Although Microsoft Defender is generally a good anti-malware solution, the program can often affect innocuous objects, leading to very poor false positive scores in third-party evaluation programs.
Earlier today, one such incident occurred when IT and system admins started reporting that after updating the Defender definition, they could no longer access shortcuts to apps in the taskbar and Start menu. can do Apparently the issue was caused by a Security Intelligence update. Version 1.381.2140.0As Defender will delete all shortcut (.lnk) files located inside ProgramData\Microsoft\Windows\Start Menu\Programs.
Users say the issue is occurring on Windows 10, although it’s possible that Windows 11 is also affected. System admins were working around the issue by configuring the Attack Surface Reduction Rule (ASR) rule “92e97fa1-2edf-4476-bdd6-9dd0b4dddc7b” to audit only (via Reddit).
A few hours ago, Microsoft 365 Status’ official Twitter handle confirmed the issue and said it was looking into the issue:
We are investigating an issue where users are unable to access application shortcuts on the Start menu and taskbar in Windows. For more details and updates, please follow SI MO497128 in your admin center.
— Microsoft 365 Status (@MSFT365Status) January 13, 2023
An hour later, Microsoft updated its status to say that it had identified the issue and reverted the policy:
We identified that a specific principle was causing the effect. We’ve rolled back the rule to prevent further impact while we investigate further. For more information, please follow SI MO497128 in your admin center.
— Microsoft 365 Status (@MSFT365Status) January 13, 2023
However, IT admins are still apparently a bit angry that they will now need to restore deleted shortcuts.
Thanks for the tip majortom1981!