How to Enable or Disable Microsoft Defender Cloud Protection
Microsoft Defender cloud protection is a built-in Windows security feature that stops new viruses and attacks almost instantly by checking live threat data from Microsoft servers. Regular virus updates only happen a few times a day, but this cloud setting flags risky files and checks them against live security systems within seconds.
You can turn this protection on or off at any time through your Windows security settings to decide whether your PC shares diagnostic data to spot new threats.
To enable or disable Microsoft Defender Cloud Protection, open Windows Security, go to Virus & threat protection Manage settings, and toggle Cloud-delivered Protection on or off. This feature enhances real-time threat detection by sending suspicious files to Microsoft for analysis.
Why use Cloud Protection?
Traditional definition updates can lag behind emerging malware. Tapping into cloud intelligence lets Defender block brand-new threats before standard signature files ever download.
What happens when done?
Disabling Microsoft Defender Cloud Protection cuts off incoming security updates from the cloud. This leaves hardware more vulnerable to viruses and online dangers. Enabling ‘Automatic sample submission’ allows Microsoft to collect files for threat inspection, so understanding privacy implications remains important.
How to change settings in Windows Security
The Windows Security app manages Microsoft Defender Cloud Protection settings. Opening the application and navigating to ‘Virus & threat protection’ reveals the necessary controls.
- Click the search box on your taskbar and type Windows Security.
- Select Windows Security from the list.

- Click on Virus & threat protection.

- Look for Virus & threat protection settings and click Manage settings.

- Toggle Cloud-delivered Protection to On or Off.

How to use Group Policy (Admin Privileges Required)
IT administrators and advanced users manage Microsoft Defender Cloud Protection configurations through the Group Policy editor. Searching for ‘Edit group policy’ opens the tool, requiring a specific directory path inside the editor interface.
- Click the Start menu and search for Edit group policy.
- Select it to open the editor.

- In the left menu, follow this path: Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > MAPS.
- On the right side, double-click Join Microsoft MAPS.

- Choose Enabled and set it to Basic MAPS or Advanced MAPS.

- Click OK and close the window.
Summary
Microsoft Defender Cloud Protection is a vital security feature that connects devices to Microsoft's threat analysis service for real-time defense against the latest digital attacks. Keeping this toggle active offers maximum protection.
Does cloud protection impact system performance?
Microsoft Defender Cloud Protection is designed to be lightweight and generally improves computer security without slowing down daily tasks, as it transmits minimal data and performs heavy analysis in the cloud.
What data is sent to Microsoft when cloud protection is enabled?
When Microsoft Defender Cloud Protection is enabled, Microsoft collects telemetry data (information about how the software is used) and metadata (data about other data) regarding potential threats. It may also upload suspicious files if automatic sample submission is turned on, all to help improve security for everyone.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!