Protection against phishing, malware, and other threats targeting email and collaboration tools in Microsoft 365
The message about the IT administrator limiting access usually means Microsoft Defender Antivirus has been disabled by policy or by the presence of another antivirus, not that the Windows account lacks admin rights.
Since McAfee was removed, the main things to check are:
- Confirm Defender is the active antivirus provider
- Open the Windows Security app.
- Go to Virus & threat protection.
- Under Who’s protecting me?, select Manage providers.
- Verify that Microsoft Defender Antivirus is listed and can be turned on.
If a non‑Microsoft antivirus is still listed as active, Defender will stay disabled until that product is fully removed.
- Turn on real‑time protection in Windows Security
- Select Start > Settings > Update & Security > Windows Security > Virus & threat protection.
- Under Virus & threat protection settings, select Manage settings.
- Switch Real‑time protection to On.
- For best protection, also turn on Cloud‑delivered protection and Automatic sample submission.
- Check if Defender was turned off by policy (common cause of “Page not available”)
Group Policy or registry settings can disable Defender and block access to some Windows Security pages. To see if this is the case:- Open an elevated Command Prompt (Run as administrator).
- Run:
GPresult.exe /h gpresult.html - Open
gpresult.htmland look for entries under Windows Components/Microsoft Defender Antivirus such as:- Policy: Turn off Microsoft Defender Antivirus
- Setting: Enabled
- Also look for registry items like:
- Key path:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender - Value name:
DisableAntiSpyware - Value data:
0x1 (1)
- Key path:
- Verify Defender service state (to confirm it’s not being blocked by another AV)
- Open Services (
services.msc). - Look under Windows Defender > Operational for Microsoft Defender Antivirus Service.
- If starting the service shows a message like “started and then stopped… Some services stop automatically…”, this indicates Defender was turned off to preserve compatibility with another antivirus or by policy.
- Open Services (
- Ensure no other antivirus is still installed or partially present
- If any non‑Microsoft antivirus remains installed, Defender will either be turned off or run only in passive mode.
- Fully uninstall any remaining non‑Microsoft antivirus products. After uninstall, Defender should automatically return to active mode.
Once policies disabling Defender are removed and no other antivirus is active, Microsoft Defender Antivirus should become available again in the Windows Security app and real‑time protection can be turned on.
For a home PC, if the “IT administrator has limited access” message persists after removing other AV and clearing policies, a repair or reset of Windows Security/Defender configuration (or a Windows reset while keeping files) may be needed, but that is beyond the scope of the provided context.
References:
- Microsoft Defender Antivirus in the Windows Security app
- Antivirus and antimalware software: FAQ
- Scan an item with Windows Security
- Troubleshoot Microsoft Defender Antivirus while migrating from a non-Microsoft solution
- Troubleshoot Microsoft Defender Antivirus service startup problems
- Enable and configure Microsoft Defender Antivirus always-on protection
- Windows Security App Overview
- Windows Defender update - Microsoft Q&A