Windows 11 has no supported, universal switch to permanently remove or disable Microsoft Defender Antivirus. You can temporarily turn off real-time protection, use a registered third-party antivirus as the active provider, or use passive mode in eligible Microsoft Defender for Endpoint configurations—but none of these permanently removes Defender.
Defender can turn back on after a reboot, policy refresh, Windows update, or removal of another antivirus product. Tamper protection can also block changes to protected settings, so the right approach depends on whether you need a temporary troubleshooting change or a different antivirus provider.
Here are five approaches, what each changes, and their limitations.
Before you start: Defender and Windows Security are different
Microsoft Defender Antivirus is the malware-protection engine. Windows Security is the application that displays security status and provides links to settings. Disabling or removing the Windows Security app does not disable Defender Antivirus or Windows Firewall. It can instead leave the interface showing stale or misleading information.
Recommended Free Tools
#1 Best Overall
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
Microsoft no longer supports the old registry trick using DisableAntispyware=1. That value worked only with antimalware platform versions before 4.18.2108.4, released in September 2021. It is not a current Windows 11 solution.
1. Turn off Real-time protection in Windows Security
This is the simplest supported way to stop Defender from actively scanning files for a short time, such as while testing software that Defender incorrectly blocks. It is not a permanent Defender shutdown.
- Open Windows Security from the Start menu.
- Select Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Set Real-time protection to Off.
Windows may turn the setting back on automatically. Other Defender features can remain active, and an administrator’s security policy can override the local setting.
If the switch will not stay off
In Windows Security, go to Virus & threat protection > Virus & threat protection settings and check Tamper protection. When it is enabled, protected Defender settings may ignore changes made through the interface, registry, Group Policy, or other management tools.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchDo not leave real-time protection off longer than necessary. Turn it back on from the same screen when testing is complete.
Rank #2
- Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
- Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
- Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
- Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
- From Sandisk, a brand professional photographers trust to take on assignments.
2. Turn off Tamper protection, then use PowerShell temporarily
If you are troubleshooting a personal device and have administrator permissions, Microsoft’s documented individual-device path lets you turn off Tamper protection in Windows Security. This is not a permanent Defender shutdown. On a managed device, an organization may control the setting.
- Open Windows Security.
- Select Virus & threat protection.
- Select Virus & threat protection settings.
- Set Tamper protection to Off.
- Open PowerShell as an administrator and run:
Set-MpPreference -DisableRealtimeMonitoring $true
This changes real-time monitoring only; it does not permanently remove Defender or guarantee that every Defender component is disabled. To restore real-time monitoring, run:
Set-MpPreference -DisableRealtimeMonitoring $false
To inspect Defender’s current status, run:
Get-MpComputerStatus
On a managed computer, Microsoft Defender for Endpoint, Intune, Group Policy, Configuration Manager, or another administrative policy may override a local PowerShell change.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →About the DisableTamperProtection command
You may see this command recommended online:
Set-MpPreference -DisableTamperProtection $true
Microsoft documents it in the context of Microsoft Defender for Endpoint troubleshooting mode. Troubleshooting mode is a temporary, enterprise-controlled mechanism—not a general Windows 11 consumer switch. When the mode ends, protected settings return to their configured state. The device also needs to be online for the temporary tamper-protection process to work correctly.
3. Configure the Local Group Policy setting
Windows 11 Pro, Enterprise, and Education editions include Local Group Policy Editor. The Defender policy uses counterintuitive wording: enabling Turn off real-time protection tells Windows to turn real-time protection off.
Rank #3
- Capacity Display Variance: 500GB external ssd often appears as around 465GB on Windows. MacOS can show full 500 GB capacity. This is binary calculation difference and doesn’t affect SSD hard drive actual physical storage
- 1050 MB/s Speed: Instantly access to your files with blazing-fast 10Gbps external SSD read up to 1050MB/s and write up to 1000MB/s. LED Light indicates USB SSD instant activity
- Data Security: Solid state drives S.M.A.R.T. health diagnostics and adaptive TRIM optimizing data block management ensures consistent write speeds and extends the longevity of the portable SSD
- USB-C & USB-A Cable: Both cables featuring rapid USB 3.2 Gen2, this USB SSD effortlessly bridges devices, enabling seamless cross-platform file transfers and backup between computers, smartphones, tablets and iPhone
- Always Fast: No slowdowns for large file transfers. With SLC caching (25% of current available capacity allocated as high-speed cache), this external SSD delivers steady 10Gbps for transfers within the cache capacity
- Search for
gpeditin Start and select Edit group policy. - Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Real-time Protection.
- Double-click Turn off real-time protection.
- Select Enabled, then select Apply and OK.
- Close Group Policy Editor. Restart Windows or refresh policy from an elevated Command Prompt with
gpupdate /force.
This policy targets real-time protection, not every Defender Antivirus capability. It also does not defeat Tamper protection. Microsoft says Group Policy changes to protected settings can be ignored when Tamper protection is enabled, and Group Policy cannot turn Tamper protection off.
Local policy can also lose to a higher-precedence organizational policy. Microsoft lists this precedence order for Defender settings, from highest to lowest:
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →| Priority | Management source |
|---|---|
| 1 | Microsoft Defender for Endpoint security settings management |
| 2 | Group Policy |
| 3 | Microsoft Configuration Manager co-management |
| 4 | Microsoft Configuration Manager standalone |
| 5 | Microsoft Intune MDM |
| 6 | Microsoft Configuration Manager with tenant attach |
| 7 | PowerShell Set-MpPreference, MpCmdRun, or WMI |
That is why a policy can look correct in Local Group Policy Editor while Defender continues running on a work or school computer.
4. Install a registered third-party antivirus product
Installing and maintaining a compatible non-Microsoft antivirus product is the closest normal consumer alternative to running Defender as the primary antivirus. Microsoft says Defender capabilities can be disabled or placed into passive mode when another antivirus or antimalware product is installed, recognized, and kept up to date.
- Choose a reputable antivirus product that supports Windows 11.
- Download it from the vendor’s official website or a trusted distribution channel.
- Install it and allow the installer to register it with Windows Security.
- Open Windows Security > Virus & threat protection > Manage providers.
- Confirm that the third-party product is listed as the active antivirus provider.
This is provider takeover, not permanent removal of Defender’s files or services. Windows may keep Defender components installed, and Defender can become active again if the third-party product is removed, disabled, expires, or is no longer recognized as a functioning provider.
Rank #4
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Do not install two full antivirus products and assume they will cooperate. Use Manage providers to verify which product is active.
5. Use Microsoft Defender for Endpoint passive mode
Passive mode is not the same as disabled mode. In passive mode, Defender Antivirus remains present but is not the primary antivirus product. Microsoft documents this mode for devices onboarded to Microsoft Defender for Endpoint and meeting the applicable requirements; it is not a general Windows 11 Home or consumer setting.
On an eligible device, check the mode in an elevated PowerShell window with Get-MpComputerStatus. Inspect the AMRunningMode value:
| Value | Meaning |
|---|---|
Normal |
Defender Antivirus is active. |
Passive mode |
Defender is installed but is not the primary antivirus product. |
EDR Block Mode |
Defender is operating with Endpoint detection and response block mode. |
SxS Passive Mode |
Defender is running alongside another antivirus with limited periodic scanning. |
In applicable Defender for Endpoint scenarios, Microsoft documents ForceDefenderPassiveMode with a value of 1 for passive mode and 0 for active mode. This is an enterprise configuration, not a supported permanent-disable recipe for an unmanaged personal PC.
After Defender has been switched to active mode, Tamper protection may prevent it from returning to passive mode even when ForceDefenderPassiveMode is set to 1. Organizations should manage this state through their Defender for Endpoint configuration rather than relying on an undocumented local workaround.
Best Value
- MADE FOR THE MAKERS: Create; Explore; Store; The T7 Portable SSD delivers fast speeds and durable features to back up any endeavor; Build your video editing empire, file your photographs or back up your blogs all in an instant
- SHARE IDEAS IN A FLASH: Don’t waste a second waiting and spend more time doing; The T7 is embedded with PCIe NVMe technology that brings fast read and write speeds up to 1,050/1,000 MB/s¹, making it almost twice as fast as the T5
- ALWAYS MAKE THE SAVE: Compact design with massive capacity; With capacities up to 4TB, save exactly what you need to your drive – from large working files to game data and everything in between
- ADAPTS TO EVERY NEED: Whether using a PC or mobile phone, count on the T7 for extensive compatibility²; It’s a true team player when it comes to heavy-duty application usage or file-saving
- HI RESOLUTION VIDEO RECORDING: Record Ultra High Resolution (4K 60fs) videos directly onto the T7 Portable SSD with your favorite camera or mobile devices; Supports iPhone 15 Pro Res 4K at 60fps video and more³
What “permanently disable Defender” really means
There are three different goals that are often confused:
| Goal | Appropriate approach | Is it permanent? |
|---|---|---|
| Temporarily stop file scanning | Turn off Real-time protection in Windows Security or use Set-MpPreference |
No |
| Use another antivirus as the main provider | Install and maintain a registered third-party product | Only while that provider remains active |
| Run Defender without primary antivirus duties | Use Defender for Endpoint passive mode where eligible | Controlled by enterprise configuration |
| Remove Defender permanently from Windows 11 | No supported universal Microsoft method | No |
If you only need an application to install or run, consider adding a narrowly scoped exclusion instead of disabling protection globally. Exclusions reduce protection for the selected file, folder, process, or extension, so use them only when you understand the risk and remove them afterward. In managed environments, use supported Defender tools such as Get-MpPreference to inspect configuration rather than assuming registry values show the complete policy state.
Why common internet fixes fail
- Changing
DisableAntispyware: obsolete on current Defender platforms and not a supported Windows 11 permanent-disable method. - Disabling Windows Security: does not disable Defender Antivirus or Windows Firewall.
- Using Group Policy with Tamper protection enabled: protected policy changes can be ignored.
- Running
Set-MpPreference -DisableRealtimeMonitoring $true: changes real-time monitoring only and may be restored or overridden. - Stopping Defender services manually: unsupported, unreliable, and likely to be reversed by Windows or security policy.
FAQ
Can I permanently disable Microsoft Defender on Windows 11 Home?
No supported universal method permanently disables or removes Defender Antivirus on Windows 11 Home. You can temporarily turn off real-time protection or install a properly registered third-party antivirus so it becomes the active provider.
Why does Defender turn back on after I disable it?
Windows can restore real-time protection, Tamper protection can block changes, and organizational tools such as Intune, Group Policy, Configuration Manager, or Defender for Endpoint can enforce their own settings. Defender may also become active again when a third-party antivirus is removed or stops being recognized.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsDoes turning off Windows Security turn off Defender?
No. Windows Security is the status and settings interface. Disabling that app does not disable Microsoft Defender Antivirus or Windows Firewall and can make the displayed status inaccurate.
Is Defender passive mode available to everyone?
No. Microsoft documents passive mode for eligible devices onboarded to Microsoft Defender for Endpoint, generally in enterprise configurations. It is not a general Windows 11 consumer setting.
What should I do if Defender blocks a safe program?
First verify the program’s source and scan it with a trusted service or security product. For controlled testing, temporarily turn off real-time protection or create a narrow, temporary exclusion rather than attempting to disable all Defender features. Restore protection or remove the exclusion when finished.
The Bottom Line
There is no supported, universal way to permanently disable Microsoft Defender Antivirus in Windows 11. Use Windows Security or PowerShell for short troubleshooting sessions, use a registered third-party antivirus if you want another product to take over, or use Defender for Endpoint passive mode only when your organization’s device meets Microsoft’s requirements. Avoid obsolete registry recipes and remember that disabling the Windows Security app does not disable Defender.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

