For most people on Windows 11, the right antivirus is the one already running: Microsoft Defender Antivirus in Windows Security, with real-time, cloud-delivered and tamper protection switched on. Pay for a suite only for extras you will use, pick it from recent independent lab results, and run one real-time scanner, never two.
This guide covers what Windows already does and how to check it, what a paid suite really adds, how to read the AV-TEST, AV-Comparatives and SE Labs reports without being misled by small differences, the red flags (scareware, free products that sold browsing data, the US ban on Kaspersky), what Macs and phones rely on instead, and when a small business should move from antivirus to endpoint detection and response (EDR). If you are setting up a new PC, start with our guide to setting up Windows 11.
Do you need antivirus on Windows 11?
You need antivirus protection, and on Windows 11 you already have it. The Windows Security app is part of Windows and protects the PC from its first start. It brings together Microsoft Defender Antivirus, the Windows Firewall and Smart App Control. Defender Antivirus is included at no extra cost, and it watches for the everyday threats: viruses, ransomware, and spyware such as the keyloggers described in our guide to snooping attacks.
The protection is several features, not one scanner:
| Feature | What it does | Where to find it in Windows Security |
|---|---|---|
| Real-time protection | Scans files and programs as they are opened, downloaded or run | Virus & threat protection > Manage settings |
| Cloud-delivered protection | Asks Microsoft's cloud about files Defender has not seen before; on by default | Virus & threat protection > Manage settings |
| Tamper protection | Stops other apps from switching Defender's settings off | Virus & threat protection > Manage settings |
| Controlled folder access | Lets only trusted apps change files in protected folders; off by default | Virus & threat protection > Ransomware protection |
| Microsoft Defender SmartScreen | Warns about reported phishing and malware sites, and about downloads that are not well known | App & browser control > Reputation-based protection |
| Potentially unwanted app (PUA) blocking | Blocks apps that are not strictly malware but show ads, mine cryptocurrency or do other things you did not ask for | App & browser control > Reputation-based protection |
| Smart App Control | Blocks malicious or untrusted apps; apps that Microsoft's cloud model trusts, or that carry a valid signature, run | App & browser control |
Cloud-delivered protection is the part that matters most against new malware. When Defender meets a suspicious file it has not seen before, such as a program just downloaded from the internet, it sends a query about the file, including its hash, to Microsoft's cloud protection service. If the service cannot decide at once, Defender locks the file and uploads a copy for deeper analysis, then the file is either allowed to run or blocked in all future encounters. Microsoft calls this block at first sight, and says that in many cases it cuts the response to new malware from hours to seconds. It only works while cloud-delivered protection is on.

How good is the free, built-in product? Independent labs test it alongside paid suites. In AV-TEST's June 2026 round of Windows 11 home products, tested in May and June, Microsoft Defender Antivirus scored 6 of 6 for protection, 5.5 for performance and 6 for usability: 17.5 of a possible 18. In AV-Comparatives' Real-World Protection Test for February to May 2026, it blocked 396 of 400 test cases, placing it in the top results cluster, with no false alarms. SE Labs gave it a total accuracy rating of 98% in its April to June 2026 home report. This guide does not rank products, and those results do not make Defender the best choice for everyone. They do mean that good detection does not require a subscription.
Important
Antivirus does not replace security updates. Windows 10 reached end of support on October 14, 2025, and Microsoft warns that a PC without security updates is at greater risk from viruses and malware. Antivirus cannot close the flaws that patches fix. Upgrade to Windows 11, enrol in consumer Extended Security Updates (available until October 12, 2027) or replace the PC; our guide to updating your computer or phone covers each route.
Check the protection Windows already gives you
A few minutes in Windows Security tells you whether the built-in protection is actually on. Open it from the Start menu (type Security), then:
- See who is protecting the PC. Select Virus & threat protection, then under Who's protecting me? choose Manage providers. If another antivirus is listed as the active one, Defender Antivirus is standing aside (see the red flags below).
- Check the core switches. Under Virus & threat protection settings, select Manage settings and confirm that Real-time protection, Cloud-delivered protection, Automatic sample submission and Tamper protection are on. With tamper protection on, other apps cannot change these settings; as an administrator you still can, here.
- Update the definitions. Select Protection updates > Check for updates. Windows also downloads this security intelligence through Windows Update.
- Turn on ransomware protection. Select Manage ransomware protection and switch on Controlled folder access.
- Check reputation-based protection. In App & browser control > Reputation-based protection, keep SmartScreen and potentially unwanted app blocking on, and look at the state of Smart App Control.
To check the same things from PowerShell, for example on several PCs, run:
Get-MpComputerStatus | Select-Object AMRunningMode, IsTamperProtected, RealTimeProtectionEnabled
AMRunningMode reads Normal when Defender Antivirus is the active antivirus, and True in the other two columns means tamper protection and real-time protection are on.
Controlled folder access deserves the extra step because it is off by default. Once on, it lets only trusted apps change files in protected folders: Documents, Pictures, Videos, Music and Desktop by default, plus any folder you add. Defender decides which apps to trust from their prevalence and reputation. When an unknown app, such as ransomware, tries to encrypt or delete files there, the change is blocked and you get a notification.

If it blocks a program you use, allow that one app rather than switching the feature off, and allow as few as you can: an allowed app that is later compromised can change those folders too. Two limits are worth knowing. Controlled folder access works only while Defender Antivirus is the active antivirus with real-time protection on, and it is not a backup. The ransomware page in Windows Security can connect OneDrive so that files can be restored after an attack; keep a backup either way.
What a paid antivirus suite actually adds
Mostly features around the antivirus, rather than a better antivirus. Detection engines are shared more widely than brand names suggest. AV-Comparatives notes that G Data, Total Defense and VIPRE use the Bitdefender engine, that F-Secure, Fortect and TotalAV use the Avira engine, and that AVG and Norton use the Avast engine. In its February to May 2026 Real-World Protection Test, Avast One Free Antivirus, AVG AntiVirus Free and the paid Norton Antivirus Plus each blocked 397 of 400 test cases: the same result, free or paid.
What the money buys is the rest of the box. The product reviews in AV-Comparatives' Summary Report 2025 describe extras such as VPNs, password managers, dark web scanners, identity protection, cloud backup, parental controls and firewalls. A suite is worth it when you would otherwise pay for those separately:
| Extra | Worth paying for when |
|---|---|
| Licence for several devices | You want one subscription across PCs, Macs and phones. Many vendors sell licences for five devices that can be mixed across Windows, macOS and Android. |
| VPN | You often use public Wi-Fi and have no VPN already. Check the data allowance: when AV-Comparatives reviewed Avira Free Security for 2025, its VPN was limited to 1 GB a month. |
| Password manager | Nobody in the household uses one yet. |
| Identity or dark web monitoring | You want alerts when your email address or personal details appear in leaked data. |
| Parental controls | You need content filters and time limits on children's devices. |
| Cloud backup | You have no other backup. A backup is the real recovery plan for ransomware, whichever product you run. |
If you already pay for Microsoft 365 Personal or Family, the subscription includes the Microsoft Defender app for Windows, Mac, iOS and Android, which may cover the multi-device need on its own.
Check the price you will pay in year two. AV-Comparatives found that most vendors apply auto-renewal when you buy from their website, that the majority make it mandatory, and that the renewal price can be much higher than the first-year discount. Its advice is to judge protection, performance and ease of use first, and price last.
One trade-off is easy to miss. On a home PC, installing a third-party antivirus puts Defender Antivirus into disabled mode automatically (or passive mode, if Smart App Control is on or in evaluation). With it go Defender's real-time and cloud-delivered protection, controlled folder access and potentially unwanted app blocking. The suite then has to cover ransomware and unwanted apps by itself, so check that it does.
How to read independent antivirus tests
Three labs publish regular, detailed tests of Windows antivirus for home users. Each measures slightly different things, so read at least two. As of September 2026, the latest reports are:
| Lab | Latest home-user reports | What it measures | How it scores |
|---|---|---|---|
| AV-TEST | Windows 11, June 2026 round (tested May and June 2026, 16 products) | Protection against zero-day attacks and widespread malware; slowdown when opening websites, downloading, launching and installing apps and copying files; false warnings and blocks | Up to 6 points each for protection, performance and usability, 18 in all; 10 points earns the seal of approval, 17.5 the TOP PRODUCT award |
| AV-Comparatives | Real-World Protection Test, February to May 2026 (released June 15, 2026, 400 test cases); Malware Protection Test, March 2026 (released April 15, 2026, 10,000 test cases); Performance Test, April 2026 (released April 22, 2026) | Attacks arriving from the web; malware arriving by USB drive, network drive or already on disk; system impact on a low-end PC; false alarms in each protection test | Awards by statistical results cluster; products with above-average false positives are downgraded |
| SE Labs | Home Anti-Malware, April to June 2026 (report written July 27, 2026) | Targeted attacks built from well-established techniques, plus public email and web threats; how legitimate software is handled | Protection accuracy and legitimate accuracy combined into a total accuracy rating |
AV-Comparatives also published a factsheet for July and August 2026 on September 11, 2026; the lab releases its full Real-World reports, with a false-alarm test and awards, in June and November. To read any of these without being misled:
- Read protection and false positives together. A false positive is a clean file or website wrongly blocked. A product that blocked everything would top a protection chart and be unusable, which is why AV-TEST scores usability (in the June 2026 round, its usability test included a system scan of 1,223,746 legitimate files), AV-Comparatives downgrades awards for above-average false alarms, and SE Labs folds legitimate software into its total rating.
- Treat small gaps as ties. AV-Comparatives groups results statistically and considers every product in a cluster equally effective, provided its false positives are below average. With 400 test cases, one missed test case moves a product by 0.25 percentage points.
- Look at more than one round and more than one lab. AV-Comparatives itself advises against buying on the strength of one test, or one type of test, and suggests trying the product before paying.
- Match the edition. Labs test named editions and versions, free or paid, and AV-Comparatives says its performance results apply only to the exact versions it lists. A vendor's free product and its top suite can share an engine and still differ in features.
- Weigh performance against your hardware. AV-Comparatives runs its performance test on a machine it calls low-end: an Intel Core i3 with 8 GB of RAM and an SSD. If your PC is older or modest, read that column first.
- Check the test follows a standard. The Anti-Malware Testing Standards Organization (AMTSO) publishes a testing standard. AV-TEST's 2026 Windows consumer series is confirmed compliant with AMTSO Standard v1.3, and SE Labs' report went through AMTSO certification. Treat a comparison that publishes no method as marketing.
Each report covers a window of one to four months, and products change between rounds. That is why the reports carry dates, and why this guide points to the rounds current in September 2026 instead of naming a winner.
Red flags when choosing antivirus
Pop-ups that say your PC is infected
Scareware is fake security software, or a fake warning, designed to frighten you into paying, installing something or calling a number. The FTC describes the pattern: a pop-up that looks like it comes from a well-known company says there is a problem with your computer and urges you to call; the person who answers asks for remote access, pretends to scan for viruses, then charges to remove a problem that does not exist.
The FTC's rule of thumb is short. Real security warnings never ask you to call a phone number, and legitimate tech companies do not contact you by phone, email or text to say your computer has a problem. The same scammers send fake renewal invoices that use names such as McAfee and Norton. Check your card statement, and contact the company through a number you know is real, never the one in the message. Genuine detections appear in Windows Security, not on a web page, and SmartScreen in Microsoft Edge can warn you about known tech support scam sites.
Warning
Never give remote access to someone who contacted you first about a virus, and never install "security" software that a pop-up or a caller tells you to download.
Two real-time scanners at once
Two antivirus products that both scan in real time get in each other's way, and Windows is designed to prevent it. On Windows 10 and 11 home PCs, Defender Antivirus steps aside automatically when another antivirus registers as the primary one. Microsoft warns that if the Windows Security Center service has been disabled, Defender cannot detect the other product and stays active; the two then conflict, which hurts performance and is not supported. Uninstall the old product before installing a new one, then confirm under Manage providers that exactly one antivirus is on.
Free antivirus paid for with your browsing data
A free product has to make money somewhere. In February 2024 the US Federal Trade Commission charged that Avast had collected browsing data through its antivirus software and browser extensions, kept it indefinitely and, from 2014 to 2020, sold it through its subsidiary Jumpshot to more than 100 third parties, while telling users its products would block tracking. The final order, in June 2024, required Avast to pay US$16.5 million and banned it from selling, disclosing or licensing web browsing data for advertising.
The lesson applies to any free product. Read its privacy policy, and during installation decline the data-sharing programs and browser extensions you do not need; AV-Comparatives' reviews describe installers that offer both.
Vendors your government restricts: Kaspersky in the US
In June 2024 the US Department of Commerce issued a Final Determination, published in the Federal Register on June 24, 2024, finding that Kaspersky's cybersecurity and antivirus software poses undue and unacceptable risks to US national security; among the risks it cited, the company is subject to the jurisdiction of the Russian government. According to the Bureau of Industry and Security:
- from July 20, 2024, Kaspersky could no longer enter new agreements with US persons;
- from September 29, 2024, it may not provide antivirus signature or codebase updates to US customers, or operate the Kaspersky Security Network in the US;
- from the same date, reselling Kaspersky software, or building it into other products, is prohibited in the US.
The ban is about who controls the software and its update channel, not about detection: Kaspersky Premium still appears in lab tests run outside the US, including AV-TEST's June 2026 round. For a US user, the practical point is that a copy still installed has been cut off from updates since September 29, 2024 and should be replaced; the BIS page links to CISA's removal guides. The determination covers the US and US persons, so elsewhere, check your own government's guidance.
Antivirus on a Mac, iPhone or Android phone
Mac. macOS has its own built-in antivirus, XProtect. It uses signatures that Apple updates automatically and separately from system updates (a Mac checks for them daily by default), blocks known malware and moves it to the Trash, and adds an engine that removes infections and another that looks for unknown malware by its behaviour. Before that, Gatekeeper and notarization, Apple's malware scan of apps distributed outside the App Store, are designed to stop malware from launching even once. A third-party product earns its place on a Mac when you want one suite across all your devices, or when a business needs central management and reporting.
iPhone and iPad. Every third-party app runs in a sandbox designed to stop it gathering or changing information stored by other apps. It also means a security app cannot inspect or clean other apps the way a Windows antivirus does. On an iPhone, the protection you control is installing iOS updates promptly.
Android. Phones with Google Play have Google Play Protect, which is on by default. It checks apps when you install them and scans the device periodically, including apps from outside Google Play, can send unknown apps to Google for a code-level check, and warns about, deactivates or removes harmful apps. Keep it on, be wary of apps from unknown sources, and install system updates as they arrive; our guide to updating a phone shows how, including from a computer.
When a small business needs EDR, not antivirus
Antivirus judges files on one PC, and its warnings appear to whoever is sitting at that PC. Once a business has several computers, that model breaks: nobody sees the pattern across machines, and a warning one employee dismisses is lost. Endpoint detection and response fixes both problems. Each device continuously reports behaviour (processes, network activity, sign-ins, registry and file changes) to a central console, related alerts are grouped into incidents, and an administrator can respond remotely, for example by isolating the affected device.

For small and medium businesses the usual Microsoft route is Microsoft Defender for Business, designed for organizations of up to 300 users and included in Microsoft 365 Business Premium or sold on its own. It builds on the Defender Antivirus already in Windows and adds EDR, automated investigation and remediation, and centralized management, with apps for Mac, iOS and Android devices. Its manual response actions include running an antivirus scan, isolating a device, stopping and quarantining a file, and blocking or allowing a file by indicator. Other security vendors sell business EDR as well.
The part people underestimate is the person. EDR produces alerts that someone has to read and act on, including outside office hours. Decide who that is before you buy: an internal IT lead, or a provider who watches the console for you.
Our IT support service covers endpoint security for small teams: EDR such as Microsoft Defender for Business, patching for operating systems and apps, and removing local admin rights, alongside device management. Endpoint tools protect laptops and desktops; the websites and servers you expose to the internet need a different check, which our security scanning service runs on a schedule. More guides on the subject are under security.
Which option fits your situation
| Your situation | What to do |
|---|---|
| One Windows 11 PC | Keep Microsoft Defender Antivirus, check the settings above and turn on controlled folder access |
| A household with Macs, phones and children | Consider a suite for its multi-device licence and parental controls, or the Defender app that comes with Microsoft 365 Personal and Family |
| An older or low-powered PC | Read the performance results from AV-TEST and AV-Comparatives before switching from Defender |
| Still on Windows 10 | Fix the missing updates first: Windows 11, consumer Extended Security Updates or a new PC |
| In the US with Kaspersky installed | Replace it: Kaspersky has been barred from updating it there since September 29, 2024 |
| A business with several PCs | Move to centrally managed EDR, such as Microsoft Defender for Business, with a named person responsible for the alerts |


