You cannot uninstall Microsoft Defender Antivirus from Windows 10 or Windows 11, but installing a compatible third-party antivirus switches it into disabled mode automatically.
This guide covers that supported route, the temporary off switches in Windows Security, Group Policy and PowerShell, the real uninstall command for Windows Server, and what to do when Defender keeps turning itself back on.
Method 1 (Recommended): Use a third-party antivirus and let Defender step back
Microsoft documents this as the normal way to replace Defender on Windows 10 and Windows 11. Your PC stays protected the whole time, because the new product takes over before Defender stands down.
- Install a compatible antivirus product from its vendor's official website and finish its setup.
- Restart the PC if the installer asks you to.
- Press Start, type Security and open Windows Security.
- Select Virus & threat protection and confirm the page now names your new antivirus as the active provider.
- Leave Defender alone from here; Windows has already moved it to disabled mode.
If the other product expires or is uninstalled, Defender Antivirus turns itself back on so the PC is never left without real-time protection.
First: What removing Defender actually means
Defender Antivirus runs in one of three states. Knowing which one you want saves you from fighting the system.
| State | When it happens | What still works |
|---|---|---|
| Active mode | Defender is the only antivirus on Windows 10 or 11 | Real-time scanning, scheduled scans, threat removal, updates |
| Disabled mode | A non-Microsoft antivirus is installed on Windows 10 or 11 (automatic) | Nothing from Defender Antivirus; the other product protects the PC |
| Passive mode | Business devices onboarded to Microsoft Defender for Endpoint, or Windows 11 with Smart App Control on | Defender scans for detection only and does not remediate threats itself |
| Uninstalled | Windows Server only, removed with a PowerShell cmdlet | Nothing; the feature is gone until reinstalled |
Turning off real-time protection in Windows Security is none of these states. It is a short pause, and Defender switches it back on after a short while.
Can you uninstall Windows Defender on Windows 10/11/8.1?
| Operating system | Can Defender be uninstalled? | What to do instead |
|---|---|---|
| Windows 11 | No, it is built in | Install another antivirus; Defender moves to disabled mode automatically |
| Windows 10 | No, it is built in | Same as Windows 11 |
| Windows 8.1 | Not covered by current Microsoft documentation | Windows 8.1 support ended on January 10, 2023, so it gets no security updates; upgrade to a supported Windows version |
| Windows Server 2019 and newer | Yes | Run Uninstall-WindowsFeature Windows-Defender as administrator after installing another antivirus |
| Windows Server 2016 | Yes | Run Uninstall-WindowsFeature Windows-Defender and Uninstall-WindowsFeature Windows-Defender-Gui |
On Windows Server, Defender does not step back on its own when another antivirus is installed, which is why Microsoft documents a manual uninstall there and not on client editions.
How to decide which approach fits your goal
| Your goal | Use this | Why |
|---|---|---|
| Switch to a different antivirus for good | Method 1: install the other product | Windows disables Defender for you and protection never lapses |
| Install one app Defender blocks, right now | Method 2: pause real-time protection | It turns back on by itself, so you cannot forget it |
| Stop Defender scanning or deleting one file or folder | Method 3: add an exclusion | Everything else stays protected |
| Manage a fleet of work PCs | Method 4: Group Policy | Central control, but tamper protection can override it |
| Script a test or build machine | Method 5: PowerShell | One line, easy to reverse |
| Remove Defender from a server | Uninstall-WindowsFeature on Windows Server | The only supported full uninstall |
Prerequisites before you change anything
| Requirement | Why it matters |
|---|---|
| An administrator account | Defender settings in Windows Security, Group Policy and PowerShell need admin rights |
| Tamper protection status known | With tamper protection on, Group Policy and scripted changes to protected settings are ignored |
| A replacement antivirus, if the change is permanent | Microsoft warns the device is vulnerable to malware with Defender off and no other product |
| Not a work-managed PC | If your organization manages Defender, the switches are unavailable or reset by policy |
| Saved work | A full uninstall on Windows Server needs a restart |
Method 2: Disable real-time protection (works best for short-term use)
This pause is meant for a few minutes, such as installing a trusted program that Defender keeps blocking. Scheduled scans continue to run while it is off.
- Press Start, type Security and open Windows Security.
- Select Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- If Tamper protection is On, switch it Off first; real-time protection cannot be turned off while it is on.
- Switch Real-time protection to Off and select Yes at the User Account Control prompt.
- Do the task that needed the pause, then switch Real-time protection and Tamper protection back On.
If you forget, real-time protection turns itself back on after a short while. Files you download while it is off are not checked until the next scheduled scan.

Method 3: Add exclusions instead of fully disabling Defender
An exclusion stops Defender scanning or deleting one file, folder, file type or process while the rest of the PC stays protected. Microsoft calls this safer than turning protection off.
- Open Windows Security and select Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Scroll to Exclusions and select Add or remove exclusions.
- Select Add an exclusion and choose File, Folder, File type or Process.
- Pick the item and confirm; it now appears in the exclusion list.
- To undo it later, select the entry and choose Remove.
Exclusions apply to real-time scanning only. Scheduled scans and other security products can still scan the item, and a process exclusion is safest with its full path.
Method 4: Disable via Group Policy (Pro/Enterprise/Education)
Microsoft's Windows 11 edition comparison lists Group Policy for Pro, not Home, and Enterprise and Education are managed the same way. Microsoft warns that turning off real-time protection this way drastically reduces protection, and tamper protection makes Windows ignore the change.
- Press Win + R, type
gpedit.mscand press Enter. - Go to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Real-time Protection.
- Open Turn off real-time protection.
- Select Enabled, then select OK.
- Restart the PC so the policy applies.
To reverse it, set the same policy to Not Configured. Tamper protection cannot be turned off through Group Policy, so a policy that appears to apply may still do nothing.
Method 5: PowerShell control (fast, scriptable, often temporary)
Run Windows PowerShell as administrator. The same tamper protection rule applies: with it on, the change does not stick.
Set-MpPreference -DisableRealtimeMonitoring $true
Turns off Defender real-time protection. Run Set-MpPreference -DisableRealtimeMonitoring $false to turn it back on, which Microsoft recommends.
You should see: The command returns no output. Windows Security then shows Real-time protection as Off, or reports that the setting is managed.
Method 6: Registry changes (usually overkill, easy to break)
Older guides tell you to create a DisableAntiSpyware value. Microsoft has removed that key for this purpose, so it no longer disables Defender on current Windows 10 and Windows 11.
| Registry value | Current status | Use it? |
|---|---|---|
| DisableAntiSpyware / DisableAntivirus | Removed for consumer devices; ignored on devices onboarded to Defender for Endpoint from platform 4.18.2108.4; protected by tamper protection since Windows 10 version 1903 | No |
| ForceDefenderPassiveMode under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection | Puts Defender in passive mode on Windows Server onboarded to Defender for Endpoint | Servers only |
On a home PC, installing another antivirus does what the old registry tweak used to do, without editing the registry at all.
How to check whether Defender is really off
Run this in PowerShell to read the mode Defender Antivirus is running in.
Get-MpComputerStatus | select AMRunningMode
Reports the running mode of Microsoft Defender Antivirus on this PC.
You should see: Normal, Passive or EDR Block Mode means Defender Antivirus is still enabled. Any of those after Method 1 means the other antivirus is not registered with Windows Security.
In Windows Security > Virus & threat protection, the page also names the antivirus provider currently protecting the PC.
Troubleshooting: what to do when Defender won’t stay off
Real-time protection turns itself back on
The Windows Security switch is a temporary pause by design.
- Use Method 1 if you want Defender off permanently.
- Use an exclusion from Method 3 if only one app or folder is the problem.
A Group Policy or PowerShell change does nothing
Tamper protection blocks changes to protected settings even when the tool reports success.
- Open Windows Security > Virus & threat protection > Manage settings.
- Check whether Tamper protection is On.
- Switch it Off, apply the change, then switch it back On once the change is no longer needed.
The Real-time protection switch is grayed out
Your organization manages Defender through policy.
- Ask your IT administrator; the setting is controlled centrally.
- On a personal PC, reset any Turn off real-time protection policy from Method 4 to Not Configured.
Defender stays active after another antivirus is installed
If the Windows Security Center service is disabled, Defender cannot detect the other product and stays active.
- Restart the PC so the new antivirus can register with Windows Security.
- Leave the Windows Security Center service at its default; Microsoft warns against disabling Defender-related services.
- Reinstall the other antivirus if Windows Security still does not list it.
Defender keeps deleting a file you trust
The file matches a detection, so Defender quarantines or removes it.
- Open Windows Security > Virus & threat protection > Protection history and check the detection.
- Restore the file only if you trust its source and publisher.
- Add the file or its folder as an exclusion (Method 3) so it is not removed again.
Common mistakes that make it look like Defender was removed
| What you did | What actually happened |
|---|---|
| Turned off Real-time protection | A temporary pause; it comes back on automatically |
| Ran two antivirus products at once | Microsoft advises against it; it can slow the PC and cause update errors such as 0x80070643 |
| Set DisableAntiSpyware in the registry | Current Windows ignores it for this purpose |
| Disabled the WinDefend or SecurityHealthService service | Microsoft warns this can cause severe instability and breaks how other antivirus products show in Windows Security |
| Hid the Defender tray icon or context menu entry | Only the shortcut is gone; protection keeps running |
Removing the old Scan with Windows Defender context menu entry is a cosmetic change only.
How to turn Defender back on
- Uninstall the third-party antivirus from Settings > Apps, or let its subscription lapse.
- Restart the PC; Defender Antivirus re-enables itself automatically.
- Open Windows Security > Virus & threat protection > Manage settings.
- Switch Real-time protection, Cloud-delivered protection and Tamper protection to On.
- Set any Group Policy you changed back to Not Configured.
The steps to uninstall a program in Windows 11 apply to most antivirus suites.
FAQs
Can I remove Microsoft Defender?
Not on Windows 10 or Windows 11. Defender Antivirus is built into both, and the supported route is installing another antivirus, which moves Defender to disabled mode automatically. Only Windows Server lets you uninstall it, with Uninstall-WindowsFeature Windows-Defender.
How do I remove Windows Defender permanently?
Install a compatible third-party antivirus. Windows 10 and Windows 11 then keep Defender Antivirus in disabled mode for as long as that product provides real-time protection. If it expires or is removed, Defender turns back on so the PC is not left unprotected.
How do I remove Windows Defender on Windows 11?
You cannot uninstall it, but you can replace it. Install another antivirus and Windows 11 disables Defender Antivirus automatically. For a short pause, turn off Real-time protection under Windows Security > Virus & threat protection > Manage settings.
How do I remove Windows Defender on Windows 10?
Windows 10 works the same way as Windows 11. Defender Antivirus cannot be uninstalled, but installing a third-party antivirus disables it automatically, and Windows Security has a temporary Real-time protection switch for short tasks.
How do I turn off Windows Defender?
Open Windows Security, select Virus & threat protection, then Manage settings, and switch Real-time protection to Off. Turn off Tamper protection first if it is on. Real-time protection switches itself back on after a short while.
How do I stop Windows Defender from deleting a file?
Add the file or its folder as an exclusion. In Windows Security, go to Virus & threat protection > Manage settings > Add or remove exclusions, then select Add an exclusion. Only exclude files you are sure are clean.
Can I remove Windows Defender with PowerShell?
On Windows 10 and Windows 11, PowerShell can only switch settings, such as Set-MpPreference -DisableRealtimeMonitoring $true. A real uninstall through PowerShell exists only on Windows Server, using Uninstall-WindowsFeature Windows-Defender.
How do I remove Windows Defender on Windows Server?
Install your other antivirus first, then run Uninstall-WindowsFeature Windows-Defender as administrator on Windows Server 2019 and newer. Windows Server 2016 also needs Uninstall-WindowsFeature Windows-Defender-Gui. Restart the server to finish.
Can I remove Windows Defender on Windows 11 Home?
No edition of Windows 11 lets you uninstall Defender Antivirus. On Home, as on other editions, installing another antivirus disables it automatically, and the Windows Security switch pauses real-time protection temporarily.
Is it safe to turn off Windows Defender?
Only if another antivirus is protecting the PC. Microsoft warns that a device with Defender disabled and no other security product is vulnerable to malware, and that files downloaded while real-time protection is off are not scanned.
Bottom Line
Install the antivirus you want to use and let Windows put Defender into disabled mode, and use an exclusion for any single file Defender keeps blocking. Windows 10 and Windows 11 cannot uninstall Defender, the registry tweaks no longer work, and every manual off switch is either temporary or overridden by tamper protection.





