Home › Knowledgebase › KB-587

How to set up and use Windows 11's built-in ransomware protection with controlled folder access

Summary

This guide helps you troubleshoot and resolve: How to set up and use Windows 11's built-in ransomware protection with controlled folder access. Follow the steps below to fix the issue.

Quick Tip: Need immediate assistance? 💻 Open a Ticket

Common Causes

Windows 11 includes a powerful built-in security feature called Controlled Folder Access, which forms part of Microsoft Defender Antivirus. When enabled, it protects the contents of specified folders — such as your Documents, Desktop, and Pictures — from unauthorised modification by ransomware and other malicious programs. Only approved applications are permitted to write to these protected locations, while any unapproved attempt is blocked and logged.

For small business and home office users across Australia, this provides an important extra layer of defence against ransomware attacks that can encrypt or destroy critical business files. This guide explains how to enable Controlled Folder Access, add your own folders, and allow trusted applications to continue working normally.

Before you begin

Controlled Folder Access is disabled by default on new Windows 11 installations. You must enable it manually to receive its protection.

Enabling Controlled Folder Access

  1. Open the Start menu and type Windows Security, then press Enter.
  2. In the Windows Security window, select Virus & threat protection from the left-hand navigation pane.
  3. Scroll down to the Ransomware protection section and click Manage ransomware protection.
  4. Locate the Controlled folder access toggle switch.
  5. Click the toggle to switch it to On.
  6. If prompted by User Account Control, click Yes to confirm the change.

Once enabled, Windows automatically protects your default system folders: Documents, Pictures, Videos, Music, Desktop, and Favourites.

Enabling Controlled Folder Access may cause some older or less common applications to be blocked from saving files to protected folders. If an application you trust stops working correctly, you will need to add it to the allowed apps list as described below.

Adding your own protected folders

Your business may store important files in locations other than the default folders — for example, on a secondary drive or in a shared company directory. You can add these locations to Controlled Folder Access.

  1. Return to the Ransomware protection page in Windows Security (follow steps 1–3 above).
  2. Under the Controlled folder access heading, click Protected folders.
  3. Click Add a protected folder.
  4. Browse to the folder you wish to protect, select it, and click Select Folder.
  5. Repeat for any additional folders that contain critical business data.
You can protect folders on external drives and network shares, but be aware that network share protection may affect other users on your network. Test carefully before applying to shared locations.

Allowing trusted applications

When Controlled Folder Access blocks an application, Windows displays a notification in the Action Centre. The blocked application is also recorded in the Windows Security event log. To allow a trusted application to write to protected folders:

  1. Open Windows Security and navigate to Virus & threat protection > Manage ransomware protection.
  2. Click Allow an app through Controlled folder access.
  3. Click Add an allowed app.
  4. Choose Recently blocked apps to see a list of applications that have been prevented from writing to protected folders.
  5. Select the application you trust and click Add.
  6. If the application is not listed, click Browse all apps, navigate to the application's executable file (typically in C:\Program Files or C:\Program Files (x86)), and select it.
Only allow applications that you are certain are legitimate and from a trusted source. Adding a malicious or compromised application to the allowed list defeats the purpose of ransomware protection.

Testing your protection

After configuration, verify that Controlled Folder Access is working correctly:

  1. Open Notepad and type a short test sentence.
  2. Attempt to save the file to your Documents folder.
  3. If Notepad has not been added to the allowed apps list, the save will be blocked and you will see a notification: Unauthorised changes blocked.
  4. Add Notepad to the allowed apps list using the steps above, then attempt to save again. The save should now succeed.

Troubleshooting common issues

An application keeps getting blocked

Files are missing from a protected folder

Controlled Folder Access cannot be enabled

Performance impact

Controlled Folder Access adds a small amount of overhead when applications write to protected folders. For most modern computers this is negligible. If you notice significant slowdowns, review the number of protected folders and the number of allowed applications — excessive entries can increase processing time.

Best practices for Australian small businesses

If you manage multiple computers for your organisation, consider deploying Controlled Folder Access settings via Group Policy or Microsoft Intune to ensure consistent protection across all devices.

For further assistance with security configuration or if you need help recovering from a suspected ransomware incident, please Open a Ticket and our support team will assist you.

Still Having Issues?

Need more help? If the issue persists after trying these steps, please open a support ticket and our team will assist you.

💻 Open a Ticket