Microsoft Defender runs so quietly that I rarely think about it. However, it only scans what Windows Security allows, and the app keeps a list of places to skip. I've opened that page plenty of times to manage the ransomware protection Windows leaves switched off by default, yet I had never looked at the exclusion list. When I finally did, it wasn't empty.
Five folders sat on the list, and I remembered adding none of them
To see the list on your own PC, open Windows Security from the Start menu and click Virus & threat protection. Under Virus & threat protection settings, click Manage settings, scroll down to Exclusions, and click Add or remove exclusions. Windows asks for administrator approval before it opens the page, which feels right for a list that shows exactly where Defender never looks.
Popular Now: Some Switch 2 cartridges now require a software update before players can launch them offline
I expected a blank page. Instead, I found five folder entries, and four of them belonged to Android Studio.

They covered the Gradle cache, the Android SDK, the IDE's own data folder, and a test project called MyApplication. I never typed any of those paths. Android Studio's Build Analyzer flags antivirus scanning as a cause of slow builds and offers to exclude exactly these folders, so I most likely clicked through that offer at some point and forgot about it.
The fifth entry, C:\TEKKEN 7 Ultimate Edition, was most likely mine, even though I can't recall adding it. I uninstalled the game a while back, yet the exclusion stayed put long after the folder lost its purpose.

Best Deals: HP 14 Laptop
Prices last scanned 22 hours and 54 minutes ago
That kind of leftover matters more than it looks. A folder exclusion covers every file and subfolder inside it, and Defender skips all of it during real-time protection, scheduled scans, and on-demand scans alike.
Four of my five paths also sat inside my user profile, where any program I run can write files without an administrator prompt. A malicious script dropped into one of those folders would skip Defender's antivirus scans entirely, leaving only its other protections to catch it. That's exactly why some malware adds exclusions of its own.
Our Latest TweakTown Guides
- These powercfg commands explain why your PC wakes at night or won't sleep
- Snipping Tool handles most of my screenshots, but this open-source app still does the jobs it can't
- I almost uninstalled 7-Zip after File Explorer learned RAR, and then I hit the gaps
- Your Windows PC is enforcing policies you never set, and one command lists them
- Here's the four Windows 11 components I only add when a job calls for them
Every entry needs a reason, and mine had run out of them
My rule for the audit was simple. Each entry had to point at something I still use, and I had to know why it was there. The TEKKEN 7 entry failed right away, since the game is gone.
Guide Q&A
Powered by TweakBot
From TweakTown's coverage of this guide.
What Windows requirements apply to using a Dev Drive with Microsoft Defender performance mode?
How can administrators manage Microsoft Defender exclusions through Intune or Group Policy?
Can Android Studio add Microsoft Defender exclusions again after a user removes them?
Does Microsoft Defender Offline scan honor exclusions configured in Windows Security?
Want something else? Ask TweakBot.
The Android Studio entries took a little more thought. The IDE is still installed, but I haven't opened it in more than a year. In other words, four exclusions were speeding up builds I no longer run, and they left four folders unscanned in exchange.
When you can't remember where an entry came from, Event Viewer can often tell you when it appeared. Press eventvwr.msc, and press Enter. Then go to Applications and Services Logs > Microsoft > Windows > Windows Defender > Operational, click Filter Current Log in the right pane, type 5007 in the Event ID box, and click OK.


Each 5007 event records a Defender setting change along with its old and new values. Not every one involves exclusions, so look for events whose new value mentions Exclusions followed by a path. Those show when the entry appeared. The log only holds a limited history, though, so an entry from years ago may have rolled off already.
Removing an entry is the easy part. On the Exclusions page, click the entry to expand it, then click Remove. I removed all five.

If you prefer a terminal, open PowerShell as administrator and run Get-MpPreference | Select-Object ExclusionPath, ExclusionExtension, ExclusionProcess to list path, file type, and process exclusions in one go. Then remove one with Remove-MpPreference -ExclusionPath "C:\TEKKEN 7 Ultimate Edition", swapping in your own path.

Some entries won't budge, though. On a PC that a work or school account manages, exclusions pushed through Group Policy or Intune may refuse to delete, return at the next policy refresh, or stay hidden from the list. They belong with the policies your PC enforces even though you never set them, and your IT team decides whether they stay.
Narrow exclusions still do the job, and Protection history confirms it
None of this makes exclusions bad. Defender sometimes flags a tool I trust, and an exclusion is the right fix when that happens. The fix just needs to be narrow. Instead of excluding a whole folder, click Add an exclusion, choose File, and select the one executable that keeps getting flagged.

I'd also stay away from the Process option unless you know what it does. It tells Defender to skip every file that program opens, which reaches much further than the program itself.
Developers get a cleaner option, too. A Dev Drive lets Defender run in performance mode, which scans files after they open instead of holding up the build. Microsoft describes that as far better protection than a folder exclusion, so it's the better starting point for project folders. If I ever go back to Android development, my projects are going on one.
Once the list was clean, I scanned the Android folders that still exist. In Virus & threat protection, click Scan options, select Custom scan, click Scan now, and pick the folder. Afterward, open Protection history from the left pane. If a file you trust shows up there and you've confirmed where it came from, add that single file back as an exclusion rather than restoring the whole folder.

The exclusion list belongs in every routine security check
I now treat this list the way I treat startup apps and saved credentials, as something to open every few months rather than once. While you're in Windows Security, check the apps you've allowed through Controlled Folder Access, too, since that list quietly grows over time as well. After that, the apps allowed through Windows Firewall are the next list I'd go through.







