Microsoft Defender for Endpoint
Endpoint protection

Microsoft Defender Antivirus Compatibility

In brief

The compatibility table now separates Smart App Control from Defender Antivirus state and documents additional combinations, including hybrid mode and revised passive or disabled states with third-party antivirus. The page also updates catch-up quick scan guidance, Smart App Control wording, and Endpoint DLP links.

What Defender admins need to know

Review the revised matrix when assessing endpoint protection status and antivirus coexistence.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.service: defender-endpoint ms.subservice: ngp ms.localizationpriority: medium ms.date: 07/02/08/21/2026 ms.topic: how-to author: chrisda ms.author: chrisda

  • The version of Windows installed on an endpoint
  • Whether Microsoft Defender Antivirus is the primary antivirus/antimalware solution on the endpoint
  • Whether the endpoint is onboarded to Defender for Endpoint
  • Whether Smart App Control is enabled

The following table summarizes the state of Microsoft Defender Antivirus in several scenarios.

Antivirus/antimalware solution Onboarded to Defender for Endpoint? Smart App Control StateMicrosoft Defender Antivirus stateSmart App Control State
Microsoft Defender Antivirus Yes On, Evaluation, or OffActive modeN/A
Microsoft Defender Antivirus No Off or EvaluationActive mode
On, Evaluation, or OffMicrosoft Defender AntivirusNoOnHybrid mode
A non-Microsoft antivirus/antimalware solution YesPassive mode (automatically) or No Evaluation or OnPassive mode
A non-Microsoft antivirus/antimalware solution No Passive modeEvaluation or On
A non-Microsoft antivirus/antimalware solutionNoOff Disabled (automatically)N/A or Off