Skip to content
How‑To Guides

How Windows Defender Works in Windows 11

Windows Defender on Windows 11 is far more capable than most users realise — it provides real-time protection, ransomware defence, network firewall, and browser protection in one built-in suite. This guide covers every feature, how to run scans, and how to configure Defender for maximum protection.

How Windows Defender Works in Windows 11

Windows Defender — officially Microsoft Defender Antivirus, part of the broader Windows Security suite — has gone from “barely adequate” to genuinely competitive over the last five years. Independent testing organisations (AV-TEST, AV-Comparatives, SE Labs) now consistently rate it alongside the paid third-party products it used to lag behind. For home users and many small businesses: it’s more than sufficient, and installing a separate antivirus on top of it often creates more problems than it solves. For the bigger picture, our Windows 11 How-To Guides pulls everything together.

That said, Defender is only as effective as its configuration. Default settings are sensible, but there are specific behaviours, reporting options, and features worth understanding to use it well rather than just assuming it’s running correctly.

Where to find Windows Security

Win+S → “Windows Security” → opens the main dashboard. The coloured icons show the status of each protection area: green means active and healthy, yellow means attention needed, red means something is off and requires action. If anything shows yellow or red: click it to see what needs addressing before anything else.

The dashboard covers six areas: Virus & threat protection, Account protection, Firewall & network protection, App & browser control, Device security, and Device performance & health.

Virus & threat protection — the core

Virus & threat protection includes real-time scanning, cloud-delivered protection, and tamper protection. These three settings should be on for any internet-connected machine:

  • Real-time protection: scans files as they’re accessed. Turning this off is almost never the right call; if it’s off, turn it back on immediately.
  • Cloud-delivered protection: sends suspicious files to Microsoft’s cloud for rapid analysis. Responses to new threats come faster through the cloud than waiting for the next definition update. Turns on by default; leave it on.
  • Automatic sample submission: sends samples of suspicious files to Microsoft. Improves detection for everyone but involves sending files to Microsoft. Off if privacy is a concern; on if you’re okay with the trade-off.
  • Tamper protection: prevents other software from disabling Defender’s protections. This should always be on. If it’s off: something may have disabled it, which is itself a concern worth investigating.

Protection updates happen automatically through Windows Update. Check the definition version: Virus & threat protection → Protection updates → the version date should be recent (within the last day or two). Stale definitions (more than a week old) usually indicate an issue with Windows Update connectivity.

Running scans

Defender runs background scans automatically when the computer is idle. Manual scan options are available through Virus & threat protection → Scan options:

  • Quick scan: checks the most common malware locations (memory, startup entries, system files). Takes 5-15 minutes. Good for routine checks.
  • Full scan: scans every file on every drive. Can take hours on a large drive. Run occasionally (monthly or when you suspect something specific). High disk usage during the scan is expected.
  • Custom scan: scans a specific folder or drive. Useful when you’ve downloaded something from an untrusted source and want to check just that.
  • Microsoft Defender Offline scan: boots into a minimal environment outside Windows to scan for rootkits and deeply-embedded malware that can hide from a normal scan. Run this if a scan found something but couldn’t fully remove it, or if you suspect a particularly persistent infection.

Controlled folder access

One of Defender’s more powerful features that’s often overlooked: Controlled folder access blocks untrusted applications from writing to protected folders (Documents, Pictures, etc.). This is effective against ransomware — ransomware can’t encrypt your files if it can’t write to the folders they’re in.

Enable it: Virus & threat protection → Manage ransomware protection → Controlled folder access → On. After enabling: some legitimate applications may be blocked from accessing those folders. If a trusted app stops working correctly: Virus & threat protection → Manage ransomware protection → Allow an app through Controlled folder access → add the application.

Firewall & network protection

Windows Firewall is separate from antivirus but part of the same security suite. Three network profiles: Domain (corporate networks), Private (home/office networks you trust), and Public (untrusted networks like café Wi-Fi). Each has its own firewall rules with different strictness levels.

The most important action: verify the firewall is active for all three profiles. Windows Security → Firewall & network protection → all three should show “Firewall is on.” If any show as off: turn them on. The public profile is the most restrictive and most important to keep on — it protects against threats on shared/untrusted networks.

Our guide on Windows 11 initial configuration covers the security settings to check during setup, and our notification management covers the Windows Security notification settings. For Defender’s enterprise configuration and Group Policy options, Microsoft’s Defender documentation covers the full configuration options available in managed environments.

App & browser control

Controls SmartScreen — Microsoft’s reputation-based filter for applications and websites. SmartScreen checks files and URLs against Microsoft’s known-good and known-bad database. Three levels:

  • Warn: shows a warning when unrecognised apps or sites are encountered. You can choose to proceed.
  • Block: prevents accessing unrecognised apps or sites entirely. More restrictive; some legitimate software from small developers will trigger this.
  • Off: disables SmartScreen entirely. Not recommended.

“Warn” is the appropriate default for most users — it provides a safety net while still allowing access to legitimate but less-common software. “Block” is appropriate for machines used by less tech-savvy users where the extra friction of occasional false positives is acceptable for better protection.

Exclusions — when to use them

If Defender is flagging a legitimate file or application as malicious (a false positive): adding an exclusion tells Defender to ignore that file, folder, or process. Virus & threat protection → Manage settings → Exclusions → Add or remove exclusions.

Be careful with folder exclusions. Adding an entire “C:UsersNameDownloads” folder to exclusions because one file was wrongly flagged means Defender won’t scan anything in Downloads — which is one of the highest-risk locations on any PC. Instead: exclude the specific file or application, not the folder it happens to be in.

Signs that Defender exclusions have been incorrectly configured: many exclusions in the list, particularly broad folder paths. Malware sometimes adds exclusions to prevent Defender from detecting its own files. Reviewing the exclusions list periodically is part of maintaining good security hygiene.

Protection featureDefaultRecommended
Real-time protectionOnOn — never disable
Cloud-delivered protectionOnOn
Tamper protectionOnOn — investigate if off
Controlled folder accessOffOn (especially on home machines)
SmartScreen for appsWarnWarn
Firewall (all profiles)OnOn

The single most impactful thing most Windows users can do for security: enable Controlled folder access. Real-time protection and the firewall are already on by default and working. Controlled folder access is the off-by-default feature that provides meaningful ransomware protection that very few home users have enabled — and enabling it costs nothing beyond the minor friction of occasionally allowing a legitimate application access to a protected folder.

Performance impact of Windows Defender

A concern that comes up regularly: does Defender slow down the PC? The honest answer: yes, slightly, as all real-time antivirus does. The scan overhead is most noticeable during full scans, during periods of high disk activity (compiling code, large file operations), and immediately after boot when Defender performs its initial checks. On SSDs, the impact is considerably lower than on HDDs because the scan reads happen faster.

For users noticing significant slowdowns during development or compilation work: adding the build output folders and source directories to Defender exclusions can recover meaningful performance without exposing user data to risk. The source and build folders are created by tools you control and pose less risk than downloads or email attachments. Check: Virus & threat protection → Manage settings → Exclusions → Add an exclusion → Folder → select your project directory.

Windows Security notifications

Windows Security generates notifications for: threat detections, scan completions, definition update failures, and protection features turning off. Most of these are worth seeing — they’re actual security events rather than marketing. The exception: “Scan results” notifications after every quick scan can be noisy if you have scheduled scans running frequently.

To manage these: Windows Security → Settings (gear icon, bottom left of the dashboard) → Notifications → manage which notification types are active. Most users benefit from keeping threat detection and protection status notifications on while disabling repetitive scan-completion notifications.

Third-party antivirus and Defender coexistence

Installing a third-party antivirus automatically disables Defender’s real-time protection — Windows prevents two real-time scanners from running simultaneously because they create conflicts. This is expected and correct. The third-party product takes over; Defender enters “passive mode” and continues running periodic scans without blocking anything in real-time.

If you uninstall a third-party antivirus: Defender’s real-time protection should re-enable automatically. If it doesn’t: Windows Security → Virus & threat protection → Real-time protection → toggle back on. Occasionally, incomplete uninstalls of third-party products leave Defender in passive mode without the original antivirus actually running — leaving the machine effectively unprotected. Check this if you’ve recently switched antivirus products.

Defender and corporate-managed devices

On domain-joined or Intune-managed Windows 11 machines: Defender settings are often controlled by IT policy. Individual settings may be greyed out or reset to policy values after manual changes. In managed environments: Defender is typically configured for the organisation’s security requirements, which may be stricter or different from what’s described here. Windows Security → Settings → at the bottom of the settings page, it shows whether settings are managed by an administrator.

Microsoft Defender for Business and Microsoft Defender for Endpoint (the enterprise versions) extend the consumer Defender with threat analytics, centralised management, attack surface reduction rules, and endpoint detection and response (EDR). These features aren’t available in the consumer Windows Security app but are relevant context for understanding why enterprise machines may have Defender behaviours different from what’s described in this guide for home users.

For most home users, Windows Defender in its default configuration with Controlled folder access enabled is genuinely sufficient protection. Adding a reputable third-party antivirus doesn’t meaningfully improve this — the detection rates are similar, and adding another layer of software adds complexity and potential conflicts without proportional security improvement. The recommendation from most security researchers now: keep Defender, use a password manager, enable multi-factor authentication on important accounts. These three measures together protect against the vast majority of threats that actually affect regular users.

Reviewing protection history

Windows Security → Virus & threat protection → Protection history shows all recent detections, blocked items, and actions taken. This is worth reviewing occasionally — not to find active threats, but to understand what Defender is encountering. Regular appearances of the same type of threat (for example, PUA — Potentially Unwanted Applications — from the same source) can indicate a source of unwanted software worth addressing at the root rather than just having Defender repeatedly clean up after it.

Each entry in the protection history shows: the threat name, what action was taken (quarantined, removed, blocked), and the file path of the detected item. The file path is particularly useful — if threats are repeatedly being detected in the same folder (Downloads, a specific application’s data folder), it suggests the source of the infection rather than isolated incidents.

What Defender doesn’t protect against

Being clear about Defender’s limitations helps maintain realistic security expectations:

  • Phishing via email or web: Defender blocks known phishing sites and suspicious downloads, but it can’t stop you from willingly providing your credentials to a convincing fake website. This is a human problem that requires phishing awareness rather than technical controls.
  • Zero-day exploits: newly discovered vulnerabilities that haven’t been added to threat databases aren’t caught by definition-based scanning. Cloud-delivered protection helps here (real-time cloud analysis catches more) but doesn’t eliminate the gap.
  • Software you deliberately install: if you download and run something suspicious, Defender will warn you through SmartScreen, but if you override the warning and run it anyway, you’ve effectively made a decision that overrides the protection.
  • Account compromises: a stolen password lets an attacker into your accounts without any malware being involved. Defender can’t protect accounts that aren’t protected by strong, unique passwords and two-factor authentication.

These limitations are important to understand because they show where technical tools end and security practices begin. Defender handles the technical malware threat well. The other vectors — phishing, credential theft, social engineering — require user education and good account hygiene that no antivirus product addresses on its own. If this sounds familiar, Set Up a VPN on Windows 11 is worth a look.

Nikolas Lamprou

Nikolas Lamprou (MSc; GCFR, SC-200, Security+) has been working with computers professionally since 2009 — starting with web development and e-commerce, and moving into cybersecurity over the years. Based in Greece, he brings over 15 years of real-world IT experience to SolveTechToday, where he writes about Windows fixes, software reviews, security tools, and AI applications. His goal is straightforward: cut through the noise and give readers clear, honest guidance on the tech decisions that matter.

Stay Ahead

Fix your next problem before it starts

Get the week's best Windows fixes, software picks, and security guides delivered straight to your inbox. No noise, just solutions.

Press ESC to close · Try "Windows 11" or "Chrome"