Skip to content
Digital lock and binary code representing ransomware defense

Turn On Windows Ransomware Protection (Controlled Folder Access)

Enable Microsoft Defender ransomware protection on Windows 11 — Controlled folder access, OneDrive recovery habits, and what to do if files get encrypted.

9 min readransomware, Windows 11, Controlled folder access

Ransomware encrypts your photos and invoices, then demands payment. Controlled folder access in Microsoft Defender is the built-in brake: unknown apps cannot silently rewrite your Documents and Pictures.

It is not a complete strategy. Protection + versioned backups + sane browsing beats any neon “anti-ransomware optimizer” from a pop-up. For active infections, use remove malware. For phishing that delivers the payload, see spot phishing emails.

What Controlled folder access does

When enabled, only trusted apps may change files in protected folders. Suspicious or unknown executables get blocked — including some legitimate tools the first time they run.

Layer Role
Controlled folder access Blocks unauthorized changes to key folders
Real-time Defender Stops many payloads before they run
Versioned cloud / file history Recovers files if encryption succeeds
Offline external backup Survives when cloud sync also gets encrypted

Create a system restore point before major experiments, but do not treat restore points as ransomware recovery.

Enable ransomware protection on Windows 11

  1. Open Windows Security (search for it)
  2. Go to Virus & threat protection
  3. Under Ransomware protection, click Manage ransomware protection
  4. Turn Controlled folder access On
  5. Click Protected folders → review defaults (Documents, Pictures, Videos, Music, Favorites typically)
  6. Add a protected folder for anything important elsewhere (e.g. D:\Clients, C:\Work)

Also confirm:

  • Real-time protection = On
  • Cloud-delivered protection = On
  • Automatic sample submission = On (recommended for home users)

If Windows Security is missing or managed by another antivirus, use that product’s ransomware/folder guard — running two real-time suites at once causes pain.

Allowlist apps without training yourself to click Yes

When a block toast appears:

  1. Read the app path — is it C:\Program Files\YourApp\ or Downloads\invoice.exe?
  2. Only allow software you installed on purpose
  3. Ransomware protection → Allow an app through Controlled folder access → Add an allowed app

Common allowlist candidates: Photoshop, Lightroom, accounting tools, trusted backup agents, developer tools writing into Documents.

Never allow:

  • Random EXEs from email
  • Crack/keygen tools
  • “Optimizer” cleaners you do not recognise

OneDrive / cloud version history habits

If you use OneDrive:

  1. Right-click the OneDrive tray icon → Settings → confirm sync is healthy
  2. Practice restoring: website → file → Version history
  3. Know Files Restore (OneDrive / Microsoft account) for mass rollback windows
  4. Prefer not to keep your only backup as always-connected sync — maintain a periodic offline copy

Third-party backup tools (see affiliate card) help when you want scheduled images to an external drive you unplug afterward. Air-gapped beats always-online for ransomware.

What to do if files are already encrypted

  1. Disconnect WiFi/Ethernet to limit spread on LAN
  2. Do not wipe yet if you need forensic samples or unpaid decryptors — but do not pay as a first plan
  3. Boot Safe Mode and scan with Defender Offline / reputable second opinion (malware guide)
  4. Check for decryptors only from trusted projects (e.g. No More Ransom) matching the exact strain
  5. Restore from offline backup or cloud versions from a clean PC when possible
  6. Rotate passwords and enable 2FA — assume stealers ran first
  7. Report to local cybercrime pathways (IC3 in the US, Action Fraud in the UK)

Paying ransoms funds crime and often fails. Insurance/legal teams may have different guidance for businesses; home users should prioritise clean restore.

Reduce how ransomware arrives

  • Do not enable macros on unexpected Office docs
  • Prefer password manager + passkeys over reused passwords on webmail
  • Patch Windows (update stuck?)
  • Be suspicious of “your parcel fee” texts and fake OneDrive shares
  • Skip pirated software and fake codec installers

Controlled folder access troubleshooting

Issue Fix
App cannot save projects Allowlist the real .exe under Program Files
Backup tool fails Allow the backup service executable
Too many prompts You may be running unsigned portable tools — install proper versions
Setting greyed out Another AV or organisation policy manages the device
Performance worry Impact is usually small; exclusions beat turning protection off

Practical weekly routine

  1. Confirm Controlled folder access still On after major Windows upgrades
  2. Glance at Protection history for repeated blocks
  3. Test restoring one file from backup
  4. Keep an external drive backup that is unplugged when not in use

Ransomware protection is a seatbelt. Backups are the airbag. Use both — and ignore anyone selling a miracle “one-click ransomware immune” toolbar.

Allowlisting without training bad habits

Controlled folder access will block some legitimate portable apps that write into Documents. Prefer installing the proper Program Files edition, then allowlist that signed binary. If Windows notifies you about something.exe in Downloads, do not allow it — that pattern is how ransomware gets a foothold. Review Protection history weekly for repeated blocks from the same unknown path.

Backup fire drills

Once a quarter, restore one file from OneDrive version history or your imaging tool. Prove you know the steps before an emergency. Keep at least one backup destination that is offline when you are done copying. Pair folder protection with cautious email habits (phishing) and a clean malware response plan (malware removal). Restore points alone are not ransomware recovery (restore points).

OneDrive Files Restore window

Know how to use OneDrive’s account-level Files Restore for mass ransomware rollbacks, and that the window is limited in time. Practise restoring a single file today. Business accounts may use SharePoint versioning instead — learn your admin’s process. Offline disk images remain the strongest last resort when cloud sync also uploaded encrypted files.

If an allowlist prompt cites an unfamiliar path under AppData\Local\Temp, deny it and scan the PC before you approve anything.

Frequently Asked Questions

Will Controlled folder access break apps?

Sometimes legitimate apps need allowlisting. Windows will notify you; approve only software you recognize.

Is Windows Security enough against ransomware?

It is a strong free baseline. Pair it with versioned backups and cautious downloading. Skip fake ‘ransomware shield’ pop-ups.

Should I pay a ransom?

Generally no — payment does not guarantee recovery and funds criminals. Restore from clean backups when possible and report the crime.

Does a restore point recover ransomware-encrypted files?

Do not rely on it. Attackers often delete shadow copies. Use offline/cloud version history instead.

Is OneDrive ransomware-proof?

No sync is magic, but Version history and Files Restore can roll back mass encryption if you notice quickly.