Updated: October 2026
An installer gets quarantined halfway through, or a test tool trips a detection, and the ticket says "just turn Defender off." Turning it off takes four clicks. Here's how to disable Windows Defender temporarily on one PC, why tamper protection quietly ignores the shortcuts, and what to use instead on managed devices so protection comes back on.
Check What Defender Blocked First
Open Windows Security, go to Virus & threat protection and select Protection history. Every block and quarantine is listed there with the file path and the detection name. Often, the fix is sitting on that screen.
If the detection is a false positive on a file you trust, restore that one item and allow it. If a line-of-business app keeps tripping the same rule, a narrow exclusion for its exact path beats switching protection off for the whole machine. And if the detection name looks like a real threat, stop. Fake installers are how a trojan virus usually gets in, and that one isn't going on the PC.
Server teams see the same pattern at scale. A database group blames Defender for slow queries, asks for it off, and the real cause turns out to be an exclusion written with the wrong syntax.
How to Disable Windows Defender Temporarily on One PC
On a personal or unmanaged Windows 10 or 11 PC, the supported switch lives in the Windows Security app:
- Open Windows Security and select Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Switch Real-time protection to Off and accept the UAC prompt.
- Run the install or test.
- Switch Real-time protection back to On.
Step 5 matters even though Windows has a safety net. Microsoft's support page says real-time protection "will turn back on automatically after a short while." It doesn't say how long. Scheduled scans keep running in the gap, but files downloaded or installed while it's off aren't scanned until the next scheduled scan.
So the gap is the risk. Anything that lands on the disk in that window gets a free pass until the next scan runs. Keep the window short, download the installer before you switch protection off, and don't browse while you wait.
If the toggle is greyed out with a "managed by your administrator" note, the PC is under policy. The Windows Security app won't override that, and neither should you. Skip to troubleshooting mode below.
Why Tamper Protection Ignores Your Script
Search for this topic and you'll find the same three shortcuts: a registry value, a Group Policy setting and Set-MpPreference -DisableRealtimeMonitoring $true. On a current Windows build, all three tend to do nothing.
That's tamper protection. With it on, real-time protection, behavior monitoring and cloud protection stay on, exclusions can't be added, and registry changes to Defender settings are blocked. Microsoft's tamper protection overview warns that changes made through a management tool, Group Policy included, "might appear to succeed" while tamper protection blocks them. The command returns without an error. Protection stays on.
It works this way because switching off the antivirus is the first thing an attacker's script tries. An exploit that lands with admin rights gets the same PowerShell you do, so the lock can't depend on who's typing. Microsoft turns tamper protection on by default for new Defender for Endpoint deployments.
Matt Soseman walks through what tamper protection locks and why he doesn't recommend switching it off.
On Managed Devices, Use Troubleshooting Mode
For devices onboarded to Microsoft Defender for Endpoint, Microsoft built a sanctioned way to open the lock. A Security Administrator opens the device page in the Defender portal, selects More options, then Turn on troubleshooting mode. Activation can take up to 15 minutes.
While it's active, a local admin can change settings that policy usually locks, including tamper protection itself with Set-MpPreference -DisableTamperProtection $true. They still can't turn off or uninstall Microsoft Defender Antivirus. The troubleshooting mode docs (updated September 2026) set the limits: it switches off after four hours, a device gets eight hours per 24, and policy-managed settings revert to their previous values when it ends.
That revert is the feature. Nobody has to remember to switch tamper protection back on, and the user gets notified when the window opens, is about to close and closes. The session also shows up in the device timeline, so the change is on the record.
Migrations are where this earns its keep. One admin moving servers off McAfee used it to test a backout plan into passive mode:
Better Than Off: Narrow Exclusions and Passive Mode
Often the ask behind "turn it off" is narrower: stop scanning this one thing. Here's what fits each case:
| Situation | Use | Protection left on |
|---|---|---|
| One installer on an unmanaged PC | Real-time protection toggle, back on after | Scheduled scans |
| A trusted app keeps getting blocked | Exclusion for its exact file or folder path | Everything else |
| Managed device, locked settings | Troubleshooting mode | Defender Antivirus stays installed |
| Another antivirus is the primary | Passive mode or automatic disable | The other product |
For an exclusion, use a full path: Add-MpPreference -ExclusionPath "C:\Program Files\Contoso\app.exe". Remove it with Remove-MpPreference once the vendor fixes the detection. Microsoft's list of exclusions to avoid rules out C:\Temp, user profile folders, extensions like .exe and .ps1, and processes like powershell.exe. It also flags a trap: Defender reads %TEMP% as the system account, so it points at C:\Windows\Temp, not the user's temp folder.
If a different antivirus is the real primary, Windows 10 and 11 already handle it. Install a compatible third-party product and Defender switches itself off. Remove that product or let its license lapse and Defender turns back on. On devices onboarded to Defender for Endpoint, it drops into passive mode instead. Windows Server doesn't switch on its own, and Microsoft says not to stop the WinDefend or MsMpEng services by hand.
Confirm Defender Is Back On
Don't trust the toggle. Ask Defender directly in an elevated PowerShell window:
powershellGet-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabled, AMRunningMode Get-MpPreference | Select-Object ExclusionPath, ExclusionProcess
A healthy result reads True, True, True and Normal. Passive or EDR Block Mode is fine when another antivirus is the primary on purpose. Any False, or an exclusion nobody can explain, means the job isn't finished. Our PowerShell commands guide covers running checks like this against a remote machine.
OpenFrame can run the same two lines as a script across a client's devices and collect the output, so one forgotten toggle shows up as one row, not a surprise in next month's incident.
The Short Version
To disable Windows Defender temporarily on an unmanaged PC, switch off real-time protection in Windows Security, do the install, then switch it back on. Windows turns it back on after a short while anyway. On managed devices, tamper protection blocks registry, Group Policy and PowerShell shortcuts, so use Defender for Endpoint troubleshooting mode, which reverts on its own after four hours. Before any of that, check Protection history: a restored false positive or a narrow exclusion often does the job without switching anything off.
If you're weighing Defender's paid tiers for a client fleet, our Microsoft Defender XDR review is the next read.
Dmytro Koval
Head of Product Engineering
Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.
