Beacon Hub

Understanding the category

The protection already on your devices

Microsoft Defender Antivirus, XProtect and Gatekeeper, Play Protect and the iOS sandbox: what each platform provides by default, and how to check it is working.

Last reviewed: 16 September 2026 · part of the Beacon Hub 2026 edition

Quick answer. Every current consumer platform ships with malware protection that is on by default and updates itself: Microsoft Defender Antivirus on Windows, XProtect and Gatekeeper on macOS, Google Play Protect on Android, and on iOS a design that restricts what any application can reach in the first place. Checking that this is working costs nothing and should precede any purchase.

Why this changed

Through the 1990s and 2000s, buying antivirus software was ordinary advice because desktop operating systems shipped with nothing. That stopped being true in stages, and the consequence is often missed: the protection is now supplied by the company that also writes the operating system, ships with it, and updates through the same channel as everything else. It is not a trial, it does not expire, and for most people it required no decision at all.

This does not make paid products pointless. It changes what they are selling — from "protection versus no protection" to "this protection, plus management across a household, plus support, plus bundled tools, instead of the one you already have". That is a narrower proposition, and a fair one to weigh on its merits.

Windows

Windows includes Microsoft Defender Antivirus as part of the operating system's security component, with real-time scanning, cloud-assisted lookups, behaviour monitoring, and controls that restrict which applications may modify protected folders. Microsoft's SmartScreen additionally checks downloads and sites for reputation before they run or load.

One behaviour is worth knowing because it causes confusion. When you install a third-party antivirus product, Windows generally steps its own real-time protection aside so two scanners do not fight over the same files. If you later remove the third-party product, the built-in protection resumes. If an expired trial leaves a product installed but no longer updating, that is the genuinely bad state: one scanner disabled, another not maintained. Removing the lapsed product restores the built-in one.

Where to look

Open the Windows Security application from the Start menu and read the status shown under virus and threat protection. It will tell you which product is providing real-time protection and whether definitions are current. That screen is the authoritative answer for your machine — no web page can tell you.

macOS

Apple's protection is layered and largely invisible. Gatekeeper checks that software is signed by an identified developer and has been submitted to Apple for automated malware screening before it will run. XProtect matches known malicious content against signatures that Apple updates separately from full system updates, and a removal component can clean up known families. Applications are also constrained by system integrity protections that limit what any process can alter, even with administrator rights.

The frequent claim that Macs cannot be infected is simply wrong, and Apple's own maintenance of XProtect is the plainest evidence against it. What is true is that the delivery route has shifted: on macOS the common problem is a user being persuaded to install something and approve its permissions, which no scanner reliably prevents.

Android

Android applications run sandboxed from each other and must request permissions for sensitive access. Google Play Protect scans applications on the device and checks those installed from the Play Store, and it is enabled by default on certified devices.

The residual risk on Android concentrates in two places: software installed from outside the Play Store, and permissions granted carelessly — particularly accessibility services, which legitimately allow one application to observe and act on the screen, and which malicious applications therefore request. Reviewing what has accessibility access is a five-minute job with a better return than most scans.

iOS and iPadOS

Apple's mobile platform takes the restriction further. Applications are distributed through a review process, run sandboxed, and cannot read other applications' data or scan the device's storage. The consequence is specific and often misunderstood: a security application on iOS cannot perform a malware scan of the device, because the platform gives it no access to do so. That is a deliberate design decision, not a shortcoming of the applications.

What security apps can legitimately provide on iOS is described on our mobile page — mostly web filtering, breach alerts and VPN functions, which are real features that operate within the platform's rules.

Checking what is switched on

Do this on the device itself, in its own settings. No website can inspect your device, and any page that claims to be doing so is not.

  1. Windows: Start menu, then Windows Security. Check virus and threat protection status and confirm updates are current.
  2. macOS: System Settings, then General and Software Update. Keep automatic updates on — this is how XProtect definitions arrive.
  3. Android: Play Store, then your profile icon, then Play Protect. Confirm scanning is on, and review Settings, then Accessibility, for applications that should not be there.
  4. iOS: Settings, then General, then Software Update, and turn on automatic updates. Then review which apps hold permissions under Privacy and Security.

Menu names shift between versions. If the path above does not match your device, search the vendor's own support site rather than following instructions from a third party — including us.

What the platform does not give you

  • A view across the household. Each device reports for itself. Nothing tells one person whether every device in the house is up to date.
  • A support relationship for this specific problem. Platform support is general; a security vendor's support exists for exactly this.
  • Bundled extras. A password manager, a VPN and breach monitoring are separate purchases unless a suite includes them.
  • Filtering outside the browser. Browser safe-browsing protects the browser. System-wide filtering that also covers links opened from messaging apps is usually a third-party feature.

Whether that list is worth an annual fee is the whole question, and it depends entirely on your household. The 2026 review works through it.

A note on free third-party scanners

Free versions of commercial products are a marketing channel: they are funded by upgrade prompts, and some have historically been funded by other means as well. That is not a reason to avoid them, but it is a reason to weigh them against the protection you already have rather than against nothing. If a free scanner would replace your platform's own real-time protection while nagging you daily, it is worth asking what you gained.

Running a paid product alongside

One real-time scanner at a time. Two products both intercepting every file operation can slow a machine noticeably and can each flag the other's activity. On Windows this is handled automatically, as described above; on macOS, installing more than one product with system extensions is a support problem waiting to happen.

If you do subscribe to something, uninstall it properly rather than letting it lapse. A lapsed product that no longer updates is worse than no product, because it can leave the built-in protection standing aside for a scanner that has stopped receiving definitions. Before you subscribe to anything, it is worth reading how these subscriptions renew and how they are cancelled.