To disable Antimalware Service Executable in Windows 11 for a short time, open Windows Security, select Virus & threat protection, select Manage settings, and switch Real-time protection to Off. Windows turns it back on by itself after a short while, so the lasting fixes are to reduce how much work the process does or to install another antivirus program, which makes Microsoft Defender Antivirus step aside automatically.
Applies to: Windows 11 with Microsoft Defender Antivirus. Checked against Microsoft Support and Microsoft Learn on October 6, 2026.
What Antimalware Service Executable is
Antimalware Service Executable is the main background process of Microsoft Defender Antivirus, the antivirus program built into Windows 11. Microsoft’s documentation lists the same component under three names in Task Manager:
| Task Manager tab | Name shown |
|---|---|
| Processes | Antimalware Service Executable |
| Details | MsMpEng.exe |
| Services | Microsoft Defender Antivirus (service name WinDefend) |
The process checks files as you open, download, and run them, and it also carries out scheduled scans and security intelligence updates. That is why it is always present. If you are not sure how to look at it, see our guide on how to open Task Manager in Windows 11.
Before you turn anything off
- Sign in with an administrator account. Windows Security lets an administrator on the device change these protection settings.
- Your PC is unprotected while Real-time protection is off. Microsoft states that files you open or download are not scanned for threats during that time. Avoid downloads, email attachments, and USB drives from other people until protection is back on. For the full procedure and its limits, see how to disable Windows Defender in Windows 11.
- There is no supported permanent off switch for home PCs. Microsoft designed Defender to stay on unless another antivirus program takes over. The reasons the older tricks fail are explained further down. Not sure which product is active? See how to check what antivirus you have on Windows 11.
- A busy process is often temporary. High CPU or disk use during a scan, or right after an update, usually ends when the scan finishes.
How to turn off Real-time protection in Windows Security
This is the official way to pause Antimalware Service Executable. Use it to test whether Defender is causing a slowdown or blocking an installer you trust.
- Select Start and type Security. Open Windows Security from the results. The app opens on its home page.
- Select Virus & threat protection. You see the current threat status and scan controls.
- Under Virus & threat protection settings, select Manage settings. A page of protection switches opens.
- Switch Real-time protection to Off. If Windows asks for permission to make the change, approve it.
- Do the task you needed to test, then return to the same page and switch Real-time protection back to On.

Expect the process to stay in Task Manager. Turning off Real-time protection stops the on-access scanning that causes most of the load, but the Microsoft Defender Antivirus service keeps running. Microsoft also notes that Real-time protection turns back on automatically after a short while, so this setting cannot be used as a permanent switch.
How to reduce CPU and disk use without disabling protection
If your goal is a faster PC, these options usually help more than switching protection off, and they keep you protected. Work through them in order.
Let the current scan finish and update Defender
- Open Windows Security and select Virus & threat protection.
- Look under Current threats. This area shows when the last scan ran and how long it took. If a scan is in progress, let it finish.
- Select Protection updates, then select Check for updates to install the latest security intelligence.
- Restart the PC if the process is still unusually busy afterward.
Add an exclusion for a trusted folder
An exclusion tells Defender to skip specific items. It is the right fix when one known, trusted location keeps triggering scans, such as a folder of virtual machine disks, a game library, or a software build folder.
- Open Windows Security and select Virus & threat protection.
- Select Manage settings.
- Under Exclusions, select Add or remove exclusions.
- Choose to add an exclusion and pick one of the four types: File, Folder, File type, or Process.
- Browse to the item and confirm. It now appears in the exclusions list.
To undo it, return to Add or remove exclusions, select the exclusion, and select Remove.
Keep exclusions as narrow as possible. Microsoft warns that Defender no longer checks excluded items for threats, so never exclude your Downloads folder, a whole drive, or anything you did not create or install yourself. A Folder exclusion covers everything inside that folder. A Process exclusion covers the files that process opens during real-time scanning, not the program file itself.
Many tutorials suggest adding MsMpEng.exe or the Windows Defender program folder as an exclusion. Microsoft’s performance troubleshooting guidance does not list that as a fix. It recommends finding the files or programs that are actually being scanned heavily and excluding those.
Move the scheduled scan to a quieter time
Microsoft Defender Antivirus scans your device regularly. If that scan starts while you are working, you can add your own schedule with Task Scheduler.
- In the search box on the taskbar, type Task Scheduler and open the app.
- In the left pane, expand Task Scheduler Library > Microsoft > Windows, then scroll down and select the Windows Defender folder.
- In the top center pane, double-click Windows Defender Scheduled Scan.
- In the properties window, select the Triggers tab, then select New at the bottom of the window.
- Choose how often the scan should run and when it should start, such as weekly at a time when the PC is on but you are away from it. Confirm your choices to save the trigger.
Reschedule the scan instead of disabling the Windows Defender tasks.
Lower the CPU limit for scans with PowerShell
Defender has a setting for the maximum average percentage of CPU a scan should use. Microsoft documents the default as 50 and accepts values from 5 through 100. Microsoft’s troubleshooting guidance suggests lowering it to 20 or 30 on PCs where scans cause slowdowns.
- Select Start, type PowerShell, and open Windows PowerShell. If the command in the next step reports that you do not have permission, close the window and open PowerShell again as an administrator.
- Type Set-MpPreference -ScanAvgCPULoadFactor 30 and press Enter. The new limit applies to later scans.
- Optional: type Set-MpPreference -EnableLowCpuPriority $true and press Enter. This tells Defender to use low CPU priority for scheduled scans.
To go back to the default, run Set-MpPreference -ScanAvgCPULoadFactor 50. Microsoft describes this value as guidance for the scanning engine and not a hard cap, so brief spikes above it are normal. It applies to scans, not to the real-time checks that happen when you open files.
Find out exactly what Defender is scanning
Microsoft includes a performance analyzer for Microsoft Defender Antivirus that records which files, file extensions, and processes are taking the most scan time. It requires Defender platform version 4.18.2108.7 or later.
- Open PowerShell and run New-MpPerformanceRecording -RecordTo recording.etl.
- Repeat whatever makes the PC slow, such as launching the game or starting the build.
- Press Enter in the PowerShell window to stop and save the recording.
- Run Get-MpPerformanceReport -Path recording.etl -TopFiles 3 -TopScansPerFile 10. The report lists the three files that took the most scan time and the ten longest scans for each.
Use the result to decide on one narrow exclusion, and only if you recognize and trust the file or program named in the report.
Install another antivirus program to replace Defender
This is the only lasting way that Microsoft supports to stop Microsoft Defender Antivirus from being your active scanner. Microsoft states that when you install a compatible non-Microsoft antivirus program, Microsoft Defender Antivirus automatically turns itself off. If that program later expires, is uninstalled, or stops providing real-time protection, Defender can turn itself back on automatically.
With another antivirus program installed, Windows Security shows that product in the Virus & threat protection section, with a Microsoft Defender Antivirus options link below its name. That link contains a switch for limited periodic scanning, an optional occasional Defender scan that runs alongside the other product. Leave it off if you want Defender to do as little as possible.
Keep in mind that the replacement program runs its own background scanner, which also uses CPU and memory. Do not run two antivirus programs with real-time protection at the same time.
Why Group Policy, Registry, and service methods no longer work
Older guides describe several ways to switch Defender off for good. On a current Windows 11 PC they are either ignored or risky.
- Tamper protection blocks them. This Windows Security setting stops apps and scripts from changing important Defender settings, and it keeps Real-time protection turned on. While it is on, an administrator can still use the switches inside the Windows Security app, but Microsoft says changes made to protected settings through Group Policy are ignored.
- The DisableAntiSpyware Registry value has been removed. Microsoft says this legacy setting was meant for PC makers and IT staff deploying a different antivirus product, was never intended for consumer devices, and is no longer necessary because Defender turns itself off when it detects another antivirus program. Adding the value to the Registry on a home PC does not disable Defender.
- The Group Policy setting is for managed PCs. Local Group Policy Editor has a policy named Turn off real-time protection under Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Real-time Protection. Setting it to Enabled has no effect while Tamper protection is on, and Microsoft warns that disabling real-time protection drastically reduces protection and is not recommended.
- Stopping the service can damage Windows. Microsoft specifically says not to disable, stop, or modify the services and processes used by Microsoft Defender Antivirus and the Windows Security app, including WinDefend, MsMpEng, SecurityHealthService, and wscsvc, because doing so can cause severe instability. That rules out ending the task, changing the service startup type, running stop commands, and deleting the Defender folder.
Tamper protection has its own switch on the Manage settings page of Virus & threat protection. We recommend leaving it on. Turning it off mainly makes it easier for malware to disable your antivirus.
How to confirm the change and undo it
- Check the switch: open Windows Security > Virus & threat protection > Manage settings and look at Real-time protection.
- Check which antivirus is active: in Virus & threat protection, under Who’s protecting me?, select Manage Providers. The page names the antivirus product that is protecting the PC.
- Check with PowerShell: run Get-MpComputerStatus. The RealTimeProtectionEnabled row shows True or False, and the AMRunningMode row shows Normal when Defender is the active antivirus. SxS Passive Mode means Defender is running alongside another antivirus product with limited periodic scanning.
- Undo everything: switch Real-time protection back to On, remove any exclusion you no longer need, and set the scan CPU limit back to 50. For full details, see our guide on how to turn on Windows Defender in Windows 11.
Troubleshooting
Real-time protection turned itself back on
This is the documented behavior. Windows restores Real-time protection automatically after a short while. If you need a longer break from scanning for one program, use a narrow exclusion.
The Real-time protection switch is greyed out or missing
On a work or school PC, your organization manages Defender settings and you will not be able to change them. Contact your IT department. On a home PC, check whether another antivirus program is installed. If one is, Defender is already off and that product’s name appears in Virus & threat protection.
The process is still using a lot of CPU after you turned protection off
A scan that was already running may still be finishing, and Defender may run a scan after installing a security intelligence update. Microsoft also lists these common causes of heavy Defender activity:
- Very large files such as .iso and .vhdx disk images stored in OneDrive or on a network share. Moving them to a local folder outside those locations reduces scanning delays.
- Other security software scanning the same files. If you run a VPN client, a data loss prevention tool, or a second security tool, check whether its maker recommends exclusions for Microsoft Defender Antivirus.
- Programs that are not digitally signed, and scripts that have been obfuscated, both of which take more effort to check.
If the load never settles, run a Quick scan from Virus & threat protection. For a deeper check, select Scan options and choose Full scan, which examines every file and program on the device.
You cannot find Local Group Policy Editor
Microsoft’s instructions open it by typing gpedit in the taskbar search box and selecting Edit group policy. If nothing appears, your edition of Windows 11 does not include the editor. You do not need it for any method in this article.
Exclusions cannot be added
Make sure you are signed in with an administrator account. On managed PCs, Tamper protection can also lock the exclusions list so that only your organization can change it.
Frequently asked questions
Is it safe to disable Antimalware Service Executable?
Turning off Real-time protection for a few minutes to test something is low risk if you avoid opening new files and downloads during that time. Leaving a PC without any antivirus protection is not safe. If you want Defender gone long term, install another antivirus program first.
Can I permanently disable Antimalware Service Executable in Windows 11?
Not with a supported setting on a home PC. Real-time protection turns itself back on, Tamper protection ignores policy changes, and the old DisableAntiSpyware Registry value has been removed. Installing a different antivirus program is the supported way to make Defender turn itself off.
Can I end the task in Task Manager?
You should not. The process belongs to the WinDefend service, and Microsoft warns against stopping or modifying that service because it can make Windows unstable.
Why does Antimalware Service Executable use so much memory or CPU?
It is usually running a scheduled scan, scanning after a security intelligence update, or checking a large number of files that a program is creating or opening. Activity should fall once the scan ends. If it happens every time you use one program, the performance analyzer steps above will show which files are involved.
Will turning off Real-time protection stop scheduled scans and updates?
No. The Microsoft Defender Antivirus service keeps running, and Windows turns Real-time protection back on by itself. Scheduled scans are controlled separately through Task Scheduler.
Is MsMpEng.exe a virus?
No. MsMpEng.exe is the file name Microsoft documents for the Microsoft Defender Antivirus service, and it is the same item that the Processes tab calls Antimalware Service Executable.
Does Windows 11 have a faster scanning mode for developers?
Yes. Windows 11 includes Dev Drive protection, which uses a performance mode on Dev Drive volumes that defers security checks until after a file operation completes. It is designed for developer workloads and is listed on the same Manage settings page.
Start with the exclusion and scan-schedule steps if performance is your concern, and read Microsoft’s page on Virus & threat protection in the Windows Security app for the full list of settings. Microsoft’s guide to troubleshooting Microsoft Defender Antivirus performance issues covers the less common causes of high CPU use.

Matt Jacobs has been working as an IT consultant for small businesses since receiving his Master’s degree in 2003. While he still does some consulting work, his primary focus now is on creating technology support content for SupportYourTech.com.
His work can be found on many websites and focuses on topics such as Microsoft Office, Apple devices, Android devices, Photoshop, and more.