How to Fix Microsoft Defender for Endpoint Not Entering Passive Mode
Question details
The user needs to successfully configure Microsoft Defender for Endpoint into passive mode after manual registry edits fail to apply.

- Product
- Microsoft Defender for Endpoint
- Device & OS
- Windows
- Scenario
- Configuring endpoint security settings to run alongside a third-party antivirus solution.
- Observed behavior
- Microsoft Defender ignores the ForceDefenderPassiveMode=1 registry value and continues actively blocking threats instead of running in passive mode.
Ensure you have full administrative privileges on the Windows endpoint and that your primary third-party antivirus software is correctly installed and running.
Disable Tamper Protection and Check Group Policies
Tamper Protection and Group Policy settings often override local registry changes, preventing passive mode from activating.
Tamper protection locks down Microsoft Defender to prevent unauthorized configuration changes. If it remains active, any modifications to the ForceDefenderPassiveMode registry key will be ignored.
Open the Windows Security app, go to 'Virus & threat protection', click 'Manage settings', and toggle 'Tamper Protection' to Off.
Open the Registry Editor (regedit) and ensure the ForceDefenderPassiveMode value is set to 1 under the appropriate Defender registry path.
Open the Group Policy Editor (gpedit.msc) and navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus to ensure no policies are forcing active mode.
Restart your Windows device to ensure all security policies and registry modifications are applied correctly.

Verify Configuration via PowerShell and Update Software
Use PowerShell commands to confirm the current active state of Defender and rule out software bugs by updating the OS.
Looking for a Secure and Reliable Office Suite? Try WPS Office
While managing your Windows security policies and endpoint configurations, you might also need a lightweight, cost-effective office suite. WPS Office provides a free, highly compatible alternative to Microsoft Office that is designed to run smoothly alongside any endpoint security solution.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for Windows.
- 2. Install the Software: Run the setup file and follow the lightweight installation process.
- 3. Open Your Documents: Launch WPS Office to instantly open, edit, and save your existing Microsoft Office files with perfect formatting.

Frequently Asked Questions
What is Microsoft Defender for Endpoint Passive Mode?
In passive mode, Microsoft Defender Antivirus still scans files and reports detections, but it does not actively remediate or block threats. This mode is typically used when a non-Microsoft antivirus product is deployed as the primary endpoint protection.
Why is Tamper Protection blocking my registry changes?
Tamper Protection is a built-in security feature designed to prevent malicious software or unauthorized users from altering critical security settings. It must be intentionally disabled before manual changes to the ForceDefenderPassiveMode registry key can take effect.
How can I check if my third-party antivirus is recognized by Windows?
Open the Windows Security app, navigate to 'Settings' (the gear icon at the bottom left), and select 'Security providers'. Under the Antivirus section, your third-party security software should be listed as turned on and functioning.




