

In addition, the tamper protection feature will allow a switch to active mode but not to passive mode. Instead, it will place it into passive mode.

0 and later: If a server has been onboarded to Microsoft Defender for Endpoint, the "Turn off Windows Defender" group policy setting will no longer completely disable Windows Defender Antivirus on Windows Server 2012 R2 and later. You can use one of several methods, such as the Windows Security app or Windows PowerShell, to check the state of Microsoft Defender Antivirus on your device.īeginning with platform version. Check the state of Microsoft Defender Antivirus on your device To learn more, see Microsoft Defender Antivirus compatibility. In general, we do not recommend disabling or uninstalling Microsoft Defender Antivirus. Files are not scanned, and threats are not remediated. When disabled or uninstalled, Microsoft Defender Antivirus is not used. See Requirements for Microsoft Defender Antivirus to run in passive mode. IMPORTANT: Microsoft Defender Antivirus can run in passive mode only on endpoints that are onboarded to Microsoft Defender for Endpoint. Files are scanned, and detected threats are reported, but threats are not remediated by Microsoft Defender Antivirus.

In passive mode, Microsoft Defender Antivirus is not used as the primary antivirus app on the device. Files are scanned, threats are remediated, and detected threats are listed in your organization's security reports and in your Windows Security app. In active mode, Microsoft Defender Antivirus is used as the primary antivirus app on the device. The following table describes what to expect when Microsoft Defender Antivirus is in active mode, passive mode, or disabled. Comparing active mode, passive mode, and disabled mode It depends on the operating system used and whether your device is onboarded to Defender for Endpoint. If you're using a non-Microsoft antivirus/antimalware product on your device, you might be able to run Microsoft Defender Antivirus in passive mode alongside the non-Microsoft antivirus solution.

Compatibility with other antivirus products Microsoft Defender Antivirus is built into Windows, and it works with Microsoft Defender for Endpoint to provide protection on your device and in the cloud. This protection brings together machine learning, big-data analysis, in-depth threat resistance research, and the Microsoft cloud infrastructure to protect devices (or endpoints) in your organization. Microsoft Defender Antivirus is a major component of your next-generation protection in Microsoft Defender for Endpoint. Microsoft Defender Antivirus is available in Windows 10 and Windows 11, and in versions of Windows Server.
