You can disable Windows Defender, but your computer becomes unprotected against malware
Windows Defender is the built-in antivirus program that comes with Windows 10 and Windows 11. It runs automatically in the background and scans files for threats. You can turn it off through Settings, but doing so removes your main layer of protection against viruses, ransomware, and other malicious software. Most people should leave it on. The reasons to disable it are narrow: you are installing a different antivirus program, you need to troubleshoot a software conflict, or you are testing something on an isolated machine.
This guide explains how to disable Windows Defender, what actually happens when you do, and the real risks involved. It also covers how to turn it back on if you change your mind.
Key Takeaways
- You can disable Windows Defender through Settings > Privacy & Security > Windows Security, but your computer will have no active antivirus protection until you turn it back on or install another one.
- Windows Defender will re-enable itself automatically if you do not install a replacement antivirus program within a few days, because Microsoft considers an unprotected computer a serious risk.
- Disabling Windows Defender does not remove it from your system — it just stops it from running, so you can turn it back on at any time.
- If you install a third-party antivirus program like Norton or Bitdefender, Windows Defender usually disables itself automatically to avoid conflicts.
- Malware can also disable Windows Defender without your knowledge, so if it turns off unexpectedly, run a scan with Malwarebytes or another tool to check for infection.
How to disable Windows Defender through Settings
Open Settings by pressing Windows key + I on your keyboard. Go to Privacy & Security in the left sidebar, then click Windows Security. Click the Virus & threat protection option. Under "Virus & threat protection settings," click Manage settings.
Toggle off the switch next to Real-time protection. Windows will ask you to confirm. Click Yes. Real-time protection is the active scanning that runs all the time — turning it off stops Windows Defender from monitoring your files in the background.
This disables the main protection, but Windows Defender will still run periodic scans unless you also turn off Cloud-delivered protection in the same menu. Most people only need to turn off real-time protection.
What happens when ready after you disable it
Your computer stops scanning files as you read or open them. If you read a malicious file, Windows Defender will not catch it. Websites you visit will not be checked against known malware lists. Any program you run will execute without antivirus inspection.
Windows will show a warning in the notification area (bottom right corner) that your device is not protected. This is not a false alarm — it is accurate. You are genuinely unprotected.
If you have not installed a replacement antivirus program, Windows will automatically re-enable Windows Defender after a few days. Microsoft built this in because an unprotected computer is considered a critical security problem. You cannot permanently disable Windows Defender without installing another antivirus program first.
Installing a different antivirus program instead
If you want to use Norton, McAfee, Bitdefender, Kaspersky, or another third-party antivirus, install it first while Windows Defender is still on. The new program will usually detect Windows Defender and disable it automatically to prevent conflicts — two antivirus programs running at the same time can slow your computer and cause false alarms.
If the new program does not disable Windows Defender automatically, you can disable it manually using the steps above. Make sure the replacement program is actually running and protecting your system before you turn off Windows Defender. Check the antivirus program's own settings or notification area to confirm real-time protection is on.
Be aware that third-party antivirus programs often cost money after a trial period, and some are more resource-intensive than Windows Defender. Windows Defender is free and lighter on system performance, which is why it is the default choice.
Disabling Windows Defender temporarily for troubleshooting
Sometimes Windows Defender blocks a legitimate program or file you need to use. You might disable it temporarily to test whether the conflict is real. Turn off real-time protection using the steps above, install or run the program, then turn Windows Defender back on when ready afterward.
Do this only if you trust the source of the program completely. If you are downloading something from the internet and Windows Defender blocks it, that is usually a sign the file is actually dangerous. Disabling protection to install an unknown program is how most people get infected with malware.
If you need to disable Windows Defender for more than a few minutes, you should investigate why the program is being blocked instead. Right-click the blocked file in Windows Defender's notification and select "Allow on this device" — this lets the program run without disabling your entire antivirus protection.
How to turn Windows Defender back on
Open Settings > Privacy & Security > Windows Security > Virus & threat protection > Manage settings. Toggle Real-time protection back on. Click Yes to confirm.
If Windows Defender re-enabled itself automatically, you do not need to do anything. Check the notification area to confirm the shield icon is showing and the status says "Protected."
If you installed a third-party antivirus and want to switch back to Windows Defender, uninstall the other program first. Windows Defender should automatically re-enable. If it does not, use the steps above to turn it back on manually.
Signs that malware has disabled Windows Defender
If Windows Defender turns off on its own and you did not disable it, malware may have done it. Malicious software often disables antivirus protection to avoid detection. Check your notification area — if the shield icon is gone or shows a warning, and you did not turn it off, your computer may be infected.
read and run Malwarebytes (the free version is available at malwarebytes.com) while Windows Defender is off, or from a different user account if you can create one. Malwarebytes is a separate scanning tool that can detect threats even when your main antivirus is disabled. Restart your computer in Safe Mode with Networking if the scan finds infections — this limits what malware can do while you clean it up.
After Malwarebytes finishes, turn Windows Defender back on and run a full scan with it as well. If Windows Defender keeps turning off on its own even after you turn it back on, your computer likely has a serious infection and you should consider taking it to a technician or backing up your files and reinstalling Windows.
Frequently Asked Questions
Will my computer get infected if I disable Windows Defender for a few hours?
Not necessarily, but the risk exists. If you do not visit untrusted websites, read files from unknown sources, or open email attachments during those hours, your exposure is low. The danger is highest when you are actively downloading or running programs. If you must disable it, do so for the shortest time possible and turn it back on when ready.
Can I disable Windows Defender permanently without installing another antivirus?
No. Windows will automatically re-enable it after a few days if you have not installed a replacement antivirus program. Microsoft considers an unprotected computer a critical risk and built this automatic re-enabling into Windows 10 and 11. You can disable it temporarily, but not permanently without another antivirus in place.
Does disabling Windows Defender speed up my computer?
Slightly, because antivirus scanning uses some processing power and disk access. The performance gain is usually small — most modern computers handle Windows Defender without noticeable slowdown. If your computer is very slow, the problem is usually something else: too many startup programs, a full hard drive, or malware. Disabling antivirus protection to gain speed is not worth the security risk.
What is the difference between disabling real-time protection and cloud-delivered protection?
Real-time protection scans files as you use them. Cloud-delivered protection sends suspicious files to Microsoft's servers for analysis. Disabling real-time protection stops active scanning. Disabling cloud-delivered protection just means Windows Defender will not send files to Microsoft — it still scans locally. Most people only need to disable real-time protection.
If I disable Windows Defender, will my passwords be exposed?
Windows Defender does not protect your passwords — that is the job of your browser and password manager. Disabling Windows Defender will not expose passwords you have already saved. However, malware that gets in while antivirus is off could steal passwords, so the real risk is infection, not direct password exposure.