneous CertificateServicesClient errors affecting Windows 11 24H2.
Individually, these problems are relatively small compared with vulnerabilities or system crashes. Collectively, however, they highlight the difficulty of maintaining reliable status reporting across an operating system composed of numerous independently updated security and management components.
Security software presents an especially sensitive case because the user interface is supposed to provide an authoritative answer to a simple question:Is my computer protected?
When the interface and the underlying security engine disagree, even a harmless bug can undermine that confidence.
A fix will arrive through a future Defender updateMicrosoft says it is developing a resolution and plans to distribute it through a future Microsoft Defender Antivirus update. The company has not announced a specific release date.
Until then, affected users do not need to disable Defender, reinstall Windows or install another antivirus product simply because this particular notification appears. The important distinction is whether Windows Security continues to show Defender’s protection components as active.
The incident ultimately demonstrates that security depends not only on whether defensive software functions correctly, but also on whether users can trust what that software tells them. Microsoft Defender may still be protecting affected computers, but a security warning that incorrectly tells millions of users otherwise is more than a cosmetic inconvenience—it weakens the reliability of the security interface itself.
Original report at BleepingComputer