[DISCUSSION] Disabling Microsoft Defender Antivirus (formerly Windows Defender)

Discussion in 'Windows 11' started by Espionage724, Oct 29, 2021.

  1. sonic9

    sonic9 MDL Member

    Aug 4, 2009
    192
    78
    10
    Don't forget disable tamper protection before gpedit.
    Then a working alternative is GPO "Turning off Real time protection".
     
  2. Super Spartan

    Super Spartan MDL Expert

    May 30, 2014
    1,767
    1,019
    60
    1) Disable Memory Integrity from Device Security
    2) Toggle all switches off for everything including tamper protection
    3) reboot into safe mode
    4) double click on the attached reg file to disable Windows Defender Services
    5) apply the Group Policy Rules to turn off Windows defender and "allow antimalware service to remain running always" = disabled
     

    Attached Files:

    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  3. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,093
    404
    60
    How does Defender know to disable itself if other AV is running?
     
  4. vladnil

    vladnil MDL Senior Member

    Jan 19, 2019
    475
    324
    10
    Does anyone know what the name of the file that fixes system files AND RESTORE DEFENDER is? This file needs to be removed from the system!!!
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  5. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,269
    1,183
    60
    AV registers in windows security center (SecurityHealthHost.exe) based on the file name (+digital signature) and Defender is like, I will take a break, but I will keep looking over your shoulder, just in case.
     
  6. vladnil

    vladnil MDL Senior Member

    Jan 19, 2019
    475
    324
    10
    I can't delete registry anchors when I go into the registry via Live СD. How can I delete them?
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WdNisSvc
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinDefend
     
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  7. Espionage724

    Espionage724 MDL Expert

    Nov 7, 2009
    1,093
    404
    60
    Has anyone tried making some minor background exe to fake the presence of a 3rd-party AV so Defender disables itself?

    I think I finally had real-time scanning disabled on 11 24H2 after disabling a bunch of stuff in group policy, but I'll try narrowing it down next time I'm bored of 10 :p
     
  8. TairikuOkami

    TairikuOkami MDL Expert

    Mar 15, 2014
    1,269
    1,183
    60
    This option is no longer available since July 2024 or so. Defender merely disables realtime, but it is still running in order to kick in, if 3rd party AV gets disabled by malware.
     
  9. dimon_sk

    dimon_sk MDL Novice

    Oct 27, 2018
    6
    0
    0
    I would like to reinstall Windows and do an upgrade to version 11 Enterprise LTSC 24H2 on my PC. I recently read about Windows Defender being a non-disable feature in this version.
    Usually I'm using option "Turn off Microsoft Defender Antivirus" => "Enable" in GPO for Windows 10 LTSC 21H2 and it works great. Can you tell me if I disable tamper protection will this group policy option work in Windows 11 Enterprise LTSC 24H2 or will it reset every time the PC is rebooted?
     
  10. Shortyportuguese

    Shortyportuguese MDL Addicted

    Apr 3, 2019
    520
    153
    30
    For me, I got some success to disable it
     
  11. sonic9

    sonic9 MDL Member

    Aug 4, 2009
    192
    78
    10
    GPO "Turn off Microsoft Defender Antivirus" not work anymore , since 24H2.
    GPO "Turning off Real time protection" works even after reboot.
     
  12. dimon_sk

    dimon_sk MDL Novice

    Oct 27, 2018
    6
    0
    0
    Okay, thank you... Can you tell me which group policy is responsible for Windows Defender updates via Windows Update? I would like to disable it too as I use another antivirus and these updates are useless for me...
     
  13. sonic9

    sonic9 MDL Member

    Aug 4, 2009
    192
    78
    10
    third party antivirus automatically disable windows defender which disable windows defender updates from WU too.
     
  14. James Bond 007

    James Bond 007 MDL Member

    Nov 16, 2010
    125
    88
    10
    #335 James Bond 007, Mar 4, 2025
    Last edited: Mar 4, 2025
    I have finally gotten Windows 11 24H2 IoT Enterprise LTSC (26100.1742) running in a VMware virtual machine (in unsupported configuration Legacy / MBR / No Secure Boot) and decide to do some tests regarding how to disable Microsoft Defender AntiVirus, which I consider very irritating.

    I started the virtual machine, disabled Tamper Protection in Windows Security, then went to the Group Policy Editor (gpedit.msc) and set the following :
    (1) Computer Configuration -> Administrative Templates -> Windows Components -> Microsoft Defender AntiVirus -> Real-time Protection -> Turn off real-time protection set to Enabled

    Restarted the virtual machine and Real-time protection in Windows Security was disabled with a message "This setting is managed by your administrator." :
    Disable Windows Defender 01.jpg

    Then I went back to the Group Policy Editor and set the following :
    (2) Computer Configuration -> Administrative Templates -> Windows Components -> Microsoft Defender AntiVirus -> Turn Off Microsoft Defender AntiVirus set to Enabled
    (3) Computer Configuration -> Administrative Templates -> Windows Components -> Microsoft Defender AntiVirus -> Allow antimalware service to remain running always set to Disabled

    Restarted the virtual machine and Virus and Threat Protection was completely disabled with a message "Your Virus & threat protection is managed by your organization" :
    Disable Windows Defender 02.jpg

    I am delighted to find that these Group Policy settings still work in Windows 11 24H2 IoT LTSC and Microsoft Defender AntiVirus has been successfully disabled.

    Update : It seems that the Group Policy "Turn Off Microsoft Defender AntiVirus" was reverted to "Not Configured" after some time but real-time protection remained disabled.

    Acceptable to me at this time.

    Will do more tests later.
     
  15. Super Spartan

    Super Spartan MDL Expert

    May 30, 2014
    1,767
    1,019
    60
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...
  16. James Bond 007

    James Bond 007 MDL Member

    Nov 16, 2010
    125
    88
    10