{"id":9262,"date":"2026-08-31T20:19:16","date_gmt":"2026-08-31T20:19:16","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9262"},"modified":"2026-08-31T20:19:16","modified_gmt":"2026-08-31T20:19:16","slug":"windows-bug-incorrectly-tells-users-that-microsoft-defender-antivirus-is-turned-off","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9262","title":{"rendered":"Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix.<\/p>\n<p class=\"wp-block-paragraph\">Consultants say that this advisory raises a major concern in that it will train users to ignore critical alerts, which makes them far more susceptible to attacks.<\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/learn.microsoft.com\/en-au\/windows\/release-health\/status-windows-11-25h2#incorrect-notifications-that--microsoft-defender-antivirus-is-turned-off-\" target=\"_blank\" rel=\"noopener\">Microsoft release health dashboard<\/a> update on the issue reported: \u201cAfter installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that \u2018Microsoft Defender Antivirus is turned off\u2019 even though the antivirus is functioning correctly and all settings show it as active. These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off. This issue can be observed in any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The post added: \u201cWe are working to release a resolution in a future Microsoft Defender Antivirus update and will provide more information when it is available.\u201d<\/p>\n<p class=\"wp-block-paragraph\">It then listed the various Windows client and server versions impacted: everything from the current Windows 11, version 26H1 and Windows Server 2025 back to Windows 10 Enterprise LTSC 2016 and Windows Server 2012.<\/p>\n<h2 class=\"wp-block-heading\">Bad guidance<\/h2>\n<p class=\"wp-block-paragraph\">Industry observers said the suggestion that users ignore these alerts is concerning.<\/p>\n<p class=\"wp-block-paragraph\">\u201cMicrosoft has just published guidance telling enterprises to ignore the exact signal that precedes a large share of ransomware detonations,\u201d said <a href=\"https:\/\/www.linkedin.com\/in\/akm76\/\" target=\"_blank\" rel=\"noopener\">Aman Mahapatra<\/a>, chief strategy officer for technology consulting firm Tribeca Softtech, pointing out that disabling endpoint protection is standard tradecraft across virtually every ransomware affiliate playbook over the last five years. <\/p>\n<p class=\"wp-block-paragraph\">\u201cThe alert Microsoft is telling people to disregard is the same alert an operator triggers minutes before encryption starts,\u201d he said. \u201cThat is a genuine security regression created by a bug advisory and the open-ended timeline on a fix makes it worse.\u201d<\/p>\n<p class=\"wp-block-paragraph\">More disturbingly, he expects many security operations centers (SOCs) will create rules to suppress these alerts, which will make the problem even more severe.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen a signal fires constantly and is known to be false, human response degrades in days, not weeks,\u201d Mahapatra said. \u201cA SOC seeing hundreds of these across a Windows fleet will write a suppression rule by next week, because the alternative is drowning [in false alerts], and that rule will outlive the bug by months. Nobody goes back to remove filters that are keeping the queue clean.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Mahapatra also predicted that attackers will quickly leverage the bug to help in social engineering attacks.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cAn attacker calling a help desk with \u2018You\u2019ll see Defender alerts on my machine, Microsoft says it\u2019s the known bug, ignore it\u2019 now has a corroborating vendor advisory backing the pretext,\u201d Mahapatra said. \u201cHelp desks have been primed for exactly this issue. That is a working pretext with public documentation behind it, and it will get used.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/lanethames\/\" target=\"_blank\" rel=\"noopener\">Lane Thames<\/a>, team lead for cybersecurity R&amp;D at Fortra, amplified Mahapatra\u2019s concerns.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIT teams need to be very careful about how they communicate this problem to users, and that communication should happen immediately,\u201d Thames advised. \u201cThe message cannot simply be, \u2018If Windows says Defender is turned off, ignore it.\u2019 That is exactly the behavior we spend years teaching users not to adopt.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe better message is that Microsoft is currently experiencing a known notification issue with Microsoft Defender, but users should continue reporting security warnings through the normal help desk or security channel,\u201d he said. \u201cIT should verify Defender\u2019s actual state rather than asking users to make that determination, otherwise, when the next warning is real, users may have already been trained to ignore it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">This Microsoft alert \u201ccreates a perfect opportunity for a real attack to hide in the noise,\u201d he added.<\/p>\n<h2 class=\"wp-block-heading\">Degradation of trust<\/h2>\n<p class=\"wp-block-paragraph\">But Thames stressed that there is a bigger potential issue: degradation of trust.<\/p>\n<p class=\"wp-block-paragraph\">\u201cSecurity notifications only work when users believe them. If Windows repeatedly tells someone that their antivirus is disabled when IT tells them that it isn\u2019t, eventually one of those sources loses credibility, if not both,\u201d he said. \u201cMicrosoft needs to resolve this quickly, because false security warnings have a large consequence: they degrade the trust that security controls depend on.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/tomkellermann\/\" target=\"_blank\" rel=\"noopener\">Tom Kellermann<\/a>, VP of AI security and threat research at TrendAI, a division of TrendMicro, added that in the attacks his team has analyzed, roughly 67% leverage tampering with and disabling security software, something that is is usually a precursor to \u201ca more systemic and intrusive campaign.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The Microsoft advisory\u2019s wording \u201cis a poor example of crisis communications\u201d and is \u201cridiculous,\u201d he said. \u201cDo not trust that advice [to ignore the alert]. Verify if it\u2019s accurate and involve your threat hunting teams,\u201d who can examine XDR telemetry.<\/p>\n<h2 class=\"wp-block-heading\">Preserve the evidence<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/noah-m-kenney-27499a166\/\" target=\"_blank\" rel=\"noopener\">Noah Kenney<\/a>, principal consultant at Digital 520, advised CISOs and CIOs to save evidence of this situation to prove insurance claims that will likely initially be denied.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cSix months from now, an insurer looking at a breached server won\u2019t accept \u2018Microsoft said there was a bug\u2019 as proof that Defender was running. The popup says off. Microsoft says on. The company\u2019s own telemetry has to break the tie,\u201d he said. \u201cThat means time-stamped records of sensor check-ins, Defender versions, and any gaps in reporting. CISOs should save those records now. The patch will make the warning disappear, but it will not recreate evidence if the company failed to retain it.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He noted that his greatest concern about the Microsoft alert is its wide impact on many Windows versions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWindows 11 26H1 and Windows Server 2012 are fourteen years apart, and Microsoft says this bug can hit both,\u201d he said. \u201cCompanies separate desktops, servers, legacy systems, and critical infrastructure into different patch rings, but Defender runs through all of them. The popup will get patched, but that shared failure path through the Windows estate will still be there, and a bad update can produce the same wrong security signal everywhere at once.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><em>This article originally appeared on <a href=\"https:\/\/www.computerworld.com\/article\/4216582\/windows-bug-incorrectly-tells-users-that-microsoft-defender-antivirus-is-turned-off.html\" target=\"_blank\" rel=\"noopener\">Computerworld<\/a>.<\/em><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. Consultants say that this advisory raises a major concern in that it will train users to ignore [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9263,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9262"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9262"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9262\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9263"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}