Microsoft Defender Antivirus Service is a built-in, real-time security engine. Microsoft integrates it to protect your computer from viruses, ransomware, and other malware.
It continuously scans files as they are downloaded, run, or opened, and monitors abnormal system behaviour using artificial intelligence and machine learning to identify and block threats.
However, many users, including developers and power users, are constantly figuring out ways to temporarily and permanently stop the Microsoft Defender Antivirus Service
This is because the Microsoft Defender Antivirus mechanism occasionally;
- Blocks legitimate third-party installations or flags custom code as malicious.
- Runs background scans that slow down compile times.
- Consumes high CPU usage or causes system lags
So, if you’re also looking for a precise answer to “How to stop Microsoft Defender Antivirus Service”, you must check out this verified, step-by-step guide. It guarantees shutting down the Microsoft Defender Antivirus Service on Windows, macOS, Android, and iOS. So, do explore it!
Why Stop Microsoft Defender Antivirus Services?
IT professionals, developers, and power users usually search to stop the Microsoft Defender Antivirus Service for the following reasons:
#1: Software Installation Issues: Microsoft Defender’s real-time scanning algorithm can falsely flag (false positive) heavy enterprise applications, legacy software, or hypervisors during the installation process.
#2: High Resource Consumption: The MsMPEng.exe process in Microsoft Defender can occasionally cause extreme CPU and RAM usage, leading to dropped system performance during complex compiling, gaming, or video rendering.
#3: Development & Penetration Testing: Compiling custom code performing ethical hacking or testing diagnostic tools demands isolated sandbox environments where security protocols must be disabled. Hence, disabling the Microsoft Defender antivirus service becomes a non-negotiable step.
#4: Third-Party Antivirus Installation: Sometimes the operating system hangs during a new security software deployment, requiring manual intervention.
Secure the Cloud Data Before Disabling Microsoft Defender: Critical Prerequisite
Deactivating the Microsoft Defender Antivirus Service without a robust data recovery protocol is strictly inadvisable for enterprises. This is because the moment the Defender service is disabled, your machine instantly becomes vulnerable to ransomware. Therefore, having a secure backup to retrieve corrupted cloud data is imperative.
Let’s understand the significance of a dedicated backup strategy with a simple hypothetical event:
Suppose you use the OneDrive or SharePoint sync client and a malicious payload attacks while Defender is off; it doesn’t just encrypt your local hard drive. It will immediately sync the encrypted file directly to your Microsoft 365 cloud, gutting (destroying) your company’s cloud data. Even Microsoft’s native 30-day recycle bin cannot save you from mass-encryption.
So, to tackle such a disastrous situation, IT experts and MSPs advocate for a dedicated data backup. And for that, they prefer only the SysTools Office 365 Backup & Restore Tool.
SysTool guarantees an unalterable, point-in-time backup that allows you to instantly retrieve your cloud backup data to its uninfected state.
This corporate-ready backup utility also offers exclusive & effective backup features such as:
- Comprehensive & Concurrent backups (Emails, Contacts, Calendars, Documents, Shared Mailbox, Archive Mailboxes).
- Date filter for granular backups.
- Delta backup for backing up only newly arrived or modified data in the mailbox.
- Built-in centralized dashboard to keep an eye on the backup process.
- Adherence to industry standards and compliance for data management.
- Absolute compatibility with different Windows and macOS versions.
Again, it is strongly advised to take a backup of your cloud data before modifying local endpoint security or disabling Defender!
How to Stop Microsoft Defender Antivirus Service on Windows?
Here are the 3 verified methods to switch off the Microsoft Defender Antivirus Service on Windows. Also, Microsot have introduced “Tamper Protection” in recent Windows 11 and Windows 10 updates. This hardwired security feature actively restricts any unidentifed changes to Defnender’s core files, even when an administrator using the Regisrty.
Hence, this feature needs to be disabled first. Otherwise, the Registry modifications will be ignored, or the “Disable” button in services.msc will remain greyed out. To disable it:
- Go to Windows Security.
- Click “Virus & threat protection” >> select “Manage settings”.
- Scroll down and find “Tamper Protection”.
- Toggle the switch to “Off”.
- Optional but recommended: Toggle off “Cloud-delivered protection” and “Automatic sample submission”.
Method #1: Via Group Policy Editor (11/10 Pro, Enterprise, Education)
The safest way to permanently stop the Microsoft Defender Antivirus Service on Windows 11 Pro, Enterprise, and Education is via the Local Group Policy Editor. It is an ideal solution for IT administrators managing networked devices and needing to disable the M365 Defender antivirus service across multiple profiles.
Also, it ensures that real-time protection does not automatically enable itself back on after a system reboot, which is a common frustration for IT professionals.
Step #1: Access the Run Dialog
- Open the “Run dialog” (press Win + R).
- Type “gpedit.msc” >> hit “Enter”.
Step #2: Locate the “Turn off Microsoft Defender Antivirus” Policy
- In the left pane, go to the following path: Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus
- Find and select the policy labelled “Turn off Microsoft Defender Antivirus” (in the right pane).
Step #3: Configure the Radio Button
- Click the “Enabled” radio button. Here, “Enabled” refers to enabling the shut-off command.
- Click “Apply” >> hit “OK”.
- Restart the computer. Microsoft Defender is now permanently stopped.
Method #2: Via Registry Editor (Windows 11/10 Home)
Since the Windows Home edition does not support the Group Policy Editor, using the Registry Editor is the only way to permanently shut down Microsoft Defender antivirus services. Modifying the Registry prompts the OS to bypass Defender’s startup sequence.
Note: Editing the Registry demands precise execution to prevent damaging the system’s core operational files.
Step #1: Open the Run Dialog
- Press the “Win + R” key to open the “Run Dialog”.
- Type “regedit” and press the “Enter” key.

Step #2: Navigate to Windows Defender Folder
- Go to the following path: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
- Right-click the “Windows Defender” folder >> select “New” >> click “DWORD (32-bit) Value”.
Step #3: Configure the New Value
- Name the new value “DisableAntiSpyware” >> hit “Enter”.
- Double-click “DisableAntiSpyware” >> change the “Value data” to “1”.
- Click “OK” and restart the computer.
Method #3: Fixing High CPU Usage (msmpeng.exe)
Instead of completely disabling the Microsoft Defender antivirus services and leaving the critical data vulnerable, temporarily disabling Defender from scanning its own directory can also do the trick. It is a perfect workaround for a brief window to install a blocked application or execute a trusted script.
Step #1: Navigate Windows Security Settings
- Open “Windows Security”.
- Click “Virus & threat protection”
- Select “Manage settings”.
Step #2: Add an Exclusion
- Scroll down to “Exclusions”.
- Click “Add or remove exclusions”.
- Select “Add an exclusion”.
- Click “Folder”.
Step #3: Configure MsMpEng.Exe
- Go to C:\ProgramData\Microsoft\Windows Defender and select it.
- Click “Add an exclusion”.
- Select “Process”.
- Type “MsMpEng.exe”.
- Click “Add”.
Disable Microsoft Defender Antivirus Service on Mac
There are 4 proven ways through which you can disable Microsoft Defender Antivirus Service on Mac:
Method #1: Via the Microsoft Defender App Interface
Using the native app interface is the simplest way to disable Microsoft Defender on Mac. It allows users to temporarily turn off real-time protection on macOS. Also, this method doesn’t require complex terminal commands. Or modifying deep system configuration profiles.
Step #1: Open Microsoft Defender
- In the macOS menu bar (top-right of the screen), click the “Microsoft Defender” icon (a shield).
- Select “Open Microsoft Defender”.

Step #2: Configure the Real-Time Protection Toggle
- Click on the “Settings (gear)” icon (on the left).
- Uncheck or toggle off “Real-time protection”. This may prompt you to enter your Mac administrator password.

Method #2: Using the Mac Terminal (For IT Admins)
Administrators can use the native MDATP terminal commands to instantly disable real-time protection. It is an optimal method for developers testing software or performing intensive local compilation.
Step #1: Open the Mac Terminal
- Open the Terminal (press Cmd + Space Key >> type “Terminal” >> Enter). Alternatively, go to Applications >> Utilities >> Terminal.
Step #2: Run the “mdatp health” Command
- Enter the “mdatp health” command to review the current status.
- Type the following command to disable real-time protection:
“mdatp health --set real_time_protection_enabled false”
- Hit “Enter”. Note: This command may be blocked if the Tamper Protection is configured.

To re-enable Microsoft Defender later, change “false” to “True” in the given command.
Method #3: Withdrawing System Extensions and Full Disk Access
Standard methods failed to turn off Microsoft Defender Antivirus Service on Mac? This happens due to restricted permissions.
However, it can be easily bypassed by manually revoking Full Disk Access and disabling Endpoint Security extensions within macOS System Settings. This method ensures that the antivirus service will not scan the drives and doesn’t consume background system resources.
Step #1: Access Apple Menu
- Open the Apple Menu (Apple Logo at the very top left).
- Select “System Settings”.
- Go to “Privacy & Security”
- Click on “Full Disk Access”.
Step #2: Locate Microsoft Defender and Toggle it off
- In the list, find “Microsoft Defender”.
- Toggle the switch to “Off “.

To block Microsoft Defender from tracking network and file activity, To do so, go to the “Extensions” menu (or Security settings >> disable the system extensions for Microsoft Defender.
Method #4: Via Microsoft Intune/MDM (Enterprise Macs)
Enterprise administrators often block local security settings to restrict employees from disabling the Microsoft Defender Antivirus service on Max directly.
Hence, modifying the Mobile Device Management MDM) or Microsoft Intune configuration profile from the admin portal becomes the only way to deactivate real-time protection or exclusions.
Step #1: Log into Microsoft Endpoint Manager (Intune) Admin Center
- Go to the Microsoft Endpoint Manager (Intune) admin center and log in.
Step #2: Optimize Real-Time Protection Policy
- Move to “EndPoint security”.
- Select “Antivirus”.
- Select the macOS antivirus policy allocated to the target Mac device.
- Set Real-time protection to “Not configured” or “Disabled”.
- Save the policy. Wait until the Mac syncs with the MDM server to update the changes.
Deactivate Microsoft Defender on Mobile Devices (iOS & Android)
Here’s how to switch off Microsoft Defender on iOS & Android devices:
Android Smartphones:
To deactivate Microsoft Defender on Android devices, use the native Android Settings to “Force Stop” the application. It temporarily shuts down the background service. Instantly, releasing CPU resources and extending battery life.
Standard uninstall methods might not be effective as they’re restricted by company policies.
Step #1: Find Microsoft Defender in Settings
- Open the native “Settings” app.
- Go to “Apps” or “App Management”.
- Scroll down and tap on “Microsoft Defender” (or Company Portal if it is bundled).

Step #2: “Force Stop” Microsoft Defender
- Tap the “Force Stop” button (at the bottom of the screen). Tap “OK” to confirm it.

- Note: Until you manually reboot the app or phone again, the service will remain disabled.
iOS Devices:
Method #1: Via the Microsoft Defender App
The fastest way to switch off the Microsoft Defender service on iOS devices is to toggle “Web Protection” from the dedicated Defender app.
- Open the “Microsoft Defender” application.
- Tap on the “Web Protection” card (on the dashboard).
- Toggle Web Protection to “Off”.

If the Defender app is unresponsive on your iPhone or iPad, disable it from the native iOS settings.
Method #2: Via iOS Settings
Apple prohibits traditional antivirus scanning. On iOS devices (iPhone or iPad), the Defender application uses a local loopback VPN to inspect malicious web traffic. So, to prevent the Microsoft Defender service from monitoring internet activity, disable this specific VPN profile in the iOS settings.
Step #1: Enter iOS Settings
- Open the iOS “Settings” app.
- Go to “General” >> tap “VPN & Device Management”.
- Tap on “VPN”.

Step #2: Configure the Microsoft Defender Status
- Find the “Microsoft Defender” VPN profile.
- Switch the “Connect On Demand” toggle to “Off“.

Conclusion
Knowing how to stop the Microsoft Defender Antivirus Service becomes necessary when trying to:
- Install intensive software.
- Run local developer environments
- Or troubleshoot performance issues
So, if you’re working out on “How to disable Microsoft Defender” or know someone who is struggling with Defender’s interference, bookmark this simple, step-by-step guide.
It covers the exact, verified steps IT professionals, developers, and power users apply to turn off the Microsoft Defender Antivirus Service.
You can contact us anytime at:
- General & Sales: [email protected]
- General Inquiries: [email protected]
- Technical Support: [email protected]
People Also Find Helpful:
- How to Secure Email in Outlook: A Complete User & Enterprise Guide
- What to Do When Office 365 Account Compromised?
- Office 365 Ransomware Protection – Protect Your Office 365 Data
- Can You Get Hacked Through Microsoft Teams? Common Threats Explained
- How to Unlock a Temporarily Blocked Office 365 Account?
Most Asked Questions
Why is the Microsoft Defender service greyed out in services.msc?
Microsoft Defender service being greyed out in services.msc is intentionally blocked by Microsoft to protect its foundational security engine at the kernel level. It restricts malware from scripting the service off. Hence, use the Registry or Group Policy methods (with Tamper Protection disabled) to stop Microsoft Defender.
Will installing a third-party antivirus automatically turn off Defender?
Yes, if you install a professional, third-party antivirus (such as Bitdefender, Norton, or Kaspersky) on Windows or Mac, the OS will usually detect the new software. And place Microsoft Defender into “Passive Mode” or disable its real-time scanning to avoid software installation clashes.
How do I turn Microsoft Defender back on?
If you have disabled Microsoft Defender Antivirus Service temporarily, simply restart the device. And if you used the Windows Registry Method, return to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender >> delete the “DisableAntiSpyware” value >> toggle “Tamper Protection” back on in Windows Security and restart. On iOS & Android devices, simply reopen the app and toggle it on.