Security

How to Add a Microsoft Defender Exclusion Safely (File, Folder, or Process)

Published ✓ Verified ⏱️ 3 min read February 10, 2026 · by Ryan Bennett

Microsoft Defender keeps quarantining or deleting a file or app you know is safe, and you want to tell it to leave that one thing alone.

Why: An exclusion tells Defender to stop scanning a specific file, folder, file type, or process. That’s useful for a trusted developer tool or a known false positive — but it’s also a hole in your protection: anything inside an excluded location is no longer checked. The goal is to exclude as narrowly as possible (one file or folder, not your whole drive) and only when you’re sure the item is safe.

First: are you sure it’s actually safe?

An exclusion is permanent until you remove it, so don’t add one to silence a warning you don’t understand. If you’re not certain the file is clean, scan it at virustotal.com or simply leave Defender’s detection in place. Only exclude things you trust — your own build output, a vendor’s tool flagged as a false positive, a game’s anti-cheat folder, etc.

Fix 1: Add a folder or file exclusion (the usual case)

  1. Open Windows Security (Start → type SecurityWindows Security).
  2. Select Virus & threat protection.
  3. Under Virus & threat protection settings, select Manage settings.
  4. Scroll to Exclusions and select Add or remove exclusions. Approve the admin prompt.
  5. Select Add an exclusion, then choose:
    • File — a single file (most precise; best when it’s one specific program).
    • Folder — that folder and everything inside it.
    • File type — every file with a given extension everywhere on the PC (broad — avoid unless you must).
    • Process — files opened by a named process while it runs.
  6. Browse to the item and confirm. The exclusion takes effect immediately for scheduled scans, on-demand scans, and real-time protection.

Caution: prefer File over Folder, and Folder over File type. A File type exclusion (e.g. .exe) stops Defender checking all files of that type system-wide — that’s a large blind spot.

Fix 2: Restore the file Defender already quarantined

If Defender already moved the file, add the exclusion first (Fix 1) so it isn’t re-detected, then restore it:

  1. In Virus & threat protection, select Protection history.
  2. Find the detection, expand Actions, and choose Restore (or Allow on device for an item still in quarantine).
  3. If “Restore” isn’t offered, the file may have been removed; you’ll need to obtain it again from its original source.

Fix 3: Remove an exclusion when you no longer need it

Exclusions don’t expire — clean them up so the gap doesn’t linger:

  1. Windows Security → Virus & threat protection → Manage settings → Exclusions → Add or remove exclusions.
  2. Select the exclusion you want gone, then Remove.

If “Manage settings” or “Exclusions” is greyed out

If the option is missing or locked, your device is managed by a policy (work/school) or another antivirus is the active provider. On managed devices, exclusions are controlled centrally (Intune/Group Policy) and the local UI is intentionally disabled — ask your IT admin. If a third-party antivirus is active, Defender’s settings are dimmed because it isn’t the running antivirus.

FAQ

Does an exclusion turn off my antivirus? No — it only stops scanning the specific item you chose. The rest of your PC stays protected, which is why an exclusion is much safer than turning real-time protection off.

Will an excluded file run without any warning? Yes, Defender ignores it entirely. That’s the point — and the risk. Keep exclusions narrow and trusted.

Can I exclude a website or URL? No. Exclusions cover files, folders, file types, and processes — not web addresses. SmartScreen web filtering is configured separately under App & browser control.

Sources: Microsoft Support — Virus & threat protection in the Windows Security app, Microsoft Learn — Configure custom exclusions for Microsoft Defender Antivirus

↑↓ navigate · ↵ open · Esc close See all results →