Windows Defender Antivirus Network Inspection Service issues since Windows 10 2004 update

Anonymous
2020-08-06T08:15:09+00:00

I got the 2004 update yesterday and that went well enough otherwise but I am having a problem with the Windows Defender Antivirus Network Inspection Service that I did not have previously. 

  1. I noticed in Event Viewer several Errors that began immediately upon completion of the update last night: 

The Microsoft Defender Antivirus Network Inspection Service service depends on the Microsoft Defender Antivirus Network Inspection System Driver service which failed to start because of the following error: 

The supplied user buffer is not valid for the requested operation.

  1. Further inspection has revealed that there is now a problem with Real Time Updates. 

Microsoft Defender Antivirus Real-Time Protection feature has encountered an error and failed.

  Feature: Network Inspection System

Error Code: 0x8007042c

Error description: The dependency service or group failed to start. 

Reason: The system is missing updates that are required for running Network Inspection System.  Install the required updates and restart the device.

I've got this error repeatedly (3002). 

  1. I went into security and maintenance to see what was going on with my security settings. That is not showing anything "wrong." 
  2. The Network Inspection Service is configured to manual, not automatic. I can't change this. 
  3. Real-time protection is on, and has been on. On Virus & threat protection settings, all of those are still toggled on, and those settings are the same before and after the upgrade. I haven't tried turning them on and off again yet. 
  4. I already did the August Safety scan, but I downloaded a fresh copy and am re-running it. 
  5. I did dism and sfc checks and they showed no problems that needed repair. 

Something is definitely wrong with the install of Windows Defender tho... Help? How do I fix this and stop the errors and get it reconfigured properly. Do I have to reinstall it?

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

95 answers

Sort by: Newest
  1. Anonymous
    2020-09-01T07:25:43+00:00

    Try to turn off the "Memory Integrity" under Core Isolation

    Device security -> Core isolation -> Memory integrity

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2020-08-28T22:35:40+00:00

    Yes. They were all present and set to 1 on my systems that received the update a few days ago. I never enrolled those machines in any sort of preview program.

    I was able to force the update on other machines by just adding the MpCampRing entry as a 32 bit DWORD set to 3. Windows Update immediately pulled down 4.18.2008.4 and deleted the entry I had added.

    This worked for me. Thank you

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2020-08-18T10:34:18+00:00

    Thanks for all the feedback.  Funny that 4.18.2008.4 isn't a stable release, but 4.18.2007.8-0  is actually broken (for at least some).  The catalog shows no newer version of 4.18.2007.  I'll weigh the risks of "busted NIS" vs "1909+registry hack".  But then I can just boot Linux.

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2020-08-18T10:08:18+00:00

     I wonder how many users have their security impacted (no network inspection service) and don't even know it.  The Windows security application shows everything is ok.  The only way one would know is checking event viewer, services, etc.  Most users do not.  My complaint directed at microsoft, not you;-)

    Have been wondering about that as well. Would also have expected that Windows Security to alert the user as opposed to just printing in the logs.

     I had planned to wait until EOL before upgrading OS version.  I have no trust yet in Win 2004, and this bug (including having to use registry hack to fix it) doesn't improve my confidence. 

    The Antimalware engine development/release cycle is independent of the OS development/release cycle.

    4.18.2008.4 is not yet a stable release but a preview (beta) release, check also MS Update Catalog.

    Thus with 4.18.2008.4 on W10 1909 the node got a preview release of the Antimalware engine. And this could only happen because of some related registry setting...

    Was this answer helpful?

    0 comments No comments
  5. Anonymous
    2020-08-18T09:46:18+00:00

    I had planned to wait until EOL before upgrading OS version.  I have no trust yet in Win 2004, and this bug (including having to use registry hack to fix it) doesn't improve my confidence.  I wonder how many users have their security impacted (no network inspection service) and don't even know it.  The Windows security application shows everything is ok.  The only way one would know is checking event viewer, services, etc.  Most users do not.  My complaint directed at microsoft, not you;-)

    Was this answer helpful?

    0 comments No comments