Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 5000

Only Microsoft Defender is left protecting this PC after your suite lapsed

10 min read Updated October 5, 2026 Antivirus & Endpoint Security

Fix it now

Event 5000 records that Defender’s real-time protection was enabled. On a machine that ran a paid suite for years, that is Windows doing what Microsoft documents: bringing Defender back once the other product expires, is uninstalled, or stops providing real-time protection. Nothing is broken. The question is what else stopped with it.

Run in an elevated PowerShell window; the scan takes a while, so start it and leave it

Get-MpComputerStatus | Format-List RealTimeProtectionEnabled,AMRunningMode,AntivirusSignatureLastUpdated
Start-MpScan -ScanType FullScan
  1. Open Windows Security, go to Virus & threat protection, and under Who’s protecting me? choose Manage providers. Confirm the Security providers page now shows Microsoft Defender Antivirus turned on.
  2. Open the old suite if it is still installed and read its subscription status, so you know whether it lapsed or simply failed.
  3. If it has lapsed and you are not renewing, uninstall it with the vendor’s removal tool so it cannot reclaim the registration on a future update.
  4. Let the full scan finish before you consider the machine settled.

Do not reinstall the old product just to make the log entry stop. Event 5000 is a record of protection starting, not of anything failing.

If Defender is registered, updating and scanning cleanly, the technical work is finished. The next section covers what a suite was actually giving you, so you can decide whether any of it needs replacing.

Why it happens

Windows hands antivirus duty to whichever product is registered and reporting itself as active. Microsoft documents that Defender steps aside when a non-Microsoft product is installed as the primary antivirus, into disabled mode on an ordinary Windows client, and that it can be re-enabled automatically if that product expires, is uninstalled, or otherwise stops providing real-time protection. Event 5000 is the second half of that sentence happening on your machine.

Two neighbours often appear at the same time. 5004 records that the real-time protection configuration changed, which is what a handover looks like from the configuration side. 5008 records that the antimalware engine encountered an error and failed, and it can turn up while one product’s components are being unloaded and another’s are starting. A single 5008 during a changeover is not the same as 5008 repeating on a settled machine.

So the scanning is covered. What is not covered is everything the suite bundled around the scanner, and that is where people are caught out, because none of it produces a log entry at all. Suites sell on breadth rather than on detection alone: cover for phones, tablets and Macs on one subscription, a VPN, a password manager, backup storage, identity monitoring. Those stop on the day the subscription does, silently.

Event 5100 is a separate matter and worth telling apart from anything to do with the old product. Microsoft publishes it as a warning that the antimalware platform expires soon, and 5101 as the platform being expired. Both are about Defender’s own components falling behind, usually on a machine that has been off or offline for a long time, and both are fixed with Windows Update rather than with a purchase.

The subscription ended and the product deregistered cleanly

You have this one if The suite shows an expiry date in the past, and Defender took over at about the same time.

  1. Decide whether you want the suite back. If not, uninstall it with the vendor’s removal tool so nothing half-removed remains.
  2. Confirm Defender is registered and updating on the Security providers page.
  3. Run a full scan, since cover may have been patchy during the lapse.
  4. If you do want it back, apply a current licence to the existing installation and confirm it reports a future expiry date.

A preinstalled trial ran out

You have this one if The machine is fairly new, the suite arrived with it, and this happened weeks or months in.

  1. Check whether the trial was ever tied to an account of yours. Many are not.
  2. If you do not want it, remove it properly with the vendor’s removal tool rather than leaving it to nag.
  3. Confirm Defender reports itself as on afterwards.
  4. If you do want it, buy a subscription and apply it to the installation rather than reinstalling from scratch.

The suite is still licensed but has stopped working

You have this one if The subscription is current, and Windows now names Defender as the active provider while the suite reports an error or will not start.

  1. Repair the product from Settings, Apps, using its own repair option where one is offered.
  2. If repair fails, uninstall with the vendor’s removal tool, restart, and reinstall from a fresh download.
  3. Sign back in so the current subscription applies to the new installation.
  4. Check the Security providers page and confirm the product has reclaimed the registration.

Do not buy anything in this case. A current subscription that has stopped working is a repair job, not a purchase.

Both products are now half present

You have this one if The Security providers page lists two entries, or the machine has become noticeably slower since the changeover.

  1. Pick one product and remove the other completely with its vendor’s removal tool, not through Settings alone.
  2. Restart, then confirm exactly one antivirus is registered.
  3. Run a full scan and confirm it completes without error.

Full reference

What Windows includes and what a suite adds

Capability Included with Windows Typically added by a paid suite
Real-time malware scanning Yes, Microsoft Defender Antivirus An alternative engine, not an additional one
Firewall Yes, Windows Firewall A different interface and rule management
Browser and download reputation Yes, in Microsoft Edge Extensions covering other browsers
Folder protection against ransomware Yes, controlled folder access Vendor-specific ransomware layers and rollback
VPN No Commonly bundled, with or without a data allowance
Password manager No Commonly bundled
Cloud backup No Commonly bundled with a storage allowance
Identity monitoring No Commonly bundled in higher tiers
Phones, tablets and Macs No Covered by the same multi-device subscription

Read that table as a list of decisions rather than a scorecard. The first four rows are the reason most people do not need to buy anything after a suite lapses. The last five are the reason some people do, and none of them is a scanning question.

Confirming the handover finished properly

Check What good looks like
Security providers page Exactly one antivirus, described as turned on
Get-MpComputerStatus RealTimeProtectionEnabled True
AntivirusSignatureLastUpdated A timestamp from today
Defender operational log A 5000, and no repeating 5008 after it
Get-MpComputerStatus | select AMRunningMode Normal, which is active mode
Settings, Apps No remains of the old suite listed

A single 5008 at the moment of the changeover is unremarkable. 5008 repeating on a machine that has been settled for days is an engine failure in its own right and should be treated as one.

Running the scan

Start-MpScan -ScanType FullScan runs a full scan from PowerShell, and the documented values for that parameter are FullScan, QuickScan and CustomScan. The same job from a Command Prompt is MpCmdRun.exe -Scan -ScanType 2, where 2 is the full scan. Either is worth running once after a changeover, because the period between one product stopping and the other starting is the window nothing was watching.

If Defender itself is behind

Events 5100 and 5101 report the antimalware platform expiring soon and having expired. On a machine that has been off for months, that is why Defender may not simply pick up the slack. The fix is Windows Update run to completion, followed by Update-MpSignature, and then a full scan. No licence is involved at any point, and no third-party product changes it.

Deciding whether to replace anything

  • List what you actually used. Most people used the scanner and nothing else, and Windows covers that.
  • Count devices, not people. The common reason to buy is a household with phones, tablets and Macs that Windows does not reach at all.
  • Check what you are already paying for. Cloud storage and a password manager are frequently already covered by another subscription.
  • Do not buy on the strength of the log entry. Event 5000 says protection started, which is the opposite of an emergency.

When a licence is the actual fix

The scanner is covered. Microsoft Defender is included with Windows, updates itself, and event 5000 is the record of it taking the machine back, so if that is all the old suite was doing you should not spend anything. What Windows does not replace is the breadth: cover for the family’s phones and Macs on one subscription, a VPN, a password manager and cloud backup, and rebuilding those from separate services is usually neither cheaper nor simpler. Arco supplies Norton 360 Deluxe, which bundles that kind of breadth across several devices, and can check which tier matches the number of people and devices you actually need to cover so you are not buying seats nobody will use.

Every code this article covers

Code What it points at Source
5000 Real-time protection is enabled Microsoft Learn
5004 The real-time protection configuration changed Microsoft Learn
5008 The antimalware engine encountered an error and failed, which can appear during a handover between products Microsoft Learn
Event ID 5100 The antimalware platform expires soon. A warning about Defender’s own components, not about another product Microsoft Learn

Confirm the fix worked

  1. The Security providers page lists exactly one antivirus and describes it as turned on.
  2. Get-MpComputerStatus reports RealTimeProtectionEnabled True and a signature timestamp from today.
  3. A full scan completes and writes a result to Protection history.
  4. No repeating 5008 entries appear in the Defender operational log after the changeover.
  5. The arrangement survives a restart rather than switching back after logon.

Questions people ask about this

Do I need to buy anything now that my suite has expired?

No. Microsoft Defender is included with Windows, updates itself and provides real-time protection at no cost. Buy a suite if you want the extra layers and multi-device cover, not because the machine is otherwise defenceless.

Is Defender enough for a home computer?

For most home use, yes. It scans in real time, checks against Microsoft’s cloud service, and Windows adds a firewall and browser reputation checks. The honest gaps are breadth rather than detection: no VPN, no password manager, no backup, and nothing covering your phone.

Should I uninstall the old suite or leave it?

Uninstall it, using the vendor’s removal tool. An expired product left installed can reclaim the registration on a future update and put you back where you started, with something registered and not protecting.

Will my old settings come back if I renew?

Usually, if the installation is still in place and you apply the subscription to it. If you removed it, expect to configure exclusions and rules again from scratch, which is a reason not to uninstall until you have decided.

What is event 5100 doing in the same log?

It is unrelated to your old suite. Microsoft publishes 5100 as a warning that the antimalware platform expires soon, and 5101 as it having expired. Both are about Defender’s own components and are fixed by letting Windows Update run.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

License Error ESET activation error ACT.9: your licence has expired or is no longer valid License Error Kaspersky activation error 1101: the activation code is not accepted Free Fix Kaspersky says databases are corrupted and updates keep failing Free Fix Windows Defender update error 0x80070643: security intelligence will not install
โ† Back to Knowledge Base