[Windows Client] Antivirus Posture Check Fails While Microsoft Defender Is Enabled
Last updated: September 14, 2026
Applicable to
Twingate Component: Client
Platform OS: Windows 11 and Windows 10 (all supported versions), Windows Server
Overview
The Antivirus device posture check reports antivirus as not enabled while Microsoft Defender is enabled and running normally.
This is a confirmed Microsoft issue, published on the Windows release health pages as Incorrect notifications that "Microsoft Defender Antivirus is turned off". Microsoft has confirmed it and states a resolution will ship in a future Microsoft Defender Antivirus update. No fix date has been published.
Reports rose through August and September 2026. The issue is not caused by a Windows security update and is not tied to a specific Windows build. Microsoft attributes it to Defender antivirus updates, and lists the originating update as N/A.
Symptoms
The Antivirus posture check fails in the Client or Admin Console.
Users are blocked with
Device security not met, or seeBlock reason: Verified devicein Resource access events.Microsoft Defender is enabled, with real-time protection on and signatures up to date.
Windows may also display notifications claiming Microsoft Defender Antivirus is turned off.
The failure does not clear on its own, and persists across sign-outs and Client reinstalls.
Updating the Twingate Client does not resolve it. The behavior is independent of Client version.
Cause
The Antivirus posture check reports antivirus state as confirmed by the Windows Security Center (WSC).
On impacted devices, WSC misreports antivirus status when the Security Center service starts, and then retains that incorrect value for as long as the service keeps running. Nothing on the device causes it to re-evaluate, so the wrong value persists until the service restarts or the state is changed manually.
Microsoft Defender is unaffected and continues to protect the device throughout. The Twingate Client reads the value WSC publishes, so the check continues to fail until WSC is made to re-evaluate.
Why other antivirus checks still look healthy
Checks such as Get-MpComputerStatus, the root\SecurityCenter2 WMI class, and the Windows Security app read a different source than the posture check does. These commonly report Defender as healthy on an affected device, because they are not reading the value WSC is publishing to applications.
A disagreement between those tools and Twingate is expected on an affected device and does not indicate a problem with the Client.
Resolution
Microsoft has not published a fix. Until the Defender update ships, use the workaround below.
Toggle Real-time protection
Open Windows Security > Virus & threat protection > Manage settings.
Switch Real-time protection off, then back on.
This forces Windows Security Center to re-evaluate immediately. Real-time protection is briefly disabled while you do this.
The corrected state holds until the Security Center service next starts, so the check can fail again after a reboot. Repeat the toggle if it does.
Note on updates and reboots
Updating Microsoft Defender does not resolve this issue, and Microsoft's advisory indicates the behavior appears after the latest Defender updates are installed. A reboot restarts the Security Center service and may clear the incorrect value, but it may equally re-apply it, so it is not a reliable fix.
If many devices are affected
The workaround is per-device and does not survive a reboot, so it does not scale well across a fleet.
Where a significant number of devices are blocked, consider temporarily removing the Antivirus requirement from the affected Device Security Policy until Microsoft ships the Defender fix, then re-enabling it. This restores access for affected users without changing anything on the endpoints.