Microsoft has recently addressed a growing concern among users regarding persistent Windows Security pop-ups that erroneously indicate their antivirus protection is disabled. The tech giant has clarified that these notifications stem from a software bug rather than an actual security threat.
Details on the Bug
In an official statement, Microsoft explained that the misleading alerts began surfacing following the installation of the latest Microsoft Defender Antivirus updates. The company reassured users that “the antivirus is functioning correctly and all settings show it as active,” despite the alarming warnings.
These notifications can appear at startup and intermittently thereafter, and notably, they continue to persist even if users attempt to disable them through standard notification settings. This has left many users feeling frustrated, as they cannot simply mute the alerts.
Microsoft’s release-health advisory, which was first published on August 28, 2026, at 15:34 PT and updated later that day, confirms the issue as acknowledged but unresolved. The company has committed to providing a resolution in a future update for Microsoft Defender Antivirus, although no specific timeline has been disclosed.
Scope of the Issue
The breadth of this bug has garnered significant attention. Microsoft indicated that it could affect “any version of Windows or Windows Server with Microsoft Defender Antivirus running with the latest Defender updates.” This encompasses a wide array of systems, including:
- Windows 11 versions 23H2, 24H2, 25H2, and 26H1
- Windows 10 versions 21H2 and 22H2
- Windows 10 Enterprise LTSC 2016 and 2019
- Windows Server releases from 2012 and 2012 R2 through 2016, 2019, 2022, and 2025
It appears that very few actively supported Defender-enabled systems are exempt from this issue.
User Reactions and Recommendations
Coverage from XDA Developers highlighted the understandable unease among everyday users, noting that it’s “only natural to be a little bit worried” when Windows Security repeatedly claims protection is off, especially in light of increasing AI-driven attacks and frequent zero-day security threats.
However, the outlet reassured readers that once the actual status of Defender is verified as active, “you have nothing to worry about” beyond the annoyance of the recurring pop-up. Security professionals emphasize that users should not dismiss the warning outright without verification. The recommended course of action is to open the Windows Security app directly and check for any genuine alerts under Virus & Threat Protection. If the dashboard indicates that real-time protection is enabled, users can safely disregard the notification until a fix is released.
Context of Recent Issues
The timing of this incident is particularly noteworthy, as it follows a separate, unrelated problem with Defender earlier in August. During that time, quick and full scans were triggering 0xc0000005 access violation crashes on certain systems, an issue that Microsoft has since resolved through a signature update.
These consecutive incidents underscore how routine antivirus updates can inadvertently lead to confusing side effects that may erode user trust, even when no actual vulnerabilities exist. Until Microsoft delivers the promised patch, IT administrators overseeing fleets of Windows endpoints are advised to treat the “Defender is turned off” alert as cosmetic. They should continue to monitor official channels for updates and verify protection status through PowerShell or the Windows Security dashboard, rather than relying solely on the notification itself.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC.