Fix it now
Event 5001 records that Defender’s real-time protection was disabled. On a machine with a third-party antivirus that is by design. It becomes a problem when that product has expired, because Microsoft documents Defender re-enabling itself in that case, so a machine still showing 5001 has nothing watching it.
Get-MpComputerStatus | Format-List RealTimeProtectionEnabled,AntivirusEnabled,AntispywareEnabled,AMRunningMode,AntivirusSignatureLastUpdated
- Open Windows Security, go to Virus & threat protection, and under Who’s protecting me? choose Manage providers. The Security providers page names the product Windows currently treats as your antivirus.
- Open that product and read its subscription status and expiry date. That single fact decides everything below.
- If it has expired, decide now: renew it, or uninstall it with the vendor’s own removal tool so Defender can take the registration back.
- Restart, then check the Security providers page again and confirm exactly one antivirus is listed and it is current.
Do not try to run both. While another product holds the registration, Defender will keep standing down, and two products competing for the same file operations is the state you are trying to leave.
If exactly one current product is registered and real-time protection is on, you are done. If Defender is still off with nothing valid in front of it, the next section explains why that is not the documented behaviour.
Why it happens
Windows keeps a register of installed security products. When a non-Microsoft antivirus is installed as the primary product, Microsoft documents that Defender goes into disabled mode on Windows 10 and 11, so two engines are not competing for every file operation. Event 5001 is the record of that: real-time protection is disabled. Events 5010 and 5012 sit beside it and name what went with it, scanning for malware and other potentially unwanted software, and scanning for viruses.
Passive mode is a different thing and it is worth not confusing the two, because Microsoft describes both. Its compatibility guidance says Defender enters disabled mode on Windows client when a non-Microsoft product is installed as the primary antivirus; its passive-mode guidance describes Defender entering passive mode automatically, and lists onboarding to Microsoft Defender for Endpoint as a prerequisite for passive mode. On an unmanaged PC running a consumer suite, disabled is the one you have, so there is no second engine quietly scanning underneath. Get-MpComputerStatus | select AMRunningMode settles it: Normal, Passive or EDR Block Mode.
The part most articles get backwards is what expiry does. Microsoft’s published behaviour is that Defender can be re-enabled automatically if the non-Microsoft product expires, is uninstalled, or otherwise stops providing real-time protection. Expiry is supposed to be the trigger that brings Defender back. So a machine that still shows 5001 weeks after a suite lapsed is not following the documented path, and the question to ask is what is still telling Windows the machine is covered.
There are only a few answers to that question. The expired product is still registered and still reporting itself as protecting. A product that was removed left its registration behind. Or Defender is being held off by policy that was applied while the other product was in charge. Event 5101 is a fourth and separate case: it records that the antimalware platform is expired, which is Defender’s own state rather than anything to do with the other product.
The expired suite is still registered and still reporting itself as active
You have this one if The product nags about renewal, its expiry date has passed, and the Security providers page still names it as your antivirus.
- Decide which product is protecting this machine before you change anything. Half-finished removals are what produce this state.
- Keeping it: apply a current licence, restart, and confirm the product reports a future expiry date.
- Not keeping it: uninstall from Settings, Apps, then run the vendor’s own removal tool to clear the registration.
- Restart and confirm the Security providers page lists one current antivirus.
A removed product left its registration behind
You have this one if The Security providers page lists something that no longer appears in Settings, Apps at all.
- Download the removal tool from that vendor’s own support pages. A standard uninstall often leaves the registration.
- Run it, restart, and check the Security providers page again.
- Confirm with
Get-MpComputerStatusthat RealTimeProtectionEnabled is now True. - Run a full scan afterwards, because the machine may have been unprotected for some time.
Policy is holding Defender off
You have this one if The other product is gone and its registration is clear, and Defender still refuses to enable real-time protection.
- Check whether the settings show as managed in Windows Security.
- Produce a policy report with
gpresult /h %userprofile%\Desktop\gp.htmland read the Microsoft Defender Antivirus policies in it. - On a managed machine, take this to whoever owns the policy rather than editing locally.
- Restart and confirm the setting holds rather than reverting at the next policy refresh.
Defender’s own platform is expired
You have this one if Event 5101 in the Defender log, or a machine that has been switched off or offline for months.
- Connect the machine and let Windows Update run to completion, including Defender platform updates.
- Force security intelligence with
Update-MpSignaturein elevated PowerShell. - Restart and confirm real-time protection reports itself enabled.
- Run a full scan before trusting the machine with anything sensitive.
5101 is Defender reporting its own state. It has nothing to do with anyone else’s subscription, and no licence purchase changes it.
Full reference
What each entry in this family records
| Event | What Microsoft publishes |
|---|---|
| 5000 | Real-time protection is enabled |
| 5001 | Real-time protection is disabled |
| 5004 | The real-time protection configuration changed |
| 5010 | Scanning for malware and other potentially unwanted software is disabled |
| 5012 | Scanning for viruses is disabled |
| 5100 | The antimalware platform expires soon |
| 5101 | The antimalware platform is expired |
Read them as a sequence rather than one at a time. A 5001 with 5010 and 5012 immediately after it is a handover: something took the registration and Defender stepped aside cleanly. A 5001 on its own, with no third-party product installed, is a configuration or policy change and belongs in a different investigation.
Working out where you actually stand
| What you find | What it means |
|---|---|
| A third-party product listed, subscription current | Working as designed. Defender is meant to be off |
| A third-party product listed, subscription expired | The dangerous case: registered but not protecting |
| A product listed that is no longer installed | A stale registration is holding the position |
| Defender listed, real-time protection still off | Policy or the service, not a subscription |
| Event 5101 in the log | Defender’s own platform is expired; this is a Windows Update job |
Checking it from the command line
The interface reports the last state it was told about. Get-MpComputerStatus reports what the service believes right now, which is the number to trust when the two disagree. RealTimeProtectionEnabled, AntivirusEnabled and AntispywareEnabled map directly onto events 5001, 5012 and 5010, and AMRunningMode tells you which mode Defender considers itself to be in.
Do not respond to this by turning the other product’s real-time protection off and leaving it installed. It keeps the registration either way, so Defender stays down, and you end up with two products that are both switched off. Remove one properly or licence one properly.
If you decide to keep the paid product
Renewing is the straightforward route when the suite is doing something Windows does not: covering phones, tablets and Macs on the same subscription, or providing a VPN, a password manager or backup. Those are the parts that actually lapse. Apply the licence to the installation that is already there rather than reinstalling, because a reinstall usually loses your exclusions and settings for nothing.
If you decide not to
Remove the product with the vendor’s own removal tool rather than through Settings alone, restart, and confirm on the Security providers page that Microsoft Defender Antivirus is turned on. Then run a full scan, because the window between the subscription ending and Defender coming back is a period nothing was watching. That route costs nothing and is a legitimate answer, provided you finish it.
When a licence is the actual fix
This is a case where a licence can genuinely be the fix, and also one where it often is not, so check which you have before spending anything. If the suite has lapsed and you want what it was giving you beyond the scanner, renew it: Arco supplies ESET Internet Security keys and will check which tier and device count matches what you actually run, including whether one multi-device licence is cheaper than several single ones. If you only ever used it as a scanner, Microsoft Defender covers that at no cost and the honest advice is to remove the expired product and let Windows take the machine back. What you must not do is leave it as it is, because a registered product that has stopped protecting is worse than no product at all.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
5001 |
Real-time protection is disabled | Microsoft Learn |
5010 |
Scanning for malware and other potentially unwanted software is disabled | Microsoft Learn |
5012 |
Scanning for viruses is disabled | Microsoft Learn |
Event ID 5101 |
The antimalware platform is expired. This is Defender’s own state, not another product’s subscription | Microsoft Learn |
Confirm the fix worked
- Windows Security, Virus & threat protection, Manage providers lists exactly one antivirus and it is current.
Get-MpComputerStatusreports RealTimeProtectionEnabled as True, or the third-party product shows a future expiry date.- No new 5001, 5010 or 5012 entries appear in the Defender operational log after a restart.
- A full scan completes and writes a result to Protection history.
- The state survives a restart rather than reverting at the next logon.
Questions people ask about this
Is Microsoft Defender enough on its own?
For a machine used sensibly it is a serious product: real-time scanning, cloud-delivered protection, a firewall and browser reputation checks, all included with Windows. A paid suite buys breadth, cross-platform cover and extra services, not a fundamentally better scanner.
Why did Windows not turn Defender back on by itself?
It usually does. Microsoft documents Defender being re-enabled automatically when the non-Microsoft product expires, is uninstalled, or stops providing real-time protection. If it has not happened, something is still telling Windows the machine is covered, or policy is holding Defender off. Those are the two things to check.
Can I turn Defender on and leave the expired suite installed?
Not reliably. While the other product holds the registration Defender keeps standing down. Choose one, and make the other one gone properly with the vendor’s removal tool.
Is Defender running in the background in passive mode?
Probably not, and you can check rather than guess: Get-MpComputerStatus | select AMRunningMode returns Normal, Passive or EDR Block Mode. Microsoft lists onboarding to Defender for Endpoint as a prerequisite for passive mode, and its compatibility guidance describes disabled mode on Windows client behind a non-Microsoft antivirus. On a home or unmanaged machine, expect disabled.
Does renewing have to go through the vendor?
No. A genuine key from a reseller activates the installed product exactly as a direct renewal does. Check it is for the same product family and region before buying.
