How to remove Windows Defender in Windows 10/11 and 8.1

You cannot uninstall Microsoft Defender Antivirus from Windows 10 or Windows 11, but installing a compatible third-party antivirus switches it into disabled mode automatically.

This guide covers that supported route, the temporary off switches in Windows Security, Group Policy and PowerShell, the real uninstall command for Windows Server, and what to do when Defender keeps turning itself back on.

Method 1 (Recommended): Use a third-party antivirus and let Defender step back

Microsoft documents this as the normal way to replace Defender on Windows 10 and Windows 11. Your PC stays protected the whole time, because the new product takes over before Defender stands down.

  1. Install a compatible antivirus product from its vendor's official website and finish its setup.
  2. Restart the PC if the installer asks you to.
  3. Press Start, type Security and open Windows Security.
  4. Select Virus & threat protection and confirm the page now names your new antivirus as the active provider.
  5. Leave Defender alone from here; Windows has already moved it to disabled mode.

If the other product expires or is uninstalled, Defender Antivirus turns itself back on so the PC is never left without real-time protection.

First: What removing Defender actually means

Defender Antivirus runs in one of three states. Knowing which one you want saves you from fighting the system.

State When it happens What still works
Active mode Defender is the only antivirus on Windows 10 or 11 Real-time scanning, scheduled scans, threat removal, updates
Disabled mode A non-Microsoft antivirus is installed on Windows 10 or 11 (automatic) Nothing from Defender Antivirus; the other product protects the PC
Passive mode Business devices onboarded to Microsoft Defender for Endpoint, or Windows 11 with Smart App Control on Defender scans for detection only and does not remediate threats itself
Uninstalled Windows Server only, removed with a PowerShell cmdlet Nothing; the feature is gone until reinstalled

Turning off real-time protection in Windows Security is none of these states. It is a short pause, and Defender switches it back on after a short while.

Can you uninstall Windows Defender on Windows 10/11/8.1?

Operating system Can Defender be uninstalled? What to do instead
Windows 11 No, it is built in Install another antivirus; Defender moves to disabled mode automatically
Windows 10 No, it is built in Same as Windows 11
Windows 8.1 Not covered by current Microsoft documentation Windows 8.1 support ended on January 10, 2023, so it gets no security updates; upgrade to a supported Windows version
Windows Server 2019 and newer Yes Run Uninstall-WindowsFeature Windows-Defender as administrator after installing another antivirus
Windows Server 2016 Yes Run Uninstall-WindowsFeature Windows-Defender and Uninstall-WindowsFeature Windows-Defender-Gui

On Windows Server, Defender does not step back on its own when another antivirus is installed, which is why Microsoft documents a manual uninstall there and not on client editions.

How to decide which approach fits your goal

Your goal Use this Why
Switch to a different antivirus for good Method 1: install the other product Windows disables Defender for you and protection never lapses
Install one app Defender blocks, right now Method 2: pause real-time protection It turns back on by itself, so you cannot forget it
Stop Defender scanning or deleting one file or folder Method 3: add an exclusion Everything else stays protected
Manage a fleet of work PCs Method 4: Group Policy Central control, but tamper protection can override it
Script a test or build machine Method 5: PowerShell One line, easy to reverse
Remove Defender from a server Uninstall-WindowsFeature on Windows Server The only supported full uninstall

Prerequisites before you change anything

Requirement Why it matters
An administrator account Defender settings in Windows Security, Group Policy and PowerShell need admin rights
Tamper protection status known With tamper protection on, Group Policy and scripted changes to protected settings are ignored
A replacement antivirus, if the change is permanent Microsoft warns the device is vulnerable to malware with Defender off and no other product
Not a work-managed PC If your organization manages Defender, the switches are unavailable or reset by policy
Saved work A full uninstall on Windows Server needs a restart

Method 2: Disable real-time protection (works best for short-term use)

This pause is meant for a few minutes, such as installing a trusted program that Defender keeps blocking. Scheduled scans continue to run while it is off.

  1. Press Start, type Security and open Windows Security.
  2. Select Virus & threat protection.
  3. Under Virus & threat protection settings, select Manage settings.
  4. If Tamper protection is On, switch it Off first; real-time protection cannot be turned off while it is on.
  5. Switch Real-time protection to Off and select Yes at the User Account Control prompt.
  6. Do the task that needed the pause, then switch Real-time protection and Tamper protection back On.

If you forget, real-time protection turns itself back on after a short while. Files you download while it is off are not checked until the next scheduled scan.

Windows Security Virus and threat protection page with Manage settings link
Manage settings sits under Virus & threat protection settings on this page. (Image: Microsoft)

Method 3: Add exclusions instead of fully disabling Defender

An exclusion stops Defender scanning or deleting one file, folder, file type or process while the rest of the PC stays protected. Microsoft calls this safer than turning protection off.

  1. Open Windows Security and select Virus & threat protection.
  2. Under Virus & threat protection settings, select Manage settings.
  3. Scroll to Exclusions and select Add or remove exclusions.
  4. Select Add an exclusion and choose File, Folder, File type or Process.
  5. Pick the item and confirm; it now appears in the exclusion list.
  6. To undo it later, select the entry and choose Remove.

Exclusions apply to real-time scanning only. Scheduled scans and other security products can still scan the item, and a process exclusion is safest with its full path.

Method 4: Disable via Group Policy (Pro/Enterprise/Education)

Microsoft's Windows 11 edition comparison lists Group Policy for Pro, not Home, and Enterprise and Education are managed the same way. Microsoft warns that turning off real-time protection this way drastically reduces protection, and tamper protection makes Windows ignore the change.

  1. Press Win + R, type gpedit.msc and press Enter.
  2. Go to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Real-time Protection.
  3. Open Turn off real-time protection.
  4. Select Enabled, then select OK.
  5. Restart the PC so the policy applies.

To reverse it, set the same policy to Not Configured. Tamper protection cannot be turned off through Group Policy, so a policy that appears to apply may still do nothing.

Method 5: PowerShell control (fast, scriptable, often temporary)

Run Windows PowerShell as administrator. The same tamper protection rule applies: with it on, the change does not stick.

Set-MpPreference -DisableRealtimeMonitoring $true

Turns off Defender real-time protection. Run Set-MpPreference -DisableRealtimeMonitoring $false to turn it back on, which Microsoft recommends.

You should see: The command returns no output. Windows Security then shows Real-time protection as Off, or reports that the setting is managed.

Method 6: Registry changes (usually overkill, easy to break)

Older guides tell you to create a DisableAntiSpyware value. Microsoft has removed that key for this purpose, so it no longer disables Defender on current Windows 10 and Windows 11.

Registry value Current status Use it?
DisableAntiSpyware / DisableAntivirus Removed for consumer devices; ignored on devices onboarded to Defender for Endpoint from platform 4.18.2108.4; protected by tamper protection since Windows 10 version 1903 No
ForceDefenderPassiveMode under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection Puts Defender in passive mode on Windows Server onboarded to Defender for Endpoint Servers only

On a home PC, installing another antivirus does what the old registry tweak used to do, without editing the registry at all.

How to check whether Defender is really off

Run this in PowerShell to read the mode Defender Antivirus is running in.

Get-MpComputerStatus | select AMRunningMode

Reports the running mode of Microsoft Defender Antivirus on this PC.

You should see: Normal, Passive or EDR Block Mode means Defender Antivirus is still enabled. Any of those after Method 1 means the other antivirus is not registered with Windows Security.

In Windows Security > Virus & threat protection, the page also names the antivirus provider currently protecting the PC.

Troubleshooting: what to do when Defender won’t stay off

Real-time protection turns itself back on

The Windows Security switch is a temporary pause by design.

  1. Use Method 1 if you want Defender off permanently.
  2. Use an exclusion from Method 3 if only one app or folder is the problem.

A Group Policy or PowerShell change does nothing

Tamper protection blocks changes to protected settings even when the tool reports success.

  1. Open Windows Security > Virus & threat protection > Manage settings.
  2. Check whether Tamper protection is On.
  3. Switch it Off, apply the change, then switch it back On once the change is no longer needed.

The Real-time protection switch is grayed out

Your organization manages Defender through policy.

  1. Ask your IT administrator; the setting is controlled centrally.
  2. On a personal PC, reset any Turn off real-time protection policy from Method 4 to Not Configured.

Defender stays active after another antivirus is installed

If the Windows Security Center service is disabled, Defender cannot detect the other product and stays active.

  1. Restart the PC so the new antivirus can register with Windows Security.
  2. Leave the Windows Security Center service at its default; Microsoft warns against disabling Defender-related services.
  3. Reinstall the other antivirus if Windows Security still does not list it.

Defender keeps deleting a file you trust

The file matches a detection, so Defender quarantines or removes it.

  1. Open Windows Security > Virus & threat protection > Protection history and check the detection.
  2. Restore the file only if you trust its source and publisher.
  3. Add the file or its folder as an exclusion (Method 3) so it is not removed again.

Common mistakes that make it look like Defender was removed

What you did What actually happened
Turned off Real-time protection A temporary pause; it comes back on automatically
Ran two antivirus products at once Microsoft advises against it; it can slow the PC and cause update errors such as 0x80070643
Set DisableAntiSpyware in the registry Current Windows ignores it for this purpose
Disabled the WinDefend or SecurityHealthService service Microsoft warns this can cause severe instability and breaks how other antivirus products show in Windows Security
Hid the Defender tray icon or context menu entry Only the shortcut is gone; protection keeps running

Removing the old Scan with Windows Defender context menu entry is a cosmetic change only.

How to turn Defender back on

  1. Uninstall the third-party antivirus from Settings > Apps, or let its subscription lapse.
  2. Restart the PC; Defender Antivirus re-enables itself automatically.
  3. Open Windows Security > Virus & threat protection > Manage settings.
  4. Switch Real-time protection, Cloud-delivered protection and Tamper protection to On.
  5. Set any Group Policy you changed back to Not Configured.

The steps to uninstall a program in Windows 11 apply to most antivirus suites.

FAQs

Can I remove Microsoft Defender?

Not on Windows 10 or Windows 11. Defender Antivirus is built into both, and the supported route is installing another antivirus, which moves Defender to disabled mode automatically. Only Windows Server lets you uninstall it, with Uninstall-WindowsFeature Windows-Defender.

How do I remove Windows Defender permanently?

Install a compatible third-party antivirus. Windows 10 and Windows 11 then keep Defender Antivirus in disabled mode for as long as that product provides real-time protection. If it expires or is removed, Defender turns back on so the PC is not left unprotected.

How do I remove Windows Defender on Windows 11?

You cannot uninstall it, but you can replace it. Install another antivirus and Windows 11 disables Defender Antivirus automatically. For a short pause, turn off Real-time protection under Windows Security > Virus & threat protection > Manage settings.

How do I remove Windows Defender on Windows 10?

Windows 10 works the same way as Windows 11. Defender Antivirus cannot be uninstalled, but installing a third-party antivirus disables it automatically, and Windows Security has a temporary Real-time protection switch for short tasks.

How do I turn off Windows Defender?

Open Windows Security, select Virus & threat protection, then Manage settings, and switch Real-time protection to Off. Turn off Tamper protection first if it is on. Real-time protection switches itself back on after a short while.

How do I stop Windows Defender from deleting a file?

Add the file or its folder as an exclusion. In Windows Security, go to Virus & threat protection > Manage settings > Add or remove exclusions, then select Add an exclusion. Only exclude files you are sure are clean.

Can I remove Windows Defender with PowerShell?

On Windows 10 and Windows 11, PowerShell can only switch settings, such as Set-MpPreference -DisableRealtimeMonitoring $true. A real uninstall through PowerShell exists only on Windows Server, using Uninstall-WindowsFeature Windows-Defender.

How do I remove Windows Defender on Windows Server?

Install your other antivirus first, then run Uninstall-WindowsFeature Windows-Defender as administrator on Windows Server 2019 and newer. Windows Server 2016 also needs Uninstall-WindowsFeature Windows-Defender-Gui. Restart the server to finish.

Can I remove Windows Defender on Windows 11 Home?

No edition of Windows 11 lets you uninstall Defender Antivirus. On Home, as on other editions, installing another antivirus disables it automatically, and the Windows Security switch pauses real-time protection temporarily.

Is it safe to turn off Windows Defender?

Only if another antivirus is protecting the PC. Microsoft warns that a device with Defender disabled and no other security product is vulnerable to malware, and that files downloaded while real-time protection is off are not scanned.

Bottom Line

Install the antivirus you want to use and let Windows put Defender into disabled mode, and use an exclusion for any single file Defender keeps blocking. Windows 10 and Windows 11 cannot uninstall Defender, the registry tweaks no longer work, and every manual off switch is either temporary or overridden by tamper protection.

Philip Celasco

Philip is a Texas-based technology writer and IT administrator at Techdows.com with more than 10 years of experience creating practical content for everyday users and professionals. He specializes in web browsers, particularly Chromium-based platforms such as Google Chrome, Microsoft Edge, Brave, and Opera. Through his work as an IT administrator, Philip has hands-on experience managing devices, configuring browser policies, troubleshooting software and network issues, and helping people resolve problems that affect productivity and security. His articles are based on practical testing and real-world technical experience. He covers browser settings, extensions, performance problems, privacy controls, security features, and Windows troubleshooting. Outside work, Philip enjoys the quieter side of life in Texas and stepping away from the screen when he can. He has two kids, two cats and loves to play golf with his mother during the weekends.

Leave a Reply

Your email address will not be published. Required fields are marked *