How to Disable Windows Defender in Windows 11 & 10
Windows Defender, now commonly presented as Microsoft Defender Antivirus within the Windows Security app, is Windows’ built-in protection against viruses, malware, ransomware, and other security threats. In most situations, you should keep it enabled because it provides real-time protection without requiring a separate antivirus program.
However, there are times when you may need to temporarily disable Windows Defender. For example, a legitimate application might be incorrectly detected as a threat, you may be troubleshooting software, or you may need to perform a task that conflicts with real-time antivirus scanning.
The important thing to understand is that disabling Defender reduces your computer’s protection. For that reason, the safest approach is usually to turn off Real-time protection temporarily and turn it back on as soon as you finish your task.
The steps below explain how to disable Windows Defender in Windows 11 and Windows 10.
How to Disable Windows Defender in Windows 11 & 10

There is no single universal switch called “Disable Windows Defender” in modern Windows. Instead, Windows Security provides individual protection controls, such as Real-time protection, Cloud-delivered protection, and Tamper Protection.
For most users, you do not need to completely remove or permanently shut down Microsoft Defender. If your goal is simply to stop Defender from interfering with a legitimate program temporarily, disabling Real-time protection is normally the appropriate option.
Before changing anything, make sure you understand what you are disabling and avoid downloading or running unknown files while your antivirus protection is turned off.
Step 1: Open Windows Security
The first step is to open the built-in Windows Security application. You do not need to download anything because Windows 11 and Windows 10 include Windows Security by default.
On Windows 11, select Start, type Windows Security, and then open the Windows Security app from the search results. You can also navigate through Start > Settings > Privacy & security > Windows Security > Open Windows Security.
On Windows 10, select Start, type Windows Security, and open the application. Another navigation path is Start > Settings > Update & Security > Windows Security > Virus & threat protection.
Once Windows Security opens, you will see several security areas. For this task, the section you need is Virus & threat protection.
Step 2: Open Virus & Threat Protection
Now you need to access the settings that control Microsoft Defender Antivirus.
Go to Windows Security > Virus & threat protection. On the Virus & threat protection page, look for the section labeled Virus & threat protection settings.
Select Manage settings. This page contains the controls for Defender’s real-time antivirus functionality.
If you cannot find the settings, make sure you are using an account with the necessary permissions and that another antivirus application has not taken over antivirus protection. Windows can automatically change how Microsoft Defender operates when a compatible third-party antivirus program is installed.
Step 3: Turn Off Real-Time Protection
This is the main method for temporarily disabling Windows Defender’s active antivirus scanning.
Go to Windows Security > Virus & threat protection > Manage settings > Real-time protection. You will see a switch labeled Real-time protection. Turn this switch Off.
Windows may display a User Account Control prompt asking whether you want to allow the change. Select Yes if you initiated the change yourself.
Once disabled, Microsoft Defender’s real-time scanning will temporarily stop monitoring files and applications as they are accessed. This can be useful when troubleshooting a program that is being incorrectly blocked or when testing whether antivirus scanning is causing a particular problem.
Keep in mind that this is generally a temporary change. Windows may automatically turn Real-time protection back on after some time or after a restart. That behavior is intentional because Microsoft wants to minimize the period during which your computer remains unprotected.
Step 4: Disable Cloud-Delivered Protection Only If Necessary
If Real-time protection is not the actual cause of the problem you are troubleshooting, you may not need to disable additional Defender features.
However, some troubleshooting situations may involve Cloud-delivered protection. This feature helps Microsoft Defender identify suspicious or newly emerging threats using Microsoft’s cloud-based threat intelligence.
Go to Windows Security > Virus & threat protection > Manage settings > Cloud-delivered protection. If you have a specific reason to test whether this feature is affecting an application, you can temporarily turn it off.
For normal users, though, there is usually no reason to disable Cloud-delivered protection simply because you want to stop an application from being scanned. Turning off Real-time protection for the shortest possible period is the more targeted approach.
After testing, return to the same location and turn the setting back on.
Step 5: Consider Adding an Exclusion Instead
If a legitimate program, folder, or file is repeatedly detected by Microsoft Defender, completely disabling antivirus protection may be unnecessary.
Windows provides an Exclusions feature that allows you to tell Microsoft Defender not to scan a specific file, folder, file type, or process. This can be a better solution when you trust the software and understand why Defender is detecting it.
Go to Windows Security > Virus & threat protection > Manage settings > Exclusions > Add or remove exclusions.
Select Add an exclusion, choose the appropriate exclusion type, and then select the specific item you want to exclude.
Be very careful with exclusions. An excluded folder is no longer protected by Microsoft Defender’s normal scanning mechanisms, so malicious software placed inside that location could potentially avoid detection. Only exclude files or folders that you trust and have verified.
For developers and advanced users, exclusions can sometimes be useful for trusted development directories, but they should be used narrowly rather than excluding entire drives or large system locations.
Step 6: Turn Real-Time Protection Back On
After completing the task that required Defender to be disabled, restore your protection immediately.
Go to Windows Security > Virus & threat protection > Manage settings > Real-time protection and turn Real-time protection back On.
This is one of the most important steps in the entire process. Leaving antivirus protection disabled for an extended period increases the opportunity for malware to execute without being detected.
If you temporarily disabled other protection settings, return to the same page and restore those settings as well.
Step 7: Check Your Protection Status
Finally, verify that Windows Security considers your system protected.
Go to Windows Security > Virus & threat protection and review the current protection status. You can also return to the main Windows Security dashboard and check whether any security area is reporting an issue.
If you see a warning that Real-time protection is off, turn it back on unless you have a specific and temporary reason to leave it disabled.
It is also a good idea to run a scan after completing your troubleshooting task, particularly if you downloaded or installed software while Defender was disabled.
Go to Windows Security > Virus & threat protection > Scan options, select the scan type you want, and start the scan.
Pros & Cons of Disabling Windows Defender
| Pros | Cons |
| Can help troubleshoot software conflicts involving antivirus scanning. | Your computer has less protection while real-time scanning is disabled. |
| Useful when a trusted application is incorrectly detected or blocked. | Malware can have a better opportunity to execute undetected. |
| Provides a quick way to test whether Defender is causing a particular problem. | Windows may automatically turn protection back on. |
| You can use exclusions instead of disabling protection completely. | Incorrect exclusions can create security vulnerabilities. |
| The settings are built directly into Windows 11 and Windows 10. | Some security controls may be restricted by organization policies or administrator settings. |
FAQs
Can I permanently disable Windows Defender in Windows 11?
Windows is designed to prevent users from casually disabling its built-in antivirus protection permanently. The normal Windows Security interface is intended primarily for temporary changes. Microsoft also uses protections such as Tamper Protection to prevent unwanted applications from changing important security settings.
If your goal is to prevent Defender from interfering with one trusted application, consider using a carefully selected exclusion instead of trying to permanently disable the antivirus.
Why does Windows Defender turn itself back on?
This is expected behavior. Microsoft Defender Antivirus is designed to restore protection when possible because leaving antivirus protection disabled creates a security risk. Depending on your Windows configuration, Real-time protection may automatically reactivate after a period of time or following a restart.
Do I need to disable Windows Defender before installing another antivirus?
Usually, no. When you install a compatible third-party antivirus product, Windows can detect the new security provider and adjust Microsoft’s antivirus behavior automatically. You generally should not manually disable Defender before installing security software unless the software’s official installation instructions specifically require it.
Is it safe to turn off Real-time protection?
Turning it off briefly can be reasonable for troubleshooting, but your computer is less protected while it is disabled. Avoid browsing unfamiliar websites, opening unexpected email attachments, downloading unknown programs, or installing untrusted software during that period.
The safest practice is to complete the required task and immediately restore Real-time protection.
What should I do if Windows will not let me disable Defender?
Your computer may be managed by an organization, administrator, security software, or Windows policy. In that situation, some Defender settings can be unavailable or locked.
If this is a work or school computer, do not attempt to bypass administrator-enforced security controls. Contact the appropriate administrator or IT department instead.
Is disabling Defender better than creating an exclusion?
It depends on what you are trying to accomplish. If you need to troubleshoot a general antivirus conflict, temporarily disabling Real-time protection can help determine whether Defender is involved. If a single trusted application or folder is consistently detected, a specific exclusion may be more appropriate.
However, exclusions should be kept as narrow as possible and used only for software you trust.
Does disabling Windows Defender remove Windows Security?
No. Windows Security is the broader Windows security application, while Microsoft Defender Antivirus is one of the security components it manages. Turning off Real-time protection does not mean that the entire Windows Security application has been removed.
Should I restart my computer after disabling Defender?
A restart usually is not necessary when you temporarily turn Real-time protection off through Windows Security. If you are troubleshooting a particular application, follow that application’s instructions regarding whether a restart is required.
After your troubleshooting is complete, verify that your security protections are active again.
