Fix kubectl apply Forbidden on GKE - Windows Defender Real-Time Protection Off but Still Scanning: Fix-Re-enable Windows Defender When Group Policy Turned It Off

Result check
- Keep one change per test run so you know which step helped.
- Undo temporary changes after the issue is confirmed.