logo
search
Security Policy Errors

How to Fix Microsoft Defender for Endpoint Not Entering Passive Mode

Rana GarciaRana Garcia Sep 28, 2026 869 views

Question details

The user needs to successfully configure Microsoft Defender for Endpoint into passive mode after manual registry edits fail to apply.

How to Fix Microsoft Defender for Endpoint Not Entering Passive Mode
Product
Microsoft Defender for Endpoint
Device & OS
Windows
Scenario
Configuring endpoint security settings to run alongside a third-party antivirus solution.
Observed behavior
Microsoft Defender ignores the ForceDefenderPassiveMode=1 registry value and continues actively blocking threats instead of running in passive mode.
Before you start

Ensure you have full administrative privileges on the Windows endpoint and that your primary third-party antivirus software is correctly installed and running.

Solution 1Recommended

Disable Tamper Protection and Check Group Policies

Tamper Protection and Group Policy settings often override local registry changes, preventing passive mode from activating.

Tamper protection locks down Microsoft Defender to prevent unauthorized configuration changes. If it remains active, any modifications to the ForceDefenderPassiveMode registry key will be ignored.

1
Disable Tamper Protection

Open the Windows Security app, go to 'Virus & threat protection', click 'Manage settings', and toggle 'Tamper Protection' to Off.

2
Apply the Registry Value

Open the Registry Editor (regedit) and ensure the ForceDefenderPassiveMode value is set to 1 under the appropriate Defender registry path.

3
Verify Group Policy Settings

Open the Group Policy Editor (gpedit.msc) and navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus to ensure no policies are forcing active mode.

4
Restart the Endpoint

Restart your Windows device to ensure all security policies and registry modifications are applied correctly.

Disable Tamper Protection and Check Group Policies
Centralized Management: If your device is managed by an organization, you may not be able to disable Tamper Protection locally. It must be turned off via the Microsoft Intune or Microsoft 365 Defender admin center.
Free Microsoft Office alternative

Looking for a Secure and Reliable Office Suite? Try WPS Office

While managing your Windows security policies and endpoint configurations, you might also need a lightweight, cost-effective office suite. WPS Office provides a free, highly compatible alternative to Microsoft Office that is designed to run smoothly alongside any endpoint security solution.

  1. 1. Download the Installer: Visit the official WPS Office website and download the free installer for Windows.
  2. 2. Install the Software: Run the setup file and follow the lightweight installation process.
  3. 3. Open Your Documents: Launch WPS Office to instantly open, edit, and save your existing Microsoft Office files with perfect formatting.
Highly compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx).Lightweight installation that doesn't conflict with advanced endpoint security solutions.Familiar user interface for a seamless migration with zero learning curve.Built-in document encryption to keep your sensitive business files secure.
microsoft office alternative - wps office

Frequently Asked Questions

What is Microsoft Defender for Endpoint Passive Mode?

In passive mode, Microsoft Defender Antivirus still scans files and reports detections, but it does not actively remediate or block threats. This mode is typically used when a non-Microsoft antivirus product is deployed as the primary endpoint protection.

Why is Tamper Protection blocking my registry changes?

Tamper Protection is a built-in security feature designed to prevent malicious software or unauthorized users from altering critical security settings. It must be intentionally disabled before manual changes to the ForceDefenderPassiveMode registry key can take effect.

How can I check if my third-party antivirus is recognized by Windows?

Open the Windows Security app, navigate to 'Settings' (the gear icon at the bottom left), and select 'Security providers'. Under the Antivirus section, your third-party security software should be listed as turned on and functioning.