- To disable the Microsoft Defender Antivirus permanently on Windows 11, in the “Windows Defender” key in the Registry, create the “Real-Time Protection,” “Signature Updates,” and “Spynet” subkeys, and you must create 11 different “DWORD (32-bit) Value” entries with the value of “1,” including: “DisableAntiSpyware,” “DisableRealtimeMonitoring,” “DisableAntiVirus,” “DisableSpecialRunningModes,” “DisableRoutinelyTakingAction.” The “ServiceKeepAlive” key should be set to “0”.
On Windows 11, it’s possible to disable the Microsoft Defender Antivirus solution “permanently,” and in this guide, I’ll show you how to complete this configuration by modifying the Registry.
Microsoft Defender Antivirus is the built-in antivirus software for Windows 11, designed to scan and protect your computer from viruses, spyware, hackers, and other online threats. While it’s generally recommended to keep the antivirus enabled, there may be instances where you need to disable it completely, such as when it causes performance issues, conflicts with other antivirus software, or you’re concerned about privacy.
If you must disable Defender Antivirus permanently, the recommended approach is to install another antivirus, as this action will trigger the system to turn off the anti-malware application automatically (and enable the option to turn on periodic scanning). However, it’s also possible to permanently disable the antivirus on Windows 11 through the Registry. But it’s a decision that should not be taken lightly, as it leaves your computer vulnerable to malware attacks.
In this guide, I will outline the steps to permanently turn off the default antivirus on Windows 11 Pro or Home.
Disable Microsoft Defender Antivirus on Windows 11
To disable Microsoft Defender Antivirus permanently on Windows 11, use these steps:
-
Open Start on Windows 11.
-
Search for Windows Security and click the top result to open the app.
-
Click on Virus & threat protection.
-
Click the Manage settings option under the “Virus & threat protection settings” section.
-
Turn off the Tamper Protection toggle switch.
Quick note: If you don’t turn off this feature manually, the Registry modifications won’t take effect. -
Open Start.
-
Search for regedit and click the top result to open the Registry Editor.
-
Navigate to the following path:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
-
Right-click the Windows Defender key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableAntiSpyware and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableAntiSpyware” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableRealtimeMonitoring and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableRealtimeMonitoring” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableAntiVirus and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableAntiVirus” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableSpecialRunningModes and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableSpecialRunningModes” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableRoutinelyTakingAction and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableRoutinelyTakingAction” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD ServiceKeepAlive and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Confirm the “ServiceKeepAlive” value is 0.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “Key” option.
-
Name the key Real-Time Protection and press Enter.
-
Right-click the “Real-Time Protection” key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableBehaviorMonitoring and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableBehaviorMonitoring” value from 0 to 1.
-
Click the OK button.
-
Right-click the “Real-Time Protection” key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableOnAccessProtection and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableOnAccessProtection” value from 0 to 1.
-
Click the OK button.
-
Right-click the “Real-Time Protection” key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableScanOnRealtimeEnable and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableScanOnRealtimeEnable” value from 0 to 1.
-
Click the OK button.
-
Right-click the “Real-Time Protection” key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableRealtimeMonitoring and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableRealtimeMonitoring” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “Key” option.
-
Name the key Signature Updates and press Enter.
-
Right-click the Signature Updates key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD ForceUpdateFromMU and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “ForceUpdateFromMU” value from 0 to 1.
-
Click the OK button.
-
Right-click the Windows Defender key, select New, and choose the “Key” option.
-
Name the key Spynet and press Enter.
-
Right-click the Spynet key, select New, and choose the “DWORD (32-bit) Value” option.
-
Name the DWORD DisableBlockAtFirstSeen and press Enter.
-
Right-click the newly created DWORD and choose the Modify option.
-
Change the “DisableBlockAtFirstSeen” value from 0 to 1.
-
Click the OK button.
-
Restart the computer.
Once you complete the steps, the Microsoft Defender Antivirus should be completely disabled on Windows 11 Home and Pro.
If you change your mind, you can revert the changes, but in step 8, make sure to right-click and delete the “DisableAntiSpyware,” “DisableRealtimeMonitoring,” “DisableAntiVirus,” “DisableSpecialRunningModes,” “DisableRoutinelyTakingAction,” and “ServiceKeepAlive” DWORDs, and right-click and delete the “Real-Time Protection,” “Signature Updates,” and “Spynet” keys. Also, on Windows Security > Virus & threat protection > Manage Settings, turn on the “Tamper Protection” toggle switch, and restart the computer.
Although it’s not recommended to use your computer without an antivirus, these instructions will help you keep Microsoft Defender Antivirus completely disabled on Windows 11, even after restarting the computer.
Update November 5, 2024: This guide has been updated to ensure accuracy and reflect changes to the process.