Tamper Protection helps stop other applications from silently changing key Microsoft Defender settings, including real-time and cloud-delivered protection. Microsoft notes that an administrator can still make changes through Windows Security and that Tamper Protection does not control how third-party antivirus registers. If protection switches off unexpectedly, investigate the actual provider and policy before assuming malware or disabling defenses to make a warning vanish.
Before you start
Record Windows Security's current protection provider, last change and any threat notifications. Update Windows and your approved antivirus. On a managed PC, IT may enforce settings; do not fight that policy with scripts. If you suspect malware, preserve evidence and change important account passwords from a different trusted device.Do it step by step
- Open Windows Security > Virus & threat protection > Manage settings and read the Tamper Protection state. Do not rely on a third-party utility's badge.
- Check Security providers in Windows Security to see which antivirus is active. Another registered product can change how Defender controls appear without indicating compromise.
- Review Protection history for alerts, disabled services or repeated changes. Record timestamps and affected settings before modifying them.
- If Tamper Protection is available and permitted, turn it On in Windows Security. Confirm real-time and cloud-delivered protection are in their intended state.
- Restart and check again. If the setting reverts, inspect organization policy, third-party security software and Windows updates before using a registry fix.
- For unexplained repeated changes or a named threat, run an updated scan and consider Defender Offline. Escalate to IT or incident response if administrative controls appear compromised.