kemical

Windows Forum Admin
Staff member
Premium Supporter
Joined
Aug 28, 2007
Messages
36,161
Microsoft reports relate to a bogus update from Win Defender stopping some machines from starting when secure boot is turned on:

This article describes an antimalware platform update package for Windows Defender for the following operating systems:
  • Windows 10 (Enterprise, Pro, and Home editions)
  • Windows Server 2016
Known issues in this update
  • New file path

    Because of a change in the file path location in the update, many downloads are blocked when AppLocker is enabled.

    To work around this issue, open Group Policy, and then change the setting to Allow for the following path:
    %OSDrive%\ProgramData\Microsoft\Windows Defender\Platform\*
  • Secure Boot issue in version 4.18.1901.7
    Some devices that are running Windows 10 do not start if they have Secure Boot turned on.

    We are working on this issue and plan to provide a fix in a future update. To work around this issue in the meantime, follow these steps:
    1. Restart the device, and enter the BIOS.
    2. Turn off Secure Boot, and then restart the device again.
    3. In an administrative Command Prompt window, run the following command:

      "%programdata%\Microsoft\Windows Defender\Platform\4.18.1901-7\MpCmdRun.exe" -revertplatform
    4. Wait for one minute, and then do the following:
      • Run sc query windefend to verify that the Windows Defender service is running.
      • Run sc qc windefend to verify that the Windows Defender binary no longer points to version 4.18.1901.7.
    5. Restart the device, re-enter the BIOS, and then turn on Secure Boot.
 


That seems to be fixed now. You can try updating to the latest Microsoft update for Defender on your hosted windows desktop.

The latest security intelligence update is:

  • Version: 1.299.1078.0
  • Released: 8/2/2019 9:21:41 AM

Regards,
Adrian
 


Back
Top