Turn On Windows Ransomware Protection (Controlled Folder Access)
Enable Microsoft Defender ransomware protection on Windows 11 — Controlled folder access, OneDrive recovery habits, and what to do if files get encrypted.
Ransomware encrypts your photos and invoices, then demands payment. Controlled folder access in Microsoft Defender is the built-in brake: unknown apps cannot silently rewrite your Documents and Pictures.
It is not a complete strategy. Protection + versioned backups + sane browsing beats any neon “anti-ransomware optimizer” from a pop-up. For active infections, use remove malware. For phishing that delivers the payload, see spot phishing emails.
What Controlled folder access does
When enabled, only trusted apps may change files in protected folders. Suspicious or unknown executables get blocked — including some legitimate tools the first time they run.
| Layer | Role |
|---|---|
| Controlled folder access | Blocks unauthorized changes to key folders |
| Real-time Defender | Stops many payloads before they run |
| Versioned cloud / file history | Recovers files if encryption succeeds |
| Offline external backup | Survives when cloud sync also gets encrypted |
Create a system restore point before major experiments, but do not treat restore points as ransomware recovery.
Enable ransomware protection on Windows 11
- Open Windows Security (search for it)
- Go to Virus & threat protection
- Under Ransomware protection, click Manage ransomware protection
- Turn Controlled folder access On
- Click Protected folders → review defaults (Documents, Pictures, Videos, Music, Favorites typically)
- Add a protected folder for anything important elsewhere (e.g.
D:\Clients,C:\Work)
Also confirm:
- Real-time protection = On
- Cloud-delivered protection = On
- Automatic sample submission = On (recommended for home users)
If Windows Security is missing or managed by another antivirus, use that product’s ransomware/folder guard — running two real-time suites at once causes pain.
Allowlist apps without training yourself to click Yes
When a block toast appears:
- Read the app path — is it
C:\Program Files\YourApp\orDownloads\invoice.exe? - Only allow software you installed on purpose
- Ransomware protection → Allow an app through Controlled folder access → Add an allowed app
Common allowlist candidates: Photoshop, Lightroom, accounting tools, trusted backup agents, developer tools writing into Documents.
Never allow:
- Random EXEs from email
- Crack/keygen tools
- “Optimizer” cleaners you do not recognise
OneDrive / cloud version history habits
If you use OneDrive:
- Right-click the OneDrive tray icon → Settings → confirm sync is healthy
- Practice restoring: website → file → Version history
- Know Files Restore (OneDrive / Microsoft account) for mass rollback windows
- Prefer not to keep your only backup as always-connected sync — maintain a periodic offline copy
Third-party backup tools (see affiliate card) help when you want scheduled images to an external drive you unplug afterward. Air-gapped beats always-online for ransomware.
What to do if files are already encrypted
- Disconnect WiFi/Ethernet to limit spread on LAN
- Do not wipe yet if you need forensic samples or unpaid decryptors — but do not pay as a first plan
- Boot Safe Mode and scan with Defender Offline / reputable second opinion (malware guide)
- Check for decryptors only from trusted projects (e.g. No More Ransom) matching the exact strain
- Restore from offline backup or cloud versions from a clean PC when possible
- Rotate passwords and enable 2FA — assume stealers ran first
- Report to local cybercrime pathways (IC3 in the US, Action Fraud in the UK)
Paying ransoms funds crime and often fails. Insurance/legal teams may have different guidance for businesses; home users should prioritise clean restore.
Reduce how ransomware arrives
- Do not enable macros on unexpected Office docs
- Prefer password manager + passkeys over reused passwords on webmail
- Patch Windows (update stuck?)
- Be suspicious of “your parcel fee” texts and fake OneDrive shares
- Skip pirated software and fake codec installers
Controlled folder access troubleshooting
| Issue | Fix |
|---|---|
| App cannot save projects | Allowlist the real .exe under Program Files |
| Backup tool fails | Allow the backup service executable |
| Too many prompts | You may be running unsigned portable tools — install proper versions |
| Setting greyed out | Another AV or organisation policy manages the device |
| Performance worry | Impact is usually small; exclusions beat turning protection off |
Practical weekly routine
- Confirm Controlled folder access still On after major Windows upgrades
- Glance at Protection history for repeated blocks
- Test restoring one file from backup
- Keep an external drive backup that is unplugged when not in use
Ransomware protection is a seatbelt. Backups are the airbag. Use both — and ignore anyone selling a miracle “one-click ransomware immune” toolbar.
Allowlisting without training bad habits
Controlled folder access will block some legitimate portable apps that write into Documents. Prefer installing the proper Program Files edition, then allowlist that signed binary. If Windows notifies you about something.exe in Downloads, do not allow it — that pattern is how ransomware gets a foothold. Review Protection history weekly for repeated blocks from the same unknown path.
Backup fire drills
Once a quarter, restore one file from OneDrive version history or your imaging tool. Prove you know the steps before an emergency. Keep at least one backup destination that is offline when you are done copying. Pair folder protection with cautious email habits (phishing) and a clean malware response plan (malware removal). Restore points alone are not ransomware recovery (restore points).
OneDrive Files Restore window
Know how to use OneDrive’s account-level Files Restore for mass ransomware rollbacks, and that the window is limited in time. Practise restoring a single file today. Business accounts may use SharePoint versioning instead — learn your admin’s process. Offline disk images remain the strongest last resort when cloud sync also uploaded encrypted files.
If an allowlist prompt cites an unfamiliar path under AppData\Local\Temp, deny it and scan the PC before you approve anything.
Frequently Asked Questions
Will Controlled folder access break apps?
Sometimes legitimate apps need allowlisting. Windows will notify you; approve only software you recognize.
Is Windows Security enough against ransomware?
It is a strong free baseline. Pair it with versioned backups and cautious downloading. Skip fake ‘ransomware shield’ pop-ups.
Should I pay a ransom?
Generally no — payment does not guarantee recovery and funds criminals. Restore from clean backups when possible and report the crime.
Does a restore point recover ransomware-encrypted files?
Do not rely on it. Attackers often delete shadow copies. Use offline/cloud version history instead.
Is OneDrive ransomware-proof?
No sync is magic, but Version history and Files Restore can roll back mass encryption if you notice quickly.
Related fixes
How to Set Up a VPN on Windows 11 the Right Way (2026 Guide)
Install and configure a trustworthy VPN on Windows 11 — app setup, kill switch, DNS leak checks, and what to avoid on free VPN services.
Read the fixHow to Remove Malware from Windows 11 Without Losing Your Files
Clean adware, browser hijackers, and stubborn malware on Windows 11 using Safe Mode, Windows Security, and reputable scanners — without formatting first.
Read the fixMove Google Authenticator & 2FA Before a Phone Repair
Transfer TOTP authenticator apps before drop-off so a wiped phone does not lock you out of email, banking, and crypto — export codes, cloud backup, and printed recovery sheets.
Read the fix