Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →“Windows Could Not Start The Windows Defender Network Inspection Service On Local Computer” usually refers to the WdNisSvc component, not automatically to malware or a broken firewall. Record the exact error code, confirm which antivirus is active, then check related Defender services before repairing the platform or Windows itself.
Current Microsoft documentation calls the component Microsoft Defender Antivirus Network Inspection Service; older Windows interfaces and search results may still say Windows Defender Network Inspection Service. The service name is WdNisSvc.
The safest repair order is diagnostic rather than destructive: identify the failure, check for another antivirus or management policy, inspect the Defender services and driver, scan for malware, reset Defender, repair Windows components, and only then consider recovery options.
Key takeaways
WdNisSvcis normally listed as Manual, so changing it to Automatic is not a universal fix.WdNisSvc,WdNisDrv,WinDefend, andwscsvcshould be checked together because the network-inspection service is only one part of Microsoft Defender’s protection stack.- A third-party antivirus, organizational policy, damaged Defender files, Windows corruption, a failed driver, or malware can all be possible explanations; the service error alone does not prove infection.
- Microsoft’s current repair sequence uses
MpCmdRun.exeto remove definitions, reset the Defender platform, re-enable Defender, and update signatures. - Run DISM first and
sfc /scannowsecond when Windows component or protected-system-file corruption is suspected. - Microsoft Defender Antivirus Network Inspection Service is separate from Microsoft Defender Firewall; do not disable or reset the firewall merely because the failed service name contains “Network.”
What does the Windows Defender Network Inspection Service error mean?
The error means that Windows could not start WdNisSvc, the Microsoft Defender Antivirus Network Inspection Service. The service is related to Defender’s network inspection capability, but it is not the same service as WinDefend, the main Microsoft Defender Antivirus Service, and it is not the same component as Microsoft Defender Firewall.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
Microsoft’s current Defender service-startup troubleshooting guidance lists these related components for examination:
| Component | Service or driver name | Expected configuration in Microsoft’s status table | What it represents |
|---|---|---|---|
| Microsoft Defender Antivirus Network Inspection Service | WdNisSvc |
Manual; should be running when Microsoft Defender Antivirus is active | Defender’s network-inspection service |
| Microsoft Defender Antivirus Network Inspection System Driver | WdNisDrv |
Manual | The related Defender network-inspection driver |
| Microsoft Defender Antivirus Service | WinDefend |
Automatic | The primary Defender antivirus service |
| Windows Security Center | wscsvc |
Automatic | Reports security-provider and protection status to Windows |
A WdNisSvc failure does not by itself mean that the computer is infected or that Windows must be reset. The failure can occur when another antivirus has taken over, a work or school policy controls Defender, Defender platform files are damaged, the network-inspection driver is unavailable, Windows components are corrupted, a recent update caused a problem, or malware tampered with security software.
Which Windows versions and PCs does this fix cover?
This procedure is aimed at supported Windows 10 and Windows 11 desktop installations. Windows 10 commonly places settings under Update & Security, while Windows 11 generally uses Privacy & security. Service behavior can differ on Windows Server, Microsoft Defender for Endpoint devices, and computers using passive mode or another enterprise endpoint-security product.
Work and school computers may be controlled by Group Policy, Microsoft Intune, Microsoft Defender for Endpoint, or other management software. A policy can deliberately disable or configure Defender, and a local change can be blocked or later reversed. Do not remove Defender policy settings from a managed computer without authorization from the organization’s administrator.
What should you do before trying a repair?
- Record the complete error. Take a screenshot of the Services dialog, including the number and wording of the error.
- Identify the active antivirus. Open Windows Security and check whether Microsoft Defender or another product provides antivirus protection.
- Check recent changes. Note recent Windows updates, Defender updates, antivirus installations, VPNs, firewalls, system optimizers, or security-suite removals.
- Determine whether the computer is managed. If the device belongs to an employer or school, contact the administrator before changing policies or services.
- Back up important files. Create a restore point where possible, especially before changing locally configured Defender policies or starting a recovery procedure.
Also open Event Viewer and inspect Applications and Services Logs for Microsoft Defender-related entries and the System log for Service Control Manager events. The event details can identify a dependency, driver, file, permission, or policy problem that the Services dialog does not explain.
How do you check Defender’s related services?
Use an elevated PowerShell window to inspect the services and drivers before changing anything. Open Start, search for PowerShell, right-click it, choose Run as administrator, and approve the prompt.
Get-Service WinDefend, WdBoot, WdFilter, WdNisSvc, WdNisDrv, SecurityHealthService, wscsvc |
Format-Table -Auto
Microsoft documents this status check in its service-startup troubleshooting procedure. Interpret the result as a starting point:
| Result | Meaning | Next step |
|---|---|---|
Running |
The component is active at the moment of the check. | Check Windows Security and the other related components rather than forcing a restart. |
Stopped |
The component is not currently running. | Check the error, dependencies, antivirus ownership, and Defender platform before starting it repeatedly. |
Disabled |
Startup has been blocked by configuration, policy, or security software. | Investigate the controlling policy or competing antivirus. |
| Missing service or driver | Windows cannot find the registered component. | Prioritize Windows Update, event logs, DISM, SFC, and professional support if the component remains missing. |
WdNisSvc is Manual |
Manual is the documented startup type and is not automatically a fault. | Do not change it to Automatic solely because the setting is not Automatic. |
For additional configuration and state information, run these diagnostic commands in an elevated Command Prompt:
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchRank #2
- AWARD WINNING Antivirus, anti-malware, anti-spyware & more
- 24/7 REAL TIME PROTECTION against emerging malware threats, including ransomware and viruses- without slowing you down.
- PROTECTS YOUR DEVICES ON MULTIPLE PLATFORMS: Get cyber protection for your computers, smartphones, or tablets- Compatible with Windows, Mac, Android, iOS
- DOWNLOAD AND INSTALL INSTANTLY
- UNMATCHED THREAT DETECTION: We found malware on 40 percent of devices that already had a third-party antivirus installed.
sc qc WdNisSvc
sc query WdNisSvc
sc query WdNisDrv
sc query WinDefend
These commands display configuration and state; they do not repair the service. Avoid registry scripts that recreate Defender services or rewrite service startup values from unverified websites.
Is another antivirus preventing Defender from starting?
If a third-party antivirus is installed and registered as the active provider, Microsoft Defender may be passive or intentionally unavailable. Do not force two real-time antivirus engines to run together.
- Open Windows Security and identify the registered antivirus provider.
- If Microsoft Defender should be the primary antivirus, uninstall the competing product using Windows’ normal app-uninstall process.
- If normal removal leaves remnants, use the security vendor’s official cleanup or removal utility.
- Restart Windows.
- Recheck Windows Security,
WinDefend,WdNisSvc, andWdNisDrv.
Microsoft specifically recommends uninstalling non-Microsoft antivirus software when Microsoft Defender Antivirus is intended to be the primary protection. Do not merely stop a third-party security product and assume that stopping its service removes its drivers and policy settings; follow the vendor’s official removal procedure.
Could a policy be disabling Microsoft Defender?
A disabled service or access-denied error can result from Group Policy, registry policy, endpoint management, or a security product. On an unmanaged personal computer, administrators can inspect the locally configured Defender policy location:
Free tools Windows power users keep installed
One-click scans. No signup required.
HKLMSOFTWAREPoliciesMicrosoftWindows Defender
Do not delete that key on a work, school, or enterprise-managed computer. Microsoft’s current procedure describes backing up and, where appropriate, removing locally configured Defender policies before re-enabling Defender, but that is a high-impact administrative step rather than a general consumer shortcut.
For an unmanaged PC, export the policy key before making an authorized change. If a policy returns after restart, the computer is probably being managed by a policy provider or security product; find and remove the controlling configuration instead of repeatedly deleting the key.
Should you scan for malware before repairing Defender?
Yes, when malware tampering is plausible, but the service error alone is not proof of infection. A malicious program can interfere with security services, while ordinary update, policy, driver, or component problems can produce similar symptoms.
Microsoft recommends the Microsoft Safety Scanner during Defender service-startup troubleshooting. Download it only from Microsoft, run it with appropriate administrator permissions, and follow its results. The scanner is a malware-checking measure, not a replacement for restoring Defender’s platform.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsRank #3
- THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
- PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
- SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
- GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
- MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.
If Windows Security remains usable, run a built-in scan:
- Save open work.
- Open Windows Security.
- Choose Virus & threat protection.
- Select Scan options.
- Run a Full scan, or choose Microsoft Defender Offline scan when malware may be hiding while Windows is running.
Microsoft explains that Defender Offline restarts the PC and scans outside the normal Windows environment. If the computer appears severely compromised, disconnect it from sensitive networks, preserve relevant evidence when required, and use a known-clean device for changing important account passwords.
How do you reset the Defender platform?
If another antivirus is not taking control and the related services are present, reset Defender’s definitions and antimalware platform using Microsoft’s documented MpCmdRun.exe sequence. Use an elevated Command Prompt, not an ordinary PowerShell window.
First, change to the newest Defender platform directory with this command:
(set "_done=" & if exist "%ProgramData%MicrosoftWindows DefenderPlatform" (for /f "delims=" %d in ('dir "%ProgramData%MicrosoftWindows DefenderPlatform" /ad /b /o:-n 2^>nul') do if not defined _done (cd /d "%ProgramData%MicrosoftWindows DefenderPlatform%d" & set _done=1)) else (cd /d "%ProgramFiles%Windows Defender")
Then run the following commands one at a time:
MpCmdRun.exe -RemoveDefinitions -All
MpCmdRun.exe -ResetPlatform
The first command removes Defender security intelligence and the second resets the antimalware platform. Microsoft documents both commands in its current Defender service-startup repair sequence.
Restart Windows after the reset. The reset can temporarily remove current definitions, so update Defender immediately after the restart. Do not manually delete arbitrary files from C:ProgramDataMicrosoftWindows Defender, and do not download MpCmdRun.exe from a third-party site.
How do you re-enable Defender and update its protection?
After restarting, open an elevated Command Prompt in the Defender platform directory and run:
MpCmdRun.exe -WdEnable
MpCmdRun.exe -SignatureUpdate -MMPC
The first command re-enables Defender and the second requests a security-intelligence update through Microsoft’s update channel. The published Microsoft source contains an apparent stray quotation mark beside the -WdEnable example; the command above uses valid command syntax. Command availability and behavior can vary with Windows servicing state and platform build.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #4
Then restart Windows again if requested and check:
- Windows Security > Virus & threat protection: antivirus and real-time protection should show an active status.
- Protection updates: Defender should successfully retrieve current security intelligence.
- Tamper Protection: check that the setting is enabled where appropriate and permitted by the device’s policy.
- Windows Update: install pending updates, then restart.
How do you repair Windows with DISM and SFC?
Use DISM and SFC when a Defender service, driver, executable, or related Windows component appears missing or corrupted. DISM repairs the Windows image; it is not a Defender-specific repair command. SFC then checks protected Windows system files against the repaired component state.
Open Command Prompt as administrator and run the commands in this order:
DISM.exe /Online /Cleanup-image /Restorehealth
sfc /scannow
Microsoft’s Windows repair guidance recommends running SFC after DISM. DISM normally obtains repair files through Windows Update, so an unavailable or damaged Windows Update path may require an alternate repair source.
DISM and SFC can take several minutes. Do not close the window merely because the progress percentage appears to pause temporarily. Restart after both commands complete, then repeat the service and Windows Security checks.
For deeper investigation, DISM and component-servicing details are recorded in %windir%LogsCBSCBS.log. A successful command does not necessarily mean that every Defender problem is fixed; it means that the corresponding Windows image or protected-file operation completed without reporting a failure.
Is the Defender Firewall the same as WdNisSvc?
No. Microsoft Defender Antivirus Network Inspection Service and Microsoft Defender Firewall are separate protection components. The word “Network” in WdNisSvc does not mean that the Windows Firewall service is the cause of the startup error.
Open Windows Security > Firewall & network protection to view the active network profile and Microsoft Defender Firewall state. Microsoft warns that turning off the firewall increases the device’s exposure. If an application is blocked, allow the application through the firewall using an appropriate rule rather than disabling the firewall wholesale.
An enterprise firewall or network policy may prevent local changes. If the firewall page is controlled by an administrator, escalate the issue instead of resetting firewall settings as a guess.
Recommended Free Tools
Best Value
What should you do for each common error code?
| Error or behavior | What it indicates | Best next action |
|---|---|---|
| 1068 | A dependency service or service group failed to start. | Inspect the dependency chain and identify the failed component. Check WinDefend, WdNisDrv, related drivers, and Event Viewer instead of repeatedly clicking Start. |
| 577 | Windows cannot verify a signature, or policy or security configuration is blocking the service. | Check policy, code-integrity and Defender events, third-party security software, platform files, and recent updates. Do not assume error 577 always means malware. |
| 5 | Access is denied. | Confirm that the console is elevated, then investigate policy, permissions, Tamper Protection, endpoint management, and security software. |
| 2 or 3 | A required file or path cannot be found. | Check whether the Defender platform or driver is missing, then prioritize Windows Update, the platform reset, DISM, and SFC. |
| Starts and immediately stops | The service may be failing during initialization or may be designed to run on demand rather than continuously. | Check Defender event logs, platform files, recent updates, driver errors, and malware indicators. Judge success through Windows Security and a test scan, not only continuous service state. |
Error numbers are diagnostic branches, not complete diagnoses. The event entry accompanying the error is more useful than the number alone because it can identify the dependency, file, policy, or driver that failed.
What if WdNisSvc still will not start?
Escalate gradually, preserving data and avoiding unsupported service surgery:
- Install pending Windows and Defender updates. Restart and test again.
- Remove a recently installed incompatible security product using the vendor’s official procedure, where appropriate.
- Use System Restore if a restore point predates the failure and System Restore is available.
- Perform an in-place Windows repair installation that preserves personal files and apps, where supported for the installation.
- Reset or reinstall Windows only after backing up important data and considering account, application, and recovery-key requirements.
- Contact Microsoft, the device manufacturer, or the organization’s administrator when the computer is managed, a driver repeatedly fails, malware is suspected, or Windows components remain missing.
Microsoft’s malware-removal and recovery guidance notes that irreversible malware-related changes can require restore, reset, or reinstall procedures and emphasizes backing up files before recovery.
How do you verify that the repair worked?
Do not stop after the Services console accepts a Start command. Confirm the protection outcome with this checklist:
WdNisSvcno longer displays the startup error.WinDefendis present and healthy when Microsoft Defender is the intended primary antivirus.WdNisDrvis present and has no related driver error in Device Manager or Event Viewer.- Windows Security reports active antivirus and real-time protection.
- Defender security intelligence updates successfully.
- A quick or full scan completes without an initialization error.
- Tamper Protection is enabled when appropriate and not controlled differently by an administrator.
- Microsoft Defender Firewall remains enabled unless a documented administrative policy says otherwise.
Do not use the following as first-line fixes: setting every Defender service to Automatic, disabling Tamper Protection merely to force a start, deleting registry keys without a backup, replacing WdNisDrv.sys from another computer, downloading repair scripts, running registry cleaners, disabling the firewall, or running two real-time antivirus products together.
Frequently Asked Questions
Should I change WdNisSvc from Manual to Automatic?
No. Microsoft’s current service table lists WdNisSvc as Manual, and Manual does not mean broken because Windows can start a Manual service when a component requests it. Change the startup configuration only when a documented policy or diagnostic result specifically requires it.
Does the Windows Defender Network Inspection Service error mean my PC has a virus?
No. The error alone does not prove malware. A third-party antivirus, policy, damaged Defender platform, failed driver, Windows corruption, or a recent update can produce the same symptom, although Microsoft Safety Scanner and Defender Offline are appropriate checks when tampering is plausible.
Can I fix WdNisSvc by disabling Windows Defender Firewall?
No. WdNisSvc and Microsoft Defender Firewall are separate components. Disabling the firewall can increase exposure and does not constitute a repair for the Defender Antivirus Network Inspection Service.
What is the difference between WdNisSvc and WinDefend?
WdNisSvc is the Microsoft Defender Antivirus Network Inspection Service, while WinDefend is the Microsoft Defender Antivirus Service. They are related but distinct components, so a healthy WinDefend service does not automatically prove that WdNisSvc or its WdNisDrv driver is healthy.
The Bottom Line
The safest fix for “Windows Could Not Start The Windows Defender Network Inspection Service On Local Computer” is to identify the exact error, establish whether Defender should be active, inspect WdNisSvc with WdNisDrv and WinDefend, then use Microsoft’s platform-reset and Windows-repair sequence. Do not force Manual services to Automatic, delete managed policies, or disable the firewall as a guess.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

