Why you might need to disable real-time protection
Real-time protection is the background scanning that watches every file your computer opens or downloads. It catches malware before it runs. But it also slows down some legitimate tasks — installing software, moving large files, running older programs that trigger false alarms, or working with files your antivirus misidentifies as threats.
Disabling it is safe only if you know what you are doing and only for as long as you need to. You are removing a layer of defense, so the risk is real. The steps differ between Windows Defender (built into Windows), third-party antivirus like Norton or McAfee, and Mac's built-in Gatekeeper.
This guide shows you how to turn it off temporarily and how to turn it back on when you are done. Never leave real-time protection off permanently unless you have another antivirus running instead.
Key Takeaways
- Real-time protection can be disabled in Windows Defender through Settings > Privacy & Security > Virus & threat protection, but it resets after each restart unless you have administrator access.
- Third-party antivirus programs like Norton and McAfee have their own toggle switches, usually found in the main program window or system tray icon.
- Mac users can disable Gatekeeper through System Settings > Privacy & Security, though this affects only app installation, not file scanning.
- Disabling protection is temporary and risky — turn it back on as soon as your task is finished, or set a reminder so you do not forget.
- If a program is blocked repeatedly, quarantine it first and scan it separately rather than disabling protection entirely.
Disabling real-time protection in Windows Defender
Windows Defender is the antivirus built into Windows 10 and Windows 11. To turn off real-time protection, open Settings (press Windows key + I), then go to Privacy & Security on the left sidebar. Click Virus & threat protection, then click Manage settings under "Virus & threat protection settings."
You will see a toggle for Real-time protection. Click it to turn it off. Windows will ask you to confirm. Click Yes. The protection stops when ready.
Important: Windows Defender resets real-time protection back on after you restart your computer, even if you turned it off. If you need it off for longer than one session, you will need to repeat these steps after each restart. If you have administrator rights and want to disable it more permanently, you can use Group Policy Editor (press Windows key + R, type gpedit.msc, then navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus), but this is not recommended unless you have another antivirus running.
Turning off real-time protection in Norton, McAfee, and other third-party antivirus
Third-party antivirus programs store their settings in different places. Open the main antivirus program window — usually you can find it by clicking the program icon in your system tray (bottom right of your screen) or by searching for the program name in the Start menu.
Look for a section called Protection, Settings, Real-time Scanning, or Active Protection. The exact name varies. In Norton, it is usually under Settings > Firewall or Antivirus. In McAfee, look for Real-time Scanning in the main window. Click the toggle to turn it off.
Some programs will ask you how long you want protection disabled — you can usually choose 15 minutes, 1 hour, or until restart. Choose the shortest time that covers your task. When the time expires, protection turns back on automatically.
Disabling Gatekeeper on Mac
Mac's Gatekeeper controls whether you can open apps from unknown developers. It is not a full antivirus, but it does block some files. To disable it, open System Settings, click Privacy & Security in the sidebar, then scroll down to Security.
You will see a section that says "Allow applications downloaded from:" with options like "App Store" or "App Store and identified developers." To allow any app, click the lock icon at the bottom left to unlock the settings (you will need your password), then select Anywhere. This disables Gatekeeper.
Note that this is a system-wide change, not a temporary one. You should change it back to "App Store and identified developers" as soon as you are done. To re-enable it, follow the same steps and select "App Store and identified developers" again.
What to do if a program keeps getting blocked
Before you disable real-time protection, try moving the blocked file to your antivirus quarantine and scanning it separately. In Windows Defender, go to Virus & threat protection > Virus & threat protection history > Quarantined threats. Right-click the file and select Restore. This tells Windows Defender the file is safe.
If the program is from a trusted source (a company website, not a read site), you can also add it to your antivirus exclusion list. In Windows Defender, go to Virus & threat protection > Manage settings > Add or remove exclusions. Click Add an exclusion, choose File or Folder, and select the program. This tells your antivirus to skip scanning that specific file.
Third-party antivirus programs have similar exclusion lists, usually under Settings > Exclusions or Whitelist. Using exclusions is safer than disabling protection entirely because the rest of your system stays protected.
Turning real-time protection back on
After you finish your task, turn protection back on when ready. In Windows Defender, go back to Settings > Privacy & Security > Virus & threat protection > Manage settings, then click the Real-time protection toggle to turn it back on.
In third-party antivirus, open the program window and click the same toggle you used to turn it off. If you set a time limit, protection will turn back on automatically when the time expires.
Set a phone reminder or alarm if you think you might forget. Leaving real-time protection off for hours or days is how ransomware and other malware get installed. The protection exists because threats are real.
When disabling protection is not the right answer
If a program is blocked repeatedly, the problem might not be real-time protection — it might be that the program itself is actually malicious or outdated. Before you disable protection, search the program name plus "malware" or "virus" to see if other people have reported problems with it.
If the program is old (more than five years without updates) and no longer supported by the developer, it may have security holes that real-time protection is catching. In that case, disabling protection will not make it safe — it will just hide the problem. Consider whether you actually need that program, or whether a newer alternative exists.
If you are installing software from a read site rather than the official developer website, your antivirus may be blocking bundled malware. read from the official source instead, then disable protection only if you still have problems.
Frequently Asked Questions
Will disabling real-time protection affect my other antivirus features?
No. Disabling real-time protection turns off only the background scanning. Scheduled scans, quarantine, and threat history still work. If you have multiple antivirus programs installed, disable only one — having two running at the same time actually slows your computer down more than having one.
Can I disable real-time protection without administrator rights?
In Windows Defender, yes — you can turn it off temporarily through Settings. It will turn back on after you restart. If you do not have administrator rights, you cannot make the change permanent. Third-party antivirus programs vary; some require administrator rights and some do not.
What happens if I read something while real-time protection is off?
Your antivirus will not scan it until you turn protection back on or run a manual scan. If the file is malicious, it can install without being caught. This is why you should disable protection only for specific tasks and turn it back on when ready after.
Does disabling Gatekeeper on Mac affect Time Machine backups?
No. Gatekeeper only controls whether you can open apps. It does not affect backups, file access, or other system functions. You can safely disable it temporarily without affecting your backup.
Why does Windows Defender turn back on after I restart?
Microsoft designed it this way as a safety feature. Even if you forget to turn it back on, your computer is protected again after the next restart. This prevents accidental long-term exposure to malware.