Windows Defender Says Antivirus Is Turned Off
Published August 28, 2026
If Windows Defender says antivirus is turned off after the August 2026 update, your machine is almost certainly still protected. The Windows Security toast that reads "Turn on virus protection" or "Microsoft Defender Antivirus is turned off" is showing up on a lot of healthy PCs, usually two to five minutes after every boot. This is for owners and in-house IT who just got that alert and need a straight check before anyone disables Defender or reinstalls antivirus.
Mid-August also produced a real crash: "Threat service has stopped. Restart it now," with scans failing. Microsoft already fixed that one. Here is how to tell which problem you have, prove Defender is running, and keep a cosmetic alert from paging techs or dinging a compliance dashboard.
Free Microsoft 365 tenant check. We will look at your Defender, Purview, and license state, tell you what is switched off or paid for and unused, and send it in writing. No charge and no sales call required to get the findings. Request the check.
Windows Defender antivirus turned off: two different problems
The crash: "Threat service has stopped" (already fixed)
Starting around August 19, 2026, Microsoft Defender Antivirus on Windows 10 and Windows 11 could crash with a 0xc0000005 access violation. Quick and full scans failed, and Windows Security showed "Threat service has stopped. Restart it now." BleepingComputer covered the crash, and Microsoft confirmed a fix: Defender Antivirus signature update 1.457.236.0 or later, which applies automatically through Windows Update. If that signature is on the machine, the crash is closed.
The false toast: "Microsoft Defender Antivirus is turned off" (still open)
A separate bug still shows "Turn on virus protection" or "Microsoft Defender Antivirus is turned off," usually two to five minutes after every boot, and sometimes again later. Defender is actually running normally. Microsoft confirmed it on its Windows release-health dashboard on August 28, 2026, status Confirmed, and ties it to the latest Defender Antivirus updates. There is no fix yet. Microsoft says a resolution is coming in a future Microsoft Defender Antivirus update. The toast can keep firing even if Windows Security notifications are turned off. It can show up on any current Windows or Windows Server install running those updates, including Windows 10 22H2, Windows 11 23H2 through 25H2, and Windows Server 2022 and 2025.
How to know for sure
Check the actual Defender service with a built-in Windows command, Get-MpComputerStatus (Microsoft's reference). You do not need to be a full-time admin to run it on your own PC.
- Click Start, type PowerShell, and open Windows PowerShell.
- Type
Get-MpComputerStatusand press Enter. To see only the four lines that matter, you can paste:Get-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, AntivirusSignatureVersion - Find AMServiceEnabled, AntivirusEnabled, and RealTimeProtectionEnabled. Each should read True.
- Find AntivirusSignatureVersion. For the crash, you want 1.457.236.0 or later.
If those three values are True, the toast is cosmetic. IT can run the same check across a whole fleet through an RMM, the remote monitoring tool most managed providers already use on every PC.
What to actually do
Do not disable Defender, reinstall antivirus, or make registry hacks over this alert. Leave Defender running and verify status instead.
- If you saw the crash / "Threat service has stopped": Confirm signature 1.457.236.0 or later is installed (AntivirusSignatureVersion in the output above). If it is, you are done. If it is older, run Windows Update and check again.
- If you are seeing the "turned off" toast: Run Get-MpComputerStatus. If AMServiceEnabled, AntivirusEnabled, and RealTimeProtectionEnabled are True, leave Defender alone and wait for the Defender Antivirus update Microsoft has listed. The toast can trip Defender-status checks in compliance tooling (Vanta is one example), so verify the real status rather than trusting the notification.
If you manage a fleet
Treat the toast as a known false positive until Microsoft ships the Defender Antivirus update. Point RMM and SIEM alerts at Get-MpComputerStatus (AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, and the signature version), not at the Windows Security Center notification. Silencing Windows Security notifications will not stop it. If those four checks are healthy, do not page a technician and do not open a "Defender is down" ticket. We do that check as part of security operations.
For compliance dashboards, document the Microsoft confirmation (opened August 28, 2026, status Confirmed) and attach healthy Get-MpComputerStatus output so the bug does not look like a control failure. That is the practical side of compliance work, and day-to-day fleet patching is what managed IT is for.
Frequently asked questions
Is Windows Defender actually turned off after the August 2026 update?
Usually no. Microsoft confirmed a cosmetic Windows Security Center bug on August 28, 2026, status Confirmed. Defender is typically still running. Prove it with Get-MpComputerStatus: if AMServiceEnabled, AntivirusEnabled, and RealTimeProtectionEnabled are True, the toast is cosmetic. Wait for the Defender Antivirus update Microsoft has listed.
How do I know Microsoft Defender is really running?
Open Windows PowerShell, run Get-MpComputerStatus, and check AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, plus the signature version. If those three flags are True, protection is on. IT can run the same command across a whole fleet with an RMM.
What should I do about Threat service has stopped?
That crash started around August 19, 2026, on Windows 10 and Windows 11. Microsoft fixed it in Defender Antivirus signature 1.457.236.0 or later, which applies through Windows Update. Confirm that signature version. Do not disable Defender or reinstall antivirus.
Can this false alert affect compliance tools like Vanta?
Yes. The toast can trip Defender-status checks on compliance dashboards even while Defender is running. Verify with Get-MpComputerStatus rather than the notification. Document Microsoft's Confirmed status, opened August 28, 2026, so a cosmetic bug is not treated as a failed control.
If Defender alerts are lighting up across your machines
Windows Defender saying antivirus is turned off after the August update is the kind of noise Desert Lakes Solutions handles for Phoenix-area businesses. If your Defender dashboard is lighting up across machines, we can confirm the fleet is clean: signature 1.457.236.0 or later for the crash, and a healthy Get-MpComputerStatus for the false toast.
Defender being on is the floor, not the finish line. If you want proof that the rest of the setup holds up, a penetration test shows what an attacker can actually reach once they are past the antivirus, and our compliance services turn that into the evidence an insurer or auditor asks for.
If you would like us to confirm your machines are protected and stop the false pages, Desert Lakes Solutions offers a no-pressure discovery call. Book a discovery call.