The three causes
- A third-party antivirus is installed (Norton, McAfee, Avast, AVG, ESET, Bitdefender, etc.). This is the most common cause and is normal — only one antivirus runs at a time.
- Malware has switched it off. The settings will be greyed out and Tamper Protection may be off too.
- A Group Policy / registry tweak from an old 'tweaker' tool or a former IT admin is forcing it off.
Step 1: Check for third-party antivirus
Important
Step 2: Check Tamper Protection status
Step 3: Look for malware tampering
eventvwr and press Enter. Navigate to Applications and Services Logs → Microsoft → Windows → Windows Defender → Operational.Step 4: Check for forced policy
regedit and press Enter. Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender.DisableAntiSpyware exists and is set to 1, something has forced Defender off. Take a screenshot before changing anything.Important
Was this guide helpful?
Know someone who needs this? Send them the guide.
Written by
Jordan DicksonFounder, CyberSecurityGuides
Founder of CyberSecurityGuides, writing practical, jargon-free guides that help everyday people recover from and protect against online attacks.
Reviewed by CSG Security Engineers