There are solely two ‘Friday the 13th’s in 2023, and the primary has already seen Microsoft scrambling to repair a problem that affected customers’ Begin menus and taskbars following a botched replace to its Defender antivirus.
Following the mishap, Microsoft took to the Web to substantiate (opens in new tab) that many customers had skilled “a series of false positive detections” for the “Block Win32 API calls from Office macro” Assault Floor Discount (ASR) rule, resulting in many program shortcuts (.lnk information) vanishing.
Among the many initially advised fixes from the corporate was to show the “Block Win32 API calls from Office macro” rule into audit mode, nonetheless Microsoft has now issued a extra complete repair that, after deploying, will permit customers to show the ASR rule again into block mode.
Microsoft Defender downside
The corporate has informed customers to improve to safety intelligence construct 1.381.2164.0 or later. An extract from the assistance web page reads:
“Microsoft has confirmed steps that customers can take to recreate start menu links for a significant sub-set of the affected applications that were deleted.”
The steps have been offered as a PowerShell script on a GitHub page (opens in new tab) – a developer platform that Microsoft owns. There’s additionally a set of directions for deploying the script utilizing Intune, which many customers had been vocal about when it got here to discussing the blunder on platforms like Reddit (opens in new tab) and Microsoft’s personal Tech Neighborhood web page (opens in new tab).
One person requested Microsoft “why Defender did not record the lnk file deletions”.
As the issue continues to be an ongoing supply of disruption amongst Microsoft customers, it’s unclear whether or not the repair has been sufficient for the tech big to revive a few of its misplaced religion. Total, person experiences stay a combined bag, with some claiming profitable restores, and others reporting errors.