Core Isolation prevents further activation post-restart [Windows Defender].
Core Isolation prevents further activation post-restart [Windows Defender].
Usually caused by a mismatched third-party application, the Defender's core isolation part should pinpoint the issue. You might run Autoruns via Sysinternals to temporarily turn it off for testing, or you may have to completely uninstall or upgrade the driver so core isolation works properly.
I've attempted to run Autoruns, turn off unused drivers and services, and remove devices from the device manager. However, the system still disables itself after a restart. I've also tried using a group policy script to force a value of 1 during login, but that didn't help. I'm checking for a tool that lists hidden driver files in case something is missing, though the audit still shows no history on the DWORD key.
The registry entries linked to Defender remain secured by the operating system, automatically restoring them if you alter their settings—this prevents malicious software from disabling protections. This page provides core isolation details: https://support.microsoft.com/en-gb/wind...521df09b78 You may utilize RAPR (Driver Store Explorer) in administrator mode to inspect system drivers and remove them when necessary; proceed with caution, as this differs from Autoruns' behavior and will also delete files. For core isolation to function properly, hardware and drivers must be compatible, so consider checking add-in cards, external devices, etc. The Defender dashboard and device security section can assist in diagnosing the problem.
I reviewed all drivers I didn’t need with RAPR but it didn’t help either. Event Viewer showed a message saying the Windows driver was blocked because Microsoft revoked it. Even after removing it, it still turned off after each restart. At startup, Code Integrity said it would enforce the WHQL driver and listed settings 0x0 with an exemption. I tried enabling verbose mode in the Event Viewer folder to check for details and removed my USBs to see if that affected the issue. Update: It’s still active after a restart, but I’ll watch for changes when the computer powers on.
It seems the main concern could arise if the problem driver gets reinstalled after an app update, possibly because of a software patch. Checking which applications rely on the driver and verifying if an app update is available for compatibility with core isolation might help. Additionally, a Windows update could reinstall the driver if required by system hardware, so monitoring for this behavior and potentially blocking the update may be necessary.
Day two passed without changes, so I believe the problem is resolved. I'm keeping an eye on it, but it seems the ASIO.sys from ASUSTek wasn't the cause. Windows Update hasn't reinstalled that driver yet, and no software I've installed uses it anymore. I'll mark it as fixed. Overall, the event viewer appears normal and core isolation remains active. Thanks for your assistance.