Built-in device protection: what you already have before you buy
Every current version of Windows, macOS, Android and iOS includes some protection against malicious software. This page explains, in general terms and with links to each maker's own documentation, what that protection consists of, and how to think about whether a paid product would add anything you would use.
Quick answer. Windows includes Microsoft Defender Antivirus; macOS has built-in malware checks; Android has Google Play Protect; iOS restricts apps to the App Store and runs each in a sandbox. Paid products may add extra features, coverage across several devices, or a different approach to detection. Whether that is worth paying for depends on your devices and habits, not on a general rule.
Windows
Microsoft describes Microsoft Defender Antivirus as built into Windows. It provides the core functions defined elsewhere on this site: real-time protection, cloud-delivered checks, scheduled and on-demand scans, and quarantine. It is managed from the Windows Security app.
Microsoft's documentation also explains how Defender behaves when another antivirus product is installed. In broad terms, Windows expects one product to be providing active protection at a time, and Defender steps back when a compatible third-party product takes over. This is worth knowing for two reasons: installing a paid product is not adding a second layer on top of Defender in the way many people assume, and uninstalling or letting a paid product expire should return protection to Defender. It is sensible to check in the Windows Security app that this has actually happened.
The Windows Security app is also where the firewall and other protection settings are shown, so it is the one place to look when checking what is switched on.
macOS
Apple documents the protections in macOS in its Apple Platform Security guide. The approach differs from Windows: rather than a separate antivirus application you open and manage, the protection is part of the system. It includes checks that applications come from identified developers and have passed Apple's automated notarisation checks before they open for the first time, signature-based detection of known malware, and a mechanism for removing malware that has been identified. Updates to these protections are delivered automatically and separately from full system updates.
The practical consequence is that there is little to configure, and also little to see. Some people prefer a paid product partly because it shows more of what it is doing; that is a legitimate preference, but it is a preference about visibility and features rather than evidence that the built-in protection is absent.
Android
Google explains that Google Play Protect checks apps on Android devices, including apps installed from outside the Play Store, and can warn about or disable harmful ones. Android also runs each app in its own sandbox and requires apps to request permissions for sensitive data such as location, contacts and the microphone.
Most Android malware reaches devices through apps installed from outside the Play Store, a practice sometimes called sideloading. Keeping the setting that blocks installs from unknown sources switched on, and being sceptical of any message asking you to change it, removes the most common route.
iPhone and iPad
On iOS and iPadOS, apps can normally be installed only through Apple's App Store, and each app runs in a restricted sandbox, as described in the Apple Platform Security guide. One effect is that a security app on an iPhone cannot scan other apps or the system in the way a desktop antivirus product scans a computer. Security apps for iOS therefore focus on other things: filtering web content, screening messages, monitoring for leaked account details, or providing a VPN. Check exactly which of these a product offers before assuming it does what a desktop product does.
Built-in protection compared with paid products
The table below compares the three broad options in general terms. It describes categories, not specific products, because features vary between vendors and between editions of the same product.
| Consideration | Built-in protection | Paid antivirus product | Paid security suite |
|---|---|---|---|
| Cost | Included with the device | Annual or monthly subscription | Annual or monthly subscription, usually higher |
| Core malware detection | Yes | Yes | Yes |
| Extra tools | Some, varying by system | Some, varying by product | Several, such as password manager or VPN, varying by product |
| One dashboard for several devices | Generally no; each device is managed separately | Depends on the licence | Often a selling point |
| Renewal to keep track of | No | Yes | Yes |
| Support from the vendor | Through the operating system maker | Through the security vendor | Through the security vendor |
Questions to ask yourself before paying
- Which devices do I actually need to cover? List them, including their operating systems. A product covering one computer is a different purchase from one covering a household of phones, tablets and laptops.
- Is my built-in protection switched on and up to date? On Windows, open Windows Security and look for any item that is not shown as active. On other systems, check that automatic updates are on.
- Which extra features would I really use? A password manager or VPN bundled into a suite is only worth paying for if you would use it and do not already have one.
- Am I paying to replace something I already have? On Windows, a third-party antivirus product takes over from Defender rather than adding to it. That may still be worth doing for its other features, but it is a replacement, not an addition.
- What happens at renewal? Check the renewal price and how to switch off automatic renewal before you buy. The subscription terms page covers this in detail.
Older devices and unsupported systems
Built-in protection depends on the operating system still receiving updates. When a maker stops supporting a version of Windows, macOS, Android or iOS, security fixes for that version stop too, and the built-in malware protection may stop receiving improvements. Each maker publishes its own support timelines, and the device's settings usually show whether updates are still arriving.
A paid antivirus product may continue to support an older system for a while, but it cannot repair flaws in the operating system itself; it can only try to catch the malware that uses them. For a device that will no longer be updated, the more lasting choices are to upgrade the operating system if the hardware allows it, to replace the device, or to limit what it is used for, such as keeping it away from online banking. Treat any offer that presents antivirus software as a substitute for system updates with caution.
The same reasoning applies to routers and other devices on a home network. They rarely run antivirus software at all, and their protection comes almost entirely from firmware updates provided by the maker. Checking the router's settings page for available updates once or twice a year is a small task with a real benefit.
Measures that matter regardless of the software
Official guidance for households, such as the National Cyber Security Centre's Own Your Online guides, consistently puts a small number of habits alongside security software: install updates promptly, use unique passwords with a password manager, switch on two-step verification for important accounts, and keep backups. Each of these addresses risks that antivirus software, built-in or paid, does not cover. If you have limited time, these are a better use of it than comparing antivirus products.