Privacy and Security Enable or Disable Performance Mode for Dev Drive Protection in Windows 11


DevDrive_banner.png

This tutorial will show you how to enable or disable Dev Drive protection using Microsoft Defender Antivirus protection mode in Windows 11.

Microsoft introduced Dev Drive starting with Windows 11 build 22621.2338.

Dev Drive is a new form of storage volume available to improve performance for key developer workloads. Dev Drive is built upon Resilient File System (ReFS) technology and includes file system optimizations and features that provide more control over storage volume settings and security, including trust designation, antivirus configuration, and administrative control over what filters are attached. It has been designed to meet a developer’s needs to host project source code, working folders, and package caches. It is not designed for general consumer workloads such as document libraries, installing packaged applications or non-developer tools.

By default, to give the best possible performance, creating a Dev Drive automatically grants trust in the new volume. A trusted Dev Drive volume causes real-time protection to run in a special asynchronousperformance mode” for that volume. Running performance mode provides a balance between threat protection and performance. The balance is achieved by deferring security scans until after the open file operation has completed, instead of performing the security scan synchronously while the file operation is being processed. This mode of performing security scans inherently provides faster performance, but with less protection. However, enabling performance mode provides significantly better protection than other performance tuning methods such as using folder exclusions, which block security scans altogether.

The following table summarizes performance mode synchronous and asynchronous scan behavior.

Performance mode state​
Scan type​
Description​
Summary​
Not enabled (Off)Synchronous
(Real-time protection)
Opening a file initiates a Real-time protection scan.Open now, scan now.
Enabled (On) - defaultAsynchronousFile open operations are scanned asynchronously.Open now, scan later.

An untrusted Dev Drive doesn't have the same benefits as a trusted Dev Drive. Security runs in synchronous, Real-time protection mode when a Dev Drive is untrusted. Real-time protection scans may impact performance.

For performance mode to be enabled, the Dev Drive must be designated as trusted and Microsoft Defender Real-time protection must be set to "On".

Starting with Windows 11 build 25931 (Canary), you can now enable or disable performance mode for Dev Drive protection in Windows Security.

References:

You must be signed in as an administrator to enable or disable performance mode for Dev Drive protection.




Here's How:

1 Open Windows Security.

2 Click/tap on Virus & threat protection. (see screenshot below)

Dev_Drive_protection-1.png

3 Click/tap on the Manage settings link under Virus & threat protection settings. (see screenshot below)

Dev_Drive_protection-2.png

4 Turn On (default) or Off Dev Drive protection for what you want. (see screenshot below)

Dev Drive protection will be grayed out and disabled if Real-time protection is not turned on.


The registry key and DWORD value for the Dev Drive protection setting is located below for reference, but you will not be allowed to manually change it.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection

DisableAsyncScanOnOpen DWORD

0 = On
1 = Off


Dev_Drive_protection-3.png

5 You can now close Windows Security if you like.


That's it,
Shawn Brink


 
Last edited:
Hey !
I m not a professional programmer (i have few batch , ps1 , css...).
The "Dev Drive Protection" is enabled by default , and the default drive is my primary disk (C:).
Also under my disk says "....the asynchronous scan is disabled.......".
Are all these OK for a simple user ?
Should i disable the default (enabled) or enable "asynchronous scan" ?
Thanks.
 

My Computer My Computer

At a glance

Windows 11 ProIntel 113700H16GBNVIDIA RTX 3050 ti
OS
Windows 11 Pro
Computer type
Laptop
Manufacturer/Model
HP Pavilion 17 cd2205nw
CPU
Intel 113700H
Memory
16GB
Graphics Card(s)
NVIDIA RTX 3050 ti
Screen Resolution
1980x1020
Hard Drives
Micron 512GB
Mouse
Logitech
Internet Speed
100Mbs
Browser
Vivaldi , Edge
Antivirus
Windows defender
Hey !
I m not a professional programmer (i have few batch , ps1 , css...).
The "Dev Drive Protection" is enabled by default , and the default drive is my primary disk (C:).
Also under my disk says "....the asynchronous scan is disabled.......".
Are all these OK for a simple user ?
Should i disable the default (enabled) or enable "asynchronous scan" ?
Thanks.

Hey mate, :alien:

That is normal. Dev Drive Protection would only show asynchronous scan on for the actual Dev drive, and not for a physical drive.

Create Dev Drive in Windows 11
 

My Computers My Computers

  • At a glance

    Windows 11 Pro for WorkstationsIntel i7-8700K 5 GHz64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600...ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GD...
    OS
    Windows 11 Pro for Workstations
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom self build
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING (11GB GDDR5X)
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G75 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO M.2,
    TerraMaster F8 SSD Plus NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3 wall mounted
    Cooling
    Corsair Hydro H115i
    Keyboard
    Amazon Basics Wired Full Keyboard MD005
    Mouse
    Logitech MX Master 4
    Internet Speed
    2 Gbps Download and 100 Mbps Upload
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    CyberPower CP1500PFCLCD
    Galaxy S23 Plus phone
  • At a glance

    Windows 11 ProSnapdragon X Elite (12 core) 3.42 GHz16 GB LPDDR5x-7467 MHz
    Operating System
    Windows 11 Pro
    Computer type
    Laptop
    Manufacturer/Model
    Surface Laptop 7 Copilot+ PC
    CPU
    Snapdragon X Elite (12 core) 3.42 GHz
    Memory
    16 GB LPDDR5x-7467 MHz
    Monitor(s) Displays
    15" HDR
    Screen Resolution
    2496 x 1664
    Hard Drives
    1 TB SSD
    Internet Speed
    Wi-Fi 7 and Bluetooth 5.4
    Browser
    Chrome and Edge
    Antivirus
    Microsoft Defender

My Computer My Computer

At a glance

Windows 11 ProIntel 113700H16GBNVIDIA RTX 3050 ti
OS
Windows 11 Pro
Computer type
Laptop
Manufacturer/Model
HP Pavilion 17 cd2205nw
CPU
Intel 113700H
Memory
16GB
Graphics Card(s)
NVIDIA RTX 3050 ti
Screen Resolution
1980x1020
Hard Drives
Micron 512GB
Mouse
Logitech
Internet Speed
100Mbs
Browser
Vivaldi , Edge
Antivirus
Windows defender
A simple user won't benefit from a Dev Drive volume. Dev Drive is intended for professional devs, who depend on software repositories and tool chains to compile their code. Meaning, every time they make a minor update it triggers a lot of other file updates in order to compile and test their code.

If you're doing basic scripting, then you won't see this much disk traffic.

Dev Drive makes a deal with Defender to reduce its impact since Defender knows this disk volume is reserved for coding work. You're free to play with it, but it's not going to make too much difference if you don't own a software repository or use a tool chain.
 

My Computer My Computer

At a glance

Windows 7
OS
Windows 7
Back
Top Bottom