Clear, practical technology insights
Set Up Windows SafelyLesson 8 of 18

Use Windows Security

Windows Security brings several protection areas into one dashboard: antivirus status, firewall and network protection, app and browser controls, device security and account protection. This lesson is a guided tour of those areas and the status signals they expose. It does not diagnose an active infection; the goal is to recognize normal protection state and know where to investigate a warning.

12 min Beginner Set Up Windows SafelyReviewed 2026-07-30 00:00:00
Learning objectives

What you will learn

  • Interpret Windows Security status indicators and identify the component reporting a problem.
  • Run quick and targeted scans and review protection history.
  • Verify firewall status for the active network profile.
  • Avoid unsafe troubleshooting steps such as disabling real-time protection or excluding broad folders.
Before you start

What you need

  • A Windows 10 or Windows 11 PC.
  • Administrator approval may be required for some security changes.
  • A stable internet connection for security intelligence updates.

Read the dashboard before changing anything

Microsoft describes Windows Security as the built-in interface for Microsoft Defender Antivirus, firewall, device security and other protections. Green indicators usually mean no action is required, yellow signals a recommendation, and red indicates attention is needed.

Open each flagged area and read the exact message. A warning may concern outdated security intelligence, a disabled firewall profile, an account sign-in recommendation or a hardware feature unavailable on that PC. Do not assume every yellow icon means the computer is infected.

Windows Security dashboard with protection areas and green, yellow and red status indicators.
Open the specific protection area that reports a warning; the dashboard color alone is not the diagnosis.

Choose the smallest useful malware scan

Virus & threat protection offers scan options and protection history. A quick scan checks common locations and active threats; a full scan examines more files and can take much longer. Microsoft Defender Offline is intended for difficult threats that need scanning outside the normal Windows session.

Update security intelligence before investigating a current concern. Use a quick scan for routine checks or a targeted file/folder scan when a specific download is suspicious. A full or offline scan is appropriate when symptoms, alerts or support guidance justify the extra time and restart.

  1. 1

    Open Start, search for Windows Security and launch the app.

  2. 2

    Review the status icon for every protection area.

  3. 3

    Open Virus & threat protection and check the last scan and security intelligence status.

  4. 4

    Run a Quick scan on a routine practice PC.

  5. 5

    Open Protection history and review detected or blocked items without restoring them automatically.

  6. 6

    Return to Home and confirm whether any warning remains.

Verify the firewall on the active network profile

Firewall & network protection shows Domain, Private and Public profiles. The active profile depends on the network connection. Microsoft recommends keeping the firewall enabled even when another router or network firewall exists.

A public network profile applies more restrictive discovery behavior than a private profile. Do not switch a café, airport or hotel network to Private simply to make sharing work. If an application is blocked, allow that specific app through the firewall only when you trust it and understand why it needs inbound access; avoid turning the entire firewall off.

Verification checklist
  • Windows Security Home shows no unexplained red status.
  • Security intelligence is current or an update is in progress.
  • The active network profile has Microsoft Defender Firewall enabled.
  • No broad exclusion such as the entire Downloads or C: drive has been added.

Understand third-party antivirus and exclusions

When compatible third-party antivirus is installed, Microsoft Defender Antivirus may move into a limited or passive state. Confirm the third-party product is licensed, updating and actively protecting the PC before removing it. Two real-time antivirus engines can conflict, so do not force both into the same role without vendor guidance.

Exclusions reduce scanning and can hide malicious files. Add one only for a documented compatibility problem, use the narrowest file or folder possible and record why it exists. Remove temporary exclusions after the test. If a warning or detection involves work data, credentials or repeated reinfection, isolate the device from sensitive activity and escalate.

Hands-on practice

Perform a Windows Security baseline review

Create a dated record of protection status without changing advanced controls.

  1. 1

    Capture the Windows Security home status.

  2. 2

    Check security intelligence and run a Quick scan.

  3. 3

    Review Protection history and note any unresolved item.

  4. 4

    Confirm the active firewall profile is enabled.

  5. 5

    List any exclusions or third-party antivirus product and record why each exists.

Common mistakes to avoid

  • Disabling real-time protection to improve performance without evidence.
  • Restoring quarantined files before checking the detection and source.
  • Changing an untrusted public network to Private for convenience.
  • Adding a broad exclusion that effectively removes a large part of the disk from scanning.
Lesson recap

Key takeaways

  • Windows Security combines several independent protection areas.
  • Choose a scan based on the evidence and review its result rather than only starting it.
  • Keep firewall and real-time safeguards enabled; solve narrow compatibility issues with narrow, documented changes.

Frequently asked questions

Why is Microsoft Defender Antivirus not active?

A compatible third-party antivirus product may be registered as the active provider. Confirm that product is updating and protecting the device before changing providers.

Does a green dashboard prove the PC is malware-free?

No tool can prove absolute absence. Green means Windows Security has no current action to report. Safe updates, careful downloads, account protection and backups remain necessary.

Evidence and updates

Sources and further reading

  1. Windows Security app overviewMicrosoft Support
  2. Virus and threat protection in the Windows Security appMicrosoft Support
  3. Firewall and network protection in the Windows Security appMicrosoft Support
Finish this lesson

Ready to continue?

Mark the lesson complete so your Learning Path progress stays current on this device.