How To Use Windows 11’s Built-in Antivirus (Microsoft Defender)
Microsoft Defender is the built-in antivirus tool in Windows 11 that runs in the background to stop viruses, spyware, and other threats the moment you download a bad file or visit a risky website. It protects your PC for free without needing any extra software. You can open the Windows Security app from your system tray anytime to check your computer health, run a quick virus scan, or change your safety settings.
Open Windows Security by searching for it in the Start Menu or accessing it via Settings Privacy & security. Click “Virus & threat protection” to view your PC’s security status and manage scans. Defender protects your computer automatically in the background.
What is Microsoft Defender Antivirus?
Microsoft Defender Antivirus is the built-in security program that comes with Windows 11 to protect your computer from viruses, spyware, and other online threats. It runs quietly in the background without needing a separate download or subscription, automatically scanning files and removing dangerous software to keep your personal information safe.
Why Use Built-in Antivirus?
Microsoft Defender Antivirus provides strong, free protection that is already built into Windows 11 without requiring extra software. Because it is made by Microsoft, it updates automatically through Windows Update to catch new threats right away and works smoothly without slowing down your computer or charging monthly subscription fees.
What Happens When Microsoft Defender is Active?
Microsoft Defender constantly monitors your computer in the background to catch and block threats before they can harm your files. It scans every file you download or open in real time, checks running apps for suspicious behavior, and runs scheduled system checks to catch anything that slips past initial defenses.
- Real-time Protection: It scans files as you open them. It checks downloads before they save. It monitors applications as they run. If it finds anything suspicious, it stops it immediately.
- Scheduled Scans: Defender can be set to scan your entire computer regularly. This catches anything that might have slipped through.
- Virus & Threat Protection: This is the core. It identifies and removes viruses, malware, ransomware, spyware, and other malicious software.
- Firewall Protection: Defender works with the Windows Firewall. This controls network traffic. It blocks unauthorized access to your computer.
- Account Protection: It helps secure your Microsoft account login.
- Device Security: It can check for hardware security features.
- App & Browser Control: It adds an extra layer of security for apps and your web browsing.
Active protection means a dedicated security system guards your computer constantly while you work or browse online.
Accessing Microsoft Defender Antivirus
Manage your security settings inside the Windows Security app. It is available to find and use.
Opening Windows Security
Windows Security is the central app you use to check your computer's health and manage antivirus settings. You can open it quickly by clicking the Start button, typing "Windows Security" into the search bar, and clicking the app icon in the search results.
- From the Start Menu: Click the Start button. Type "Windows Security" in the search bar. Click on the "Windows Security" app when it appears in the results.
- From Settings: Click the Start button. Click on "Settings". In the Settings window, click on "Privacy & security" in the left-hand menu. Then, click on "Windows Security".
- Using the System Tray: Look for a shield icon in the system tray (the area near the clock on your taskbar). If you see it, click on it. If you don’t see it, you might need to click the small upward arrow to show hidden icons.
Once Windows Security opens, a dashboard appears on screen. This dashboard gives you an overview of your PC’s security status. Sections like "Virus & threat protection," "Firewall & network protection," and others appear prominently.

Understanding the Windows Security Dashboard
The Windows Security dashboard is your main control center for checking your computer's health and safety status. Green checkmarks mean everything is working properly, while yellow triangles or red circles with an X let you know immediately if a threat or problem needs your attention.
- Virus & threat protection: This is the most important section for antivirus.
- Firewall & network protection: Manages your network security.
- Account protection: Helps secure your sign-in options.
- App & browser control: Protects against potentially unwanted apps and malicious sites.
- Device security: Checks for advanced security hardware.
- Device performance & health: Looks for issues with your PC’s performance and storage.
- Family options: Links to Microsoft Family Safety features.
Antivirus management focuses mainly on the "Virus & threat protection" area.
Using Microsoft Defender's Virus & Threat Protection
This is where the real action happens. Microsoft Defender Antivirus actively scans for and removes threats. Here is how to use it.
Checking Your Protection Status
Clicking on "Virus & threat protection" in the Windows Security dashboard reveals the status of your antivirus.
- Open Windows Security.
- Click on Virus & threat protection.
A section called "Virus & threat protection settings" appears on screen. Underneath this, "Current threats" (if any) and "Manage settings" become visible.

Managing Protection Settings
Virus & threat protection settings let you turn core security features like real-time scanning and cloud protection on or off. You can access these controls by opening Windows Security, going to Virus & threat protection, and clicking Manage settings.
- Go to Virus & threat protection.
- Click Manage settings.
Various protection features toggle on or off here. These settings include:
- Real-time protection: This is crucial. It scans files as they are accessed. Keep this ON.
- Cloud-delivered protection: This sends threat information to Microsoft’s cloud. It helps Defender identify new threats faster. Keep this ON.
- Automatic sample submission: If Defender finds a suspicious file, it can send a copy to Microsoft for analysis. This helps improve Defender for everyone. You can choose to turn this ON or OFF.
- Tamper protection: This prevents malware from changing or disabling your security settings. It’s highly recommended to keep this ON.

You may need to uninstall the other antivirus software first if you want to use Defender.
Performing Scans
Microsoft Defender lets you run manual virus scans whenever you want to check your computer for hidden threats. You can choose a Quick Scan to check common malware hiding spots fast, or a Full Scan to check every file and running program on your system.
Quick Scan
Quick Scan: A Quick Scan checks the most common areas where malware hides. This runs fast and catches most immediate threats.
- Open Windows Security.
- Click on Virus & threat protection.
- Under "Current threats," click on Quick Scan.

Full Scan
A Full Scan checks every file on your hard drive. This takes much longer but is more thorough. Running this periodically, perhaps once a week or month, maintains system health.
- Open Windows Security.
- Click on Virus & threat protection.
- Under "Scan options," click the dropdown arrow next to Scan now.
- Select Full Scan.
- Click Scan now.

Custom Scan
A Custom Scan lets you choose specific files or folders to scan. This proves useful when a particular download or drive might be infected.
- Open Windows Security.
- Click on Virus & threat protection.
- Under "Scan options," click the dropdown arrow next to Scan now.
- Select Custom Scan.
- Click Scan now.
A new window appears. Click 'Select folder' to choose which folders to scan, or click 'This PC' to select entire drives.
Click Select Folder or OK.
Microsoft Defender Offline Scan
This is a powerful scan. It runs outside of Windows. This means it can find and remove threats that regular scans might miss. It proves especially useful when a PC is already infected and Defender struggles to run normally. A system restart is required.
- Open Windows Security.
- Click on Virus & threat protection.
- Under "Scan options," click the dropdown arrow next to Scan now.
- Select Microsoft Defender Offline Scan.
- Click Scan now.
Microsoft Defender's full scan begins automatically after your PC restarts. This scan typically takes about 15 minutes to complete, ensuring thorough protection for your computer's files.
Your PC will restart again when the scan is complete.

What to Do If a Threat is Found
Microsoft Defender alerts you with a notification and gives you options to quarantine or remove the detected threat. Quarantining moves the dangerous file to a safe, isolated folder where it cannot harm your computer, while removing deletes it permanently.
- Quarantine: This moves the threat to a safe, isolated location on your PC. It can’t harm your system while it’s quarantined. You can choose to restore it later if you believe it was a false alarm.
- Remove: This deletes the threat from your computer.
Microsoft Defender typically handles threats automatically by quarantining them. Clicking a notification opens the "Protection history" within Virus & threat protection. Here, you see what was detected and what action was taken. Manual actions like "Quarantine all" or "Remove all" are also available if multiple threats are found.
Administrator privileges are necessary for certain Microsoft Defender Antivirus tasks in Windows 11. For example, these higher permissions are required to delete stubborn malware or change fundamental security settings within the antivirus program. This safeguards your computer from unauthorized changes.
Viewing Protection History
Protection history shows you a detailed list of all past threats that Microsoft Defender has detected and blocked on your computer. You can view this list by opening Windows Security, going to Virus & threat protection, and clicking Protection history to see what actions were taken.
- Open Windows Security.
- Click on Virus & threat protection.
- Scroll down and click on Protection history.
A list of detected threats appears. Click on "Filter" to see actions like "All," "Quarantined," "Detected," or "Cleaned."
Advanced Microsoft Defender Settings
Microsoft Defender offers more than basic scanning. You can fine-tune its behavior.
Exclusions
Exclusions tell Microsoft Defender to ignore specific files, folders, or programs that you know are safe but the antivirus mistakenly flags as a threat. You should only add items to your exclusion list if you are completely certain the files will not harm your computer.
Adding important system files to exclusions can compromise your security.
- Open Windows Security.
- Click on Virus & threat protection.
- Under "Virus & threat protection settings," click Manage settings.
- Scroll down to the bottom. Click Add or remove exclusions.
- Click the + Add an exclusion button.
- Choose whether to exclude a File, Folder, File type, or Process.
- Browse to and select the item you want to exclude.

Admin Privileges Needed: Adding or removing exclusions requires administrator privileges.
Ransomware Protection (Controlled Folder Access)
Controlled Folder Access is a ransomware protection feature that blocks unauthorized apps from changing files in your important folders. When this is turned on, only trusted programs can modify documents, pictures, and videos, keeping your personal files safe from extortion software.
- Open Windows Security.
- Click on Virus & threat protection.
- Under "Ransomware protection," click Manage ransomware protection.
- Toggle Controlled folder access to On.
Prompts appear if an app tries to access these folders. You can also click "Allow an app through Controlled folder access" to add specific programs to a safe list.

Scheduling Scans
Task Scheduler lets you set up automated virus scans so Microsoft Defender checks your computer for threats on a regular schedule. This advanced feature ensures your system stays protected automatically without needing you to remember to run scans manually.
Automated scans run through Task Scheduler (a built-in utility that runs programs on a specific schedule). This feature offers advanced control over when your computer checks for threats, ensuring continuous protection even when you are not actively using your PC.
- Press the Windows key + R to open the Run dialog.
- Type
taskschd.mscand press Enter. This opens the Task Scheduler. - In the Task Scheduler library, look for a task named Microsoft. Expand it.
- Expand Windows.
- Expand Microsoft Defender.
- Right-click on Microsoft Defender Antivirus and select Properties.
- In the Properties window, go to the Triggers tab.
- Click New... to create a new trigger.
- Set a schedule (e.g., "On a schedule" and choose daily, weekly, etc.).
- Go to the Actions tab.
- Click New....
- In the "Program/script" box, type
MpCmdRun.exe. - In the "Add arguments (optional)" box, type
-Scan -ScanType 1. (-Scan -ScanType 2is for a full scan). - Click OK on all windows to save the scheduled task.
Admin Privilege Required: Accessing and modifying the Task Scheduler requires administrator privileges.
Additional Security Features in Windows Security
Microsoft Defender is part of a larger security suite in Windows Security. Other features enhance your overall protection.
Firewall & Network Protection
Firewall & network protection controls what internet and network traffic is allowed to enter or leave your Windows 11 computer. You can manage security settings for domain networks at work, private networks at home, and public Wi-Fi hotspots to keep hackers away.
- Open Windows Security.
- Click on Firewall & network protection.
Settings appear for Domain network (for work networks), Private network (for home networks), and Public network (for Wi-Fi hotspots). Click on each type to see its status and manage specific settings, like allowing an app through the firewall.
Allowing an app through the firewall fixes programs blocked by network security. To permit an app, click "Allow an app through firewall," then choose "Change settings." Finding the specific application in the list and checking the boxes for Private and/or Public networks grants access. This action serves as a common troubleshooting step for many software issues.

Admin Privilege Required: Changing firewall settings requires administrator privileges.
Account Protection
Account protection helps secure your Microsoft account and Windows login by encouraging safer sign-in methods. You can set up Windows Hello for facial recognition or fingerprint login, or create a secure PIN instead of using a standard password.
- Open Windows Security.
- Click on Account protection.
- Follow the prompts to set up or review your sign-in options.
App & Browser Control
App & browser control protects your computer from dangerous websites, downloads, and malicious applications using built-in security filters. It uses reputation-based protection and SmartScreen to check links in Microsoft Edge and block harmful software before it downloads.
- Reputation-based protection: This checks apps, files, and Microsoft Edge links for suspicious behavior. It includes features like SmartScreen for apps and devices, and SmartScreen for Microsoft Edge.
- Exploit protection: This helps protect against attacks that exploit vulnerabilities in software.
Windows 11's Microsoft Defender Antivirus uses "Reputation-based protection settings" and "Exploit protection settings" to control security features. You can click these options to manage how Defender identifies and blocks threats based on their reputation or how programs try to exploit weaknesses.
Device Security
Device security displays the status of your computer's built-in hardware security features, such as the Trusted Platform Module security chip. It also lets you manage core isolation settings to add an extra layer of defense against advanced malware.
- Open Windows Security.
- Click on Device security.
- If available, click on Core isolation details to manage settings like Memory integrity.
Admin Privilege Required: Accessing and enabling core security features might require administrator privileges.
When Does Microsoft Defender Automatically Disable?
Microsoft Defender automatically turns off its real-time protection when it detects that you have installed a third-party antivirus program. Windows does this to prevent software conflicts and system instability that can happen when two different security programs try to scan your computer at the same time.
- When another antivirus is installed: Windows automatically disables Microsoft Defender Antivirus if it detects that you have installed another antivirus program. This is to prevent conflicts, as running two antivirus programs simultaneously can cause system instability and performance issues.
Conclusion
Microsoft Defender Antivirus provides reliable, free protection that keeps your Windows 11 computer safe from malware without needing extra software. By monitoring your protection history, running regular scans, and enabling features like ransomware protection, you can easily maintain complete digital security.
Remaining vigilant and informed about emerging threats remains key to maintaining digital security. Microsoft Defender provides a reliable partner in safeguarding your PC, allowing you to browse, work, and play online with confidence.
Does 🪟 Windows 11 have a built-in Virus protector?
A next-generation protection solution that comes with Windows 11, Microsoft Defender Antivirus is real-time, always-on antivirus protection.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard, a writer for Geek Rewind, is a tech enthusiast who loves breaking down complex IT topics into simple, easy-to-understand ideas. With years of hands-on experience in system administration and enterprise IT operations, he’s developed a knack for offering practical tips and solutions. Richard aims to make technology more accessible and actionable. He's deeply committed to the Geek Rewind community, always ready to answer questions and engage in discussions.
No comments yet — be the first to share your thoughts!