What Tamper Protection actually stops
It is not a general lock on Defender's settings. Knowing precisely what it covers explains several confusing failures — including why some cleanup tasks simply will not work.
Tamper Protection is one of the most useful things Microsoft has shipped for endpoint security, and one of the most commonly misunderstood.
It is worth knowing exactly what it covers, because the boundary explains a set of failures that otherwise look like permission bugs.
The problem it solves
The first thing capable malware does on a Windows machine is disable the defences. Historically this was easy: set a registry value, stop a service, add an exclusion. All of it scriptable, all of it doable by anything running with administrator rights.
That is the flaw Tamper Protection addresses. With it enabled, Defender's critical settings can only be changed through authorised channels — the Windows Security interface, or a properly enrolled management platform. Administrator rights are no longer sufficient.
Specifically, it blocks changes to real-time protection, cloud-delivered protection, IOAV, behaviour monitoring, and the ability to remove security intelligence updates. It also protects Defender's own files and folders from modification.
What it does not do
It is not a general lock on everything Defender-adjacent. Firewall rules, most ASR configuration, exclusions added through supported channels, and scan scheduling remain manageable.
It also does not stop you reading anything. Every diagnostic in this article works normally with it enabled.
The failures it explains
Once you know Defender's own folders are protected, several puzzling behaviours resolve at once.
Clearing protection history does not work. The detection history lives under C:\ProgramData\Microsoft\Windows Defender\Scans\History. With Tamper Protection on, deleting those files fails — even from an elevated prompt, even though Administrators appear to hold full control in the folder's ACL. The permissions are real; the protection sits above them.
This surprises people because the failure is quiet. Delete the files, get no error, list the directory, and they are still there.
Stopping the Defender service fails. WinDefend runs as a protected process. It cannot be stopped, and it should not be forced.
Some cleanup utilities silently do nothing. Any tool that promises to clear Defender's history is either failing quietly or asking you to disable Tamper Protection first.
Do not switch it off for cosmetic reasons
There is exactly one supported way to clear protection history: turn Tamper Protection off, delete the folder, turn it back on. It is deliberately not scriptable.
It is also a poor trade. Protection history is a log. It ages out on its own — the default retention is 15 days, controlled by ScanPurgeItemsAfterDelay — and a history full of resolved entries is a record of things that were handled, not a list of current problems.
Disabling a genuine anti-tampering control to tidy a log that will clear itself in a fortnight is a bad exchange. If the entries bother you, read them, confirm they are resolved, and leave them alone.
Confirm it is actually on
Get-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled, BehaviorMonitorEnabled
IsTamperProtected: True is what you want. On consumer machines it is enabled by default and can be toggled in Windows Security under Virus & threat protection settings. On managed machines it should be enforced centrally, where a local administrator cannot reach it.
The wider point
Tamper Protection is an example of a control designed around a realistic threat model: it assumes the attacker will have administrator rights, because by the time they are disabling your antivirus, they usually do.
That assumption is worth applying elsewhere. Any protection that a local administrator can silently switch off protects you from accidents, not from adversaries.