Guide to Disabling Windows Defender Protection
Introduction
This document provides a detailed guide on how to disable real-time protection and tamper protection in Microsoft Defender Antivirus. Disabling these features may be necessary for specific scenarios, such as security testing, malware analysis, or to prevent conflicts with other applications.
Method 1: Disabling Tamper Protection via Windows Security App
This is the simplest and most recommended method for disabling tamper protection on an individual device. [1]
-
Open the Start menu and search for "Windows Security".
-
In the Windows Security window, select Virus & threat protection.

-
Under "Virus & threat protection settings," click Manage settings.
-
Locate the Tamper Protection option and toggle the switch to Off.

Method 2: Disabling Real-Time Protection via Windows Security App (Temporary)
This is the most direct way to temporarily disable real-time protection.
-
Ensure Tamper Protection is disabled first (as shown in Method 1).
-
Open the Windows Security app and go to the Virus & threat protection section.
-
Click on Manage settings.
-
Locate the Real-time protection option and toggle the switch to Off.

Note: This is a temporary deactivation. Windows may automatically re-enable real-time protection after a short period or a system restart.
Method 3: Using the Defender Control Tool
For users who need a more persistent and straightforward way to disable Windows Defender, the Defender Control Tool by Sordum is a popular third-party utility. It's a portable tool that allows you to enable or disable Windows Defender with a single click. [2]
Step 1: Downloading Defender Control
-
Navigate to the official Sordum.org website to download the tool.
-
Because this tool modifies security settings, your browser and Windows Defender itself will likely flag it as malicious. This is a false positive.
Step 2: Unblocking the Download in Chrome
If Chrome blocks the download, you have two options to proceed.
Option A: Keep the File Directly (Recommended)
-
Press
Ctrl + Jto open your Chrome Downloads list. -
You will see the blocked download with a warning message.

-
Click the "Keep dangerous file" button to save the file to your computer.

Option B: Temporarily Disable Safe Browsing
If the "Keep dangerous file" option is not available, you can temporarily disable Chrome's Safe Browsing feature.
-
Click the three-dot menu in the top-right corner of Chrome and select Settings.
-
Navigate to the Privacy and security tab and click on Security.
-
Under the "Safe Browsing" section, select No protection (not recommended).

-
After selecting "No protection", you will be prompted to confirm. Click Turn off.

-
Now, try downloading the Defender Control tool again.
-
Important: After you have successfully downloaded the tool, it is crucial to go back and re-enable Safe Browsing (choose "Standard protection" or "Enhanced protection").
Step 3: Using the Defender Control Tool
-
The downloaded file will be a ZIP archive. You will need to extract its contents. The password for the archive is sordum.
-
Before running the tool, it's highly recommended to disable Tamper Protection and Real-Time Protection using Methods 1 and 2, otherwise Defender will likely delete the tool's executable.
-
Run the
dControl.exefile. -
The interface will show the current status of Windows Defender.

-
Click "Disable Windows Defender". The interface will turn red, indicating that Windows Defender is now turned off.

-
It is recommended to go to Menu -> Add it to the Exclusions List. This will prevent Defender from flagging the tool in the future.

To re-enable Windows Defender, simply open the tool again and click "Enable Windows Defender".
Conclusion
This guide has presented straightforward methods for disabling Windows Defender's protections, from using the built-in Windows Security app for temporary changes to employing a dedicated third-party tool for more persistent control. The appropriate method depends on your specific needs. Always remember to re-enable the protections as soon as possible to ensure your environment remains secure.