Windows Defender can be turned off, but doing it permanently requires disabling it in multiple places
Windows Defender is built into Windows 10 and Windows 11 and runs by default. You can turn it off temporarily through Settings, but it will turn itself back on after a restart or after a certain amount of time. To keep it off permanently, you need to disable it in three separate locations: the Windows Security app, Group Policy (on Pro and Enterprise versions), and the Task Scheduler.
Before you disable Windows Defender, understand what you are doing. Windows Defender is your computer's default protection against malware and viruses. Turning it off leaves your system exposed unless you install and actively maintain a different antivirus program. Many people disable it because they use a third-party antivirus like Norton, McAfee, or Bitdefender, which Windows Defender will often conflict with. If you are disabling it to run another antivirus, install that program first and make sure it is working before you turn off Windows Defender.
Key Takeaways
- Disabling Windows Defender through Settings alone does not keep it off permanently — it will re-enable itself after updates or restarts.
- Windows Home edition can only disable Windows Defender through Settings and Task Scheduler, because Group Policy is not available on that version.
- Windows Pro and Enterprise editions can use Group Policy Editor to permanently disable Windows Defender, which is the most reliable method.
- If you disable Windows Defender without installing another antivirus program, your computer will have no active malware protection.
Disable Windows Defender in Windows Security on any version
Open the Windows Security app by clicking the Start menu and typing "Windows Security," then press Enter. Click "Virus & threat protection" on the left side. Under "Virus & threat protection settings," click "Manage settings."
Toggle off "Real-time protection." Windows will ask you to confirm. Click "Yes." This turns off the active scanning that runs in the background, but it does not disable Windows Defender completely — it will turn back on after a restart or after several hours.
While you are in this menu, you can also toggle off "Cloud-delivered protection" and "Automatic sample submission" if you want to reduce the data Windows sends to Microsoft. These are optional steps.
Disable Windows Defender using Group Policy (Windows Pro and Enterprise only)
This method is permanent and will survive restarts. It does not work on Windows Home edition. Press the Windows key and R at the same time to open the Run dialog. Type "gpedit.msc" and press Enter. This opens Group Policy Editor.
Navigate to: Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Look for the policy called "Turn off Microsoft Defender Antivirus." Double-click it. Select "Enabled" and click "OK." Close Group Policy Editor.
Restart your computer. Windows Defender will remain off after the restart. To verify it is disabled, open Windows Security again and check that Real-time protection shows as off and cannot be toggled back on.
Disable Windows Defender in Task Scheduler (all versions)
This method disables the scheduled tasks that Windows Defender uses to run scans and updates. Press the Windows key and R, type "taskschd.msc," and press Enter. This opens Task Scheduler.
Navigate to: Task Scheduler Library > Microsoft > Windows > Windows Defender. You will see several tasks listed. Right-click each one and select "Disable." The main ones to disable are "Windows Defender Cache Maintenance," "Windows Defender Cleanup," "Windows Defender Scheduled Scan," and "Windows Defender Verification." Disable all of them.
Close Task Scheduler. These tasks will no longer run automatically, which prevents Windows Defender from performing background maintenance and scans. However, this alone will not stop Windows Defender from running if it is still enabled in Group Policy or Windows Security.
What happens after you disable Windows Defender
Once Windows Defender is fully disabled, Windows will show a notification in the system tray that your device is not protected. This notification appears because Windows has detected that no antivirus program is running. If you have installed a third-party antivirus, that program should show as active instead, and the notification should disappear.
If you see the notification and you have not installed another antivirus program, your computer is unprotected. Malware, viruses, and ransomware can infect your system without any warning or active defense. You should install a working antivirus program when ready or re-enable Windows Defender.
Windows Update will continue to install security patches for your operating system, but those patches protect the system itself, not against malware. You need active antivirus protection running at all times.
Re-enable Windows Defender if you change your mind
If you disabled Windows Defender through Group Policy, open Group Policy Editor again (Windows key + R, type "gpedit.msc"), navigate back to the same location, and set "Turn off Microsoft Defender Antivirus" to "Disabled" or "Not Configured." Restart your computer.
If you disabled it only through Windows Security, open Windows Security, go to Virus & threat protection, and toggle Real-time protection back on. If you disabled tasks in Task Scheduler, right-click each disabled task and select "Enable."
After re-enabling, restart your computer and verify that Windows Defender shows as active in Windows Security.
Why Windows Defender re-enables itself
Windows Defender is designed to turn itself back on if it detects that no other antivirus program is running. This is a safety feature. If you disable it through Settings alone without using Group Policy, Windows will re-enable it automatically after a period of time or after a major Windows Update. This is why disabling it in Group Policy is necessary for a permanent change — Group Policy settings override the automatic re-enablement.
Some Windows Updates can also reset Group Policy settings or re-enable Windows Defender. If this happens, you will need to disable it again using the same steps.
Frequently Asked Questions
Will disabling Windows Defender speed up my computer?
Disabling Windows Defender may free up a small amount of CPU and memory, but the difference is usually not noticeable on modern computers. If you are disabling it to install another antivirus program, that program will use similar resources. The real reason to disable Windows Defender is to avoid conflicts with a third-party antivirus, not to gain speed.
Can I disable Windows Defender on Windows Home edition?
Windows Home does not have Group Policy Editor, so you cannot disable it permanently through that method. You can turn it off in Windows Security, but it will re-enable itself. The most reliable way on Home edition is to install a third-party antivirus program, which will automatically disable Windows Defender's real-time protection to avoid conflicts.
What if I only want to disable Windows Defender scans, not real-time protection?
You can disable scheduled scans by disabling the tasks in Task Scheduler without disabling real-time protection in Windows Security. This keeps the background protection running but stops the automatic full-system scans that run on a schedule. Real-time protection will still monitor files as you access them.
Is it safe to run my computer without any antivirus protection?
No. Running without antivirus protection leaves your computer vulnerable to malware, viruses, ransomware, and other threats. You should always have an active antivirus program running. If you are disabling Windows Defender, you must have another antivirus program installed and actively protecting your system first.
Will disabling Windows Defender affect Windows Update?
No. Windows Update will continue to install security patches and updates for your operating system regardless of whether Windows Defender is enabled. Disabling Windows Defender only stops the antivirus scanning and threat detection, not the system updates.