How to Temporarily Disable Windows Defender in Windows 10 Pro
Windows Defender Antivirus is built into Windows 10 Pro and works through the Windows Security app. It checks files, downloads, running programs, and system activity for malware. In most situations, keeping real-time protection enabled is the safest choice, but a trusted application or installer may occasionally be blocked during setup.
Temporarily turning off Defender can help diagnose a false positive or complete a software installation that Windows Security has interrupted. The setting is designed to switch itself back on after a short time or after the next restart, depending on the circumstances. It should never be treated as a permanent solution for compatibility problems.
Before changing the protection setting, confirm that the file came from a reputable source and that you have a way to restore protection immediately. If you are trying to run an older application rather than install a suspicious file, compatibility mode may solve the problem without lowering your security settings.
What Windows Defender Controls
Windows Defender Antivirus is one part of the Windows Security system. Real-time protection scans files as they are opened, downloaded, or executed. Cloud-delivered protection and automatic sample submission can also help Microsoft identify new threats, while tamper protection prevents unwanted changes to important security settings.
Disabling real-time protection does not remove Defender from the computer. It pauses one of its active scanning functions. Scheduled scans, firewall rules, SmartScreen checks, and other Windows Security features may continue to operate. This distinction matters because turning off antivirus scanning does not create an unrestricted system.
Windows 10 can also use a third-party antivirus program. When a compatible security product is installed and recognized, Microsoft Defender may enter passive or disabled mode automatically. In that situation, some Defender controls may be unavailable because the other antivirus program is responsible for real-time protection.
Prepare Before Pausing Protection
Save your work and close programs that do not need to remain open. If you are testing an installer, download it before disabling protection, preferably from the software publisher’s official website. Avoid opening email attachments, unknown archives, cracks, key generators, or files shared through unverified links while antivirus protection is paused.
It is also useful to create a restore point before making significant system changes. A restore point will not replace antivirus protection, but it can provide a recovery option if a new program changes system files or causes startup problems. Keep the Windows Security window available so the setting can be restored quickly.
If the issue involves obtaining Windows installation media, use a trusted source such as the Windows 10 download page and verify that the download matches the intended edition and architecture. Disabling security software will not correct a damaged ISO, an incorrect installation method, or an incomplete download.
Disable Real-Time Protection
The simplest method uses the Windows Security interface. Press the Windows key, type Windows Security, and open the matching app from the search results. You can also reach it through Settings > Update & Security > Windows Security > Virus & threat protection.
Under Virus & threat protection settings, select Manage settings. Locate Real-time protection, then move the switch to Off. Windows may display a User Account Control prompt; select Yes only if you are performing the change intentionally. The status page should show that real-time protection is disabled.
Complete the necessary test or installation promptly. Do not browse unfamiliar websites, open unknown files, or connect removable media while this protection is inactive. In many cases, Windows 10 automatically turns real-time protection back on after a period of inactivity or following a restart, but you should restore it manually rather than relying on automatic behavior.
If the switch cannot be changed, review the message shown in Windows Security. Tamper protection, a third-party antivirus product, a work or school policy, or an account without administrator rights can prevent changes. Do not repeatedly force the setting through registry edits or downloaded utilities, since those actions can weaken security and create additional system problems.
Understand What Changes
Turning off real-time protection reduces the immediate scanning of files and programs. A harmful executable may be able to start without being checked at the moment it is launched. Windows Security may still show warnings, and other protections may remain active, but the computer has less defense against malware during the testing period.
The following settings are related but should not be confused with one another:
| Setting | Main purpose | Effect when disabled | Safer handling |
|---|---|---|---|
| Real-time protection | Scans files and programs as they are used | Reduces active malware scanning | Pause briefly, then restore |
| Cloud-delivered protection | Uses Microsoft’s online threat intelligence | May reduce detection of emerging threats | Leave enabled where possible |
| Automatic sample submission | Sends suspicious samples for analysis | May limit Microsoft’s ability to improve detection | Disable only for a specific privacy or diagnostic reason |
| Tamper protection | Blocks unauthorized security changes | Makes Defender settings harder to alter | Keep enabled unless an administrator has a documented reason |
| Microsoft Defender Firewall | Controls network traffic | Can expose the device to unwanted connections | Do not disable it merely to fix an application issue |
| Exclusions | Omits selected files, folders, or processes from scans | Leaves specific locations less protected | Use a narrow, temporary exclusion instead of disabling all scanning |
Real-time protection and the firewall provide different types of protection. If a program cannot connect to the internet, disabling antivirus scanning may have no effect. A firewall rule, proxy setting, application permission, or server problem could be responsible instead.
Likewise, if Windows reports that a file is infected, turning off Defender does not prove the detection is false. Check the file’s digital signature, publisher, download source, and reputation. When a warning concerns a system component or a common utility, scan the file with another trusted security service before allowing it to run.
Use Narrower Alternatives First
A temporary exclusion is often less disruptive than disabling all real-time scanning. In Virus & threat protection settings, open Exclusions, select Add or remove exclusions, and choose Add an exclusion. You can select a file, folder, file type, or process, depending on what the application requires.
Use the narrowest option possible. Excluding one verified installer is safer than excluding the entire Downloads folder. A folder exclusion can allow every future file in that location to avoid scanning, including files added accidentally or downloaded by another program. Remove the exclusion as soon as the task is complete.
Other practical alternatives can resolve software problems without changing antivirus protection:
- Re-download the installer from the publisher’s official website.
- Check whether the application has a newer Windows 10-compatible release.
- Run the program as administrator only when the publisher’s instructions require it.
- Use Windows compatibility settings for older software.
- Ask the software vendor to review a possible false-positive detection.
Some installers are blocked because they are unsigned, packed unusually, or bundled with unwanted software. A reputable developer should provide a signed package, release notes, and a support channel. If a program works only when Defender is disabled and has no verifiable publisher, consider that behavior a security warning rather than a Windows fault.
Restore Protection And Verify Status
After the installation or diagnostic test, return to Windows Security > Virus & threat protection > Manage settings and switch Real-time protection back to On. If you created an exclusion, open Exclusions, select the entry, and remove it. Restore any other security settings that were changed during troubleshooting.
Restart the computer after restoring protection. Then open Windows Security and check that the protection status is green or that no critical action is required. Select Virus & threat protection and review Protection history for detections or blocked items related to the test.
Run a Quick scan after protection is restored. If you opened several files while Defender was disabled, a Full scan may be appropriate, especially if the source was unfamiliar or the computer behaves differently afterward. Symptoms such as unexpected pop-ups, new browser extensions, slow startup, unknown processes, or changed security settings should be investigated promptly.
If Windows Security still reports that protection is off, update Windows and the Defender security intelligence. Check Settings > Update & Security > Windows Update, select Check for updates, and install available security updates. A third-party antivirus application may also need to be repaired, updated, or removed before Microsoft Defender can resume normal operation.
Keep The Change Temporary
Windows Defender is most useful when it remains active during everyday browsing, downloads, and software installation. A short pause can assist with a verified troubleshooting task, but leaving the setting disabled creates an avoidable gap in protection. Automatic reactivation is helpful, yet it should not replace a manual status check.
If the same application repeatedly triggers a detection, record the exact alert name and file path instead of switching off security permanently. Submit the file to the software publisher or Microsoft through an approved false-positive process when appropriate. This creates a better long-term fix and helps distinguish a genuine threat from a compatibility issue.
Use the Windows Security dashboard as the final check: real-time protection should be enabled, exclusions should be limited, and recent scans should show no unresolved threats. Complete those checks before returning to normal browsing or opening additional downloads.