Windows 11 Defender Firewall Will Not Load

Sparky

New member
Joined
Oct 20, 2021
Messages
1
Reaction score
0
Windows Defender Firewall works fine in Windows 10. Immediately after an upgrade to Windows 11 Firewall loads and works. After a reboot the Firewall will not load. There is no other firewall installed. Any selection in Control Panel Windows Defender produces an error. Windows Defender Firewall Service is continually toggling between "Running" and "Starting". All network selections in Windows Security/Firewall Network and Protection are grayed our. Any attempt to poll Defender status in command prompt produces an error.
 

hotbso

Member
Joined
Jan 17, 2022
Messages
8
Reaction score
1
Guys, you all have an ASUS mobo, or?

Solution:
Full credit goes to the authors of:
1) https://www.techpowerup.com/248827/...-push-software-into-your-windows-installation
2) https://twitter.com/HpDream

Long story short:
The ASUS UEFI Bios installs an exe file AsusUpdateCheck.exe and configures it as a service on each boot UNLESS you disable this in the UEFI bios, see 1).
Under certain circumstances this services adds an entry to the DebugedLoopbackApps on each invocation.
The variable DebugedLoopbackApps is maintained by the standard windows utility CheckNetIsolation.exe see 2).

So, still on W10 I disabled the start of the ASUS utility in the Bios and then could see with

CheckNetIsolation.exe loopbackexempt -s

that I had more than 1000(!) identical entries of S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134 in DebugedLoopbackApps.

These could easily be deleted with

CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134

upgrade to W11, done.
 

Vote:

Jgers

Member
Joined
Feb 15, 2022
Messages
6
Reaction score
1
Strangely enough both problems of DebugedLoopbackApps and HNS Container Networking rules stopped happening after some Microsoft updates post Win11 upgrade. It was happening for several weeks though before then.
But yep, mine's an ASUS MB too.
 

Vote:

fib3r

New member
Joined
Jan 4, 2023
Messages
3
Reaction score
0
This thread is awesome, I have exactly the described situation. But I am on W11 now and I have 730 instances of the ominous entry.

C:\Windows\System32>CheckNetIsolation.exe LoopbackExempt -s
[...]
[730] -----------------------------------------------------------------
Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134

OK.

Now I still cannot delete those, when I run I get one of the following errors.

C:\Windows\System32>CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1115 - 45B

C:\Windows\System32>CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1753 - 6D9

I cannot delete the entries with regedit either, I fear the entry is simply too big now?

Is there anything left I can try? I dont want to reinstall obviously :D
 

Vote:

Jgers

Member
Joined
Feb 15, 2022
Messages
6
Reaction score
1
This thread is awesome, I have exactly the described situation. But I am on W11 now and I have 730 instances of the ominous entry.

C:\Windows\System32>CheckNetIsolation.exe LoopbackExempt -s
[...]
[730] -----------------------------------------------------------------
Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134

OK.

Now I still cannot delete those, when I run I get one of the following errors.

C:\Windows\System32>CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1115 - 45B

C:\Windows\System32>CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1753 - 6D9

I cannot delete the entries with regedit either, I fear the entry is simply too big now?

Is there anything left I can try? I dont want to reinstall obviously :D
Have you tried running ResEdit using the PSEXEC method I used below? That was the only way I could successfully get rid of any pesky registry values..

Post in thread 'Windows 11 Defender Firewall Will Not Load'
https://www.windows11forums.com/threads/windows-11-defender-firewall-will-not-load.355/post-3766
 

Vote:

CZY3

New member
Joined
Mar 31, 2022
Messages
3
Reaction score
2
This thread is awesome, I have exactly the described situation. But I am on W11 now and I have 730 instances of the ominous entry.

C:\Windows\System32>CheckNetIsolation.exe LoopbackExempt -s
[...]
[730] -----------------------------------------------------------------
Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134

OK.

Now I still cannot delete those, when I run I get one of the following errors.

C:\Windows\System32>CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1115 - 45B

C:\Windows\System32>CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1753 - 6D9

I cannot delete the entries with regedit either, I fear the entry is simply too big now?

Is there anything left I can try? I dont want to reinstall obviously :D
I was able to delete the entry directly using Registry Editor running as an admin, but you do have to mess with some permissions settings in order to force it to allow you to do it. Jger's PSEXEC method circumvents this issue though if you don't want to bother with permissions settings. After it was deleted, I had to re-create the entry with the correct data value:

S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194-4256926629-1688279915-2739229046-3928706915,S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194-4043415302-551583165-304772019-4009825106

See my previous post in the thread for more details:
- https://www.windows11forums.com/threads/windows-11-defender-firewall-will-not-load.355/post-3757

Also @hotbso I have an Asus mobo too (B550-E) which supports what you found. Nice finds!
 

Vote:

timoh

New member
Joined
Jan 8, 2023
Messages
4
Reaction score
0
Hello Guys,

This seems to be a thread that is discussing exactly about the problem on my sons PC. I am unfortunately not too technical and need some help from you. All the advices from "Independent Advisors" on Microsoft Community forum have been useless.

First of all here are some of the symptoms.

1. Task Manager
Windows Defender Firewall status quickly changes between Running and Starting.

2. Event viewer -> System log
Event id 7024. The Windows Defender Firewall service terminated with the following service-specific error: The parameter is incorrect.

Event Data:
param1 Windows Defender Firewall
param2 %%87
6D00700073007300760063000000

3. Settings -> Firewall & network protection -> Restore settings
Nothing happens.

4. Settings -> Firewall & network protection -> Restore firewalls to default -> Restore default settings -> Use recommended settings
Either "Windows Defender Firewall can't change some of your settings. Error code 0x800706d9." or "Windows Defender Firewall can't change some of your settings. Error code 0x8007045b." shows up

The motherboard is ROG STRIX B550-I GAMING.

Defender firewall worked before the first reboot after Win 11 upgrade. I have re-installed (keeping files and apps) Windows 11 couple of times and every time the same happens: Defender firewall works until the next reboot.

When I do CheckNetIsolation.exe loopbackexempt -s I get 700 entries like this
Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-351403....

I was planning to re-install Windows 11 once again to get a working value for Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpssvc\Parameters\AppCs. Then reboot the PC (Defender Firewall breaks) and update the registry with the working value. Could you please tell me if this is the right way to do it?

Timo
 

Vote:

fib3r

New member
Joined
Jan 4, 2023
Messages
3
Reaction score
0
Have you tried running ResEdit using the PSEXEC method I used below? That was the only way I could successfully get rid of any pesky registry values..

Post in thread 'Windows 11 Defender Firewall Will Not Load'
https://www.windows11forums.com/threads/windows-11-defender-firewall-will-not-load.355/post-3766

Hello again and thanks for hanging in.

I had not tried the psexec variant and now did. It sort of solved the access rights issue. I think I made a mistake with re-assigning the access rights because I forgot to assign an OWNER in the Advanced tab, with this I was finally able to work with / edit / delete the key.

But I guess I made it worse now... Btw, my mainbord is a ASUS PRIME X570-P with Bios 3801

ANd here is what I did:

Bios Setting "APP / Armory Crate" - Disabled - I finally understand where all of this mess is coming from. I had the value enabled until today.

CheckNetIsolation.exe loopbackexempt -s - Still shows 730 entrys

[...]
[730] -----------------------------------------------------------------
Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
[...]

CheckNetIsolation.exe delete attempt - Alternatingly fails with 1753 - 6D9 or 1115 - 45B error like this:

PS C:\WINDOWS\system32> CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1753 - 6D9
PS C:\WINDOWS\system32> CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1115 - 45B

Now with psexec regedit:

editing value - Cannot edit DebugedLoopbackApps: Error writing the value's new contents - OK, lets continue


Looking at Permissions:

You do not have permission to view the current permission settings for Properties, but you can make permission changes. - Ok, lets continue


So its "empty", I can indeed see nothing / no permissions are set

Setting Permissions / full control:

My mistake: NEED TO BE OWNER AS WELL!

Potentially correct settings?
DebugedLoopbackApps - S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
PolicyVersion - 21e(hex)

So I clicked AppCs - right click / Permissions -> ok -> Add user / full control -> Advanced -> Set owner! -> Apply -> Ok

The system log:

Old Event 7024
The Windows Defender Firewall service terminated with the following service-specific error:
Access is denied.

After I decided to test-delete the whole AppCs branch:

New Event 7024
The Windows Defender Firewall service terminated with the following service-specific error:
The system cannot find the file specified.

I restored the AppCs branch, So now my registry looks nice, but my firewall is still not working.

Also I cannot use the CheckNetIsolation tool anymore.

PS C:\WINDOWS\system32> CheckNetIsolation.exe loopbackexempt -s
Error occurred 1753 - 6D9

I am open for more suggestions :)
 

Vote:

fib3r

New member
Joined
Jan 4, 2023
Messages
3
Reaction score
0
Hello again and thanks for hanging in.

I had not tried the psexec variant and now did. It sort of solved the access rights issue. I think I made a mistake with re-assigning the access rights because I forgot to assign an OWNER in the Advanced tab, with this I was finally able to work with / edit / delete the key.

But I guess I made it worse now... Btw, my mainbord is a ASUS PRIME X570-P with Bios 3801

ANd here is what I did:

Bios Setting "APP / Armory Crate" - Disabled - I finally understand where all of this mess is coming from. I had the value enabled until today.

CheckNetIsolation.exe loopbackexempt -s - Still shows 730 entrys

[...]
[730] -----------------------------------------------------------------
Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
[...]

CheckNetIsolation.exe delete attempt - Alternatingly fails with 1753 - 6D9 or 1115 - 45B error like this:

PS C:\WINDOWS\system32> CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1753 - 6D9
PS C:\WINDOWS\system32> CheckNetIsolation.exe loopbackexempt -d -p=S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
Error occurred 1115 - 45B

Now with psexec regedit:

editing value - Cannot edit DebugedLoopbackApps: Error writing the value's new contents - OK, lets continue


Looking at Permissions:

You do not have permission to view the current permission settings for Properties, but you can make permission changes. - Ok, lets continue


So its "empty", I can indeed see nothing / no permissions are set

Setting Permissions / full control:

My mistake: NEED TO BE OWNER AS WELL!

Potentially correct settings?
DebugedLoopbackApps - S-1-15-2-490905099-2794809881-2632752266-3514030558-4166392763-3416490339-321513134
PolicyVersion - 21e(hex)

So I clicked AppCs - right click / Permissions -> ok -> Add user / full control -> Advanced -> Set owner! -> Apply -> Ok

The system log:

Old Event 7024
The Windows Defender Firewall service terminated with the following service-specific error:
Access is denied.

After I decided to test-delete the whole AppCs branch:

New Event 7024
The Windows Defender Firewall service terminated with the following service-specific error:
The system cannot find the file specified.

I restored the AppCs branch, So now my registry looks nice, but my firewall is still not working.

Also I cannot use the CheckNetIsolation tool anymore.

PS C:\WINDOWS\system32> CheckNetIsolation.exe loopbackexempt -s
Error occurred 1753 - 6D9

I am open for more suggestions :)

I couldn't figure it out.

I did a BIOS update to the mobo, this re-enabled the fancy apparmour feature. So I disabled the feature again.

Then I did a scratch install of Win 11 and now the firewall works as it should.

So good luck to all of you.
 

Vote:

timoh

New member
Joined
Jan 8, 2023
Messages
4
Reaction score
0
Somehow I feel that this is not related to AsusUpdateCheck. I did the following.

1. Disabled Armoury Crate download from BIOS.
2. Was about to stop Asus update service and realised that is was stopped.
3. Replaced AsusUpdateCheck.exe with a text file in system32 directory.
4. Installed Win11 from ISO and selected keep files and apps + do not download updates.
=>

Defender firewall works and CheckNetIsolation.exe loopbackexempt -s shows empty list.

But then I did Windows update.
=>

Windows Defender stopped working.

System log: Event id 7024. The Windows Defender Firewall service terminated with the following service-specific error: The parameter is incorrect.

CheckNetIsolation.exe loopbackexempt -s shows 700 entries like which I cannot delete.

Name: AppContainer NOT FOUND
SID: S-1-15-2-490905099-2794809881-2632752266-351403....

Timo
 

Vote:

Sky187

New member
Joined
Jan 29, 2023
Messages
1
Reaction score
0
Have you tried running ResEdit using the PSEXEC method I used below? That was the only way I could successfully get rid of any pesky registry values..

Post in thread 'Windows 11 Defender Firewall Will Not Load'
https://www.windows11forums.com/threads/windows-11-defender-firewall-will-not-load.355/post-3766
Having the exact issue as described in here, just reverted back to Windows 10 for now as i can't be bothered spending too much time on this as i don't really need the upgrade yet.

For future reference, could you post a step-by-step guide on how to use PSEXEC to forcibly remove these registry keys? I have a laptop that came with Windows 11, and the DebuggedLoopbackApps entry does not exist there. Therefore it makes sense it can just be deleted on my desktop too.

Trying to gain ownership through the Registry Editor gave me a headache, as it seemed impossible to add permissions through there.
 

Vote:

Juice6694

New member
Joined
Feb 3, 2023
Messages
1
Reaction score
0
Thanks , I was able to fix my broken windows with the methods mentioned above.

Full story

Short story

The cause of the broken firewall (and broken Microsoft Store due to the firewall is broken) is because the value of this specific key is corrupted:



Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpssvc\Parameters\AppCs

Key DebugedLoopbackApps



It could be corrupted while in Windows 10 before the upgrade to 11. Or corrupted as 11.

The reason why it is broken is unclear, but it seems upgrade from windows 10 to 11 is a possible cause.



The fix:



to fix this key, a normal user has no permssion to edit this key.

And it seems the normal user can not take ownership of the key either.



The easy solution is to use psexec/psexec64 from system internal suite.



Download that.

Open cmd as admin, run this :

psexec64.exe -s -i cmd.exe then run regedit.exe

or just

psexec64.exe -s -i regedit.exe



Navigate to the key, right click on AppCs folder, select permission,

change SYSTEM user's permission to Full Controll.



Delete the key DebugedLoopbackApps , then recreate it without setting value.

Reboot the system.

Then the firewall should have been back to business.

MS Store should also be happy now.

Your Paint, Caculator, Notepad etc should have also been good for running or install or upgrade.
 

Vote:

angd163

Member
Joined
Nov 25, 2022
Messages
7
Reaction score
0
for what it is worth.

I have done three upgrades to windows 11. all have various motherboards. The system with an asus mobo a h470 is the one giving me grief with problems relating to the microsoft store and windows defender firewall. Errors saying that the system is shutting down. error codes 0x45B and 0x8007045b.

I have tried lots of suggestions but nothing seems to work. some suggestions that are beyond my skill, so i didn't try those. I cant even turn the defender firewall off.

I have turned on the firewall from avast. but it does not show up as a provider in the windows setting security settings. Is it working? thanks for any advice
 
Last edited:

Vote:

angd163

Member
Joined
Nov 25, 2022
Messages
7
Reaction score
0
all the suggestions i have tried by using cmd and powershell and DISM seems to make the situation worse not better.
Has anyone with this issue and with an asus motherboard tried a reset of windows, and has the defender firewall then loaded correctly?

TIA
 
Last edited:

Vote:

timoh

New member
Joined
Jan 8, 2023
Messages
4
Reaction score
0
Thanks , I was able to fix my broken windows with the methods mentioned above.

Full story

Short story

The cause of the broken firewall (and broken Microsoft Store due to the firewall is broken) is because the value of this specific key is corrupted:



Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpssvc\Parameters\AppCs

Key DebugedLoopbackApps



It could be corrupted while in Windows 10 before the upgrade to 11. Or corrupted as 11.

The reason why it is broken is unclear, but it seems upgrade from windows 10 to 11 is a possible cause.



The fix:



to fix this key, a normal user has no permssion to edit this key.

And it seems the normal user can not take ownership of the key either.



The easy solution is to use psexec/psexec64 from system internal suite.



Download that.

Open cmd as admin, run this :

psexec64.exe -s -i cmd.exe then run regedit.exe

or just

psexec64.exe -s -i regedit.exe



Navigate to the key, right click on AppCs folder, select permission,

change SYSTEM user's permission to Full Controll.



Delete the key DebugedLoopbackApps , then recreate it without setting value.

Reboot the system.

Then the firewall should have been back to business.

MS Store should also be happy now.

Your Paint, Caculator, Notepad etc should have also been good for running or install or upgrade.

<- This. I have tried almost every possible suggestion and this finally fixed the problem.

Timo
 

Vote:

angd163

Member
Joined
Nov 25, 2022
Messages
7
Reaction score
0
hey timo.

thanks, but just a couple of questions

1.do i need to do the psexec step? can i not just use cmd open the registry and then navigate to the entry, change the permissions,

2. delete the key debugdLoopbackASpps

3. the next step to recreate i don't know how to do that, could you please supply me with how that is done. or where i can find an easy to understand way to do this.

Thanks
 

Vote:

angd163

Member
Joined
Nov 25, 2022
Messages
7
Reaction score
0
just an update. i did a re upgrade of windows 11, no files or apps were deleted.

after it finished about 2 hours. the windows firewall was working again. I thin did a restart anb while restarting it did an update but no updates were showing. any way the update was very quick. when i logged back in the firewall returned to its behaviour as it was happening before. 2 hours later and no positive result. BTW the re upgrade did fix some other issues i was having.

Seems to me the issue has to do with asus motherboards, my other mini pc and laptop upgraded to win11 with no issues.
Wont be buying asus MB again

Hope that info helps someone.
 

Vote:

timoh

New member
Joined
Jan 8, 2023
Messages
4
Reaction score
0
hey timo.

thanks, but just a couple of questions

1.do i need to do the psexec step? can i not just use cmd open the registry and then navigate to the entry, change the permissions,

2. delete the key debugdLoopbackASpps

3. the next step to recreate i don't know how to do that, could you please supply me with how that is done. or where i can find an easy to understand way to do this.

Thanks
I am not a Windows expert but here's my two cents.

1. Yes. Without that you don't have permissions to do the registry steps.
3. I am not currently able to access any Windows machine as I am on vacation. And far as I remember DebugedLoopbackApps was a registry value rather than a key. But you can find more about registry keys and values here https://www.lifewire.com/what-is-a-registry-value-2626042

Hopefully this helps.

Timo
 

Vote:

angd163

Member
Joined
Nov 25, 2022
Messages
7
Reaction score
0
I am not a Windows expert but here's my two cents.

1. Yes. Without that you don't have permissions to do the registry steps.
3. I am not currently able to access any Windows machine as I am on vacation. And far as I remember DebugedLoopbackApps was a registry value rather than a key. But you can find more about registry keys and values here https://www.lifewire.com/what-is-a-registry-value-2626042

Hopefully this helps.

Timo
thanks for your help. Enjoy your vacation
 

Vote:

mlrpRed

New member
Joined
Apr 4, 2023
Messages
1
Reaction score
0
I found a fix that worked for me. Following the thread from Event Viewer regarding "the parameter is incorrect," I went into the Registry Editor and checked out the Windows Defender Firewall Service's parameters:

Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\mpssvc\Parameters\AppCs

For me, the DebugedLoopbackApps variable was corrupt, so I had to delete it, create a new one, and set the value to what it was in another working Windows 10 installation:

S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194-4256926629-1688279915-2739229046-3928706915,S-1-15-2-3624051433-2125758914-1423191267-1740899205-1073925389-3782572162-737981194-4043415302-551583165-304772019-4009825106

If you're having trouble modifying the register values, you need to set yourself as the owner in the Advanced permissions settings of the registry folder. Check the out the steps to do that here:


I don't know how you figured this out but it sure fixed my problem. Thank you!
 

Vote:

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top