Microsoft Defender Turned Itself Off? Third-Party AV Conflicts Explained
You open Windows Security and discover that Microsoft Defender Antivirus is turned off.
The real-time protection switch may be unavailable, Windows may say that another antivirus provider is managing the device, or Defender may appear to turn itself off again whenever you restart the computer.
This can look alarming, but it does not necessarily mean that malware has disabled your protection.
On Windows 11, Microsoft Defender Antivirus normally steps aside when a compatible third-party antivirus product registers itself as the computer’s active protection. Windows does this deliberately to prevent two real-time antivirus engines from scanning and intercepting the same files simultaneously. (Microsoft Learn)
The important question is not simply:
“Is Microsoft Defender turned on?”
It is:
“Which antivirus provider is currently protecting the computer, and is it working properly?”
Windows Security and Microsoft Defender Antivirus Are Not the Same Thing
The names can be confusing.
Windows Security is the built-in Windows application that displays the status of several protection technologies, including:
- Antivirus
- Firewall
- Account protection
- App and browser control
- Device security
- Core isolation
- Security providers
Microsoft Defender Antivirus is the antivirus engine built into Windows.
Windows Security remains installed and continues displaying information even when Microsoft Defender Antivirus is not the active antivirus. It can show the status of third-party antivirus and firewall products registered with Windows Security Center. (Microsoft Learn)
You may therefore still see the Windows Security shield icon while another company’s antivirus is handling real-time malware protection.
Features such as Windows Firewall, Microsoft Defender SmartScreen and Device Security may also remain active even when Microsoft Defender Antivirus itself has stepped aside. (Microsoft Learn)
Why Defender Automatically Turns Itself Off
A compatible antivirus product registers with Windows Security Center when it is installed.
Windows then recognises that the computer already has a primary antivirus provider and automatically disables or limits Microsoft Defender Antivirus. The third-party product should appear under the Antivirus section of Windows Security’s provider list. (Microsoft Learn)
This behaviour helps avoid:
- Two engines scanning every opened file
- Conflicting malware detections
- Files being quarantined by one product while the other is inspecting them
- Duplicate web or email scanning
- Application slowdowns
- High disk or processor usage
- Instability during software installation
- Failed updates or backups
Microsoft warns that running multiple real-time anti-malware applications at the same time can make a computer slow or unstable. (Microsoft Support)
More antivirus software is not automatically better protection.
The normal arrangement is:
- One primary real-time antivirus product
- Other Windows security features operating alongside it
- Optional specialist scanners used only when needed
Check Which Antivirus Is Actually Protecting the PC
Before trying to turn Microsoft Defender back on, check whether another product is active.
Open:
Windows Security > Virus & threat protection
Under Who’s protecting me?, select:
Manage providers
You can also open:
Windows Security > Settings > Manage providers
Expand the Antivirus section.
Windows should show the product currently responsible for protecting the device. (Microsoft Support)
You might see:
Microsoft Defender Antivirus is turned on
or:
Third-Party Antivirus is turned on
Microsoft Defender Antivirus is turned off
When the third-party product is recognised and reports that it is active, Defender being off is normally expected.
Do Not Judge Protection by the Taskbar Icon Alone
A third-party security application may display a system-tray icon even when its antivirus engine has expired, stopped or failed to register correctly.
Similarly, the Windows Security shield icon does not prove that Microsoft Defender Antivirus is the active provider.
Use Manage providers to check the status Windows is actually receiving.
Check Defender’s Status with PowerShell
For a more technical check, open PowerShell and run:
Get-MpComputerStatus
The command reports the status of the antimalware components installed on the computer. (Microsoft Learn)
For a shorter result, use:
Get-MpComputerStatus |
Select-Object AMRunningMode,
AMServiceEnabled,
AntivirusEnabled,
RealTimeProtectionEnabled,
IsTamperProtected,
AntivirusSignatureLastUpdated
The most useful field is:
AMRunningMode
Possible results include:
Normal
Microsoft Defender Antivirus is operating as the primary antivirus product.
It provides real-time scanning and can detect and remediate threats. (Microsoft Learn)
Passive
Defender is present and running, but it is not the primary antivirus.
True passive mode is mainly associated with devices onboarded to Microsoft Defender for Endpoint. Defender can provide certain scanning and endpoint-detection capabilities, but it does not behave like the primary real-time antivirus and does not normally remediate detections itself. (Microsoft Learn)
EDR Block Mode
Microsoft Defender for Endpoint’s endpoint detection and response technology is operating in block mode alongside another primary antivirus.
This is mainly relevant to managed business environments rather than an ordinary home computer. (Microsoft Learn)
SxS Passive Mode
Defender is running alongside another antivirus using limited periodic scanning rather than acting as the main real-time provider. (Microsoft Learn)
Not running or disabled
Defender is not currently providing antivirus scanning.
This can be normal when a working third-party antivirus is active. It becomes a problem when no other antivirus is genuinely protecting the computer.
Passive Mode Is Not the Same as Active Protection
People sometimes see Defender processes or definition updates and assume it must still be functioning as a second full antivirus.
That is not necessarily the case.
In passive mode, Microsoft Defender Antivirus is not the primary antivirus and does not provide normal antivirus enforcement. It can continue receiving security intelligence and supplying information to Microsoft Defender for Endpoint, but its protection capabilities are reduced compared with active mode. (Microsoft Learn)
A managed endpoint may also show detections attributed to Defender because EDR in block mode is operating behind the scenes. That does not mean two full real-time antivirus products are independently protecting the device. (Microsoft Learn)
What Is Limited Periodic Scanning?
Windows 11 may offer Limited periodic scanning when another antivirus product is active.
To find it:
- Open Windows Security.
- Select Virus & threat protection.
- Expand Microsoft Defender Antivirus options.
- Turn Periodic scanning on, when the option is available.
This allows a limited part of Microsoft Defender Antivirus to run occasional scans alongside the primary third-party antivirus. (Microsoft Learn)
However, this is not equivalent to having two complete antivirus products.
Microsoft says limited periodic scanning:
- Uses only a limited subset of Defender capabilities
- Has reduced detection and reporting
- Cannot be centrally managed like active Defender
- Is not recommended for enterprise environments
- Should not replace a properly functioning primary antivirus product (Microsoft Learn)
For a home computer, it can provide an additional occasional check. For a business, Microsoft recommends choosing one primary antivirus product and managing it properly instead. (Microsoft Learn)
What If the Third-Party Antivirus Is Intended?
When you deliberately installed another antivirus and it is working correctly, you normally do not need to force Microsoft Defender back on.
Instead, check the third-party product itself.
Confirm that:
- Its subscription or licence is active.
- Its real-time protection is enabled.
- It has received recent updates.
- It reports no unresolved errors.
- Windows Security lists it as the antivirus provider.
- Scheduled scans are completing.
- Its system-tray icon is not showing an alert.
- The application opens without requesting repair or reactivation.
If all of those checks are satisfactory, Defender being disabled is expected.
Avoid Switching Defender Services Manually
Do not open Services and repeatedly force the Microsoft Defender Antivirus Service to start while another antivirus is registered.
Windows controls Defender’s state according to the registered provider and the device’s management configuration. Manually changing associated services can cause inaccurate status information, instability and protection gaps. (Microsoft Learn)
The Expired Trial Problem
Many new computers arrive with a trial version of third-party antivirus software.
When the trial expires, several things can happen:
- The product continues protecting the computer but displays renewal warnings.
- Some protection components stop.
- The program reports itself as out of date.
- Windows stops recognising it as a healthy provider.
- Microsoft Defender automatically becomes active again.
- The failed product remains registered and prevents Defender from recovering properly.
Microsoft states that Defender can automatically re-enable if a non-Microsoft antivirus expires, is uninstalled or otherwise stops providing real-time protection. (Microsoft Learn)
Do not ignore an expired antivirus warning.
Decide whether you are going to:
- Renew and continue using that product, or
- Remove it completely and return to Microsoft Defender Antivirus
Leaving a half-working security suite installed is more likely to cause conflicts and uncertainty.
What If You Uninstalled the Other Antivirus but Defender Is Still Off?
This is one of the most common conflict scenarios.
The main application may have disappeared from the Start menu, but components can remain behind, including:
- Security services
- Filter drivers
- Browser extensions
- Network filters
- Scheduled tasks
- Update components
- Windows Security Center registration
- Quarantine or vault services
Windows may still believe that the previous antivirus is responsible for protection.
Step 1: Restart Windows
Restart the computer after uninstalling the third-party antivirus.
Do not rely only on shutting down and immediately powering it back on. A restart gives Windows an opportunity to unload security drivers, refresh provider registration and reactivate Defender.
Step 2: Check Installed Apps
Open:
Settings > Apps > Installed apps
Search for:
- The antivirus product
- Its VPN
- Browser-protection component
- Password manager
- Safe-search extension
- Security updater
- Web-protection module
- Vendor support or agent software
Some security suites install several separate components.
Remove only software that genuinely belongs to the unwanted product. A company-managed endpoint may have security agents that employees are not authorised to uninstall.
Step 3: Use the Vendor’s Official Cleanup Tool
A normal uninstall may not remove every low-level driver or registration entry.
Microsoft maintains guidance linking to cleanup and uninstall tools supplied by security-product manufacturers. Use the official tool for the exact vendor rather than a third-party “antivirus remover” from an unfamiliar download website. (Microsoft Support)
Run the vendor’s cleanup utility, restart Windows and check Manage providers again.
Step 4: Confirm Defender Has Returned
Open:
Windows Security > Virus & threat protection
If Defender has recovered, you should see its normal scanning and protection settings.
You can also run:
Get-MpComputerStatus |
Select-Object AMRunningMode,
AntivirusEnabled,
RealTimeProtectionEnabled
For a normal unmanaged Windows 11 computer using Microsoft Defender as its primary antivirus, you would expect:
AMRunningMode Normal
AntivirusEnabled True
RealTimeProtectionEnabled True
Turn Real-Time Protection Back On
When no other antivirus provider is active:
- Open Windows Security.
- Select Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Turn Real-time protection on.
If no compatible third-party antivirus is active, Defender should operate normally. Microsoft also notes that when real-time protection is turned off manually, Windows turns it back on automatically after a short period to maintain protection. (Microsoft Support)
If the switch is greyed out or immediately returns to off, investigate:
- A remaining antivirus provider
- Company management policies
- Damaged Windows components
- A disabled security service
- Malware or tampering
- An incomplete antivirus migration
Check Tamper Protection
Open:
Windows Security > Virus & threat protection > Manage settings
Find:
Tamper Protection
For a normal home computer using Microsoft Defender, keep it turned on.
Tamper protection helps prevent malicious applications from changing important Defender settings such as real-time protection, cloud protection, behaviour monitoring and security intelligence updates. (Microsoft Learn)
It does not prevent legitimate third-party antivirus products from registering with Windows Security. Microsoft specifically states that tamper protection does not alter the way non-Microsoft antivirus applications register themselves. (Microsoft Support)
This explains why installing another recognised antivirus can cause Defender to step aside even while tamper protection is enabled.
On a business device, tamper protection may be controlled by Microsoft Intune, Microsoft Defender for Endpoint or another management system. The local switch may be unavailable by design. (Microsoft Learn)
Do Not Disable Windows Security Center Services
Some online fixes recommend disabling services such as:
wscsvc
SecurityHealthService
WinDefend
MsMpEng
Sense
Do not do this as a routine troubleshooting step.
The Windows Security Center and Windows Security Health services help collect and display the current status of Microsoft and third-party protection products. Disabling them can make Windows Security show stale or inaccurate information and may prevent Defender from re-enabling after a third-party product is removed. (Microsoft Learn)
Microsoft also warns against editing Defender service start values directly in the Registry. Unsupported service modifications can leave the system unstable and may result in Windows requiring reimaging. (Microsoft Learn)
Do not use Registry scripts advertised as permanent “Defender disabling” or “Defender enabling” tools.
Repair Damaged Windows Components
When no third-party antivirus remains, Windows Security lists no other provider and Defender still refuses to start, damaged Windows components may be involved.
Open Terminal or Command Prompt as administrator and run:
DISM.exe /Online /Cleanup-Image /RestoreHealth
Allow the command to complete, then run:
sfc /scannow
DISM repairs the Windows component image, while System File Checker checks protected system files and replaces damaged or missing versions where possible. (Microsoft Support)
Restart Windows after both commands complete and check Defender again.
Also install pending updates from:
Settings > Windows Update
Security intelligence, Defender platform components and Windows Security itself are serviced through Microsoft’s update mechanisms. (Microsoft Learn)
Run a Scan After Protection Returns
Once Microsoft Defender Antivirus is active again:
- Open Windows Security.
- Select Virus & threat protection.
- Select Protection updates or Virus & threat protection updates.
- Check for updates.
- Return to Scan options.
- Run a Full scan.
When you suspect that malware may have disabled security software, also consider:
Microsoft Defender Offline scan
The offline scan restarts the computer and performs the scan outside the normal Windows session, making it harder for persistent malware to hide during the inspection.
Do not immediately reconnect unknown external drives or reopen suspicious downloads until the computer has been checked.
Could Malware Have Turned Defender Off?
Yes, malware sometimes attempts to disable antivirus, alter exclusions or interfere with security services.
However, the presence of a third-party antivirus is a much more common and legitimate reason for Defender to be disabled.
Warning signs that require deeper investigation include:
- No recognised antivirus is active.
- Defender settings changed without your involvement.
- Tamper protection was disabled unexpectedly.
- Unknown exclusions have appeared.
- Security services repeatedly stop.
- Windows Security will not open.
- Browser traffic is redirected.
- Unknown administrator accounts exist.
- Antivirus websites cannot be reached.
- The problem returns after cleanup and restart.
Microsoft explains that attackers commonly try to disable security features to remain undetected, which is one reason tamper protection exists. (Microsoft Learn)
Disconnect the computer from sensitive company systems and seek professional help when compromise is suspected.
Business Computers Work Differently
Company devices may use:
- Microsoft Defender for Endpoint
- Microsoft Defender for Business
- A third-party endpoint protection platform
- EDR running alongside another antivirus
- Microsoft Intune
- Group Policy
- Security baselines
- Central tamper protection
- Application and device-control policies
A device can legitimately show Defender in passive mode while another product supplies primary antivirus protection and Microsoft Defender for Endpoint supplies telemetry or EDR capabilities. (Microsoft Learn)
Do not uninstall corporate security software or try to force Defender into active mode.
Doing so can:
- Remove the device from central monitoring
- Break regulatory or insurance requirements
- Create duplicate real-time scanning
- Interfere with incident-response tools
- Trigger security alerts
- Leave the organisation without accurate endpoint reporting
Contact the organisation’s IT provider when the device says settings are managed, policies are greyed out or an unfamiliar endpoint product is listed.
Windows Server Is Not the Same as Windows 11
Instructions written for Windows Server should not be copied blindly to a Windows 11 PC—and Windows 11 instructions should not automatically be applied to a server.
On supported Windows client devices, Defender normally reacts automatically when another antivirus registers.
On several Windows Server versions, Microsoft Defender Antivirus may not automatically enter passive mode when a third-party product is installed, and additional configuration may be required to prevent two antivirus engines operating together. (Microsoft Learn)
Server antivirus changes should be planned and carried out by the organisation’s administrator or IT provider.
Common Mistakes to Avoid
Installing a Second Antivirus to “Back Up” the First
Two full real-time antivirus products can conflict, slow the system and produce unpredictable results.
Use one primary real-time provider. (Microsoft Support)
Forcing Defender On While Another Antivirus Is Active
Defender stepped aside for a reason.
Check the existing provider instead of fighting Windows Security Center.
Assuming the Third-Party Product Is Working Because Its Icon Appears
Check its licence, update status and Windows Security provider registration.
Leaving an Expired Trial Installed
Renew it or remove it completely.
Do not leave the computer between two partially functioning products.
Editing Defender Service Registry Values
Microsoft warns that unsupported service-start modifications can damage the security configuration severely enough to require reimaging. (Microsoft Learn)
Turning Off Windows Security Services
This can make provider reporting inaccurate and interfere with Defender’s automatic recovery. (Microsoft Learn)
Treating Limited Periodic Scanning as Full Protection
It offers reduced scanning and reporting. It is not a replacement for the primary antivirus and is not recommended as an enterprise strategy. (Microsoft Learn)
A Sensible Troubleshooting Order
When Microsoft Defender appears to have turned itself off:
- Open Windows Security > Virus & threat protection.
- Select Manage providers.
- Identify the active antivirus product.
- Confirm that the third-party antivirus licence and protection are current.
- Run Get-MpComputerStatus to check Defender’s mode.
- Leave Defender inactive when a legitimate third-party antivirus is intentionally providing real-time protection.
- Use limited periodic scanning only when you understand its limitations.
- Remove expired or unwanted antivirus software through Installed apps.
- Restart Windows.
- Use the antivirus vendor’s official cleanup tool if registration remains.
- Confirm that Microsoft Defender returns to Normal mode.
- Turn real-time protection and tamper protection on.
- Install Windows and protection updates.
- Run DISM and SFC if Windows components appear damaged.
- Run a full or offline scan when tampering is suspected.
- Contact IT before changing anything on a managed business device.
Get Help Resolving Antivirus Conflicts
Microsoft Defender turning itself off is often normal behaviour when Windows detects another antivirus product.
The real danger occurs when the third-party product has expired, failed or been incompletely removed—leaving Windows uncertain about which security engine should protect the computer.
Hamilton Group can identify the active antivirus provider, remove conflicting security software safely, restore Microsoft Defender Antivirus and investigate damaged Windows Security services or possible malware tampering.
We can also design and manage endpoint protection for businesses using Microsoft Defender for Business, Microsoft Defender for Endpoint, Intune and third-party security platforms.
Call 0330 043 0069, book a meeting with one of our experts or visit hgmssp.com for practical help securing your Windows devices.