The honest version of this answer has changed twice in ten years, which is why so much of what you find is out of date.

The short version

Windows 11 comes with Microsoft Defender Antivirus turned on. It is not a trial, it is not crippled, and it does not nag you to upgrade. In the independent lab tests that the commercial vendors themselves cite - AV-TEST and AV-Comparatives - Defender consistently lands in the same protection band as the paid suites.

So the question is not “is Windows protected”. It is: what would a paid product add for you specifically?

When Defender alone is genuinely fine

  • One or two personal machines.
  • You install updates rather than deferring them for months.
  • You mostly browse, work in a browser, use Office, and play games.
  • You are not administering machines for other people.

That describes most households. If it describes yours, the money is better spent on a backup drive.

When paying for something else is a reasonable call

You manage several machines and want one console. This is the real product difference. Defender’s central management lives in Microsoft’s business tiers; if you are running six machines for a small office and want one dashboard showing which one is out of date, that is a genuine reason to buy something.

You want the bundle. Most consumer suites are no longer sold as antivirus - they are sold as a subscription containing a VPN, a password manager, identity monitoring and cloud backup. If you would otherwise buy two of those separately, the bundle can be the cheaper route. Judge it as a bundle, not as a scanner.

You are on an older or unsupported Windows. Defender’s newest protections track the current OS. On an end-of-life version you are already exposed at a level no scanner fixes, but a maintained third-party product is at least still receiving definitions.

Someone else uses the machine. Parental controls and stricter web filtering are areas where third-party products still do more than Defender’s built-in family features.

What no antivirus protects you from

This is the part the ads skip, and it is where the actual losses happen.

  • Phishing and account takeover. If you type your password into a convincing fake login page, no scanner is involved at any point. The defences are a password manager (it will not autofill on the wrong domain, which is a better phishing detector than most humans) and multi-factor authentication.
  • Ransomware that reaches your backups. If the backup drive is plugged in and writable, it gets encrypted too. See how to back up a Windows PC properly.
  • Support scams. The ones that begin with a phone call or a full-screen browser warning. There is no malware to detect - the attack is entirely on the person.
  • Unpatched software. A current browser and a current OS prevent more infections than any scanner catches.

Four things worth doing instead of buying anything

  1. Turn on Controlled Folder Access. Windows Security > Virus & threat protection > Ransomware protection. It is off by default and blocks unauthorised programs from writing to your Documents, Pictures and Desktop folders. Expect to allow one or two legitimate apps the first week.
  2. Turn on multi-factor authentication on email first. Email is the account that resets all the others, so it is the one worth protecting hardest.
  3. Use a password manager. Unique passwords everywhere plus refusal to autofill on lookalike domains.
  4. Get a backup you have restored from. Untested backups fail exactly when you need them.

How to check Defender is actually on

Open Windows Security > Virus & threat protection. You want:

  • Real-time protection: On
  • Cloud-delivered protection: On
  • Definitions dated today or yesterday

If a third-party suite is installed, Defender will show as disabled - that is expected, and you should confirm the other product is actually active and licensed rather than an expired trial. An expired trial that has switched itself off while also keeping Defender off is the genuinely dangerous state, and it is more common than infection.

So: buy or not?

If you are a household with a couple of patched machines: no. Turn on Controlled Folder Access, set up MFA and a password manager, and buy a backup drive with the money.

If you are running machines for a business, want central visibility, or genuinely want the bundled VPN and identity monitoring: buying is reasonable - just buy it for those features, which are real, rather than for detection rates, which are broadly a wash.

Questions people also ask

Is Microsoft Defender good enough on its own?

For a typical home or small-office machine that stays patched, yes. Defender is tested by the same independent labs as commercial products and scores in the same band for detection of widespread malware. It is not the weakest link on most PCs; the person clicking the link usually is.

Should I run two antivirus programs at once?

No. Two real-time scanners fight over the same files, cause noticeable slowdowns, and can each flag the other's quarantine. Windows disables Defender's real-time protection automatically when you install another suite, which is the correct behaviour, not a bug. On-demand second-opinion scanners that do not run in real time are a different thing and are fine.

Does antivirus protect against ransomware?

Partly, and not reliably enough to be your plan. Detection helps against known families, but the thing that actually saves you is a backup the ransomware could not reach. Windows also has Controlled Folder Access, which is off by default and blocks unauthorised writes to your document folders - worth switching on.

Do I need antivirus if I only browse and use email?

That is exactly where most infections start, so yes - but Defender covers it. Browsing and email are the delivery route for the majority of consumer malware, usually through a download the person approved. The defence there is caution plus a patched browser, not a more expensive scanner.

Is paid antivirus a scam?

No, but a lot of the marketing is. The scanning engines are broadly comparable; what you are usually paying for is central management, support, and a bundle of adjacent services. If you want those, it is a reasonable purchase. If you were sold it on the premise that Windows is defenceless without it, you were sold a 2010 argument.

What about Windows 10 now that support has ended?

An unpatched operating system is a bigger risk than any antivirus can offset. Third-party antivirus on an end-of-life Windows buys you a little time against known malware and nothing at all against unpatched OS vulnerabilities. Upgrading, or moving the machine off anything sensitive, is the real answer.