Fix it now
The switch in the interface does nothing because a Windows service underneath refused to start, and Windows publishes exactly why. 1068 is a dependency that failed. 1069 is a logon failure. 1064 is the service crashing on a control request. 1073 is a duplicate registration.
services.msc
- Restart the machine and try the toggle once more before doing anything else.
- Check the subscription. McAfee lists an expired subscription among the critical protection problems on its home page, in the same list as real-time scanning being off, and no service work re-enables a feature the entitlement has switched off.
- In
services.msc, find the services whose display names begin with McAfee and try to start any that are stopped. Note the number in any failure dialog – that number is the diagnosis. - For 1068, open the service’s Properties and read the Dependencies tab, then start what it relies on first. For 1069, open the Log On tab and set it back to Local System account.
- Open Windows Security and confirm under Virus & threat protection that no second third-party antivirus is registered.
- If services crash on start or Windows reports one already exists, remove McAfee with MCPR, restart, and install a fresh package.
To reach the setting itself, McAfee’s own help gives the route as: on the Home Page click Real-Time Scanning, then Real-Time Scanning settings, then Turn on.
If scanning reports as on and survives a restart, you are done. If the toggle refuses without any service error, the next section covers the two conditions that produce that.
Why it happens
Real-time protection is not a setting, it is a driver. McAfee registers a file system filter that sits in the path of every file operation, and a set of user-mode services that configure it, feed it definitions and report to the interface. If those services are not running, the driver is either not loaded or not being managed, and the interface has nothing to switch on.
That is why the service number matters more than the message in the McAfee window. Windows tells you precisely why a service refused to start, and Microsoft publishes each of these: the dependency service or group failed to start; the service did not start due to a logon failure; an exception occurred in the service when handling the control request; the specified service already exists. Four different sentences, four different repairs.
Two other conditions produce the same visible symptom with no service broken at all. A second real-time scanner competing for the same file system callbacks can leave both products half-functional. And an expired subscription takes the feature away by design – McAfee’s own help puts an expired subscription and real-time scanning being off in the same list of critical protection problems, and Microsoft describes a non-Microsoft product that expires as one that stops providing real-time protection. People spend hours on that one because the interface presents it as a switch that will not stay on.
A dependency service is stopped or disabled
You have this one if Starting a McAfee service reports 1068, and other unrelated services on the machine also misbehave.
- Open the service’s Properties and read the Dependencies tab to see exactly what it needs.
- Confirm Remote Procedure Call (RPC) and RPC Endpoint Mapper are Running and set to Automatic.
- Start the dependencies first, then the McAfee service, then check the toggle again.
- Reverse any service-disabling tweak or optimiser profile applied to this machine, and restart.
Microsoft’s text for 1068 names a dependency service or group. A whole load-order group failing is why unrelated services on the same machine often fail together.
The service is running under the wrong account
You have this one if The start attempt reports 1069, often on a machine where an account password was recently changed.
- Open the service’s Properties and select the Log On tab.
- Set it back to Local System account unless you have a documented reason for anything else.
- Apply, start the service, and confirm it stays running after a restart.
The service crashes while handling a control request
You have this one if The start attempt reports 1064, and the service appears briefly in services.msc before stopping.
- Read the Application log in Event Viewer at that timestamp for an Application Error naming the service process.
- Do not try to repair the binary. Remove McAfee with MCPR, restart, and install a freshly downloaded package.
- If other software is also failing, run
sfc /scannowandDISM /Online /Cleanup-Image /RestoreHealthbefore reinstalling.
A duplicate service registration is in the way
You have this one if Windows reports 1073, that the specified service already exists, typically after a failed upgrade or uninstall.
- Do not delete or recreate service entries by hand.
- Run MCPR and restart the machine when it asks.
- Install a fresh package and sign in to your McAfee account.
A second security product owns the file system filter
You have this one if Another antivirus is installed, or was removed without its vendor tool, and both products behave oddly.
- Remove the other product with its own vendor removal utility and restart.
- In an elevated Command Prompt, run
fltmc filtersto see which filter drivers are still loaded. - Reinstall or repair McAfee once the machine boots with a single scanner.
Microsoft Defender is not the conflict. Microsoft documents Defender moving into disabled mode by itself when a non-Microsoft antivirus is registered on a Windows client. A second third-party suite is a different matter.
The subscription has expired
You have this one if Services are running, nothing appears in the System log, and the toggle simply will not stay on.
- Open the McAfee app and read the subscription state, then confirm it in your McAfee account.
- Renew or apply a valid licence to the account the app is signed into.
- Restart so the client re-reads its entitlement, then check the toggle again.
Full reference
Microsoft’s published text for each number
| Code | Constant | Published meaning |
|---|---|---|
1068 |
ERROR_SERVICE_DEPENDENCY_FAIL | The dependency service or group failed to start |
1069 |
ERROR_SERVICE_LOGON_FAILED | The service did not start due to a logon failure |
1064 |
ERROR_EXCEPTION_IN_SERVICE | An exception occurred in the service when handling the control request |
1073 |
ERROR_SERVICE_EXISTS | The specified service already exists |
Reading the symptom when there is no number
| What you see | What it means here |
|---|---|
| A dependency failed to start | Something the McAfee service needs is stopped or disabled |
| A logon failure | The service account was changed away from its default |
| An exception while handling a control request | The service is damaged and crashes on start |
| The service already exists | A duplicate registration, usually after a bad uninstall |
| Services start, scanning still off | Subscription state, or a second antivirus in the way |
Are you actually protected?
Check rather than hope, because this is the failure mode where the answer is most often no. Microsoft documents that on a Windows client with a non-Microsoft antivirus registered, Microsoft Defender goes into disabled mode automatically. If McAfee holds that registration while its services are dead, Defender has stood aside for a product that is not scanning – the worst of both worlds, and nothing on screen tells you so.
Microsoft also documents the escape: Defender re-enables itself if the non-Microsoft product expires, is uninstalled, or otherwise stops providing real-time protection. That is designed for exactly this situation, but it depends on McAfee actually reporting that it has stopped. A service that fails to start may not report anything at all. So open Windows Security, read what Virus & threat protection says, and if nothing is genuinely protecting the machine, treat it as urgent rather than as a switch to fiddle with later.
Turning it back on once the services are healthy
- Confirm every McAfee service in
services.mscshows Running with its intended startup type. - On the McAfee Home Page, click Real-Time Scanning, then Real-Time Scanning settings, then Turn on.
- Alternatively use the notification McAfee shows in the protection status area on the Home Page, which carries a Turn on action for exactly this problem.
- Restart and confirm the setting holds. A toggle that reverts after a reboot is a service or entitlement problem, not a setting problem.
After a Windows feature update
Feature updates occasionally reset service configurations or leave a driver mismatched with a newer build, and a service that started for years can begin failing on the first boot after one. Check for a newer McAfee build before reinstalling: a product that has not been updated in a while is the likeliest thing to be out of step with a new Windows build, and installing the current package is less disruptive than a full removal.
What not to do
- Do not delete or recreate McAfee service entries by hand. That is what turns a recoverable duplicate into an unrecoverable one.
- Do not install a second antivirus as a workaround. It produces the exact class of fault described here.
- Do not leave real-time scanning off and rely on periodic scans. Periodic scanning is not equivalent cover.
- Do not disable services on a hunch to test a dependency theory. Set anything you changed back to its default startup type first, then retest.
When a licence is the actual fix
If the services are healthy and it is the subscription that has run out, the feature is off by design and the licence is the only thing that turns it back on. Arco supplies McAfee Total Protection and can check which plan covers the devices you actually run before you commit to one. That is not the only legitimate answer, and most readers of this page do not need it: the majority of these failures are service faults that cost nothing to fix, and the subscription is only the culprit when the services are running cleanly and the toggle still refuses to hold. If you would rather not renew at all, remove McAfee cleanly with MCPR and let Microsoft Defender take over – Microsoft documents that it re-enables itself once the non-Microsoft product stops providing real-time protection, so you get working real-time scanning on the same machine today at no cost.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
1068 |
The dependency service or group failed to start | Microsoft Learn |
1069 |
The service did not start due to a logon failure | Microsoft Learn |
1064 |
An exception occurred in the service when handling the control request | Microsoft Learn |
1073 |
The specified service already exists | Microsoft Learn |
Confirm the fix worked
- Real-time scanning shows as on in the McAfee app and stays on after a restart.
- All McAfee services show Running in
services.mscwith their intended startup types. - Windows Security under Virus & threat protection lists one active antivirus provider.
- The System log shows no new Service Control Manager errors after a reboot.
- The McAfee Home Page reports its protection status as secure, with no outstanding notifications.
Questions people ask about this
Is Windows unprotected while McAfee’s real-time scanning is off?
Check, do not hope. Microsoft documents Defender going into disabled mode when a non-Microsoft antivirus is registered. If McAfee holds the registration but is not scanning, nothing is – which is why Windows Security is the first place to look, not the last.
Should I enable Microsoft Defender as well?
You cannot run both as real-time scanners, and you should not want to. Either fix McAfee or remove it and let Defender resume. Microsoft documents that it comes back automatically once the other product is uninstalled or stops providing real-time protection.
Does this always mean I need to renew?
No. Most cases are service faults and cost nothing to fix. The subscription is only the answer when the services are healthy, the System log is quiet, and the toggle still refuses to hold.
Why did this start after a Windows update?
Feature updates occasionally reset service configurations or leave a driver mismatched with a newer build. Check for a current McAfee build first; installing it is less disruptive than a full removal and reinstall.
What is the difference between 1068 and 1064?
1068 means something the service depends on failed first, so it never got to run. 1064 means it did run and threw an exception while handling a control request. The first is a dependency problem, the second is a damaged installation.
