@SecureWaffle @GossiTheDog They _must_ do that if they want to sell Windows in Europe, where they have a requirement that third-parties get the same access as their own security products do.
This is healthy in a way: if the kernel & Defender teams work out what it'd take for the latter to run in user space, I'd bet that MVP API would cover most other users with minimal additions since they all care about the same kinds of activities.