Cool, I will try reinstalling the iso. I don't remember how I managed to remove (and break) my Windows defender in my older W10 installation, but I haven't been able to redo it (as it says I have no permissions to open "Tamper protection" section).The rules for disabling Defender services are clear:
1. For a live system, Tamper Protection prevents any Defender service from being disabled. Tamper Protection doesn't allow itself to be disabled by running a reg update. This is a layered defense strategy, forcing you to use the Security Center to turn off Tamper Protection.
2. By changing the Tamper Protection reg value in an offline image, Windows will allow you to disable any Defender service from running. For a live system, some users will boot into WinRE or WinPE and mount the live system's reg hive to force the change.
3. Even better is disabling both Tamper Protection and Defender services in the offline image, using a reg file. This avoids the problem entirely. Most debloating tools or scripts are written to run on a live system, and cannot do offline images.
For the reg file, read this thread:
Disable Windows Defender in Windows 11
Just noticed the "Wdfilter" one wasn't included in the tweaks from this thread. I guess that might've been why, as I've just did a reinstall (prior to seeing garlin's thread) and I wasn't able to turn off tamper protection, either. Or accessing it at all.
Specifically, the message was:
"Page not available
Your IT administrator has limited access to some areas of this app, and the item you tried to access is not available. Contact IT helpdesk for more information"
Extra note: The "TamperProtection" value in the tweak from this thread is 4, compared to 0 from the thread garlin's linked.
I wonder if that mattered?
--
If anyone feels like looking up why I need "core isolation" menu, it is for the android player "Mumu" from https://a11.gdl.netease.com/MuMuInstaller_3.1.7.0_overseas-v3.8.18.2845_all_1713335040.exe (or https://www.mumuplayer.com/update/)
The emulator itself loads just fine even without core isolation actually.
But certain games with "emulator detection" somehow won't let me use the emulator to play the game, if I can't open the core isolation menu.
(The game in question is Black Beacon)
I've tried copying registry to another device (which doesn't have defender, it can't open windows security section at all and its blank), but the game still doesn't work.
Upon being able to see "core isolation" screen, the game lets me in and doesn't ban or detect the emulator.
I have no idea why, or maybe I am missing more registries.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity]
"Enabled"=dword:00000000
"Locked"=dword:00000000
Attachments
Last edited: