Controlled Folder Access Blocked problem in Windows Defender

Anonymous
2018-01-02T16:41:03+00:00

On 12/13 , Windows Defender did an update and ever since I keep getting messages like the following when I try to access programs such as Carbonite, Quicken, etc.  The message says:

Controlled folder Access Blocked C:\Program Folders ...qw.exe from making changes to the folder %userprofile\desktop

I have turned off the Controlled Folder Access off in Windows Defender as this error message popped up every time I wanted to access a program.  I was able to get into the program but need to know what is going on and what I can do about it.  Thank you.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

51 answers

Sort by: Most helpful
  1. Anonymous
    2018-01-02T18:53:52+00:00

    What's going on is exactly what the notification from CFA told you, the applications involved are attempting to make some sort of change in the Windows Desktop folder of the user starting the program.

    The problem with this is that it's the same type of operations that might be seen when a ransomware attack attempts to modify items in the Desktop Folder in order to make your system non-functional or encrypt whatever personal files you may have placed there.

    The decision you (and the developers of those badly behaving programs) need to make is whether the actions being attempted by these otherwise valid programs truly need to occur, since these are why Microsoft can't simply block all access to folders like the Desktop in order to avoid ransomware attacks altogether.

    Since the most common reason that older (e.g. outdated design) applications made such access to the Desktop was simply to add an icon, which is something you could do yourself with a simple set of mouse clicks.  By automating this in either their installation programs or worse yet when you're simply starting the program itself, they create issues for Microsoft when trying to protect you from programs with more malicious intent.

    If all you see when using these programs is such notifications and they otherwise seem to operate properly, then you can simply ignore the message(s) and continue using the programs with CFA fully intact.  If they don't work properly, then you'll need to allow those programs the rights within CFA to make changes to those folders or better yet, update to more current versions of these programs that no longer require this access.

    In short, it's your trashy outdated software that's making it impossible for Microsoft to easily protect you from ransomware, so either get rid of them or live with it.

    Rob

    Was this answer helpful?

    50+ people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-03-20T15:08:39+00:00

    I disagree with this "older outdated design" theory, I'm pretty sure many apps that are still currently developed, that yes, while not app store apps, like Docker are current and install an icon onto the desktop...  It is something installers should be able to do, if they can't, strange things may happen during the installation process, such as blocked installations, partial installations, rolled-back installations, installation errors, installers that drop out of the process.  Since the update I have had all of these things occur, and never had any problems with it before that.  Controlled Folder access seems a good thing to have enabled, but the desktop is not able to be removed from the list.   Programs (such as installers) should be able to function normally without being security-hobbled.  Its much like a similar problem that still exists with IFS drivers since the Anniversary update requires them signed, HFS+ and EXT2 (or later) drivers are mostly not digitally signed thus "unsecure" thus unable to function when they were working perfectly fine before that.

    Microsoft seems to be making their system less functional and more restrictive, in some ways there may be advantages, but all I've come across with them so far is blanket blocking techniques that give me less functionality out of my operating system...

    Was this answer helpful?

    30+ people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-15T22:33:02+00:00

    for me, sometimes either access is blocked to %common_desktop% and other access is blocked to documents folder.  One program belongs to MSI (live update), while others are e-book readers, specifically VitalSource Bookshelf, which is program used by major publisher of university textbooks, while even another is an app known as Wolfram CDF player for interactive text provided by Pearson's mymathlab.com; another major university textbook publisher.

    So, while anything is possible, including shoddy coding by half-ass software developers, I wonder if this statement couldn't be applied to Microsoft's developers who work on windows defender?  Maybe it's more of an issue with them not being able to include exceptions for the infinite number of apps/programs, so they make it as restrictive as possible to be effective, leaving it up to the end-user to make the necessary adjustments.  Same way how so many software companies don't do extensive testing and debugging, choosing instead to get the product to market ASAP and let their customer base figure out all the bugs.  Real professional and real customer-oriented.

    Was this answer helpful?

    30+ people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-01-02T19:22:18+00:00

    Well, guess what - both Carbonite and Quicken were updated as of yesterday to 2018 updates and versions and the same thing happens.  So it is not my "trashy outdated software" that is causing this - and I have also added Quicken to the list of folders to be included...... now what........

    Was this answer helpful?

    30+ people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-01-02T20:44:13+00:00

    Did you [leave the] selection to create an icon on the desktop while installing the program?  If you did, then it will still perform this operation, while if you didn't, then it's something else they're doing wrong that's causing the problem.

    No matter which, it's a trashy design decision that has been recommended against by Microsoft for many years.

    There's absolutely no good reason that I can think of for any program to write to the Desktop, since you always have the option to save elsewhere and can still create an icon yourself if desired.  If it's the initial action related to installing the program and icon that's involved, then allowing this to occur the first time only should be sufficient and then the notification should stop.

    I'd personally just ignore the notification if the programs otherwise work correctly, since as I mentioned above the most common reason for this is simply the icon, so if that's actually the reason I'd either ignore it or complain to the software developers support to see if they have a fix for the unnecessary operation.

    Rob

    < EDIT >  If you're not certain how to set exclusions for Controlled Folder Access or how it works in general, here's a Microsoft Blog article covering it.

    Stopping ransomware where it counts Protecting your data with Controlled folder access

    Was this answer helpful?

    10+ people found this answer helpful.
    0 comments No comments