Windows comes with a full set of security tools already installed: antivirus, a firewall, ransomware protection, and disk encryption among them. You do not need to buy anything to use them, and for most home computers they are all the protection required. The catch is that they are spread across several different menus, a few of the most useful ones are switched off by default, and Windows will not always tell you which settings matter.
This guide walks through the settings that do the real work, in the order worth checking them. Every step includes the exact path to click. The paths are written for Windows 11, with notes where Windows 10 differs, and a full pass takes about fifteen minutes.
One reassurance before you start: nothing here will break your computer or delete your files. Every change can be reversed in the same menu where you made it, so you can adjust with confidence.
Start in the Windows Security app
Click the Start button, type Windows Security, and press Enter. You can also reach it through Settings, then Privacy & security, then Windows Security. On Windows 10 the path is Settings, then Update & Security, then Windows Security.
The app opens on a dashboard of tiles: Virus & threat protection, Account protection, Firewall & network protection, App & browser control, and a few others. A green check mark on a tile means that area is fine. A yellow or red mark means something needs attention, and clicking the tile will tell you exactly what. This dashboard is home base for almost everything in this guide.
Check that virus protection is on
Windows includes its own antivirus, called Microsoft Defender, and it runs quietly in the background unless another program replaces it. In Windows Security, open Virus & threat protection, then click Manage settings under the Virus & threat protection settings heading. Three toggles are worth confirming:
- Real-time protection: scans files as they arrive and programs as they run. This is the core of the antivirus and should always be on.
- Cloud-delivered protection: lets Defender check suspicious files against the newest threat information instead of waiting for the next definition update.
- Tamper Protection: stops malware, and anyone else, from silently switching Defender off. Scroll down to find it, and leave it on.
If you have installed a separate antivirus, Defender steps aside automatically, so you never need both running at once. For most people, though, the built-in protection is enough on its own, and the decision about adding anything extra comes down to how you use the machine and who else uses it.
While you are on this screen, run a scan. Click Quick scan for a fast check, or choose Scan options and run a Full scan overnight if the computer has never had one.
Turn on ransomware protection, because it is off by default
This may be the most valuable switch in the entire app, and Windows leaves it off. Still in Virus & threat protection, scroll down to Ransomware protection and click Manage ransomware protection. Turn on Controlled folder access.
Once it is on, only apps that Windows trusts can change files in your Documents, Pictures, Videos, and Desktop folders. If ransomware ever runs on your machine and tries to encrypt your files, it gets blocked at the folder door. Our guide to how ransomware works explains why this one setting earns its place.
The trade-off is an occasional false alarm. If a program you trust suddenly cannot save files, come back to this screen, click Allow an app through Controlled folder access, and add it. That takes about thirty seconds and only needs doing once per app.
Let Windows Update finish its work
Most infections do not rely on brand-new tricks. They use old holes that were patched long ago, on computers that never installed the patch. That makes Windows Update a security setting, not an annoyance.
Open Settings, then Windows Update (on Windows 10: Settings, then Update & Security). Click Check for updates, install whatever is waiting, and restart when asked. An update that has downloaded but is still waiting on a restart protects nothing.
To stop updates from interrupting you, open Advanced options on the same screen and set Active hours to the times you normally use the computer. Windows will then restart outside those hours instead of in the middle of your work. What you should not do is pause updates for weeks at a stretch. A paused computer is an unpatched computer.
Confirm the firewall is on for every network
Back in Windows Security, open Firewall & network protection. You will see three network types listed: Domain, Private, and Public. Each one should say Firewall is on. That is the whole check, and on most machines it already passes.
The thing to resist is the temptation to switch the firewall off when a game or app has connection trouble. If a program genuinely needs through, click Allow an app through firewall and approve that one program. The wall stays standing for everything else, which is exactly how it should work.
Turn on SmartScreen and unwanted app blocking
From the Windows Security dashboard, open App & browser control, then click Reputation-based protection settings. Two toggles here earn their keep:
- Check apps and files: this is SmartScreen. When you download and run a program, Windows checks its reputation first and warns you if the file is unrecognized or known to be harmful. It is the last line of defense between a bad download and a bad week.
- Potentially unwanted app blocking: catches the gray zone that plain antivirus often ignores: adware, browser hijackers, and the junk programs that ride along inside free software installers.
If SmartScreen ever warns you about a file you just downloaded, take the warning seriously. Legitimate software from an established vendor almost never triggers it.
Tighten how you sign in
Open Settings, then Accounts, then Sign-in options. Set up a Windows Hello PIN if you have not already, and add fingerprint or face sign-in if your hardware supports it. A PIN sounds weaker than a password, but it is stored only on that one device and never travels over the internet, so it cannot be phished from you or leaked from a server.
On the same screen, find the option that asks when Windows should require you to sign in again after you have been away, and set it to When PC wakes up from sleep. Without it, anyone who opens your laptop lid is in.
Your Microsoft account password still matters, because it protects your email, your cloud files, and account recovery for the PC itself. Make it long, make it unique, and check it against known leaks with a password breach checker if you have any doubt.
Finally, check whether your disk is encrypted. Open Settings, then Privacy & security, and look for Device encryption. If the toggle is there, turn it on. Encryption means a thief who steals the laptop gets a locked box instead of your tax returns. On some editions of Windows the feature is called BitLocker instead, and you can find it by typing BitLocker into the Start menu.
A fifteen-minute first pass
Here is the whole walkthrough as a checklist. Work through it top to bottom and you will have covered more ground than most people ever do.
- Open Windows Security and clear any yellow or red warnings on the dashboard.
- In Virus & threat protection, confirm Real-time protection, Cloud-delivered protection, and Tamper Protection are on, then run a Quick scan.
- Turn on Controlled folder access under Ransomware protection.
- Run Windows Update, restart when asked, and set your Active hours.
- Confirm the firewall shows on for Domain, Private, and Public networks.
- In App & browser control, turn on Check apps and files and Potentially unwanted app blocking.
- Set a Windows Hello PIN, require sign-in when the PC wakes, and turn on Device encryption if it is offered.
Repeat the pass every few months, and after any major Windows upgrade, since large updates occasionally reset a setting or add a new one worth knowing about. Fifteen minutes a season is a fair price for a computer that mostly defends itself.