Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

An installer gets quarantined halfway through, or a test tool trips a detection, and the ticket says "just turn Defender off." Turning it off takes four clicks. Here's how to disable Windows Defender temporarily on one PC, why tamper protection quietly ignores the shortcuts, and what to use instead on managed devices so protection comes back on.

Check What Defender Blocked First

Open Windows Security, go to Virus & threat protection and select Protection history. Every block and quarantine is listed there with the file path and the detection name. Often, the fix is sitting on that screen.

If the detection is a false positive on a file you trust, restore that one item and allow it. If a line-of-business app keeps tripping the same rule, a narrow exclusion for its exact path beats switching protection off for the whole machine. And if the detection name looks like a real threat, stop. Fake installers are how a trojan virus usually gets in, and that one isn't going on the PC.

Server teams see the same pattern at scale. A database group blames Defender for slow queries, asks for it off, and the real cause turns out to be an exclusion written with the wrong syntax.

How to Disable Windows Defender Temporarily on One PC

On a personal or unmanaged Windows 10 or 11 PC, the supported switch lives in the Windows Security app:

  1. Open Windows Security and select Virus & threat protection.
  2. Under Virus & threat protection settings, select Manage settings.
  3. Switch Real-time protection to Off and accept the UAC prompt.
  4. Run the install or test.
  5. Switch Real-time protection back to On.

Step 5 matters even though Windows has a safety net. Microsoft's support page says real-time protection "will turn back on automatically after a short while." It doesn't say how long. Scheduled scans keep running in the gap, but files downloaded or installed while it's off aren't scanned until the next scheduled scan.

So the gap is the risk. Anything that lands on the disk in that window gets a free pass until the next scan runs. Keep the window short, download the installer before you switch protection off, and don't browse while you wait.

If the toggle is greyed out with a "managed by your administrator" note, the PC is under policy. The Windows Security app won't override that, and neither should you. Skip to troubleshooting mode below.

Why Tamper Protection Ignores Your Script

Search for this topic and you'll find the same three shortcuts: a registry value, a Group Policy setting and Set-MpPreference -DisableRealtimeMonitoring $true. On a current Windows build, all three tend to do nothing.

That's tamper protection. With it on, real-time protection, behavior monitoring and cloud protection stay on, exclusions can't be added, and registry changes to Defender settings are blocked. Microsoft's tamper protection overview warns that changes made through a management tool, Group Policy included, "might appear to succeed" while tamper protection blocks them. The command returns without an error. Protection stays on.

It works this way because switching off the antivirus is the first thing an attacker's script tries. An exploit that lands with admin rights gets the same PowerShell you do, so the lock can't depend on who's typing. Microsoft turns tamper protection on by default for new Defender for Endpoint deployments.

Matt Soseman walks through what tamper protection locks and why he doesn't recommend switching it off.

On Managed Devices, Use Troubleshooting Mode

For devices onboarded to Microsoft Defender for Endpoint, Microsoft built a sanctioned way to open the lock. A Security Administrator opens the device page in the Defender portal, selects More options, then Turn on troubleshooting mode. Activation can take up to 15 minutes.

While it's active, a local admin can change settings that policy usually locks, including tamper protection itself with Set-MpPreference -DisableTamperProtection $true. They still can't turn off or uninstall Microsoft Defender Antivirus. The troubleshooting mode docs (updated September 2026) set the limits: it switches off after four hours, a device gets eight hours per 24, and policy-managed settings revert to their previous values when it ends.

That revert is the feature. Nobody has to remember to switch tamper protection back on, and the user gets notified when the window opens, is about to close and closes. The session also shows up in the device timeline, so the change is on the record.

Migrations are where this earns its keep. One admin moving servers off McAfee used it to test a backout plan into passive mode:

Better Than Off: Narrow Exclusions and Passive Mode

Often the ask behind "turn it off" is narrower: stop scanning this one thing. Here's what fits each case:

SituationUseProtection left on
One installer on an unmanaged PCReal-time protection toggle, back on afterScheduled scans
A trusted app keeps getting blockedExclusion for its exact file or folder pathEverything else
Managed device, locked settingsTroubleshooting modeDefender Antivirus stays installed
Another antivirus is the primaryPassive mode or automatic disableThe other product

For an exclusion, use a full path: Add-MpPreference -ExclusionPath "C:\Program Files\Contoso\app.exe". Remove it with Remove-MpPreference once the vendor fixes the detection. Microsoft's list of exclusions to avoid rules out C:\Temp, user profile folders, extensions like .exe and .ps1, and processes like powershell.exe. It also flags a trap: Defender reads %TEMP% as the system account, so it points at C:\Windows\Temp, not the user's temp folder.

If a different antivirus is the real primary, Windows 10 and 11 already handle it. Install a compatible third-party product and Defender switches itself off. Remove that product or let its license lapse and Defender turns back on. On devices onboarded to Defender for Endpoint, it drops into passive mode instead. Windows Server doesn't switch on its own, and Microsoft says not to stop the WinDefend or MsMpEng services by hand.

Confirm Defender Is Back On

Don't trust the toggle. Ask Defender directly in an elevated PowerShell window:

powershell
Get-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabled, AMRunningMode
Get-MpPreference | Select-Object ExclusionPath, ExclusionProcess

A healthy result reads True, True, True and Normal. Passive or EDR Block Mode is fine when another antivirus is the primary on purpose. Any False, or an exclusion nobody can explain, means the job isn't finished. Our PowerShell commands guide covers running checks like this against a remote machine.

OpenFrame can run the same two lines as a script across a client's devices and collect the output, so one forgotten toggle shows up as one row, not a surprise in next month's incident.

The Short Version

To disable Windows Defender temporarily on an unmanaged PC, switch off real-time protection in Windows Security, do the install, then switch it back on. Windows turns it back on after a short while anyway. On managed devices, tamper protection blocks registry, Group Policy and PowerShell shortcuts, so use Defender for Endpoint troubleshooting mode, which reverts on its own after four hours. Before any of that, check Protection history: a restored false positive or a narrow exclusion often does the job without switching anything off.

If you're weighing Defender's paid tiers for a client fleet, our Microsoft Defender XDR review is the next read.

Dmytro Koval

Dmytro Koval

Head of Product Engineering

Hi! My name is Dmytro, but everyone calls me Dima. I’m a Software Developer and together with the development team, I help bring Flamingo to life — putting it on its feet from a technical perspective. Originally from Lviv, Ukraine 🇺🇦, but currently based in Spain, where I’ve been enjoying the blend of great weather, culture, and nature. I’m passionate about the mountains and love traveling — exploring new places and cultures really inspires me. These experiences constantly recharge me and give me a fresh perspective, both personally and professionally.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Disable Windows Defender Temporarily

Open Windows Security, select Virus & threat protection, then Manage settings under Virus & threat protection settings, and switch Real-time protection to Off. Do the install or test, then switch it back on. Microsoft says real-time protection turns back on automatically after a short while, and scheduled scans keep running while it is off.
Tamper protection is on. It keeps real-time protection, behavior monitoring and cloud protection enabled and blocks changes made through PowerShell, the registry or Group Policy. The command can return without an error while nothing changes. On devices managed with Microsoft Defender for Endpoint, use troubleshooting mode to change protected settings for a limited time.
Troubleshooting mode in Microsoft Defender for Endpoint can take up to 15 minutes to start and switches off automatically after four hours. Each device gets up to eight hours per 24 hours. When it ends, policy-managed settings, including tamper protection, revert to their previous values.
Run Get-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabled, AMRunningMode in PowerShell. A healthy device shows True, True, True and Normal. Passive or EDR Block Mode is expected when another antivirus is the primary. Also check Get-MpPreference for exclusions you did not mean to leave behind.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.