Windows Defender startup type registry value is Manual instead of Disabled after installing Symantec Endpoint Protection


Article ID: 158056


Updated On:


Endpoint Protection


After installing Symantec Endpoint Protection 12.1.3 (SEP 12.1 RU3), the Windows Defender service startup type is set to Manual. With previous versions of SEP, the service startup type was set to Disabled.


This behavior is as designed. A Windows 8 update prevents any direct changes to the registry key that controls the Windows Defender service startup type. In response to this change, SEP 12.1 RU3 instead changes only the value HKEY_LOCAL_MACHINE\Software\Microsoft\Windefend\DisableAntiSpyware to to Disabled (0x0). Windows Defender then automatically changes its own startup type to Manual (0x3).