Windows Defender stays on by default, and you can turn it off temporarily or permanently depending on what you need

Windows Defender (now called Microsoft Defender) runs automatically on Windows 10 and Windows 11 to scan for malware and viruses. Most of the time you should leave it on. But there are real reasons you might need to disable it: you're installing software that Defender keeps blocking, you're running performance tests, or you're using a different antivirus program that conflicts with it. Turning it off is straightforward, but doing it safely means understanding what you're losing and for how long.

The key difference is temporary disable versus permanent disable. Temporary means Defender turns back on after a restart or after a set time. Permanent means you've changed Windows settings so it stays off until you turn it back on again. Which one you choose depends on whether you're solving a one-time problem or making a permanent switch to different security software.

Key Takeaways

  • Temporary disable through Windows Security settings is the safest approach if you only need Defender off for an hour or a day.
  • Disabling real-time protection stops active scanning but leaves other Defender features running, which is different from turning off Defender entirely.
  • If you install a different antivirus program, that program usually disables Defender automatically to avoid conflicts.
  • Permanent disable requires changing Group Policy (Windows Pro and Enterprise) or Registry settings, and leaves your device without built-in protection unless you install something else.
  • Restarting your computer will re-enable Defender's real-time protection if you only disabled it temporarily through the Settings menu.

How to temporarily disable real-time protection

This is the method to use if you need Defender off for a few hours while you install something or run a test. Open Windows Security (search for it in the Start menu), then click Virus & threat protection on the left side. Under "Virus & threat protection settings," you'll see a toggle for Real-time protection. Click it to turn it off. Windows will ask you to confirm — click yes.

When you do this, Defender stops scanning files in real time, but it doesn't disappear entirely. Other features like your firewall and account protection stay active. The real-time protection will turn back on automatically when you restart your computer, or after a few hours if you don't restart. This is why it's the safer choice for a quick task — you don't have to remember to turn it back on.

If you're doing this because a program keeps getting blocked, you can also add that program to Defender's exclusions list instead of turning off the whole scanner. In the same Virus & threat protection settings, scroll down to "Virus & threat protection settings" and click Manage settings. Then click Add or remove exclusions and add the program's folder. This way Defender stays on for everything else.

How to permanently disable Defender on Windows Pro or Enterprise

If you're switching to a different antivirus program permanently, you may need to disable Defender at a deeper level. This requires access to Group Policy Editor, which is only available on Windows Pro, Enterprise, or Education editions — not on Windows Home.

Press the Windows key and R together to open the Run dialog, type gpedit.msc, and press Enter. Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus. Find the setting called Turn off Microsoft Defender Antivirus and double-click it. Select Enabled and click OK. Your computer will need to restart for this to take effect.

Once Defender is disabled this way, it stays off until you reverse the setting. This is permanent in the sense that restarting won't turn it back on — but it's not irreversible. If you ever need Defender again, you go back to the same Group Policy setting and select Disabled or Not Configured.

How to disable Defender on Windows Home edition

Windows Home doesn't have Group Policy Editor, so you'll need to use the Registry instead. This is more technical and leaves less room for error, so only do this if you're comfortable editing the Registry or if you're following specific instructions from your antivirus software.

Press Windows key and R, type regedit, and press Enter. Navigate to HKEY_LOCAL_MACHINE > SOFTWARE > Policies > Microsoft > Windows Defender. If the Windows Defender folder doesn't exist, right-click on Microsoft, select New > Key, and name it "Windows Defender". Right-click in the empty space on the right, select New > DWORD (32-bit) Value, and name it DisableAntiSpyware. Double-click it and change the value from 0 to 1. Close the Registry and restart your computer.

Like the Group Policy method, this disables Defender until you change the value back to 0. If something goes wrong during this process, you can undo it by setting the value back to 0 or deleting the key entirely.

What happens when you disable Defender

When real-time protection is off, Defender stops scanning files as you read or open them. Your computer becomes more vulnerable to malware during that time. Windows will show you a notification that your device isn't protected, and that notification will stay visible until you turn Defender back on or install a different antivirus program.

If you've permanently disabled Defender and haven't installed a replacement antivirus, your device has no built-in malware protection. This is why permanent disable only makes sense if you're when ready installing a different security program — not as a standalone choice. Most modern antivirus programs (Norton, McAfee, Bitdefender, Kaspersky, Avast) will detect that Defender is running and disable it automatically during their own installation, so you usually don't have to do this manually.

When your antivirus program disables Defender automatically

If you install a third-party antivirus program, it will usually turn off Defender on its own during installation. You don't need to disable Defender first. The new program recognizes that two antivirus engines running at the same time cause conflicts — they slow your computer down and sometimes block each other's legitimate actions.

If you install antivirus software and Defender is still running, check the antivirus program's settings to see if there's an option to disable Windows Defender or to manage system protection. Some programs require you to manually turn off Defender if it didn't happen automatically. If both are still running after installation, restart your computer — sometimes the change takes effect only after a restart.

Re-enabling Defender after you've disabled it

If you used the temporary disable method through Windows Security, Defender turns back on automatically after a restart or after a few hours. You don't have to do anything.

If you disabled it through Group Policy, go back to the same location (Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus), find Turn off Microsoft Defender Antivirus, and select Disabled or Not Configured. Restart your computer.

If you disabled it through the Registry, go back to HKEY_LOCAL_MACHINE > SOFTWARE > Policies > Microsoft > Windows Defender, find the DisableAntiSpyware value, and change it from 1 back to 0. Restart your computer. Defender will resume running on the next startup.

Frequently Asked Questions

Will my computer get infected if I disable Defender?

Not automatically, but your risk goes up significantly. Malware doesn't jump onto your device just because Defender is off — you still have to read or open an infected file. The difference is that Defender won't catch it. If you're disabling Defender, do it only for the specific time you need it, and avoid downloading files from untrusted sources during that window.

Can I disable just the firewall part of Defender?

Yes. In Windows Security, go to Firewall & network protection, click on each network type (Domain, Private, Public), and toggle the firewall off for the ones you want. This is separate from disabling the antivirus scanner. You can have one on and one off.

Why does Defender keep turning back on after I disabled it?

If you used the Settings menu to disable real-time protection, it turns back on after a restart or after several hours — that's by design. If you want it to stay off, you need to use Group Policy (Windows Pro/Enterprise) or Registry (Windows Home). If you've already done that and it's still turning back on, another program may be re-enabling it, or a Windows update may have reset your settings.

Do I need to uninstall Defender to use a different antivirus?

No. You can't uninstall Defender on Windows — it's part of the operating system. You just disable it and install your new antivirus program. The new program will handle the disabling for you in most cases.

Is it safe to have Defender disabled permanently?

Only if you have a different antivirus program running. Leaving your device without any real-time malware protection is not safe. If you're switching antivirus programs, disable Defender only after you've installed and verified that the new program is running.