Windows Defender — the antivirus and security suite built into Windows 11 — is one of the most underappreciated security tools on any Windows machine. Most users know it exists but few have explored its full capabilities, and a significant number have inadvertently disabled or misconfigured settings that reduce its effectiveness. This Windows Defender guide covers every major feature, how to configure each one correctly, and how to use the Security Dashboard that consolidates your security posture across device protection, firewall, account security, and app protection. For the bigger picture, our Complete Guide to Online Security and Privacy pulls everything together.
The case for relying on Windows Defender as your primary antivirus is stronger in 2026 than it has ever been. Independent testing organisations consistently score Windows Defender at parity with or ahead of most paid consumer antivirus products in malware detection rates. Microsoft’s scale advantage — billions of Windows devices providing telemetry that improves signature definitions — and the deep OS integration that allows Windows Defender to monitor the kernel, memory, and boot process from privileged positions that third-party antivirus cannot access, make it a genuinely capable security product that no longer deserves the reputation it had a decade ago.
Windows Defender Guide: The Security Dashboard Explained
This Windows Defender guide starts with the Security Dashboard — the centralised control panel that should be the first stop for any security review. Access it by searching “Windows Security” in the Start menu or by clicking the shield icon in the system tray. The dashboard presents coloured status indicators for eight security domains: Virus & threat protection, Account protection, Firewall & network protection, App & browser control, Device security, Device performance & health, Family options, and Protection history.
Each item should show a green checkmark. Any yellow warning or red X indicates a configuration issue requiring attention. Yellow warnings are non-critical — commonly indicating a setting that Windows recommends changing but that is not immediately dangerous. Red X indicators are urgent — typically indicating that real-time protection is off, the firewall is disabled, or a critical security feature has been turned off by another application. This Windows Defender guide recommends reviewing the Security Dashboard monthly to catch any drift from the correct configuration, particularly after Windows updates that occasionally reset specific settings.
The Protection History section at the bottom of the Virus & threat protection page is one of the most useful views in this Windows Defender guide context — it shows a timestamped log of every threat detected, every scan completed, and every action taken by Windows Defender. Reviewing it occasionally reveals whether Windows Defender is actively intercepting threats (which should inform whether additional precautions are needed) or whether the device has had a quiet history. If the history shows multiple recent detections that were “Allowed” rather than “Quarantined” or “Removed,” investigate those items — allowed items may represent a user or application that manually permitted a flagged item that should have been blocked.
Windows Defender Guide: Step-by-Step Configuration
- Confirm real-time protection is active. Windows Security → Virus & threat protection → Virus & threat protection settings → Real-time protection → On. This is the most critical setting in this Windows Defender guide — it enables continuous monitoring of files, downloads, and processes as they occur, rather than waiting for a scheduled scan to find threats after the fact.
- Enable Cloud-delivered protection. Same settings page → Cloud-delivered protection → On. This setting sends suspicious file hashes to Microsoft’s cloud infrastructure for real-time comparison against the global threat database — catching threats within seconds of them being identified anywhere in Microsoft’s sensor network, before definitions are even deployed locally.
- Enable Automatic sample submission. Same page → Automatic sample submission → On. This sends suspicious files to Microsoft for analysis — contributing to the global threat intelligence while enabling faster local definition updates. For users with specific confidentiality concerns about file samples being submitted, this can be disabled, but the protection benefit is meaningful.
- Enable Tamper Protection. Windows Security → Virus & threat protection → Virus & threat protection settings → scroll down → Tamper Protection → On. This setting prevents malware from disabling Windows Defender by blocking configuration changes to security settings that are not made through Windows Security itself. Without Tamper Protection, malware’s first action is typically to disable Windows Defender — Tamper Protection specifically closes this vector.
- Enable Controlled Folder Access. Windows Security → Virus & threat protection → Ransomware protection → Controlled folder access → On. As covered in our companion guide on protecting against ransomware, this feature blocks unauthorised applications from modifying files in protected folders — the most important ransomware mitigation available in Windows Defender.
- Configure Exploit Protection. Windows Security → App & browser control → Exploit protection → System settings. The defaults are appropriate for most users — review whether any settings show “Override” status indicating they have been changed from defaults, which may indicate a previous application configuration that weakened protection.
- Enable Smart App Control (Windows 11 22H2+). Windows Security → App & browser control → Smart App Control. This feature blocks applications that are not signed by a trusted developer or verified by Microsoft’s AI-based reputation service. It can only be enabled on a clean Windows installation or after a reset — if it shows “Evaluation” mode, it is learning; if it shows “Off” and cannot be enabled, a system reset is required to re-enable it.
- Review firewall profiles. Windows Security → Firewall & network protection → confirm all three network profiles (Domain, Private, Public) show “Firewall is on.” Never disable the firewall for any network profile without understanding which specific application requires it and re-enabling immediately after.
Step four — Tamper Protection — is the most impactful single setting change in this Windows Defender guide for users who have not already enabled it. It was added specifically to address the attack pattern where malware’s first action is registry modification to disable antivirus before delivering its payload. With Tamper Protection active, Windows Defender cannot be disabled through registry edits, command line, or Group Policy from outside Windows Security — only Windows Security itself can make configuration changes, and only with the current logged-in user’s permission.
Windows Defender Guide: Feature Comparison With Paid Antivirus
| Feature | Windows Defender | Typical paid antivirus | Notes for this Windows Defender guide |
|---|---|---|---|
| Real-time malware detection | Excellent | Excellent | Parity in independent lab tests (AV-TEST, AV-Comparatives) |
| Ransomware protection | Strong (Controlled Folder Access) | Variable | Windows Defender’s built-in CFA is highly effective |
| Firewall | Built-in (Windows Defender Firewall) | Often adds own firewall | Two firewalls can conflict; Windows Defender sufficient |
| Browser protection | SmartScreen (Edge, Defender extension) | Browser extension | SmartScreen works in Chrome/Firefox via extension |
| Exploit protection | Yes (EMET successor) | Yes (most paid suites) | Windows Defender’s implementation is strong |
| Password manager | No | Often bundled | Use dedicated password manager instead |
| VPN | No | Often bundled | Use dedicated VPN service instead |
| Cost | Free (included) | $30–$100/year | Windows Defender sufficient for most users |
The table’s honest assessment of Windows Defender for this Windows Defender guide is that the case for paid antivirus has narrowed significantly. The main remaining arguments for paid antivirus are: bundle features (VPN, password manager, dark web monitoring) that may provide value if you would otherwise pay for them separately, and cross-platform protection covering Android and macOS alongside Windows. For users who already have dedicated tools for each of those functions — a standalone VPN, a password manager, and a separate antivirus for other devices — the incremental security improvement of paid antivirus over a correctly-configured Windows Defender is negligible. According to AV-TEST’s independent testing laboratory, Windows Defender consistently achieves 100% detection rates for widespread malware and 97–99% for zero-day threats in recent test cycles, comparable to premium paid products.
Windows Defender Guide: Running Scans and Responding to Threats
Beyond the configuration covered in this Windows Defender guide, knowing how to use Windows Defender’s scanning capabilities and how to respond correctly to detections is equally important. Real-time protection catches the majority of threats at the moment of encounter, but scheduled scans and on-demand scans provide additional assurance for files that were on the system before real-time protection was enabled, or that arrived through channels that bypass real-time scanning (encrypted archives, offline media).
Running a full scan: Windows Security → Virus & threat protection → Scan options → Full scan → Scan now. A quick scan (the default) checks only the locations most commonly used by malware; a full scan checks every file on every drive and takes significantly longer (30–90 minutes) but provides comprehensive coverage. Run a full scan quarterly, after recovering from a suspected infection, after receiving a device that was previously used by someone else, and after connecting removable media you are not certain is clean. The Windows Defender Offline scan option (also in Scan options) boots into a protected environment before Windows loads, allowing detection of bootkit and rootkit threats that operate below the OS layer and can evade standard real-time scanning.
When Windows Defender detects a threat, it presents three options: Quarantine (moves the file to an isolated location where it cannot execute), Remove (permanently deletes the detected file), and Allow (marks the file as trusted and permits it to run). This Windows Defender guide recommends always choosing Quarantine or Remove — never Allow — unless you have specific, verified knowledge that the detected file is a legitimate tool flagged as a false positive by name, version, and publisher. Allowing a genuinely malicious file defeats the entire purpose of having Windows Defender active. For legitimate false positives — custom scripts, developer tools, or administrative utilities that Windows Defender incorrectly flags — add an exclusion specifically for that file path rather than globally allowing the malware signature. Our companion guide on removing malware from Windows covers the full response workflow when Windows Defender cannot fully remove a detected threat. Reviews from outlets like major technology publications consistently find that Windows Defender, properly configured per this Windows Defender guide, provides protection comparable to premium antivirus for most home and small business users — making the case for paying for replacement antivirus software largely unnecessary for users who invest the time in correct configuration.
Windows Defender Guide: Advanced Features Worth Knowing
This Windows Defender guide would be incomplete without covering several advanced features that most users have never discovered. Microsoft Defender Application Guard (available in Windows 11 Pro and Enterprise) opens untrusted websites and Office documents in an isolated virtual container — if malware is present in the document, it executes within the container and cannot reach the host system. Enable it in Windows Security → App & browser control → Isolated browsing → Install Microsoft Defender Application Guard. After installation, opening Microsoft Edge in Application Guard mode (available from the Edge toolbar) loads the current site in a protected container. This is the Windows Defender guide feature most valuable for users who regularly open documents from untrusted sources or browse sensitive sites with elevated risk.
Microsoft Defender Credential Guard, available in Windows 11 Pro and Enterprise, uses hardware virtualisation to protect authentication credentials from being extracted even by code running at kernel level. It prevents the Pass-the-Hash and Pass-the-Ticket attacks that extract Windows credentials from LSASS memory — a common attack technique in enterprise environments. Enable it through Group Policy (Computer Configuration → Administrative Templates → System → Device Guard → Turn On Virtualization Based Security) or through Windows Security Center if Credential Guard support is listed. This Windows Defender guide feature is primarily relevant in corporate environments where credential theft and lateral movement are in-scope threats, but home users on Windows 11 Pro can enable it as an additional defence layer at no cost.
The Microsoft Defender for Endpoint integration, available in Microsoft 365 Business Premium and enterprise subscriptions, extends Windows Defender from a device-level tool to an organisational security platform — providing centralised visibility, incident response workflows, and threat hunting capabilities across all enrolled devices. For home users, this is beyond the scope of this Windows Defender guide, but small business owners should note that Microsoft 365 Business Premium includes Defender for Endpoint at a per-user cost that often makes it more economical than deploying separate endpoint detection and response tools across a fleet of business devices. The move from managing Windows Defender on individual devices to managing it centrally through the Microsoft 365 Defender portal is the natural progression for growing organisations that have already standardised on Microsoft 365 as their productivity platform.
One Windows Defender guide topic that generates frequent questions: what happens if Windows Defender conflicts with a third-party antivirus? Windows 11 automatically disables Windows Defender’s real-time protection when it detects a compatible third-party antivirus — this is by design, to prevent conflicts and performance issues from running two concurrent antivirus engines. Windows Defender continues running the firewall, SmartScreen, and other components; only the antivirus engine steps back. If you uninstall the third-party antivirus, Windows Defender reactivates automatically. This Windows Defender guide recommends not running third-party antivirus alongside Windows Defender unless the third-party product is specifically integrated to work alongside rather than replace the Windows Defender engine (Microsoft Defender for Endpoint can be deployed in passive mode alongside some EDR tools in enterprise configurations). Our guide on Firewall Settings Guide covers an adjacent issue.






