Windows 10 Home - "Unauthorized changes blocked"

Anonymous
2017-12-05T21:26:24+00:00

THIS WAS ANSWERED BY ANDRE DA COSTA ON 12/5/17 - his "fix" worked perfectly - I thought I marked this "ANSWERED" - please check his answer, below this initial post.  

https://answers.microsoft.com/en-us/profile/e5564792-9930-4912-828b-e206924b132a

I'm using Windows 10 x64 Home on an HP laptop - Suddenly, I can no longer download photos from my SD card using the port on my laptop and my Photoshop Elements 15 - I get the following messages:

Unauthorized changes blocked

Controlled Folder Access blocked C:...\PhotoDownloader...from making changes to the folder %userprofil...$test$

Or:

Unauthorized changes blocked 

Controlled Folder Access blocked C:...\PhotoshopElement...from making changes to the folder %userprofile%\Documents

I want to use Photoshop in order to rename each photo as I download and I'm afraid this is completely blocking my use of Photoshop at all

I'm not computer literate so any help you can give needs to be in detailed, step by step format.

Thank you for any help you can offer

<Moved from Windows  / Windows 10  / Files, folders, & storage>

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments
Answer accepted by question author
Anonymous
2017-12-05T21:35:41+00:00

Open Windows Defender Security Center

Click Virus & threat protection

Click Virus & threat protection

Scroll down to the bottom then toggle off Controlled folder access

Try again

Was this answer helpful?

700+ people found this answer helpful.
0 comments No comments

88 additional answers

Sort by: Most helpful
  1. bhringer-9380 4,350 Reputation points Volunteer Moderator
    2018-02-25T02:08:13+00:00

    Don't know if they're applicable but there are search results for Event IDs 1127 and 1128 at http://www.eventid.net/

    ~bhringer

    Was this answer helpful?

    0 comments No comments
  2. Anonymous
    2018-02-25T01:34:57+00:00

    The 1125 and 1126 Event IDs are the Audit and Block mode events for Network Protection:

    https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/network-protection-exploit-guard

    The 1121 and 1122 Event IDs are the Block and Audit mode events for Attack Surface Reduction:

    https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-attack-surface-reduction

    Here’s the complete list of Event IDs for Windows Defender Exploit Guard, and of course this list sent me right over to the Security-Mitigations Kernel Mode log. Some very interesting stuff there – like a long string of ACG Audit events with only a PID identifier:

    https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard

    I haven’t found anything yet for the1127 and 1128 Event IDs, and I really don’t know what to make of some of these events myself at this point – but if they’re making you nervous, you might want to run the standard integrity checks and maybe a couple of third-party malware checks:

    https://answers.microsoft.com/en-us/windows/forum/windows_10-update/system-file-check-sfc-scan-and-repair-system-files/bc609315-da1f-4775-812c-695b60477a93

    https://answers.microsoft.com/en-us/protect/forum/protect_other-protect_scanning-windows_other/list-of-malware-removal-tools/d824b9af-ebd8-4c47-94e2-8ee6c544c100

    GreginMich

    Was this answer helpful?

    0 comments No comments
  3. Anonymous
    2018-02-24T23:51:35+00:00

    dell lap top

    Was this answer helpful?

    0 comments No comments
  4. Anonymous
    2018-02-24T21:47:13+00:00

    Thanks GreginMich

    I found the log you pointed to and found a couple extra:-

     1127,1128 refer for blocked changes to memory 

    more worrying is this one which doesn't seem to make any sense - unless its normal for a hard disk process to access the internet?

    1126,1125 - Your IT administrator would have caused Windows Defender Exploit Guard to block a potentially dangerous network connection.

    Detection time: 

    User: 2018-02-24T18:26:02.796Z

    Destination: NT AUTHORITY\SYSTEM

    Process Name: \Device\HarddiskVolumeShadowCopy1

    Was this answer helpful?

    0 comments No comments