How to disable Windows Defender
Modern Windows treats Microsoft Defender like a guard who refuses to take a break. You flip the switch off, and a minute later it flips back on. You stop the service, Windows brings it right back. You edit the registry, and the system acts like nothing happened. Here's what still works in 2026, what doesn't anymore, and how to actually disable Defender without fighting the operating system in an endless loop.

Modern Windows treats Microsoft Defender like a guard who absolutely refuses to take a break. You flip the toggle off — a minute later it switches back on. You stop the service — the system immediately revives it. You modify the registry — the OS acts as if it noticed nothing. Let’s examine what still works in 2026, what no longer does, and how to actually disable Defender without entering an endless loop with the operating system.
Tamper Protection: Defender’s chief gatekeeper
This is the component most outdated online guides remain silent about. Tamper Protection is a built-in safeguard against unauthorized changes that prevents disabling Defender via group policies, registry edits, stopping services, or third-party admin utilities. As long as Tamper Protection is enabled, any such attempt gets rolled back by the system within a minute or two.
You can find the toggle under “Windows Security” → “Virus & threat protection” → “Manage settings.”

Virus & threat protection toggles, including Tamper Protection
Tamper Protection: the bottom toggle in the list
While Tamper Protection remains on, the other methods in this article are nearly useless: Windows simply reverts the settings anyway. Disable it first.
Why legacy methods no longer work
Group Policies
The gpedit.msc route still exists in Windows Pro and Enterprise editions: Computer Configuration → Administrative Templates → Windows Components → Microsoft Defender Antivirus → “Turn off Microsoft Defender Antivirus.” The issue is that with Tamper Protection active, Windows completely ignores this policy. With Tamper Protection off, the policy tends to merely reduce Defender’s activity rather than turn it off entirely — hardly the unambiguous outcome it delivered a few years ago.
Registry Edits
The old trick involving the DisableAntiSpyware value under HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender has zero effect in current Windows builds. Microsoft removed support for this parameter: even if you manually create the key and assign the proper value, Defender disregards it entirely and continues running as usual.
Stopping Services
Any attempt to manually halt, disable, or terminate the Defender service process also fails: Windows Security Center monitors the service status and automatically restarts it, typically within a couple of minutes. What’s more, its startup type in the services console is set to “Automatic (Protected),” further complicating manual interference.
What genuinely works in 2026
There aren’t many viable options, but they succeed precisely because the system itself respects them, rather than bypassing its protection through trickery.
Disable Tamper Protection in “Virus & threat protection” — the essential first step before anything else
Temporarily turn off Real-time protection, but bear in mind that Windows reactivates it on its own after some time, so this is not a permanent fix
Add the loader’s folders, files, processes, and extensions to exclusions via “Manage settings” → “Exclusions” — this works more reliably but is not guaranteed for every piece of software
Completely disable Defender with a third-party tool such as DControl, which keeps protection off until the next system restart
How to disable Defender with DControl
DControl (Defender Control) fully shuts down Defender and stops Windows from turning it back on by itself until the system reboots. The sequence is as follows:
First, turn off Tamper Protection — without this, DControl may also fail to achieve a complete result
Download the archive: Download DControl (.rar)
Extract the archive and run the file as administrator
Click the red “Disable Windows Defender” button
Once the window header turns red with the message “Windows Defender is turned off,” protection is completely deactivated and will not return on its own until the next reboot.

Defender Control window displaying “Windows Defender is turned off”
A red window header indicates that Defender is disabled
How to turn Defender back on
Open DControl again and click “Enable Windows Defender,” then in “Windows Security” re-enable the toggles for real-time protection, cloud-delivered protection, and Tamper Protection. This is worth doing when you’ve finished gaming and no longer need the loader for that session, especially if the computer isn’t used solely for gaming.
If the loader remains blocked after all these steps, the cause could be UAC or a third-party antivirus. Consult the full guide to disabling Windows protection for a cheat or the short guide on disabling UAC.
Frequently Asked Questions About Disabling Microsoft Defender
Why does Defender turn itself back on automatically?
As long as Tamper Protection is active, Windows automatically rolls back any changes to Defender settings within one to two minutes after a manual attempt to disable it through the registry, services, or group policies.
Does the DisableAntiSpyware registry edit still work in 2026?
No, Microsoft has discontinued support for this parameter in modern Windows builds. Defender completely ignores the registry key even if you create it manually.
Is it enough simply to turn off Tamper Protection?
Turning off Tamper Protection on its own reduces Defender’s activity but does not disable it entirely. For a guaranteed outcome you additionally need a utility like DControl.
Is it safe to use DControl?
The tool has been in use for a long time and is built specifically to manage Defender’s state. As with any protection disabling, use it on a dedicated gaming computer and download it exclusively via the direct link in the ForgeCheats guide.
Do you need to disable Defender before every gaming session?
No, if you leave protection disabled through DControl, that state persists until the next system reboot. After the computer restarts, Defender turns back on and the steps must be repeated.