How-To

How to Enable Ransomware Protection in Windows 11 Using Controlled Folder Access

5 min read Editorial

Ransomware attacks target personal documents, photos, and work files by encrypting them until you pay a ransom. Windows 11 includes a built-in defense layer called Controlled Folder Access that stops unknown programs from writing to your most important directories. When this feature is active, only applications you explicitly approve can modify files inside your protected folders. Enabling it takes a few minutes and requires no third-party software.

Before You Start: You will need an account with administrator privileges. If you are signed in as a standard user, you will be prompted to enter an administrator password when you toggle the feature on. Enterprise environments using Windows 11 Pro or Enterprise may have this setting managed by group policy, which would require contacting your IT department.

  1. Step 1: Open Windows Security

    Click the Start button on your taskbar and type Windows Security. Select the Windows Security app from the search results to launch the central hub for system protection. This panel consolidates firewall rules, network monitoring, and malware scanning into one interface. If you do not see the app in the results, click the search icon in the taskbar and type the name there instead. The Windows Security window should open immediately with a large shield icon displayed at the top.

  2. Step 2: Navigate to Virus & threat protection

    Click the Virus & threat protection tile in the main dashboard. You will see a new page load with several management sections below the heading. Look for the current protection status banner, which displays your last scan date and overall safety rating. This section houses the ransomware-specific controls you need to configure. Scroll down carefully, because the ransomware settings sit near the bottom of this page.

  3. A close-up shot of a Windows 11 desktop showing the Virus and threat protection settings page with a highlighted Ransomw
    The Ransomware protection section sits near the bottom of the Virus and threat protection page.
  4. Step 3: Access Ransomware protection settings

    Scroll to the bottom of the Virus & threat protection page and click the Ransomware protection heading. A submenu will expand showing two primary options: Controlled folder access and Core isolation memory integrity. Click the Open ransomware protection button that appears beneath the Controlled folder access label. Windows will display a brief explanation of how the feature monitors file changes and blocks suspicious write operations. Read through the warning about potential app conflicts before proceeding.

  5. Step 4: Turn on Controlled folder access

    Toggle the Controlled folder access switch to the On position. Windows will immediately begin monitoring your default protected directories, which include Documents, Pictures, Desktop, and Downloads. You will see a confirmation banner appear at the top of the page indicating that the feature is active. If the toggle refuses to switch on, check the Troubleshooting section below for registry and group policy fixes. The system will now block any unapproved application from modifying files inside these folders.

  6. Step 5: Allow apps through Controlled folder access

    Click the Allow an app through Controlled folder access link. A new window will open listing every program currently permitted to write to your protected directories. Click the Add an allowed app button and choose Allow an app from Microsoft Store or Allow an app from the web. Browse to the executable file of the program you want to grant access to, such as a backup utility or cloud sync client. Once added, the app will appear in the list with a green checkmark indicating it can bypass the ransomware filter.

  7. Step 6: Review and manage protected folders

    Click the Protected folders link to view and customize your monitored directories. You will see the default Windows folders listed with a shield icon next to each name. Click Add a protected folder and navigate to any additional location you want to safeguard, such as an external drive or a custom project directory. You can also click Remove to exclude a folder if it contains temporary files that trigger false alarms. Changes take effect immediately without requiring a system restart.

Troubleshooting: Common Issues & Fixes

Controlled folder access may not activate or function as expected in a few scenarios. Review the following solutions if you run into problems.

Advertisement
  • The toggle will not turn on. Open gpedit.msc if you are on Windows 11 Pro or Enterprise. Navigate to Computer Configuration > Administrative Templates > Windows Components > Microsoft Defender Antivirus > Managed By Antimalware. Ensure this policy is set to Not Configured or Disabled. Return to Windows Security and try the toggle again.
  • An important app keeps getting blocked. Open the allowed apps list and click Add an allowed app. Choose Allow a previously allowed app and select the program from the dropdown. If the app is missing, you must add it manually using the Browse option and point to its .exe file.
  • Protected folders show a red warning icon. Right-click the folder in File Explorer and select Properties. Go to the Security tab and verify that your user account has Full control permissions. Restore the default permissions if they were altered by a third-party optimization tool.
A laptop screen displaying the Controlled folder access dashboard with a green active toggle and a list of monitored fol
Controlled folder access monitors your key directories and blocks unauthorized file changes.

Once Controlled folder access is running, Windows will quietly monitor your files in the background. You will only notice the feature when it blocks a suspicious write attempt or prompts you to approve a trusted program. Keep the allowed apps list updated whenever you install new software that syncs or backs up your documents. Regularly review the protected folders to remove directories that no longer need monitoring.

Pro Tip: Enable the Allow apps downloaded from the Internet to pass Controlled folder access option if you frequently download tools from official websites. This prevents your browser from triggering constant pop-ups while still blocking truly malicious executables.

Controlled folder access works alongside Windows Defender SmartScreen and Exploit Guard to form a layered defense against file encryption attacks. You do not need to purchase third-party antivirus software to gain basic ransomware protection on Windows 11. The built-in tools handle the heavy lifting while you focus on your daily tasks.

Over to you: Have you ever encountered an app that got blocked by Controlled folder access, and how did you resolve it?

Advertisement
Share:
Editorial
Written by
Editorial

Windows & Microsoft news editor at 9to5Windows. Covering everything from Windows 11 builds to enterprise updates.

Advertisement