Cyber Security News

Microsoft Confirms False “Defender Antivirus Turned Off” Alerts Spreading Across Windows Devices

Microsoft has confirmed that a wave of alarming Windows Security pop-ups telling users their antivirus protection is disabled is nothing more than a software bug, not an actual security issue.

In an official statement, Microsoft said the erroneous notifications began appearing after devices installed the latest Microsoft Defender Antivirus updates, and that “the antivirus is functioning correctly and all settings show it as active” despite what the warning claims.

The company added that the alerts “can appear when Windows starts and intermittently afterward” and, notably, “persist even if notification settings are turned off,” meaning affected users cannot simply mute them through standard notification controls.

Microsoft’s release-health advisory, first opened on August 28, 2026, at 15:34 PT and updated later that same day, lists the issue as confirmed but unresolved, with the company stating only that it is “working to release a resolution in a future Microsoft Defender Antivirus update”. No specific fix timeline has been shared yet.

The scale of the bug is what has drawn the most attention. Microsoft says it can strike “any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates“.

That includes Windows 11 versions 23H2, 24H2, 25H2, and 26H1, Windows 10 versions 21H2 and 22H2, both Windows 10 Enterprise LTSC 2016 and 2019, and Windows Server releases from 2012 and 2012 R2 through 2016, 2019, 2022, and 2025. Very few actively supported Defender-enabled systems appear to be exempt.

Coverage from XDA Developers framed the situation as understandably unsettling for everyday users, noting that “it’s only natural to be a little bit worried” when Windows Security repeatedly insists protection is off, “especially given the backdrop of accelerating, AI-fueled attacks and frequent Windows zero-day security threats” .

The outlet reassured readers that once Defender’s actual status has been verified as active, “you have nothing to worry about” beyond the annoyance of the recurring pop-up.

Security professionals stress that users should not simply dismiss the warning as a false alarm without checking. The recommended approach is to open the Windows Security app directly and confirm that there are no genuine alerts under Virus & Threat Protection; if the dashboard shows real-time protection enabled, the notification can be safely ignored until Microsoft ships a fix.

The timing is notable, as it follows a separate and unrelated Defender problem earlier in August, in which quick and full scans were triggering 0xc0000005 access violation crashes on some systems, an issue Microsoft has already resolved through a signature update.

Taken together, the back-to-back incidents highlight how routine antivirus updates can introduce confusing side effects that erode user trust even when no actual vulnerability exists.

Until Microsoft’s promised patch lands, IT administrators managing fleets of Windows endpoints are advised to treat the “Defender is turned off” alert as cosmetic, while continuing to monitor official channels for the fix and verifying protection status through PowerShell or the Windows Security dashboard rather than the notification itself.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

49 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

12 hours ago