Windows 11 · Security How-To
Microsoft Defender in Windows 11: What It Is and How to Use It
Microsoft Defender is the antivirus already built into Windows 11, so there is nothing to install — you manage it through the Windows Security app. Press Start, type Windows Security, and open Virus & threat protection. From there you can confirm real-time protection is on, run a scan, add exclusions and turn on ransomware protection. For most people it is already working and needs nothing more than a periodic check.
What Microsoft Defender actually is
Microsoft Defender Antivirus is a full, real-time antivirus and anti-malware component that ships inside every copy of Windows 11 and is turned on by default. It is not a trial and there is nothing to buy. It continuously watches files and programs as you open them, downloads fresh threat definitions through Windows Update automatically, and quarantines anything it recognises as malicious.
It did not always do this much. Defender began years ago as a consumer anti-spyware tool and grew, release by release, into the all-round antivirus it is today. If you enjoy that back-story — including how the enterprise "Forefront" line fits in — we cover it separately (see the archive note near the end). For now, the practical point is that on Windows 11 the built-in protection is genuinely capable, not a placeholder that begs you to install something better.
Step 1 — Open Windows Security and check your status
Before changing anything, confirm what is already running. Microsoft's Stay protected with Windows Security page uses the same route — search the Start menu for the app, then work from Virus & threat protection.
- Click Start, type
Windows Security, and press Enter. (You can also go to Settings > Privacy & security > Windows Security and click Open Windows Security.) - On the home screen you will see tiles such as Virus & threat protection, Firewall & network protection and App & browser control. A green tick means that area is healthy.
- Select Virus & threat protection. Under Current threats you can see when the last scan ran and whether anything needs attention.
If a message says another antivirus is your active provider, that is expected when you have a third-party product installed — Defender steps aside so the two do not fight. More on that below.
Step 2 — Confirm real-time protection is on
Real-time protection is the always-on shield that scans files the moment they are accessed. It should be on.
- In Windows Security, select Virus & threat protection.
- Under Virus & threat protection settings, click Manage settings.
- Make sure Real-time protection is switched On. While you are here, leaving Cloud-delivered protection and Automatic sample submission on is recommended — they let Defender check suspicious files against Microsoft's live threat intelligence and react to brand-new malware faster.
Windows 11 treats real-time protection as a safety baseline. If you toggle it off, Windows turns it back on automatically after a short delay (and after a restart) whenever there is no other active antivirus. That is intentional: there is no supported way to permanently disable Defender from this screen, and you should not try to. Turn it off only for a moment when a trusted installer genuinely requires it, then let it re-enable.
Step 3 — Run a scan
Real-time protection handles day-to-day threats, but you can also scan on demand — useful if a machine was acting strangely or you just want reassurance.
- Go to Virus & threat protection and click Quick scan for a fast check of the places malware most often hides.
- For a thorough sweep, click Scan options, choose Full scan, then Scan now. This checks every file and running program and can take a while.
- If you suspect something stubborn that hides while Windows is running, choose Microsoft Defender Antivirus (offline scan). Your PC restarts and scans before Windows fully loads, roughly 15 minutes, which catches rootkits and persistent malware ordinary scans miss.
You can also scan a single file or folder from File Explorer: right-click it and choose Scan with Microsoft Defender. On Windows 11 this may sit under Show more options in the right-click menu.
Step 4 — Add an exclusion (only when you're sure)
Occasionally Defender flags a file you know is safe — a development tool, a game mod, a niche utility. You can tell it to skip a specific file, folder, file type or process.
- Open Virus & threat protection > Manage settings.
- Scroll to Exclusions and click Add or remove exclusions. Approve the User Account Control prompt.
- Click Add an exclusion and pick File, Folder, File type or Process, then browse to the item.
An excluded folder is a blind spot — Defender will not scan anything inside it, so malware placed there goes unnoticed. Only exclude items from sources you fully trust, keep the scope as narrow as possible (a single file beats a whole folder), and remove the exclusion once you no longer need it. If you are only trying to recover a file Defender quarantined by mistake, use Protection history to restore it instead of adding a blanket exclusion.
Step 5 — Turn on ransomware protection (Controlled folder access)
Windows 11 includes a specific defence against ransomware called Controlled folder access, which only lets trusted apps change files in your protected folders. It is off by default — both points are stated plainly in Microsoft's controlled folder access documentation on Microsoft Learn — so this is one of the few genuinely worthwhile things to enable yourself.
- Open Windows Security and select Virus & threat protection.
- Scroll down to Ransomware protection and click Manage ransomware protection.
- Switch Controlled folder access to On and approve the User Account Control prompt.
- Use Protected folders to review or add folders (Documents, Pictures, Desktop and similar are covered by default), and Allow an app through Controlled folder access to whitelist any legitimate program that gets blocked.
Because it is strict, Controlled folder access sometimes blocks ordinary apps — even built-in ones like Notepad — from saving into a protected folder. If a trusted program suddenly cannot save, add it via Allow an app through Controlled folder access rather than turning the feature off. The same steps apply on Windows 10.
Step 6 — Firewall & network protection
Microsoft Defender also includes the Windows Firewall, which controls what network traffic is allowed in and out. It should be on for every network profile.
- In Windows Security, select Firewall & network protection.
- Confirm the firewall is On for Domain network, Private network and Public network.
- Public Wi-Fi should always use the Public network profile, which is the most restrictive — Windows normally sets this for you when you decline to be "discoverable" on a new network.
Most people never need to touch the advanced rules here. If an app legitimately needs inbound access, use Allow an app through firewall rather than disabling the firewall.
Step 7 — Reputation-based protection (SmartScreen)
Under App & browser control, Reputation-based protection uses Microsoft Defender SmartScreen to warn you about malicious or low-reputation apps, files, websites and downloads before they run.
- Select App & browser control, then Reputation-based protection settings.
- Leave Check apps and files and SmartScreen for Microsoft Edge on. Phishing protection is worth enabling — it warns you if you type your Windows password into a risky app or website.
- Potentially unwanted app blocking stops bundled adware and junkware that comes riding along with free downloads; keeping it on is a good idea.
Do you still need a third-party antivirus?
For the average Windows 11 user who installs updates and avoids obviously sketchy downloads, Microsoft Defender Antivirus is a legitimate primary antivirus. It performs strongly in independent lab testing, it is free, and it layers a firewall, SmartScreen reputation checks and ransomware protection on top of the core scanner — no nagging, no subscription.
A paid security suite still makes sense for some people, but usually for the extras rather than the detection: a bundled VPN, a password manager, cross-platform coverage for phones and Macs, or granular parental controls. That is a features decision. If you do install another antivirus, remember what happens next: Windows 11 automatically steps Defender down so the two do not conflict, and turns it back on if you ever uninstall the other product — Microsoft's compatibility guidance for Microsoft Defender Antivirus confirms the automatic step-down and the automatic re-enable.
Frequently asked
Do I need to install Microsoft Defender in Windows 11?
No. Microsoft Defender Antivirus is built into Windows 11 and is switched on by default, so there is nothing to download or install. You reach it through the Windows Security app. As long as no other antivirus has taken over, Defender's real-time protection is already running and keeping its definitions up to date automatically.
Is Microsoft Defender good enough on its own, or do I need a third-party antivirus?
For most home users who keep Windows updated and browse sensibly, Microsoft Defender Antivirus in Windows 11 is a legitimate primary antivirus — it scores well in independent lab tests and includes a firewall, SmartScreen reputation checks and ransomware protection. You do not need to buy a second antivirus for basic safety. Some people still choose a paid suite for extras like a VPN, password manager or parental controls, but that is a features decision, not a sign that Defender is inadequate.
What happens to Microsoft Defender if I install another antivirus?
When you install a compatible third-party antivirus, Windows 11 automatically steps Microsoft Defender Antivirus down from active real-time scanning so the two do not conflict. Defender stays available in passive mode and its optional periodic scanning can be turned on for a second opinion. If you later remove the other antivirus, Windows turns Defender's real-time protection back on automatically.
How do I run a full scan with Microsoft Defender in Windows 11?
Open the Windows Security app, select Virus & threat protection, then choose Scan options, select Full scan and click Scan now. A full scan checks every file and running program on the drive and can take a while. For a deeper check against hidden malware, choose Microsoft Defender Antivirus (offline scan) instead, which restarts the PC and scans before Windows fully loads.