Windows Defender turns off through Settings, but it stays partly active unless you also disable it in Group Policy

Windows Defender is the built-in antivirus that runs on every Windows machine. Turning it off completely requires two separate steps: disabling the real-time protection in Settings, then disabling the service itself through Group Policy Editor. If you skip the second step, Windows will re-enable Defender automatically after a few hours. Most people who think they have turned it off have only done the first step.

You should know upfront that Windows makes this deliberately difficult. The system is designed to keep you protected, and Microsoft assumes you are installing a different antivirus program, not leaving your computer unprotected. If you are switching to another antivirus, that program will usually handle the Defender shutdown for you during installation.

Key Takeaways

  • Disabling real-time protection in Settings alone is not enough — Defender will turn itself back on within hours.
  • You must also disable the Windows Defender service through Group Policy Editor (gpedit.msc) to keep it off permanently.
  • Group Policy Editor is only available on Windows Pro, Enterprise, and Education editions — Home edition users cannot access it.
  • If you are installing a different antivirus program, let that program handle the Defender shutdown instead of doing it manually.
  • Turning off all antivirus protection leaves your computer vulnerable to malware, ransomware, and other threats.

Disable real-time protection in Windows Settings

Open Settings by pressing the Windows key and typing "Settings", then press Enter. Click the search box at the top and type "virus", then click "Virus & threat protection" when it appears.

Under "Virus & threat protection settings", click "Manage settings". You will see a toggle for "Real-time protection" — click it to turn it off. Windows will ask you to confirm; click "Yes". The toggle will turn gray, indicating that real-time scanning is now disabled.

Close Settings. This step stops Defender from actively scanning your files, but the service itself is still running in the background. Within a few hours, Windows will automatically turn real-time protection back on. To prevent that, you must complete the next step.

Disable the Windows Defender service through Group Policy Editor

This step only works on Windows Pro, Enterprise, or Education. If you are running Windows Home edition, you cannot access Group Policy Editor, and Defender will re-enable itself no matter what you do in Settings.

Press the Windows key and type "gpedit.msc", then press Enter. Group Policy Editor will open. Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Click on the "Microsoft Defender Antivirus" folder to see the options inside.

Look for the setting called "Turn off Microsoft Defender Antivirus". Double-click it to open the policy. Select "Enabled", then click "explore" and "OK". Close Group Policy Editor. Your computer will no longer re-enable Defender automatically.

Restart your computer for the change to take full effect. After restart, open Settings again and return to "Virus & threat protection" to confirm that real-time protection remains off and the service shows as disabled.

What happens if you are on Windows Home edition

Windows Home does not include Group Policy Editor, so you cannot permanently disable Defender through the standard method. Any changes you make in Settings will revert within hours.

Your options are limited. You can install a third-party antivirus program, which will usually disable Defender during its own installation. You can also use the Registry Editor (regedit.msc) to make the same change that Group Policy would make, but this is more error-prone and requires careful editing of system files. If you are not comfortable with the Registry, the simplest path is to upgrade to Windows Pro or install a different antivirus program.

Let your new antivirus program handle the shutdown

If you are installing a different antivirus — Norton, McAfee, Bitdefender, or another program — do not manually disable Defender first. Instead, install your new antivirus and let it manage the Defender shutdown during its setup process. Most commercial antivirus programs are designed to detect Defender and disable it automatically.

This approach is safer because the new antivirus will may support that Defender is fully disabled before it starts protecting your system. If you disable Defender manually and then the new antivirus fails to install or set up properly, you could end up with no protection at all.

Why Windows makes this so difficult

Microsoft intentionally makes Defender hard to turn off because leaving a computer completely unprotected is dangerous. Malware, ransomware, and other threats spread quickly through unprotected systems, and many people disable Defender without understanding the risk.

The re-enabling behavior is a safety feature. If you disable Defender and then forget about it, Windows will turn protection back on automatically rather than leaving you exposed. This is the same reason that Windows Update cannot be permanently disabled — the system is designed to protect itself even when the user does not actively manage it.

Verify that Defender is actually off

After you complete both steps, confirm the change by opening Settings and navigating back to "Virus & threat protection". The real-time protection toggle should be off, and the status should show "Virus and threat protection is off". If it shows "Virus and threat protection is on" or the toggle is back on, the change did not stick and you may need to restart your computer again.

You can also check the Windows Security app directly. Press the Windows key, type "Windows Security", and press Enter. Click "Virus & threat protection" in the left menu. If Defender is truly disabled, this section will show a warning that your device is not currently protected.

Frequently Asked Questions

Will turning off Defender slow down my computer?

Disabling Defender frees up some system resources, but the performance gain is usually small — most users will not notice a difference. The real cost is security: your computer becomes vulnerable to malware and other threats. The trade-off is rarely worth it unless you are installing a different antivirus program that provides better protection for your specific needs.

Can I turn off Defender just for certain folders or programs?

Yes. In "Virus & threat protection settings", scroll down to "Exclusions" and click "Manage exclusions". You can add specific files, folders, file types, or processes that Defender will skip. This is safer than disabling Defender entirely because the rest of your system remains protected.

What if Defender keeps turning itself back on?

This usually means you completed the Settings step but not the Group Policy step. If you are on Windows Pro or Enterprise, go back to Group Policy Editor and make sure the "Turn off Microsoft Defender Antivirus" policy is set to "Enabled". If you are on Windows Home, you cannot permanently disable Defender without using the Registry or installing a different antivirus program.

Is it safe to run my computer without any antivirus?

No. Running without antivirus protection exposes your computer to malware, ransomware, spyware, and other threats that can steal your data, lock your files, or damage your system. If you are turning off Defender, you should have a different antivirus program installed and active before you disable it.

Do I need to restart Windows after disabling Defender?

A restart is not strictly required after disabling real-time protection in Settings, but it is required after making changes in Group Policy Editor. Restarting ensures that all background processes recognize the new settings and prevents Defender from re-enabling itself unexpectedly.