Fix it now
Windows Security is a full antivirus, included with the licence you already hold, and for a patched Windows 11 PC with a careful owner it is a defensible answer rather than a compromise. What it does not do is reach devices that are not Windows, filter traffic in browsers other than Edge, or tell anybody but the person at the keyboard when something happens.
- Buy nothing if you run one Windows 11 PC, keep it patched, work in a standard account and have a backup. Turn on controlled folder access instead: Windows Security, then Virus & threat protection, then Ransomware protection, then Manage ransomware protection.
- Buy a multi-device suite if you are covering a household or a small office across Windows, macOS and Android and want one subscription and one renewal date.
- Buy a suite if you want site and download reputation applied outside Microsoft Edge. Microsoft documents SmartScreen evaluating sites and downloads when Edge is the browser, not in Chrome or Firefox.
- Buy business protection with a console, not consumer antivirus, as soon as somebody other than the user is accountable for the machines. You are paying for alerting and reporting, not a better scanner.
- Know what you give up. Controlled folder access requires Microsoft Defender Antivirus to be the primary antivirus in active mode with real-time protection on, so installing a suite switches it off.
- Spend on a tested backup and on multi-factor authentication before spending on a scanner. Neither is an antivirus decision and both remove more risk.
If the machine is still on Windows 10, the consumer Extended Security Updates programme runs to 12 October 2027 and there are two no-cost routes into it – syncing your PC settings, or redeeming 1,000 Microsoft Rewards points – for Windows 10 version 22H2 Home, Pro, Pro Education and Workstations.
One patched PC, one careful adult, backups running: the answer is that you already have antivirus and can keep your money. Below is exactly what the built-in product covers, where it is genuinely weaker, and what paying does not fix.
Why it happens
Windows Security is more than a scanner, and it is worth knowing what is already switched on. Virus and threat protection provides on-access scanning with cloud lookups. App and browser control holds reputation-based protection: Check apps and files, SmartScreen for Microsoft Edge, phishing protection, potentially unwanted app blocking and SmartScreen for Microsoft Store apps. Firewall and network protection wraps the Windows firewall. Device security exposes core isolation and memory integrity. All of it is covered by the Windows licence you already hold, and definitions arrive through the normal update channel.
Controlled folder access is the one genuinely strong anti-ransomware control in that list, and it is the one people do not use. It stops untrusted applications writing to folders you nominate. Microsoft’s own instructions for reaching it begin with the assumption that it is off: open Windows Security, go to Virus & threat protection, then under Ransomware protection select Manage ransomware protection, and if controlled folder access is turned off, you need to turn it on. It requires Microsoft Defender Antivirus to be the primary antivirus in active mode with real-time protection enabled.
That last requirement is the sentence that changes the buying advice, because it is a genuine cost of switching. Install a paid suite and Microsoft Defender Antivirus goes into disabled mode automatically on Windows 10 and 11 – which means controlled folder access stops working. If ransomware was the reason you were buying, check that the replacement has an equivalent folder-level control rather than assuming a longer feature list covers it.
One Windows PC, one careful adult
You have this one if A single machine, current updates, a standard user account, and files backed up somewhere other than that machine.
- Stay with Windows Security. Switch controlled folder access on, confirm the firewall is on, and leave it alone.
- Expect a noisy first week from controlled folder access while legitimate applications ask for permission, and work through the prompts rather than switching it off.
- Spend the money you did not spend on a second copy of your data, held somewhere the machine cannot reach.
A household with phones, tablets and a Mac
You have this one if Three Android phones, an iPad and a MacBook alongside the Windows PC.
- This is the honest case for a paid suite: the built-in product covers none of those devices, and one subscription with one renewal date is a real convenience rather than a marketing claim.
- Check the vendor’s own device counts before buying. Bitdefender, for example, sells Total Security as an individual licence for 5 devices and a family licence for 25, covering Windows, Mac, Android and iOS.
- Buy the device count you need rather than the one that rounds up neatly, and reclaim seats when a device is retired.
Somebody else is accountable for the machines
You have this one if A small office where an owner, an office manager or a provider answers for ten laptops they cannot see.
- Move to business protection with a console rather than buying ten consumer licences. The console is the product; the scanner is the same class of engine either way.
- Endpoint protection with central reporting is included in Microsoft 365 Business Premium, which is why consumer antivirus in a company is usually the wrong shape rather than merely the wrong price.
- Whatever you choose, confirm how an alert reaches a human outside working hours before you sign.
Browsers other than Edge, and mail in a desktop client
You have this one if Chrome or Firefox as the daily browser, or Outlook and Thunderbird pulling mail down locally.
- Microsoft documents SmartScreen evaluating websites and downloads when Microsoft Edge is the browser. Other browsers rely on their own reputation services.
- A suite that inspects traffic gives the other browsers a comparable check, which is a real difference rather than a feature-list one.
- Weigh it against what you lose: with Defender Antivirus disabled, controlled folder access goes with it.
Full reference
The comparison on the points that actually decide it
| What you are comparing | Windows Security, built in | A paid consumer suite | Business protection with a console |
|---|---|---|---|
| Cost | Included in the Windows licence | Per household or per device, annually | Per user or per device, often bundled with a productivity plan |
| Ransomware folder protection | Controlled folder access, needs Defender active | Vendor’s own control; check it exists | Policy-driven and centrally enforced |
| Site and download reputation | SmartScreen, documented for Microsoft Edge | Applied to traffic in any browser | At the endpoint and usually at the mail gateway too |
| Devices that are not Windows | Not covered | One subscription across Windows, Mac, Android and iOS | Covered, with enrolment and policy |
| Central console and alerting | None | An account page, not a console | Incidents, alerts and reports an administrator reads |
| Who finds out about a detection | The person at that machine | The person at that machine | An administrator, wherever they are |
| Bundled extras | None | Usually VPN, password manager, tune-up tools | Rarely; bought separately |
Where the free option is genuinely weaker
Reach is the honest weakness. If the household has three Android phones and a MacBook, the built-in product covers none of them, and buying one subscription that does is a sensible purchase. Browser coverage is the second: Microsoft documents SmartScreen evaluating sites and downloads in Microsoft Edge, and third-party browsers use their own reputation services, which are not always as aggressive.
Visibility is the third and the most important one in a business. If you are responsible for ten machines that are not in front of you, the built-in product tells the user and nobody else. That is the strongest argument for moving a small company onto something with a console, and it has nothing to do with detection quality.
Be sceptical of the bundled extras. The VPN, password manager and tune-up tools inside a security suite are usually the weakest versions of those products, and they are the components most often used to justify a higher tier. If you want a good password manager, buy a password manager.
What paying changes, and what it does not
The failures that cost households and small companies real money are stolen credentials, a reused password, an unpatched browser, and an email persuading somebody to pay a fraudulent invoice. No scanner addresses any of those. Multi-factor authentication on the mail account and a backup you have actually restored from remove more risk than any change of engine, and both are free or nearly so.
There is one genuine safety net worth knowing about in the other direction. Microsoft documents that where Defender Antivirus has been disabled automatically because a non-Microsoft product was installed, it is re-enabled automatically if that product expires, is uninstalled, or otherwise stops providing real-time protection. A lapsed subscription therefore leaves the machine scanned rather than naked – but with stale expectations, so check which engine is active after any lapse.
If the machine is still on Windows 10
This changes the question, because the operating system rather than the antivirus is the exposure. Windows 10 reached end of support on 14 October 2025. Consumer Extended Security Updates run to 12 October 2027, and Microsoft publishes three enrolment routes for Windows 10 version 22H2 Home, Pro, Pro Education and Workstations editions: syncing your PC settings, redeeming 1,000 Microsoft Rewards points, or a one-off purchase. Two of those three cost nothing, and enrolment is open until the programme ends.
For organisations the commercial ESU programme runs for a maximum of three years after end of support. Either way, ESU is a bridge with a published end date rather than a plan, and buying antivirus for an unpatched operating system is treating the wrong layer.
Checking your own machine before you buy
Three things are worth confirming, and none costs anything. Open Windows Security and check that virus and threat protection reports as on and that no third-party product has taken over unexpectedly. Under Virus & threat protection, follow Ransomware protection to Manage ransomware protection and turn controlled folder access on. Under App & browser control, check that reputation-based protection is enabled. If all three are healthy and your files are backed up somewhere the machine cannot reach, you have a defensible position and the purchase is optional rather than overdue.
When a licence is the actual fix
If cross-platform coverage is the actual requirement, a multi-device suite is a reasonable purchase: several devices across several operating systems under one subscription and one renewal date, which is exactly what the built-in product cannot do. Bitdefender Total Security is one of the products built for that job, sold as an individual licence covering five devices and a family licence covering twenty-five, across Windows, Mac, Android and iOS. Arco supplies it and will work out the device count you genuinely need rather than the one that rounds up neatly. If you tell us you have a single patched Windows 11 PC, a current browser and a backup, we will tell you that Windows Security is doing a reasonable job and that you should keep your money.
Questions people ask about this
Is Microsoft Defender good enough on its own?
For a patched Windows 11 machine used by somebody who does not run unknown executables, yes. It is a full antivirus with cloud-assisted detection, not a stub, and it includes controlled folder access as a real anti-ransomware control. It is weaker on devices that are not Windows, on browsers other than Edge, and wherever an administrator needs to see what happened on somebody else’s machine.
Do I need to turn Windows Security off before installing something else?
No, and you should not try. On Windows 10 and Windows 11, Microsoft Defender Antivirus goes into disabled mode automatically when a non-Microsoft antivirus is installed. It is also re-enabled automatically if that product expires, is uninstalled, or otherwise stops providing real-time protection, which is a useful safety net at renewal time.
What do I lose by installing a paid suite?
Controlled folder access, unless the suite provides an equivalent. Microsoft requires Defender Antivirus to be the primary antivirus in active mode with real-time protection enabled for controlled folder access to run, so once another engine takes over that control stops. If ransomware protection is why you are buying, confirm what replaces it before you switch.
Will installing a suite slow my PC down?
On current hardware you are unlikely to notice it during normal work, though you will notice the first full scan. On an older laptop with a mechanical disk the extra background services are noticeable, which is true of every product in this class, including the built-in one during a scheduled scan.
What is the cheapest honest option?
Nothing at all, because Windows Security is included in the licence you already hold, and controlled folder access, the firewall and reputation-based protection cost nothing to switch on. Paid suites are normally sold on a discounted first term with automatic renewal on by default, so ask for the standing renewal terms before buying and reclaim device seats you have stopped using.
My PC is still on Windows 10. Does antivirus fix that?
No. Windows 10 reached end of support on 14 October 2025, and the exposure is the operating system rather than the scanner. Consumer Extended Security Updates run to 12 October 2027 for Windows 10 version 22H2 Home, Pro, Pro Education and Workstations, and two of the three enrolment routes – syncing your PC settings, or redeeming 1,000 Microsoft Rewards points – cost nothing.
