Can't disable Windows Defender by using group policies

ivanmatic 31 Reputation points
2021-01-18T05:33:40.593+00:00

I have recently installed Win 10 Pro
No matter how many times i try to disable Defender Antivirus with Group Policy Editor (Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus) by activating the policy "Turn off Windows Defender Antivirus" and clicking OK, Windows just ignores all my attempts and revert it back on like nothing happened...

It just turns Turn off Windows Defender Antivirus from enabled back to Not configured
When i close gpedit and open it back again i can see it's back to Not configured

I've been using PC's for 25 years without Antiviruses by using only common sense and Process Explorer
Why is Microsoft forcing me to use something i don't want on my own computer?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,724 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,747 questions
{count} votes

Accepted answer
  1. Teemo Tang 11,331 Reputation points
    2021-01-19T02:47:33.58+00:00

    Sorry, my fault.
    I test again on my two devices, one is 2004 and another is 20H2. The Group policy method on 2004 machine succeed and on 20H2 machine failed, just like yours.
    57957-2004png.jpg
    On 20H2 machine, after I enabled Turn off Windows Defender Antivirus and restart computer, Windows Defender is not turned off even this policy return back Not Configured.
    57934-2009.jpg
    So I search online and find out this good case, try the tool named Autoruns to disable Windows Defender service.
    https://www.tenforums.com/antivirus-firewalls-system-security/167105-unable-disable-windows-defender-1909-a.html


5 additional answers

Sort by: Most helpful
  1. SUNOJ KUMAR YELURU 13,921 Reputation points MVP
    2021-01-18T06:34:42.837+00:00

    @ivanmatic

    I found the solution. It turns out that Windows Defender is so ingrained within Windows 10 that it comes with its own "anti-tamper" protection.

    This does two things: prevents you from creating the registry key in HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender by giving you a generic error message and also renders the group policy change ineffective.

    In order to disable this, I had to follow these instructions:

    1. Go to Virus & threat protection
    2. Click on Manage Settings
    3. Turn off Tamper Protection
    4. Proceed to enable the group policy Turn off Windows Defender Antivirus in Computer Configuration/Administrative Templates/Windows Components/Windows Defender Antivirus or add the registry key.
    5. Restart PC

    refer - https://superuser.com/questions/1500683/cant-disable-windows-defender-via-group-policy-or-the-registry

    Please don’t forget to Accept the answer and up-vote wherever the information provided helps you, this can be beneficial to other community members.


  2. Teemo Tang 11,331 Reputation points
    2021-01-18T06:44:48.75+00:00

    Your method is correct.
    When you install some 3rd party antivirus (AV) programs, they may automatically turn off Microsoft Defender Antivirus. In this case you may not be able to turn on Microsoft Defender Antivirus again until the 3rd party AV program has been disabled (turned off) or completely uninstalled.
    If you have a 3rd party AV program installed and disable Microsoft Defender Antivirus, this will also disable periodic scanning.
    If you have Windows 10 build 18305 or higher installed, you will need to turn off Tamper Protection to be able to disable Microsoft Defender Antivirus.

    Refer to this article below for detailed steps
    https://www.tenforums.com/tutorials/5918-how-turn-off-microsoft-defender-antivirus-windows-10-a.html
    Please note: Information posted in the given link is hosted by a third party. Microsoft does not guarantee the accuracy and effectiveness of information.

    -------------------------------------------------------------------------------------

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. ivanmatic 31 Reputation points
    2021-01-19T04:18:59.717+00:00

    yeah i do have 20H2, i'm gonna check it

    0 comments No comments

  4. Mark Heitbrink 96 Reputation points
    2021-01-25T13:26:30.823+00:00

    Hi ivanmatic-7206

    since August 2020 (Microsoft Defender Antimalware platform Version 4.18.2007.8, KB 4052623) you can not longer disable Windows Defender by Group Policy for Security Reason. The only way to disable it, is to install a 3rd Party Antiviurs, that disables Defender via API or disable it manually as an Administrator by clicking it.

    https://learn.microsoft.com/en-us/windows-hardware/customize/desktop/unattend/security-malware-windows-defender-disableantispyware