Microsoft informed some customers:
Event Viewer displays an error for System Guard Runtime Monitor Broker service
Status: Mitigated
Affected platforms:
| OS Versions |
Message ID |
Originating KB |
Resolved KB |
| Windows 10, version 22H2 |
WI982633 |
KB5049981 |
- |
| Windows Server 2022 |
WI982632 |
KB5049983 |
- |
The Windows Event Viewer might display an error related to SgrmBroker.exe, on devices which have installed Windows updates released January 14, 2025 (the Originating KBs listed above) or later.
This error can be found underWindows Logs > System as Event 7023, with text similar to 'The System Guard Runtime Monitor Broker service terminated with the following error: %%3489660935'.
This error is only observable if the Windows Event Viewer is monitored closely. It is otherwise silent and does not appear as a dialog box or notification.
SgrmBroker.exe refers to the System Guard Runtime Monitor Broker Service.
This service was originally created for Microsoft Defender, but it has not been a part of its operation for a very long time.
Although Windows updates released January 14, 2025 conflict with the initialization of this service, no impact to performance or functionality should be observed.
There is no change to the security level of a device resulting from this issue.
This service has already been disabled in other supported versions of Windows, and SgrmBroker.exe presently serves no purpose.
Note: There is no need to manually start this service or configure it in any way (doing so might trigger errors unnecessarily).
Future Windows updates will adjust the components used by this service and SgrmBroker.exe.
For this reason,please do not attempt to manually uninstall or remove this service or its components.
Workaround:
No specific action is required, however, the service can be safely disabled in order to prevent the error from appearing in Event Viewer.
To do so, you can follow these steps:
1) Open a Command Prompt window. This can be accomplished by opening the Start menu and typing 'cmd'.
The results will include "Command Prompt" as a System application. Select the arrow to the right of "Command Prompt" and select "Run as administrator".
2) Once the window is open, carefully enter the following text:
sc.exe config sgrmagent start=disabled
3) A message may appear afterwards. Next, enter the following text:
reg add HKLM\System\CurrentControlSet\Services\SgrmBroker /v Start /d 4 /t REG_DWORD
4) Close the Command Prompt window. This will prevent the related error from appearing in the Event Viewer on subsequent device start up.
Note that some of these steps might be restricted by group policy set by your organization.
Next steps: We are working on a resolution and will provide an update in an upcoming release.
Thank you very much for your reply and the info contained in it. I "do not" plan on doing any kind of work around for this as it is MS that caused this and MS should fix this and let users know when a fix is available and an update provided. I noticed that in your post you said "Microsoft informed some customers:" and I feel that MS should have inform all customers not just some. It is also stated in the post that:
"SgrmBroker.exe refers to the System Guard Runtime Monitor Broker Service.This service was originally created for Microsoft Defender, but it hasnot been a part of its operation for a very long time.""Although Windows updates released January 14, 2025 conflict with the initialization of this service, no impact to performance or functionality should be observed.There is no change to the security level of a device resulting from this issue.Thisservice has already been disabled in other supported versions of Windows*, and* SgrmBroker.exe presently serves no purpose*."*
Why hasn't this service been disabled for all versions of Windows instead of just disabling it for other supported versions of Windows and why is it still an active service and still part of the Windows Services since it has not been a part of the operation of Microsoft Defender for a very long time? This is the kind of things that make users lose faith in Microsoft. This Cumulative Update has the feel of an Optional Cumulative Update Preview that MS sends out in the third/fourth week of the month so users that choose to install these can find problems before the Patch Tuesday update is sent out. I for one do not install these type of updates as I do not want to be a tester (guinea pig) and screw up my computer. Thank you again for the information but I will just leave it as it is and let MS take care of this.
Respectfully,