Microsoft has addressed a known issue where users received erroneous notifications stating that "Microsoft Defender Antivirus is turned off" even when the antivirus was functioning correctly. This problem arose after installing recent Windows updates.
The fix for this issue was included in the Microsoft Defender Antivirus update, version 4.18.26080.4, which was released on September 17. Microsoft confirmed the resolution in a Windows release health dashboard update.
The bug, acknowledged by Microsoft in late August, had been affecting users in the Release Preview Channel of the Windows Insider program since at least June. It impacted all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025 releases, triggering alerts in the Windows Security app.
This is not an isolated incident; Microsoft has previously asked users to disregard incorrect errors. In April 2025, the company addressed false BitLocker encryption errors and 0x80070643 failure errors after WinRE updates. In July 2025, users were advised to ignore erroneous Windows Firewall alerts, and a month later, incorrect CertificateServicesClient errors were reported after the July 2025 preview update and subsequent Windows 11 24H2 updates.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Microsoft has resolved an issue causing incorrect "Defender Antivirus is turned off" alerts after installing recent updates, with the fix included in Microsoft Defender Antivirus update version 4.18.26080.4. This matters because the false alerts affected all supported Windows client and server versions, creating confusion about system security status.