For most New Zealanders, the antivirus question is no longer whether to run one, but whether the free tool already sitting on their PC is doing the job. Microsoft Defender Antivirus — the security engine built into every copy of Windows 10 and Windows 11 — has quietly grown from a basic afterthought into a product that now scores alongside paid rivals in independent laboratory testing. This review looks at how Defender actually performs in 2026: what the labs measure, where its protection thins out, the flaws found in its own scanning engine this year, and how it fits the way Kiwis bank, stream and work online. If you are weighing up the wider free-antivirus question, our guide on whether Microsoft Defender is enough free protection in NZ takes the broader view; here we focus on the Defender product itself.
Key Points
- Defender is free, built into Windows 10 and 11, and runs with low system impact — there is nothing to buy or install.
- Independent labs (AV-TEST, AV-Comparatives) rated its online malware detection alongside leading paid suites through 2026.
- Its offline detection is weaker — around 89% versus roughly 98% online — because it leans heavily on Microsoft’s cloud.
- Web and phishing protection (SmartScreen) is strongest in Microsoft Edge; Chrome and Firefox get less, and the old Chrome extension is being retired.
- It has no built-in VPN or password manager; those need separate tools or a Microsoft 365 subscription.
- Keep Windows Update on: engine flaws such as RoguePlanet were found and patched automatically during 2026.
What Is Microsoft Defender Antivirus?
Microsoft Defender Antivirus is the malware-protection engine that comes pre-installed and switched on in every modern copy of Windows. You manage it through the “Windows Security” app, and for most people it simply runs in the background from the first time the laptop boots. “Antivirus” here means software that watches files, memory and running programs for signs of malware — viruses, trojans, ransomware and similar threats — and blocks or removes anything it judges to be dangerous.
The modern version is a long way from the signature-only scanner Microsoft shipped a decade ago. Today it combines a local detection engine with cloud-based analysis: when it meets a file it has not seen before, it can check a fingerprint of that file against Microsoft’s online threat network and get a verdict in a fraction of a second. “Signatures” are fingerprints of known malware stored on your PC; “cloud-based” means the hard identification work happens on Microsoft’s servers, which keeps the local footprint small. Because it is part of Windows rather than a bolt-on, it generally uses fewer background resources than heavy third-party suites and needs no setup or account to start working.
Microsoft also ships a separate Microsoft Defender app for phones, tablets and Macs, but that is tied to a paid Microsoft 365 subscription and is a different product from the free Windows engine reviewed here. For the average Windows household, “Defender” means the protection that is already running the moment you switch on a new laptop.
Quick Facts
| Developer | Microsoft |
|---|---|
| What it is | Built-in antivirus, firewall and device-health engine, managed in the Windows Security app |
| Platforms | Windows 10 and Windows 11 (built in); a separate Microsoft Defender app covers Android, iOS and Mac via Microsoft 365 |
| Licence & price | Free — included with your Windows licence, no subscription |
| How to get it | Pre-installed and active; open it via Start > Windows Security |
| Updates | Security intelligence and engine updates delivered through Windows Update |
| Latest lab results (2026) | AV-TEST: up to 6/6 protection, performance and usability; AV-Comparatives real-world ~98–99% |
What Comes Built In — and What Does Not
It helps to separate basic malware scanning from a full privacy and identity toolkit. Defender covers the core security layers well, but several things people expect from a paid “security suite” are simply not part of the free tool:
- Real-time scanning: on-access protection that checks files as they are opened, downloaded or run.
- Firewall: Windows Defender Firewall monitors network traffic and blocks unsolicited inbound connections.
- Ransomware protection: a feature called Controlled Folder Access, which is present but switched off until you enable it.
- SmartScreen: web and download reputation checking, strongest inside Microsoft Edge.
- Not included: a VPN, a password manager, dark-web monitoring or cross-platform identity tools — those need separate apps or a paid Microsoft 365 subscription.
Independent Lab Results: How Well Does It Detect Malware?
The fairest way to judge any antivirus is to look at the independent testing houses rather than the vendor’s own marketing. Two names dominate: AV-TEST in Germany and AV-Comparatives in Austria, both of which run Defender through the same gauntlet as the paid products.
In AV-TEST’s 2026 consumer cycles for Windows, Microsoft Defender has repeatedly earned top or near-top marks — scoring the full 6 out of 6 for protection and performance, with usability rated at or close to 6 out of 6. In one four-week review it detected 100% of more than 11,000 malware samples. AV-Comparatives has been similarly positive: in its Real-World Protection testing during 2026, Defender blocked in the region of 98–99% of live, internet-sourced threats. On those headline numbers, Defender’s everyday malware blocking genuinely sits beside paid leaders such as Bitdefender and Norton.
The Catch: Weaker Protection Offline
Those scores come with one important condition — they assume a live internet connection. Because Defender leans heavily on Microsoft’s cloud to identify unfamiliar files, its accuracy drops when a PC is cut off from the network. AV-Comparatives has measured Defender’s offline detection at around 89%, well below the roughly 98% it manages online and behind several rivals that keep larger local signature databases and reach into the high 90s even when disconnected.
For a home laptop that is almost always online, this gap matters less. It becomes relevant if you regularly handle files on a machine with no connection, plug in USB drives from unknown sources, or work somewhere with patchy internet — situations where a competitor’s stronger offline engine has a clear edge. It is worth remembering that these laboratory tests measure detection under controlled conditions; in real life the biggest variable is still user behaviour, which no scanner can fully override.
Where Defender Falls Short: Browsers and Phishing
The most practical weakness that shows up in a close look at Defender is how its web protection depends on which browser you use. SmartScreen — the layer that flags fraudulent websites, dangerous downloads and known phishing pages — is built into Microsoft Edge and works best there. Phishing, where a fake login page tricks you into handing over a password, is one of the most common ways ordinary people lose access to email, banking and social accounts, so this layer is worth understanding.
If you browse with Google Chrome, Mozilla Firefox or Brave, SmartScreen’s site checking does not automatically follow you. Microsoft once offered a “Microsoft Defender Browser Protection” extension for Chrome to close that gap, but that extension is being retired — it was not rebuilt for Chrome’s Manifest V3 extension system, and Microsoft now points users to Edge instead. In other words, the earlier advice to “just install the extension” no longer holds. The good news is that Chrome, Firefox and Brave all include their own built-in dangerous-site and download warnings (Google Safe Browsing and equivalents), so you are not unprotected on other browsers — you are simply relying on the browser’s defences rather than Defender’s.
- Edge: full SmartScreen site and download reputation, phishing blocking and Microsoft family-safety filters.
- Chrome / Firefox / Brave: no native Defender web filtering; rely on each browser’s own Safe Browsing protection.
- Trackers and ads: Defender does not strip ad trackers; that is a job for the browser or a dedicated tool.
- Parental controls: Microsoft Family Safety web filtering is enforced only in Edge.
A Security Concern in Its Own Engine
One point rarely covered in older reviews deserves attention. Because Defender runs on hundreds of millions of devices with deep, trusted access to Windows, flaws in Defender itself are attractive targets. During 2026 a researcher working under the name “Chaotic Eclipse” disclosed a run of elevation-of-privilege flaws in the Microsoft Malware Protection Engine — the core component Defender uses to scan files.
The best known, nicknamed RoguePlanet and tracked officially as CVE-2026-50656 (rated 7.8 on the CVSS severity scale), abused a timing flaw in the way Defender checks a file and then re-opens it, letting a local attacker gain SYSTEM-level control of a fully updated PC. It followed earlier engine flaws from the same researcher — including one nicknamed RedSun — and was later joined by another, ShieldBreak (CVE-2026-69414). The practical takeaway is reassuring rather than alarming: Microsoft patched RoguePlanet in July 2026 and shipped a fix for ShieldBreak in September 2026, and those fixes arrive automatically through Defender’s engine and Windows Update. The lesson is simply to leave automatic updates on. A full read-out of Microsoft’s own documentation is available on Wikipedia for readers who want the background.
Defender vs Paid Security Suites
Whether the free tool is enough depends on what you are comparing it against. The table below summarises how Defender’s free engine stacks up against a typical paid suite across the layers people actually care about.
| Security layer | Microsoft Defender (free) | Typical paid suite |
|---|---|---|
| Online malware detection | Excellent (lab-certified in 2026) | Excellent to near-perfect |
| Offline detection | Weaker (around 89%) | Stronger (large local databases) |
| Phishing / web protection | Strong in Edge only | Works across all browsers |
| Ransomware shield | Controlled Folder Access (off by default) | Included, often with cloud rollback |
| VPN & password manager | Not included | Usually bundled |
| System impact | Very low (built in) | Low to moderate |
| Price | Free with Windows | Annual subscription |
If you would rather weigh up named products, our round-up of the best antivirus software for New Zealand compares paid options side by side. A handful of alternatives Kiwis commonly consider:
| Product | Type | Where it is strong |
|---|---|---|
| Microsoft Defender | Free, built into Windows | Zero cost, low impact, strong online detection |
| Bitdefender | Paid suite | Consistent top lab scores, strong offline engine |
| Norton 360 | Paid suite | Bundled VPN, password manager and backup |
| ESET | Paid suite | Light footprint, granular controls |
| AVG | Free and paid tiers | Free option with browser-wide web shields |
Getting the Most Out of Defender
If you decide Defender suits your budget and habits, a few minutes of setup meaningfully raises your protection, because some of its best tools are off by default.
The most valuable is Controlled Folder Access, Defender’s ransomware shield. Once enabled, it stops any program that is not on its trusted list from changing files inside protected folders such as Documents, Pictures and Desktop — so even if ransomware slips past the scanner, it cannot quietly encrypt your files. To switch it on, open Windows Security, go to Virus & threat protection > Manage ransomware protection, and turn on Controlled folder access. Real-time protection must be on for it to work.
- Expect occasional friction: it can block legitimate apps — some games or editing tools — from saving. You then allow them manually under “Allow an app through Controlled folder access”.
- Keep separate backups: pair it with an automatic cloud or external-drive backup so you can always recover.
- Leave Windows Update on: this is how Defender receives engine fixes and new threat intelligence.
- Scan removable drives: right-click a USB drive in File Explorer and choose “Scan with Microsoft Defender” before opening unfamiliar files.
Using Defender Safely in New Zealand
New Zealand’s fast fibre and 5G networks — Chorus fibre plus mobile from Spark, One NZ and 2degrees — give most homes a quick, stable link back to Microsoft’s cloud, so Defender’s cloud-assisted detection works well here. The weak spot to plan around is phishing protection outside Edge, which matters because so much daily life in Aotearoa runs through logins worth protecting.
Whatever browser you use, slow down and check the web address before entering a password on sites such as:
- Banking: ANZ, ASB, BNZ, Westpac NZ and Kiwibank — always type the address or use a saved bookmark rather than following an email link.
- Government: RealMe, IRD’s myIR and ACC — these are frequently impersonated in scam texts and emails.
- Investing: Sharesies, Hatch and Kernel — confirm you are on the genuine domain before logging in.
- Shopping: Trade Me and major retailers — be wary of “too good to be true” listings and payment redirects.
Turning on multi-factor authentication wherever it is offered, and using a dedicated password manager to spot fake login pages, closes most of the gap Defender leaves on non-Edge browsers.
Who Should Rely on Defender — and Who Should Not
For a large share of mainstream users, Defender is genuinely enough as a standalone antivirus, provided it is backed by sensible habits. If you mostly visit well-known sites, avoid opening unexpected attachments, steer clear of pirated software and game mods, and keep Windows updated, the built-in tool keeps an ordinary PC clean at no cost.
It is a comfortable fit for:
- Confident users who recognise phishing, use multi-factor authentication and keep backups.
- Edge users happy to browse in Microsoft Edge, where SmartScreen is fully active.
- Budget-conscious households wanting lab-certified malware defence without an annual fee.
Consider a paid suite instead if you are:
- A committed Chrome or Firefox user who wants automatic phishing protection in every tab.
- Handling high-value or business data from home and wanting stronger offline detection and extra layers.
- Sharing a PC with children or less tech-savvy relatives who are more likely to click a bad link or install something risky.
The Verdict
Microsoft Defender has earned its place as a capable, resource-light and completely free baseline that matches many paid products for everyday online malware detection. Its limits are real but specific: weaker protection offline, phishing defence that is strongest only in Edge, and no bundled VPN or password manager. None of those are dealbreakers for a cautious, connected, Edge-using household — for that profile, Defender is genuinely enough. If you need browser-independent web protection, dependable offline detection or an all-in-one privacy bundle, a paid suite still earns its keep. Either way, the most important security step is free: keep Windows Update running and treat every unexpected login prompt with suspicion.
Sources
- AV-TEST — Microsoft Defender Antivirus for Windows (test results)
- AV-Comparatives — Is Microsoft Defender Enough? An Independent View
- Microsoft Learn — Protect folders with Controlled Folder Access
- Microsoft Learn — Microsoft Defender Antivirus and passive mode
- BleepingComputer — Microsoft Defender “RoguePlanet” zero-day (CVE-2026-50656)
- Help Net Security — Microsoft releases fix for RoguePlanet Defender flaw
- Microsoft Support — Stay protected with Windows Security
Frequently Asked Questions
Is Windows Defender good enough on its own in 2026?
For most everyday users, yes. It earns top or near-top marks from AV-TEST and AV-Comparatives for online malware detection and runs with very low system impact. Pair it with careful browsing, multi-factor authentication and regular updates and it is a solid standalone antivirus for an ordinary home PC.
How much does Windows Defender cost in New Zealand?
Nothing. It is included with your Windows 10 or Windows 11 licence and is already installed and active. Threat intelligence and engine updates arrive automatically through Windows Update, with no subscription or renewal fee.
Does Defender protect me when I use Chrome or Firefox?
Its SmartScreen web and phishing protection is built for Microsoft Edge and does not automatically extend to other browsers. The old Chrome extension is being retired, so on Chrome, Firefox or Brave you rely on each browser’s own Safe Browsing warnings instead. File scanning on your PC still works regardless of browser.
What happens to Defender if I install another antivirus?
Windows detects the new program and steps Defender’s real-time scanning aside so the two do not clash, leaving your chosen product as the active scanner. If you later remove that antivirus, Defender automatically switches its real-time protection back on.
Should I turn on Controlled Folder Access?
It is worth enabling for extra ransomware protection, as it is off by default. Go to Windows Security, open Manage ransomware protection and switch on Controlled folder access. Be aware it can occasionally block legitimate apps from saving files, which you then allow manually, so pair it with regular backups.




