How to Turn On Windows Defender Tamper Protection in Windows 11

8 min read

Help Desk Geek is reader-supported. We may earn a commission when you buy through links on our site. Learn more.

Windows Security shows Tamper Protection as On or Off, but you’re not sure what that switch actually does. Here’s what it protects, how to check it, and how to turn it on if it’s off.

What Is Tamper Protection?

Tamper Protection is a setting in Microsoft Defender Antivirus available on Windows 10 and Windows 11, though its presence and default state depend on your platform version and how Defender is configured. When it’s on, it locks core Defender settings: real-time protection, cloud-delivered protection, and behavior monitoring. Nothing can change them except the Windows Security app itself or your organization’s approved management tools.

That matters because disabling antivirus is usually an attacker’s first move. Security researchers have proven the point with Defender bypass techniques like “RedSun” and “BlueHammer.” If malware or a remote intruder can flip off real-time protection through the Registry or a script, the rest of the attack goes undetected. Tamper Protection closes that door. It refuses changes made from outside the official app.

There’s nothing to download or install here. You’re just checking a switch that already ships with Windows.

Before You Begin

Make sure you have:

  • A PC running Windows 10 (version 1709 or later) or Windows 11
  • An administrator account (standard users can view the setting but can’t change it)
  • Microsoft Defender Antivirus set as your primary antivirus (not overridden by a third-party security suite)
  • A few minutes; this is a two-minute check, not a project
RequirementDetails
DeviceAny Windows 10 or Windows 11 PC
OS versionWindows 10 1709+ or Windows 11
Account typeLocal administrator
CostFree, built into Windows

Step-by-Step Guide

Step 1: Open Windows Security

Click Start, type “Security,” and select Windows Security from the results. This launches the built-in app that manages Defender Antivirus, firewall, and device security. No separate install needed.

Windows Security app home screen showing the grid of protection tiles including "Virus & threat protection"

Step 2: Open Virus & threat protection

From the Windows Security home screen, select Virus & threat protection. This page shows your overall protection status and any active warnings.

Virus & threat protection overview page showing current protection status and the "Virus & threat protection settings" section with the "Manage settings" link, including a yellow warning banner if Tamper Protection is off

If Tamper Protection is off, you’ll usually see a yellow or red banner near the top of this page. Everything green is a good sign, but check the actual toggle anyway. Some setups don’t show a banner even when the setting is off.

Step 3: Open Manage settings

Under Virus & threat protection settings, select Manage settings. This opens the page where every individual Defender protection gets its own switch.

Step 4: Find the Tamper Protection toggle

Scroll down past Real-time protection, Cloud-delivered protection, and Automatic sample submission until you reach Tamper Protection. The switch reads either On or Off.

Virus & threat protection settings (Manage settings) page showing the Tamper Protection On/Off toggle switch alongside Real-time protection and Cloud-delivered protection
Close-up of the Tamper Protection toggle control itself, showing the On state

Step 5: Turn it on if it’s off

If the toggle reads Off, click it once. Windows may prompt you with a User Account Control dialog; click Yes to confirm. The switch flips to On immediately. Any warning banner on the Virus & threat protection page should clear within a few seconds.

Expected result: The toggle shows On, and no yellow or red warnings remain on the Virus & threat protection page. Defender now rejects any attempt to change its settings from outside this app.

Configuration: Why Tamper Protection Might Already Be Off

If you found it switched off, one of these is almost always the reason:

  • Clean install or factory reset. A fresh Windows install needs a moment, and an internet connection, before Defender fully initializes and turns Tamper Protection on. Reboot, connect to Wi-Fi, and check again after Windows Update finishes.
  • You recently removed a third-party antivirus. When another antivirus program runs as your primary protection, Windows stands Defender down, including Tamper Protection. Uninstalling that program should hand control back to Defender. Sometimes the switchover leaves settings in a weird state; toggling it on manually fixes that.
  • A workplace policy manages it. On a work or school device, IT can control Tamper Protection tenant-wide through the Microsoft Defender portal, Intune, or Configuration Manager. See the greyed-out section below if that’s your situation.
  • Something actively disabled it. If you didn’t do a reset or swap antivirus, and it’s off anyway, treat that as a red flag. Malware that disables antivirus protection is exactly what Tamper Protection is built to stop. Run a full scan and check for other signs your antivirus has been disabled without your knowledge.

If the Toggle Is Greyed Out (Managed by Your Organization)

On a work or school laptop, you may find the Tamper Protection switch greyed out and unclickable, sometimes with a note reading “Some settings are managed by your organization.”

IT departments enforce Tamper Protection centrally so one policy applies to every device, instead of relying on each user to keep it on. That’s the whole point of the greyed-out switch. Don’t try to override it locally.

What to do instead:

  • Don’t try registry edits or scripts to force the toggle. Tamper Protection is built to block that kind of change, so it likely won’t work. It may also violate your company’s security policy.
  • Contact your IT or security administrator if you need it temporarily adjusted for legitimate troubleshooting.
  • Confirm the note is really about organizational management by checking the exact wording under the toggle.

If you’re an admin managing Tamper Protection across a fleet of devices, that configuration happens through the Microsoft Defender portal, Intune, or Configuration Manager, not the local Windows Security app. That’s a separate, admin-level workflow. An individual user doesn’t need to touch it.

Advanced: Checking Status with PowerShell

On a handful of older Windows 10 builds (1709/1803/1809) and some Windows Server editions, the Tamper Protection toggle doesn’t appear in the Windows Security UI at all. If that’s you, check status with PowerShell instead.

  • Click Start, type “PowerShell,” right-click Windows PowerShell, and select Run as administrator.
  • Run the following cmdlet:
Get-MpComputerStatus | Select-Object IsTamperProtected
  • Check the output: True means Tamper Protection is active; False means it isn’t.

This command is read-only and won’t change anything. Toggling Tamper Protection is a GUI action by design. If the output comes back False, update Windows fully via Windows Update, then check the Windows Security app again rather than trying to flip it from the command line.

Quick Verification: Is Defender Itself Actually Protecting You?

Turning on Tamper Protection locks your settings from unauthorized changes. It doesn’t tell you whether Defender is actually scanning anything. Confirm Defender itself is active and current:

  • On the Virus & threat protection page, check that Real-time protection is On.
  • Look at Virus & threat protection updates and confirm Security intelligence shows a recent date. If it’s more than a few days old, click Check for updates.
  • Open Settings > Windows Update and click Check for updates to make sure the OS and Defender’s platform updates are current.
Windows Settings Windows Update page with the "Check for updates" button visible
  • Optionally, run a Quick scan from the Virus & threat protection page to confirm scanning actually works end to end.

If real-time protection won’t stay on, or definitions won’t update no matter what you try, that points to a deeper problem. Possibly active malware, possibly a conflicting security tool. Worth a full malware scan rather than just re-flipping this one toggle.

Tips and Hidden Features

  • Turning Tamper Protection off temporarily for troubleshooting: Some legitimate fixes, like certain Group Policy or script-based Defender changes, need Tamper Protection off. Switch it off via Manage settings, make the change, then switch it back on right away.
  • Tamper Protection vs. third-party antivirus: If you run a paid antivirus suite as your primary protection, it likely has its own self-protection feature doing a similar job. Defender’s Tamper Protection sits dormant in that setup since Defender itself is standing down.
  • Warning banners are your friend: Get in the habit of glancing at the Virus & threat protection page now and then. A yellow or red banner is Windows actively telling you something needs attention.

Wrapping Up

For most people, this is a two-minute fix: open Windows Security, flip the Tamper Protection toggle on, done. The only real judgment call is the greyed-out scenario. If IT manages your device, leave it alone and loop in your admin instead of hunting for a workaround.

StepActionApplies To
1-4Check status via Windows Security > Virus & threat protection > Manage settingsAll users
5Toggle Tamper Protection onHome/personal PCs
Contact IT if greyed outWork/school devices
Run Get-MpComputerStatusOlder builds without the UI toggle

If Tamper Protection keeps turning itself off after you re-enable it, that’s not normal. It suggests something on the PC is actively fighting the setting, and that’s worth treating as a malware investigation rather than a settings glitch.

Resources