A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Task Scheduler stopped working after updates
Hi
I'm having a very serious issue in my environment that is preventing some of our machines to no longer sync with InTune after what seems to be caused by recent Defender (or windows) updates that have caused Defender policies to start blocking critical processes and services.
About a week ago around September -16/19th many of our intune enrolled machines received Windows cumulative, drivers, defender definitions and security updates via InTune pushed update rings,
on reboot many of these machines were broken with the following symptoms:
- InTune sync would not complete successfully
- task scheduler app or service would not start
- certain services refused to start such as task scheduler, software protection, etc
- office 365 apps would start with an error message asking to repair which would do nothing and then crash the application
-checking licensing in the Office 365 app would do nothing - system very slow
nothing was changed in our environment lately except for the creation of 1 InTune configuration that would wake sleeping hibernating machines to do maintenance this configuration was pushed to all devices but was later disabled to troubleshoot this issue.
there were other Defender related policies in place that had been in place since late 2024 early 2025
(we suspect that recent updates caused conflicts with our existing system configurations and started blocking critical processes)
we were noticing many system file blocks during the issues such as Windows security blocking lsass.exe and svchost.exe
all the Defender policies have now either been disabled and in some cases instead of a block configuration they were set to audit to avoid further issues
to note that some devices did not encounter this issue and newly enrolled machines do not have this issue
another important note is that we use crowdstrike as our main antivirus
EDR block mode in the defender portal as well as tamper protection were enabled since many years but these two settings were disabled during the onset of the issue last week to avoid conflicts
up to now the only sure way to recover one of these machines to our knowledge is to do a Windows reset and keep files although this works it is very tedious and we have many machines to fix so it is not ideal if there is a better method
however lately we had discovered that by disconnecting the work school account from the computer and rebooting would sometimes free the system of these issues where task scheduler and other services could start and in some cases we were also able to reconnect the machine and have the user sign in normally while maintaining all apps and settings pretty much intact
however this has not been too repeatable for the most part as some machines are fixed with this method while others are not
another important note is to say that we have a mix of enrolled devices some are entra joined others are hybrid joined
I have open cases with Microsoft at this time but I've yet to find a viable solution without doing a full windows reset on all these devices
any guidance or help would be greatly appreciated
thanks