Microsoft Defender Real-Time Protection Won’t Turn On: Fixes
Windows Security says real-time protection is off, the switch is unavailable, or the setting does not stay on. First check which antivirus provider is active and whether the device is managed. Tamper Protection is designed to keep protected settings, including real-time protection, on; switching it off is not a routine fix for enabling protection.
Fix 1: Check the active security provider
Open Windows Security → Settings → Manage providers. If another antivirus is active on a personal PC, Defender may be inactive by design. Keep a working antivirus enabled. If you intend to use Defender instead, uninstall the other product through its supported removal procedure, restart, and check the provider again. See turn on Defender after removing antivirus.
Fix 2: Check protection and management status
Open Windows Security → Virus & threat protection → Manage settings and enable Real-time protection if the control is available. Leave Tamper Protection enabled. Install Windows and Defender security-intelligence updates, then restart after saving work.
If settings say managed by your organization, check whether this is a work/school device or is enrolled in device management. Ask IT to check the effective policy and antivirus mode. Do not disconnect a managed device or delete its security-policy registry keys to bypass those controls.
Fix 3: Review a known local policy on a personal PC
Only if you own and manage the PC and previously changed local Defender policy, review that specific setting in gpedit.msc → Computer Configuration → Administrative Templates → Windows Components → Microsoft Defender Antivirus. An old Turn off Microsoft Defender Antivirus or Turn off real-time protection policy may need returning to Not Configured after you confirm no other management source sets it.
Windows Home does not include Local Group Policy Editor. Avoid deleting the whole Defender policy key as a generic repair; identify the responsible product or setting and use its supported reversal procedure instead.
Fix 4: Inspect Defender’s reported state
Open Windows PowerShell as administrator and run this read-only check:
Get-MpComputerStatus | Select-Object AMRunningMode, AntivirusEnabled, RealTimeProtectionEnabled, IsTamperProtected
Review the result together with the active provider and policy. A disabled or passive state can have several causes; it does not prove Tamper Protection prevented enabling protection. If Defender should be the active provider but remains unhealthy, collect Windows Security errors and contact Microsoft or your administrator.
FAQ
Why does the switch change back? Another registered antivirus, an effective management policy or a security-service problem can affect the state. Check those sources rather than repeatedly weakening Tamper Protection.
Should I turn Tamper Protection off? Keep it on during ordinary troubleshooting. Managed environments have documented diagnostic workflows for protected settings; an administrator should use those only when a specific investigation requires them.
Sources: Microsoft Learn — Tamper Protection, Microsoft Learn — Real-time protection