A Windows 11 device is enrolled in Microsoft Intune and is already onboarded to Microsoft Defender for Endpoint. A third-party antivirus product is then installed on it and registers itself with Windows as the active antivirus solution. Which statement correctly describes the resulting state of Microsoft Defender Antivirus on that device?
- AIt moves into passive mode, so real-time protection is handed to the third-party product while the built-in engine keeps receiving security intelligence updates, can still run on-demand scans, and reports what it sees to Defender for Endpoint. Correct
- BIt is switched off entirely by the third-party installation and stops scanning, so nothing Microsoft Defender Antivirus does can be observed until the third-party product is uninstalled from the device.
- CIt remains the active antivirus solution alongside the third-party product, so two real-time engines inspect the same file operations and the device is protected by both engines at once.
- DIt is uninstalled from the device by Windows as soon as another antivirus product registers, and it can be brought back solely by rebuilding the device or by repairing the operating system image.
Why A is correct: Correct. On a Windows client that is onboarded to Microsoft Defender for Endpoint, installing a third-party antivirus places Microsoft Defender Antivirus in passive mode rather than disabling it, which preserves updates, on-demand scanning and reporting while the third-party product owns real-time protection.
Why B is wrong: This is tempting because it describes what happens on a Windows client that has not been onboarded to Microsoft Defender for Endpoint, where the built-in engine does step aside completely. It is wrong here because onboarding changes that outcome, leaving the engine running in a reduced role rather than switched off.
Why C is wrong: This is tempting because layered protection sounds safer and administrators often assume both engines simply coexist. It is wrong because Windows recognises a single registered real-time antivirus solution, and running two real-time engines against the same file operations is not the supported design.
Why D is wrong: This is tempting because third-party security products often insist that competing agents be removed before installation. It is wrong because Microsoft Defender Antivirus is a built-in platform component that is not uninstalled when another product registers; its mode changes instead.