Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Malwarebytes vs Microsoft Defender: Do You Need Both on the Same PC?

11 min read Updated October 4, 2026 Antivirus Comparisons

Fix it now

Microsoft’s documentation settles the second half of this question: if another antivirus product is installed and working, Microsoft Defender Antivirus turns itself off. Not passive, off. So Malwarebytes with real-time protection enabled replaces Defender rather than joining it, and the pairing people describe as free and safe is Defender plus Malwarebytes used as a scanner, because scanning is what the free build does.

  1. Keep Defender and add the free Malwarebytes app if you want a second opinion at no cost. Real-Time Protection, Web Protection and Malware Protection are all paid features, so the free build cannot take the antivirus role.
  2. Buy Malwarebytes if you want its real-time layers – Web Protection, Malware Protection, Ransomware Protection and Exploit Protection on Windows – and accept that Defender stands down when you do.
  3. Skip the purchase for remote desktop defence. Malwarebytes publishes Remote Desktop Monitoring, which alerts you when remote desktop programs are found on the device, and it is in the free feature list.
  4. Skip it if you were told limited periodic scanning gives you both. Microsoft says that feature uses only a small part of Defender and cannot detect most malware or unwanted software.
  5. Do not install Malwarebytes alongside a third antivirus. Malwarebytes publishes that running it with another antivirus can cause blocking, loss of internet connectivity and system crashes.

Check which product is actually protecting the machine in Windows Security, under Virus & threat protection, where Windows names the current provider. Get-MpComputerStatus | select AMRunningMode tells you what Defender itself is doing; Microsoft documents the values as Normal, Passive and EDR Block Mode, and passive mode applies to endpoints onboarded to Defender for Endpoint rather than to a home PC.

If that answers it, you can stop. Below is why Windows behaves this way, what each product’s free and paid tiers actually contain, and when paying is the right call.

Why it happens

The version of this story most people have heard is that Windows lets a third-party antivirus take over and puts Defender into passive mode, where it can still run scheduled scans as a second opinion. That is true on a managed enterprise endpoint and wrong on a home PC, and the difference matters because the whole appeal of the pairing rests on it.

Microsoft’s compatibility documentation splits the outcomes by whether the device is onboarded to Microsoft Defender for Endpoint. On a Windows 10 or 11 device that is onboarded, a non-Microsoft antivirus puts Defender into passive mode automatically. On a device that is not onboarded – which is every ordinary home and small-office PC – the documented outcome is disabled mode. The limited periodic scanning page says the same thing in plainer words: if another antivirus product is installed and working, Microsoft Defender Antivirus turns itself off.

There is a consumer-facing consolation prize, and it is worth knowing exactly how small it is. Limited periodic scanning is a toggle in Windows Security, under Virus & threat protection, beneath the name of the non-Microsoft product, in a section called Microsoft Defender Antivirus options. Microsoft’s own description of it is that it uses only a small part of Microsoft Defender Antivirus to find threats and cannot detect most malware or unwanted software, and that Microsoft does not support the feature in enterprise settings. It is a periodic sweep, not a second engine.

You want two opinions and you do not want to pay

You have this one if A careful user, a patched machine, and a nagging worry that one scanner is not enough.

  1. Leave Defender in place and install the free Malwarebytes app. Its free features are the scanners plus Privacy Controls, Remote Desktop Monitoring, Windows Firewall Control, Scam Guard and the Digital Footprint Scan.
  2. Because Real-Time Protection is a paid feature, the free build has nothing to register as your antivirus with, so Defender stays on.
  3. Run the scanner when something feels wrong rather than on a schedule. Scheduled Scan is a paid feature too.

The machine keeps picking things up

You have this one if Software appears that nobody admits to installing, and the same PC has been cleaned more than once.

  1. This is the case for paying. Malwarebytes’ paid features are Real-Time Protection, Web Protection, Malware Protection, Scheduled Scan, and on Windows, Ransomware Protection and Exploit Protection.
  2. Accept that Defender turns itself off when you do this. Windows Security will show Malwarebytes as the provider.
  3. If you want Defender still doing something, turn on limited periodic scanning and read Microsoft’s warning about what it can and cannot find before relying on it.

Remote desktop is reachable from the internet

You have this one if You or somebody in the house opened RDP to make working from elsewhere easier, and never closed it.

  1. Close the port or put it behind a VPN. Antivirus is not the correct fix for an exposed service, and no product in this comparison changes that.
  2. Malwarebytes’ Remote Desktop Monitoring will tell you when remote desktop programs are present on the device – it is under Privacy Controls, on the Remote Desktop programs tab, and it is a free feature.
  3. Do not buy a subscription for this. Buy it for the real-time layers if you want them, and fix the exposure separately.

What is left is a straightforward question about one machine. Defender is built into Windows, updated with it, and costs nothing. Malwarebytes’ paid build adds browser-independent web filtering, behavioural ransomware protection and exploit protection for browsers and document readers. Neither of those lists is a reason to run both, because you cannot: the moment one takes the real-time role, the other stops doing it.

Full reference

What Windows actually does when a second antivirus arrives

Device What Microsoft documents happens to Defender
Windows 10 or 11, not onboarded to Defender for Endpoint Disabled mode, automatically. Microsoft: if another antivirus product is installed and working, Microsoft Defender Antivirus turns itself off
Windows 10 or 11, onboarded to Defender for Endpoint Passive mode, automatically. Files are scanned by EDR, and Defender itself does not remediate
Windows Server Passive mode must be set deliberately, with the ForceDefenderPassiveMode value under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection
Any device, checking the state Get-MpComputerStatus | select AMRunningMode returns Normal, Passive or EDR Block Mode

In passive mode Microsoft documents that scheduled scans are not run and a configured schedule is ignored, apart from catch-up quick scans and the quick scan that follows a security intelligence update. That is another reason not to treat a standing-down Defender as a working second layer.

Free against paid, in both products

Microsoft Defender Malwarebytes
Cost Included with Windows Free build, plus paid subscriptions sold by device count
Real-time engine Yes, until another product is installed and working Real-Time Protection is a paid feature
Free scanning Quick, full and custom scans Quick Scan and Custom Scan; Threat Scan and Scheduled Scan are paid
Web filtering SmartScreen, strongest inside Edge Web Protection, paid; Browser Guard extension separately
Ransomware defence Controlled folder access, which you switch on in Windows Security Ransomware Protection on Windows, paid
Exploit mitigation Exploit protection settings in Windows Security Exploit Protection on Windows, paid
Remote desktop Not part of the antivirus Remote Desktop Monitoring, free, under Privacy Controls
Other free tools Windows Firewall, SmartScreen, tamper protection Privacy Controls, Windows Firewall Control, Scam Guard, Digital Footprint Scan
Management surface Group Policy, Intune, PowerShell The local app, or a separate business console

Where each one earns its place

Defender is a serious product with the Microsoft telemetry estate behind it, tight integration with Windows, tamper protection to stop malware disabling it, and cloud-delivered detection. On a patched machine used by someone who does not install random downloads, it is a reasonable single layer at no cost. If you keep documents you cannot replace, turn on controlled folder access, because that is Defender’s ransomware defence and it waits until you ask for it.

Malwarebytes grew up as a remediation tool for the category people actually meet: adware, browser hijackers, bundled toolbars, aggressive optimiser software and the grey zone of potentially unwanted programs. It is still the tool most technicians reach for on a machine that has been thoroughly messed with, and the free build does that job without displacing anything. The subscription buys real-time layers, and it is those – not the scanner – that you are paying for.

Checking which product is live

  1. Open Windows Security and go to Virus & threat protection. Windows names the current antivirus provider there.
  2. If a non-Microsoft product is named, look beneath it for Microsoft Defender Antivirus options, which is where limited periodic scanning lives.
  3. In PowerShell, run Get-MpComputerStatus | select AMRunningMode to see what Defender itself reports.
  4. Do not assume a green tick in one product means the other is doing nothing harmful. Two real-time products fighting over the same files is exactly what Malwarebytes warns produces blocking, connectivity loss and crashes.

One machine, one decision

  • One careful adult, patched Windows, nothing exposed: Defender, with the free Malwarebytes app installed for occasional scans. This costs nothing and is the right starting point.
  • A shared family PC where software appears on its own: pay for Malwarebytes and let it take the real-time role, knowing Defender turns itself off.
  • You are cleaning up a machine right now: run the free scanner first and decide about a subscription once the machine is clean.
  • Remote desktop reachable from the internet: close it. Then decide about antivirus.
  • Several machines for a business: neither consumer choice fits well. A managed endpoint product with a central console is the right shape.

When a licence is the actual fix

A Malwarebytes subscription is the right purchase for a specific machine profile: one that keeps getting reinfected, one shared by people with different judgement about downloads, or one where you want web filtering that works outside the browser rather than only inside Edge. On that machine the free build is not enough, because scanning cleans up after the event instead of blocking the download, and Real-Time Protection, Web Protection, Malware Protection, Ransomware Protection and Exploit Protection are all on the paid side of Malwarebytes’ own feature list. Arco supplies Malwarebytes licences and can tell you whether the device count on the plan covers the household or office you have in mind. If your situation is one careful user on a patched PC, we will say so – Defender is already doing that job for nothing, and adding a paid product turns it off rather than adding to it.

Questions people ask about this

Will Malwarebytes turn Defender off without telling me?

Effectively yes, and that is Windows behaving as documented rather than a fault. Microsoft states that when another antivirus product is installed and working, Microsoft Defender Antivirus turns itself off. Windows Security will show the new product as the provider. What you cannot have on an ordinary PC is two real-time engines both live.

How do I check which engine is actually protecting me?

Open Windows Security, go to Virus & threat protection, and read the provider Windows names there. In PowerShell, Get-MpComputerStatus | select AMRunningMode reports what Defender is doing; Microsoft documents the values as Normal, Passive and EDR Block Mode. Passive is an onboarded-endpoint state, so on a home PC do not expect to see it.

Is limited periodic scanning a second opinion?

Not much of one, and Microsoft says so. Its own page states that the feature uses only a small part of Microsoft Defender Antivirus to find threats and that it cannot detect most malware or unwanted software, and that Microsoft does not support it in enterprise settings. Turn it on if you like, but do not let it change what you buy.

Is it worth paying when Defender is free?

Sometimes, and it depends entirely on the machine. For a careful user on patched Windows, Defender plus the free Malwarebytes scanner is honestly enough. Pay when the machine’s history says the user will click things, when several people share it, or when you specifically want browser-independent web filtering and behavioural ransomware protection.

Does Malwarebytes replace a firewall?

No. Its free feature list includes Windows Firewall Control, which is a way of managing the firewall Windows already has rather than a replacement for it. Leave Windows Firewall on regardless of which antivirus you run.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Best Antivirus With a VPN Included: When the Bundle Beats Buying Both Review Free vs Paid Antivirus: What the Free Tier Quietly Leaves Out Review Bitdefender Antivirus Plus vs Internet Security vs Total Security Explained Review Trend Micro Maximum vs Premium Security: Identity Cover or Just Antivirus
โ† Back to Knowledge Base