How to Exclude Files from Windows Security
Windows Security can skip a trusted file, folder, program process, or file type during Microsoft Defender scans. The setting is useful when a safe file is repeatedly flagged, but it also creates a small gap in protection. Only exclude something you trust and understand.
What a Windows Security exclusion does
An exclusion tells Microsoft Defender Antivirus not to scan a selected item in the usual way. You can point Windows Security to:
- One specific file
- A whole folder
- A process
- Every file with a certain extension
That last option is broader than it may sound. An extension exclusion can affect matching files wherever they are stored, not just in one folder.
An exclusion is also different from restoring a file that has already been blocked or removed. Adding an exclusion may help with future scans, but it doesn't automatically bring back an item that Windows Security has already quarantined or deleted. It also may not bypass every type of warning or block.
For that reason, check the file first. If you don't know where it came from or why it was flagged, leaving the protection in place is the safer choice.
How to exclude a file through Windows Security
The steps below work as the main route for how to exclude files from Windows Security on Windows 10 and Windows 11. The wording is very similar, although some page layouts can look slightly different.
1. Open Windows Security
Select the Start button and type Windows Security.
Open the Windows Security app from the search results.
2. Open Virus & threat protection
On the Windows Security home page, select Virus & threat protection.
This page contains the Microsoft Defender settings that control virus scans and related protection features.
3. Open the settings area
Find Virus & threat protection settings.
Select Manage settings underneath it. You may need to scroll down the page before you see this link.
4. Open the exclusions list
Scroll to the Exclusions section.
Select Add or remove exclusions. Windows may ask you to approve the change through a permission prompt. If it does, allow the Windows Security app to continue.
5. Choose File
Select Add an exclusion, then choose File.
A file browser will open. Browse to the file you want Microsoft Defender to leave out of its scans. Select the file, then confirm your choice.
The file should now appear in the exclusions list.
Use this option when you want to leave out one known file, such as a program file that Defender keeps flagging. If the program creates or uses several files in one location, a single-file exclusion may not cover all of them. In that case, consider whether a folder or process exclusion is actually needed—but choose the narrowest option that solves the problem.
How to exclude a folder in Windows 10 or Windows 11
If you need to exclude a group of trusted files in one location, you can add the folder instead of selecting each file separately.
This is the usual path for how to exclude folder from Windows Defender Windows 11:
- Open Windows Security from the Start menu.
- Select Virus & threat protection.
- Under Virus & threat protection settings, choose Manage settings.
- Scroll to Exclusions.
- Select Add or remove exclusions.
- Choose Add an exclusion.
- Select Folder.
- Browse to the folder, select it, and confirm.
On Windows 10, use the same general route for how to exclude files from Windows Security Windows 10. The labels are still Virus & threat protection, Manage settings, and Add or remove exclusions. The screen may look a little different depending on the Windows version and updates installed, but those are the menu names to look for.
A folder exclusion applies to the selected folder and the files stored inside it. That makes it wider than a single-file exclusion. Be careful with folders that receive downloads, email attachments, or files from other people. A trusted folder today may contain something unsafe later.
How to add or remove an exclusion later
You can return to the same page whenever you need to review the list:
Windows Security > Virus & threat protection > Virus & threat protection settings > Manage settings > Add or remove exclusions
Each exclusion appears in the list with its type and location.
To remove one, select the exclusion. Windows Security will show a Remove option. Select it, then confirm if Windows asks.
Removing an exclusion allows Microsoft Defender to scan that item again. It doesn't necessarily undo any earlier action taken on the file. If the file was already quarantined or removed, the exclusions page is not a recovery tool.
It's a good habit to check this list after troubleshooting. If you added an exclusion for a one-time installation or test, remove it once you no longer need it.
File, folder, process, and file-extension exclusions compared
The four choices solve different problems. Picking the smallest one is usually the better approach.
A single file
Choose File when one specific file is trusted but keeps causing a detection.
This gives you a narrow exclusion. It won't automatically cover other files in the same folder.
A folder
Choose Folder when several trusted files in one location need to be left out of scans.
This is easier than adding many separate files, but it covers more content. Don't use a broad folder exclusion when a single-file option is enough.
A process
Choose Process when a trusted program process is the item being scanned or flagged.
A process is a running program or background task. This option is different from excluding the program's installation folder. It may affect files handled by that process, so use it only when you understand which program you are excluding.
A file extension
Choose the file-extension option when you need to exclude files with a particular ending, such as a specific type of file.
An extension exclusion is especially broad because it can apply to matching files in different folders. It isn't limited to one saved location. Only use this choice when you have a clear reason to exclude that entire file type.
Think of the choices from narrowest to broadest: one file, one folder, a process, then a file type that may appear anywhere. That isn't a strict rule for every situation, but it helps you avoid making a larger exclusion than necessary.
How to stop Windows Security from blocking or removing a file
If you're asking how to stop Windows Security from removing files, first separate two different situations.
The file is being detected during a scan
If the file is trusted and you want to prevent future scans from flagging it, add the smallest suitable exclusion through the steps above. You might exclude the file itself, its folder, the related process, or its extension.
An exclusion is not a promise that Windows Security will ignore every warning connected to that item. The available results and the type of alert can vary. It also doesn't make an unsafe file safe.
The file has already been blocked or removed
An exclusion isn't the same as restoring a quarantined or removed file. The information available for this setting supports adding exclusions, but it does not provide a recovery process for files that Windows Security has already taken action against.
So don't add an exclusion and assume the missing file will return. Check the alert shown in Windows Security and follow the recovery choices provided there if you decide the detection was wrong. If you aren't sure, keep the file blocked and get help from someone you trust.
This boundary matters. An exclusion changes how future scans treat an item. It doesn't act as a general switch for turning off Windows Security.
What to check when an exclusion does not work
If the alert continues, go back to Add or remove exclusions and check a few basics.
Confirm the correct item was added.
A file exclusion must point to the exact file. A folder exclusion must point to the folder that actually contains the file. If a program uses files in another location, excluding the first folder may not cover those files.
Check the exclusion type.
You may have excluded a program file while Windows Security is flagging a process, a different file, or a matching file extension. Compare the alert with the item in your exclusions list.
Look for a typo or changed location.
If the file was moved, renamed, or replaced, the original exclusion may no longer match the current item.
Check whether you added too little—or too much.
A single file may not cover a whole program. A file-extension exclusion may cover far more files than you intended. Choose the smallest target that matches the real problem.
Review access and settings.
Windows may require permission before you can change protection settings. If you can't edit the exclusions list, the device may be managed by someone else, or your account may not have the needed permission.
Don't keep widening the exclusion blindly.
Adding a folder, process, and extension for the same issue makes protection weaker without proving that the original setting was wrong. Remove unused entries and keep the list easy to understand.
Using policy or command-line methods for managed Windows environments
For a personal computer, the Windows Security app is the clearest way to add an exclusion. In a workplace, school, or other managed environment, exclusions may be controlled centrally instead.
Microsoft Defender custom exclusions can be configured through:
- Microsoft Intune
- Mobile device management (MDM)
- Group Policy
These tools let an administrator apply settings across managed Windows devices. If a setting keeps changing back, or if the exclusions controls are unavailable, contact the person who manages the computer rather than trying to work around the policy.
You may also see instructions online for how to exclude files from Windows Security command line. Command-line changes can be useful for administrators, but the correct syntax depends on the tool, Windows setup, and management method being used. The available information here identifies the supported management routes but does not provide a command-line format to copy safely.
For that reason, don't paste an unverified command into PowerShell or Command Prompt just to bypass a detection. Use the Windows Security screen for a local change, or ask your administrator to apply the exclusion through Intune, MDM, or Group Policy.
After you add an exclusion, review it on the exclusions page. Make sure it names the exact file, folder, process, or extension you meant to change. When the problem is over, return to that same page and remove the entry—especially if it was broader than one trusted file.