What is Automatic Sample Submission?
Windows Security (formerly Windows Defender) includes a cloud-based protection feature called Automatic Sample Submission. When Defender encounters a file it considers suspicious or unrecognized, it automatically uploads a copy of that file to Microsoft’s cloud servers for deep analysis. While this drastically improves the security ecosystem by allowing Microsoft to quickly identify new malware, it poses a potential privacy risk. If you regularly work with sensitive, proprietary, or highly confidential documents (such as legal contracts or unreleased source code), you may not want these files automatically transmitted to a third-party server without your explicit consent.
How to Turn Off Automatic Sample Submission
You can easily disable this feature through the standard Windows Security interface. This ensures that files are scanned locally on your machine but never uploaded to Microsoft.
- Click the Start Menu and type Windows Security. Press Enter to open the app.
- In the left-hand sidebar, click on Virus & threat protection.
- Scroll down to the section titled “Virus & threat protection settings.”
- Click the blue Manage settings link.
- Scroll down until you find the Automatic sample submission toggle.
- Click the toggle to switch it to the Off position.
- If prompted by User Account Control (UAC), click Yes to confirm the change.
What Happens Next?
Once disabled, Windows Defender will continue to scan your files locally using its downloaded virus definitions. However, if it encounters an unknown file that it suspects might be malicious, it will no longer upload it automatically. Instead, you will occasionally receive a notification asking for your permission to send a specific file to Microsoft for analysis. You can choose to allow or deny these requests on a case-by-case basis, giving you complete control over your data privacy.