But surely windows will activate defender? Since any AV must register in windows and considering that MS isn't exactly known for respecting user wishes I'd expect defender to start up the same nanosecond any other AV stops.
Though I'd never out myself in a position to test that.
There's a reason they're paid for doing so. If it was beneficial they'd do it for free.
I’m sure that there are other reasons - do you have any in mind?
I run Glasswire [1] which started as a detailed bandwidth monitor but now has a firewall feature that sits on top of Defender and works with the rules list so not trying to replace anything.
Its simple and adds the biggest win in this article's list of recommendations imho which is Block on Fist Sight. In addition to asking, Glasswire also checks every new or updated network service requestor's VirusTotal score. No Group Policy or PowerShell magic required.
[1] www.glasswire.com
Taking a quick look MAPS block at first sight, it appears to look at both the executable file and non-portable executable files such as JS, VBS, or macros, then stop execution, however it isn't clear if this also includes things such as dll files or the python script being executed by python.exe.
The firewall feature of GlassWire, or any application level firewall will only block traffic for your typical, well behaved programs, to save some bandwidth, and possibly block some telemetry if the program isn't too mischievous. This is because GlassWire doesn't stop the program, and can't tell if you're the one running the executable or another application is running it programmatically, so if EvilApp.exe notices it can't connect to the internet, it could just use something innocent you've allowed such as Firefox or python to send/receive data on its behalf (or just do that from the start).
This is why it's still important to check the bandwidth of programs you trust for abnormalities, even if you've only allowed trusted programs and block everything else, and why it's so important to keep programs up to date and only run stuff you don't fully trust in a sandbox (since I doubt MAPS block on first sight is perfect either).
In a business environment I've always been an advocate of staging one machine taking a drive image and using that image to clone the rest. Resolved so many issues if the end-user mucks up their machines so bad you just reflash the drive image and send them on their way.
Given how many devices use out of the box drivers, combined with the amount of drivers distributed with Windows update, that part of the story has gotten much better as well.
Also there are features that allow downloading the install image from Microsoft servers similar to what Apple has had for years. But this might be a enterprise customers only feature.
One caveat is that SCCM is not free, and we have a dedicated guy managing it. Not sure how much work that entails (he's not full-time), I rarely if ever touch our Windows environment (I'm running Linux on my own machine).
Still hate the shovelware. If it were a good product I would choose to install it.
Sadly that's discontinued now as Windows descends further into consumer abuse and anti-features. https://www.howtogeek.com/402888/looking-for-a-microsoft-sig...