The bug itself doesn't pose any direct security risk, but it certainly causes confusion.
Microsoft has confirmed that a new "Microsoft Defender Antivirus is turned off" warning on Windows devices is a false alarm caused by a software bug. In a support update posted Friday, the company advised users to ignore these alerts so long as real-time Windows Security protection is marked as active in Settings.
Recent Defender updates from late August are behind the bug. Erroneous notifications appear during bootup and sometimes while a PC is in use, stating that Defender is turned off, even when the antivirus feature works correctly and all settings show it as active. Worse, these messages continue to appear even after users deactivate Defender notifications. Thankfully, the bug itself doesn't cause a direct security risk because the antivirus engine and scanning remain operational.
The issue affects Windows 11, Windows 10, and multiple Windows Server versions. Users are advised to open Windows Security, go to Virus & threat protection, and confirm that real-time protection shows as On. If there are no real alerts on the dashboard and protection is active, consider "Defender is off" pop-ups as false until Microsoft fixes it in a future Defender update.
Microsoft asked customers this week to ignore alerts that Defender Antivirus has been turned off after installing the latest Defender updates.
This isn't the first time Microsoft has told customers to ignore incorrect alerts and errors being displayed on their systems after installing updates.
In April, the company confirmed and fixed a bug that caused invalid 0x80070643 failure errors after installing the April 2025 Windows Recovery Environment (WinRE) updates and addressed an issue that was triggering incorrect BitLocker drive encryption errors on Windows 10 and Windows 11 devices.
In July 2025, it also asked users to disregard erroneous Windows Firewall alerts that appeared after rebooting following the installation of the June 2025 preview update.
One month later, Microsoft said that the July 2025 preview update and subsequent Windows 11 24H2 updates were triggering incorrect CertificateServicesClient (CertEnroll) errors.
Via extremetech / bleepingcomputer / Pic Screenshot Credit: Cole Kan/PCMAG/Microsoft/Getty Images.