We have machines running a separate antivirus solution; therefore, it disables Microsoft Defender Antivirus. I have this same standard configuration across thousands of PCs at many clients.
ONE client is showing an issue where end users that are seeing a cessation of work every 5 minutes for about 5-10 seconds. They cannot do anything and must wait for the OS to give up control again. It began happening to mostly systems that have magnetic HDD drives, and that have recently been upgraded to 21H2. We have found this to be due to MsMpEng.exe (Microsoft Defender Antivirus) trying to start, then giving up, assuming because it finds it is not the AV in control. We have verified that the AV we install is running, and that Microsoft Defender Antivirus is not running, and we have even disabled the option offered to do "periodic scans" by Defender. The other symptom is that MsMpEng.exe writes logs every 5 minutes after this pause in the OS has happened, this is how we know it is Defender. The files are in C:\ProgramData\Microsoft\Windows Defender\Support and called "MpWppTracing-blahblahblah.bin". A google search on this symptom anytime in the last year has very few hits.
Anyone see this, and how do we stop it?
Exclude files and folders:
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\ProgramData\Microsoft\M
Exclude processes:
MsMpEng.exe
exclude these in your AV as well.
as for the every 5 minutes check task scheduler
in services disable Windows Defender Advanced Threat Protection service helps protect against advanced threats by monitoring and reporting security events that happen on the computer. and