You can disable Microsoft Defender temporarily or permanently, but understand what you're losing first
Microsoft Defender is built into Windows and runs by default. You can turn it off, but doing so removes your system's real-time protection against malware, viruses, and other threats — even if you install another antivirus program. Most people who disable Defender do so because they're installing a different security tool and want to avoid running two antivirus programs at once, which can slow your computer or cause conflicts.
If you're disabling Defender to make room for another antivirus, that's a reasonable choice. If you're disabling it because you think you don't need antivirus protection, that's a genuine security risk. Before you turn it off, decide whether you're replacing it with something else or leaving your system unprotected.
Key Takeaways
- Disabling Defender through Settings is temporary — it turns back on after a Windows update or restart, depending on your Windows version.
- Turning off Defender through Group Policy or Registry Editor is more permanent but requires Windows Pro or higher, and still resets after major updates.
- Running two antivirus programs at once slows your computer and can cause conflicts, so disable Defender only if you're installing a different antivirus tool.
- If you disable Defender without replacing it, your computer has no real-time malware protection and is vulnerable to infection.
Disable Defender temporarily through Settings
The quickest way to turn off Defender is through the Windows Settings app. This method works on all Windows versions and is the easiest to reverse.
Open Settings (press Windows key + I), then go to Privacy & Security on the left sidebar. Click Windows Security, then click Virus & threat protection. Under "Virus & threat protection settings," click Manage settings. Toggle off Real-time protection. Windows will ask for confirmation — click Yes.
This disables Defender's real-time scanning immediately. However, this change is temporary. On most Windows 11 systems, Defender turns back on automatically after a restart. On Windows 10, it may stay off longer, but a Windows update will re-enable it. If you want a more permanent solution, use the Group Policy method below.
Disable Defender permanently through Group Policy (Windows Pro and higher only)
If you have Windows Pro, Enterprise, or Education edition, you can use Group Policy Editor to disable Defender more permanently. This method survives restarts but not major Windows updates.
Press Windows key + R to open the Run dialog. Type gpedit.msc and press Enter. Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Find the policy called Turn off Microsoft Defender Antivirus and double-click it. Select Enabled, then click Apply and OK.
Restart your computer for the change to take effect. Defender will remain off until you reverse this setting or a major Windows update resets it. To turn Defender back on, return to the same policy and select Not Configured or Disabled.
If you have Windows Home edition, Group Policy Editor is not available. You'll need to use the Registry Editor method instead, or stick with the Settings method.
Disable Defender through Registry Editor (all Windows versions)
Registry Editor is available on all Windows versions and allows a more permanent disable than Settings, though updates can still re-enable Defender.
Press Windows key + R, type regedit, and press Enter. Navigate to HKEY_LOCAL_MACHINE > SOFTWARE > Policies > Microsoft > Windows Defender. If the Windows Defender folder doesn't exist, right-click on Windows, select New > Key, and name it Windows Defender.
Right-click in the empty space on the right side of the Registry Editor window, select New > DWORD (32-bit) Value, and name it DisableAntiSpyware. Double-click the new entry and set the value to 1, then click OK. Restart your computer.
Defender will be disabled after the restart. To re-enable it, delete the DisableAntiSpyware entry or change its value back to 0. Be careful when editing the Registry — mistakes here can cause Windows problems. If you're not comfortable with Registry Editor, use the Settings or Group Policy method instead.
What happens when you disable Defender without a replacement
If you turn off Defender and don't install another antivirus program, your computer loses real-time protection against malware, ransomware, and viruses. Windows will show a warning in Settings that your device is not protected, but that warning alone doesn't stop an infection.
Malware can install silently in the background, steal your passwords, encrypt your files for ransom, or use your computer to attack other systems. You may not notice anything is wrong until significant damage has occurred. If you're disabling Defender, have a specific replacement antivirus tool ready to install immediately.
Re-enable Defender after disabling it
If you disabled Defender through Settings, it will turn back on automatically after a restart or Windows update on most systems. To turn it back on manually, return to Privacy & Security > Windows Security > Virus & threat protection > Manage settings and toggle Real-time protection back on.
If you disabled it through Group Policy, open Group Policy Editor again, navigate to the same policy, and select Not Configured or Disabled. If you used Registry Editor, delete the DisableAntiSpyware entry or set its value to 0. Restart your computer in either case.
After re-enabling, Defender will scan your system for threats. This scan can take several minutes depending on how many files you have. Let it finish before using your computer for other tasks.
Why Defender turns back on after updates
Microsoft treats Defender as essential to Windows security, so major updates reset it to the default state — on. This is intentional. Even if you disable Defender through Group Policy or Registry, a Windows 10 or Windows 11 feature update will re-enable it. Monthly security updates may also reset it.
If you're using a different antivirus program and Defender keeps turning back on, check your antivirus software's settings. Many antivirus programs have an option to disable Defender automatically when they install, or to keep it disabled. Some programs manage this through a compatibility mode. If your antivirus doesn't offer this, you'll need to disable Defender again after each major Windows update.
Frequently Asked Questions
Can I disable Defender if I'm using Norton, McAfee, or another antivirus?
Yes, and you should. Running two antivirus programs at once causes slowdowns and conflicts. Most third-party antivirus installers will disable Defender automatically, but check your antivirus settings to confirm. If it didn't disable Defender, do it manually through Settings before running both programs together.
Will disabling Defender speed up my computer?
Slightly, because Defender uses CPU and disk resources for scanning. However, the slowdown is usually noticeable only on older computers or during scans. If you're disabling Defender just for speed, you're trading security for a small performance gain — not a good trade. If speed is the issue, upgrade your RAM or switch to a lighter antivirus instead.
What if I see "Tamper Protection" when I try to disable Defender?
Tamper Protection prevents changes to Defender settings, even by you. It's on by default in Windows 11. To disable Defender, you must first turn off Tamper Protection in Privacy & Security > Windows Security > Virus & threat protection > Manage settings. Scroll down and toggle off Tamper Protection. Then disable Defender as described above.
Does disabling Defender affect Windows Firewall?
No. Defender and Windows Firewall are separate tools. Disabling Defender turns off antivirus scanning but leaves your firewall active. Your firewall still blocks unauthorized network connections, but you lose protection against malware files already on your system.
Can I schedule Defender scans if I disable real-time protection?
Yes. You can disable real-time protection but keep scheduled scans running. This is useful if you want to reduce constant scanning but still check for threats periodically. However, scheduled scans don't protect you between scans — malware can install and run in the gaps. This approach works only if you're confident your other security measures prevent infection.