You can disable Windows Defender, but you should understand what you're losing first
Windows Defender is built into Windows 10 and 11 as your default antivirus protection. Disabling it means your computer no longer has active scanning for malware, viruses, or suspicious files — unless you install a different antivirus program first. Most people who want to turn it off are either switching to third-party antivirus software, troubleshooting a conflict with another program, or working on a machine they control completely in an isolated environment.
The permanent methods differ depending on your Windows version and whether you have administrator access. Some approaches disable Defender temporarily (it may turn back on after updates), while others disable it more completely. None of them are hidden — Windows will tell you Defender is off, usually with a red warning icon in your system tray.
Key Takeaways
- Disabling Windows Defender removes your active antivirus protection, so install a replacement antivirus program before you turn it off.
- The Settings app method (Settings > Privacy & Security > Virus & threat protection) is the simplest and works on most Windows 10 and 11 machines.
- Group Policy Editor (gpedit.msc) provides a more permanent disable on Windows Pro, Enterprise, or Education editions, but does not exist on Home editions.
- Windows may re-enable Defender after major updates, so check periodically if you need it to stay off long-term.
- If you do not have administrator access, you cannot disable Defender — only an admin account can make this change.
Disabling Defender through Settings (works on all Windows versions)
This is the most straightforward method and works whether you have Windows Home, Pro, Enterprise, or Education. Open Settings by pressing Windows key + I, then navigate to Privacy & Security in the left sidebar. Click Virus & threat protection, then click Manage settings under "Virus & threat protection settings."
You will see a toggle for Real-time protection. Click it to turn it off. Windows will ask you to confirm — click Yes. The toggle will turn gray, and Defender will stop scanning files in real time. This change takes effect immediately, but it may revert after Windows updates or after you restart your computer.
While you are in this menu, you can also disable Cloud-delivered protection and Automatic sample submission by toggling those off as well. These settings control whether Defender sends suspicious files to Microsoft for analysis and whether it learns from those submissions.
Using Group Policy Editor for a more permanent disable (Windows Pro, Enterprise, Education only)
If you have Windows Pro, Enterprise, or Education (not Home), you can use Group Policy Editor to disable Defender more thoroughly. Press Windows key + R to open the Run dialog, type gpedit.msc, and press Enter. If you see an error saying the file was not found, you have Windows Home edition and this method will not work.
In Group Policy Editor, navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Look for the policy called Turn off Microsoft Defender Antivirus. Double-click it, select Enabled, and click OK. Close Group Policy Editor.
This method disables Defender at a deeper level than the Settings app, but it is not truly permanent — Windows updates can reset Group Policy settings, and you should verify the setting is still in place after major updates. You can check by returning to the same location in Group Policy Editor and confirming the policy still shows Enabled.
Disabling Defender through Services (advanced method)
You can also disable Defender by stopping the Windows Defender service. Press Windows key + R, type services.msc, and press Enter. Scroll down to find Windows Defender Advanced Threat Protection Service and Windows Update Medic Service. Right-click each one, select Properties, and change the Startup type dropdown to Disabled. Click OK.
If the service is currently running, you will also see a Stop button in the Properties window — click it to stop the service immediately. This method is more technical than using Settings or Group Policy, and mistakes here can cause other Windows functions to behave unexpectedly. Use this only if the other methods do not work for you.
What to do before you disable Defender
Before you turn off Windows Defender, install a replacement antivirus program. Leaving your computer without any active antivirus protection, even for a short time, exposes you to malware. Download and install your chosen antivirus software while Defender is still running, then disable Defender only after the new program is fully installed and running.
If you are disabling Defender because it conflicts with another program, check whether that program has its own antivirus or security features. Some software (like some VPN applications or system utilities) includes built-in protection that may be sufficient on its own, but you should verify this before relying on it. If the conflicting program does not include antivirus protection, find a different antivirus that does not conflict instead of running unprotected.
Why Defender might turn back on after you disable it
Windows 10 and 11 automatically re-enable Defender if no other antivirus program is detected. If you disable Defender but do not install a replacement, Windows will turn it back on after a few days. This is a safety feature — Microsoft does not want computers running without protection.
Major Windows updates can also reset Defender to its default state, turning it back on even if you disabled it through Group Policy. After installing a large update (like a version upgrade from 21H2 to 22H2), check your Defender settings to confirm they are still as you set them. If Defender has re-enabled, you will need to disable it again using the same method you used before.
Checking whether Defender is actually off
After you disable Defender, verify it is off by opening Settings again and returning to Privacy & Security > Virus & threat protection. The status at the top should show "No security provider" or "Virus & threat protection is managed by your organization" (if you used Group Policy). If it still shows "Windows Defender" with a green checkmark, the disable did not take effect.
You can also check the system tray (the icons in the bottom right of your taskbar). If Defender is off, you should see a red or yellow warning icon indicating that your antivirus protection is not active. If you see a green checkmark, Defender is still running.
Frequently Asked Questions
Will disabling Defender slow down my computer?
Disabling Defender may free up a small amount of CPU and memory, but the difference is usually not noticeable on modern computers. If you are disabling it to fix a performance problem, the real issue is likely something else — check your Task Manager (Ctrl + Shift + Esc) to see what is actually using your resources.
Can I disable Defender without administrator access?
No. Disabling Defender requires administrator privileges on your account. If you do not have admin access, you cannot disable it. Ask the person who manages your computer (your IT department, parent, or device owner) to make the change for you.
What happens if I disable Defender and do not install another antivirus?
Your computer will have no active antivirus protection, making it vulnerable to malware and viruses. Windows will re-enable Defender automatically after a few days if it detects no other antivirus program is running. Do not leave your computer unprotected — install a replacement antivirus before disabling Defender.
Does disabling Defender affect Windows Firewall?
No. Windows Firewall is separate from Defender and will continue running even if you disable Defender. Firewall controls what network traffic can reach your computer, while Defender scans files for malware. You can disable one without affecting the other.
Can I re-enable Defender after I disable it?
Yes. Use the same method you used to disable it — toggle Real-time protection back on in Settings, or change the Group Policy setting back to Not Configured. Defender will resume scanning immediately.