Microsoft asks users to ignore 'Antivirus is turned off' errors

by · BleepingComputer

Microsoft asked customers this week to ignore incorrect alerts that Defender Antivirus has been turned off after installing the latest Defender updates.

Although this issue has been affecting users in the Release Preview Channel of the Windows Insider program since June, it appears Microsoft didn't notice it until now.

The erroneous alerts appear on affected systems in the Windows Security app and prompt users to "Tap or click to turn on Microsoft Defender Antivirus."

The known issue affects all supported Windows client and server versions, including the latest Windows 11 26H1 and Windows Server 2025 releases.

"After installing the latest updates for Microsoft Defender Antivirus, notifications might appear stating that "Microsoft Defender Antivirus is turned off," even though the antivirus is functioning correctly and all settings show it as active," Microsoft explained in a Friday release health dashboard update.

"These notifications can appear when Windows starts and intermittently afterward. They persist even if notification settings are turned off."

Microsoft says it's working on a fix and will release it to affected customers in a future Microsoft Defender Antivirus update.

Defender Antivirus turned off alert (MarcelDekker)

This isn't the first time Microsoft has told customers to ignore incorrect alerts and errors being displayed on their systems after installing updates.

In April, the company confirmed and fixed a bug that caused invalid 0x80070643 failure errors after installing the April 2025 Windows Recovery Environment (WinRE) updates and addressed an issue that was triggering incorrect BitLocker drive encryption errors on Windows 10 and Windows 11 devices.

In July 2025, it also asked users to disregard erroneous Windows Firewall alerts that appeared after rebooting following the installation of the June 2025 preview update.

One month later, Microsoft said that the July 2025 preview update and subsequent Windows 11 24H2 updates were triggering incorrect CertificateServicesClient (CertEnroll) errors.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

Get the report