Defender falsely says it's off. Alert fatigue is the bug.
Microsoft confirmed Defender Antivirus shows false 'turned off' notifications you can't dismiss. Here's the PowerShell check, and why teaching staff to ignore alerts costs more than the bug.
Since late last week, Windows machines have been telling their users that Microsoft Defender Antivirus is turned off. It isn't. Microsoft confirmed the known issue on its Windows release health dashboard on August 28 and is still working on a fix. The security bug here is not the false positive. It's the week your staff spend learning that a red security warning is something you click past.
What actually happened
Microsoft's entry is specific: after installing the latest Defender Antivirus updates, notifications may appear stating that Defender is turned off "even though the antivirus is functioning correctly and all settings show it as active." The notifications fire at Windows startup and intermittently afterward. Then the part that makes it a real operational problem — they persist even if notification settings are turned off. You cannot mute this.
The affected list is not a corner case. Client: Windows 11 26H1, 25H2, 24H2, 23H2; Windows 10 22H2 and 21H2; Windows 10 Enterprise LTSC 2019 and 2016. Server: Windows Server 2025, 2022, 2019, 2016, 2012 R2, and 2012. That is close to everything running Defender. Status is Confirmed, originating update is listed as N/A, and Microsoft says a resolution will ship in a future Defender Antivirus update with no date attached.
To confirm your own machines are actually protected, run this in an elevated PowerShell prompt:
Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled
Three True values means Defender is running and the notification is lying. That is the authoritative answer — not the toast, not the Security Center icon.
Why a false alert matters for your business
Every security control you own eventually depends on a person deciding whether a warning is real. That decision is a trained reflex, and this bug is training it in the wrong direction across your entire fleet, several times a day, for an unknown number of weeks.
We have watched this movie. A team gets a stream of warnings that turn out to be nothing. They stop reading the text and start recognizing the shape — red banner, shield icon, dismiss. Then a real one arrives wearing the same shape. The gap between "Defender is off (it isn't)" and a genuine tamper alert, a ransomware detection, or a fake AV popup from a malvertising redirect is a few pixels and a sentence nobody is reading anymore.
That last one is the immediate risk. Scareware has impersonated exactly this notification for twenty years. "Your antivirus is disabled, click to fix" is the oldest fake-AV pretext there is, and Microsoft has just spent a week making the real version indistinguishable from the fake one by volume. A user who has dismissed the legitimate alert forty times is primed to click the fraudulent one.
Three things to do, none of which take an hour:
Tell your team, in writing, today. One message: Defender is fine, Microsoft confirmed the bug, ignore the popup, and — this is the important half — never click a link or button inside any antivirus warning. Report it instead. Give them a named person to report to.
Verify centrally, don't trust the toast. Run Get-MpComputerStatus across the fleet via your RMM or Intune and keep the output. If you cannot query endpoint protection state without walking to a desk, that gap is a bigger finding than this bug.
Watch the release health dashboard yourself. Microsoft published this within hours. If the first you heard of it was a user ticket, your monitoring loop for vendor-confirmed issues is a person remembering to check, which is not a loop.
Alert fatigue is not a soft problem. It is the failure mode that turns a working control into a decoration, and it accumulates quietly until the day it matters.
Key takeaways
- Microsoft confirmed on August 28 that recent Defender Antivirus updates trigger false "Defender is turned off" notifications while protection is fully active
- The notifications appear at startup and intermittently, and persist even when notification settings are disabled — there is no mute
- Affected platforms span Windows 10 21H2 through Windows 11 26H1 and Windows Server 2012 through 2025
- Verify real status with Get-MpComputerStatus and check AMServiceEnabled, AntivirusEnabled, and RealTimeProtectionEnabled
- The operational risk is trained dismissal: fake-AV scareware uses this exact pretext, and your users are being conditioned to click past it
- Microsoft says a fix ships in a future Defender update, with no committed date
If you can't answer "is endpoint protection on across all 40 machines?" from a query, you don't have an answer. We build the boring operational layer for small teams — central status checks, vendor advisory monitoring that isn't a person remembering, and a written escalation path staff actually use. See what we operate, or tell us how you'd verify your fleet today.
Sources: Microsoft Windows release health, BleepingComputer.
- #microsoft-defender
- #windows
- #alert-fatigue
- #endpoint-security
- #it-operations
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Australia's data centre power rules: no carve-outs
Canberra will legislate a 100% renewable standard for AI data centres over state objections. Energy policy is now a cloud region variable — price it.
Read itMeta's capture LED is now enforced in software
Meta is shipping an update that kills recording when the smart glasses capture LED is covered. A privacy indicator you can patch is a policy, not a hardware guarantee.
Read it