Controlled Folder Access Blocked problem in Windows Defender

Anonymous
2018-01-02T16:41:03+00:00

On 12/13 , Windows Defender did an update and ever since I keep getting messages like the following when I try to access programs such as Carbonite, Quicken, etc.  The message says:

Controlled folder Access Blocked C:\Program Folders ...qw.exe from making changes to the folder %userprofile\desktop

I have turned off the Controlled Folder Access off in Windows Defender as this error message popped up every time I wanted to access a program.  I was able to get into the program but need to know what is going on and what I can do about it.  Thank you.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

51 answers

Sort by: Most helpful
  1. Anonymous
    2018-09-09T04:48:48+00:00

    "In short, it's your trashy outdated software that's making it impossible for Microsoft to easily protect you from ransomware, so either get rid of them or live with it."

    Included in that trashy outdated software is the latest release of Visual Studio 2017, IISExpress, and many other Microsoft tools. It seems like Defender could at least check the app's certificate before blocking it.

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  2. Anonymous
    2018-08-29T01:26:20+00:00

    To me, Microsoft's current implementation of CFA is so user-unfriendly that it's essentially unusable by the vast majority of consumers.

    One simple solution: Just give us a prompt that "Application X is trying to write File Y to Controlled Folder Z."  Then present me with two buttons and a checkbox. The two buttons are "Allow" or "Deny" and the checkbox is "Remember this answer for each time that Application X attempts to write to Controlled Folder Z". 

    As it's currently implemented, it's insanity for users to have to remember to turn off CFA at just the right moment and then remember to turn it back on.  And if we forget to turn it off before the infraction, we're only notified AFTER the write fails and we have no way of easily allowing the write to succeed.  Even if we were to comb through our logs (more insanity) we're only given the option of adding an exception AFTER the write has failed.  Are we supposed to add the exception and then go back and retrace our steps in the hope that the original write is attempted again?  Especially when it was likely an app or driver install--are we supposed to reinstall the app/driver?  That re-installation could create a whole new set of problems.

    Another simple solution is for Microsoft to allow the write to happen, but to a Quarantined folder, and then alert users that we can optionally and easily right-click on the file in the Quarantine folder and have it moved to the originally intended Controlled Folder.  This solution is not mutually-exclusive with the first solution above, i.e. both solutions would be of value independently and with or without the other solution.

    Was this answer helpful?

    6 people found this answer helpful.
    0 comments No comments
  3. Anonymous
    2018-03-25T19:54:19+00:00

    See the answer in this thread:

    https://answers.microsoft.com/en-us/protect/forum/protect_defender-protect_scanning-windows_10/control-folder-access-blocked-cprogram-filesqwexe/0842c0df-98b0-428e-9299-7c7c8e6d3084

    For issues with installing applications, simply turn Controlled Folder Access off for the duration of the installation, and then back on again when the installation finishes.

    GreginMich

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  4. Anonymous
    2018-03-25T18:14:23+00:00

    I too am getting this same pop up. I have updated my virus protection and spybot and I am getting---- unauthorized changes blocked. controlled folder access folder blocked C: \windows Rundll32.exe from making changes to the folder %userprofile%favorites.

    it has taken my favorites and task bar favorite.

    HELP!!

    I have done everything it has said to do and my controlled settings is faded out so can't do anything

    Was this answer helpful?

    5 people found this answer helpful.
    0 comments No comments
  5. Anonymous
    2018-09-09T17:00:29+00:00

    Included in that trashy outdated software is the latest release of Visual Studio 2017, IISExpress, and many other Microsoft tools. It seems like Defender could at least check the app's certificate before blocking it.

    Actually Mark, If you'll look at the date of the original post in this thread as well as the applications involved, what I stated was likely true for those applications, but as with others who continue to find and abuse this badly outdated question, you've chosen to pile on in a thread that has nothing to do with your own individual problem simply because the title included "Controlled Folder Access blocked".

    Since this thread began, even I have experienced a single instance of similar CFA notifications relating to portions of the Internet Explorer browser I'd just recently been using during a browsing session that also included several obvious attacks, since I had been purposefully "browsing dangerously" in order to test other security features of Windows 10.  In my particular case, these notifications only stopped once I completely shut down and rebooted the operating system, since which time they haven't re-appeared.

    My experience makes me believe that some of these odd notifications relating to operating system files or those for major applications might relate to either remnants of malicious attacks or other flaky issues with application operation that the CFA components are mistaking for possible malicious ransomware activity.

    Based on this, my first recommendation is to try powering down and rebooting Windows 10, making sure that any possible attacks or other problems you might have noticed with the application(s) involved during the most recent sessions have all been resolved as well.  If the application is misbehaving as my Internet Explorer clearly was, it's easily possible that the CFA protection is mistaking this activity as malicious.

    If the problem seems more permanent, then I tend to agree with GlenProuty's theory in an earlier post that there may be some form of corruption in either the OS or the application's themselves.  His suggestion to perform a repair upgrade of the OS or possibly a repair of the application itself are both potentially valid methods to try and resolve the problem.

    Also, as always it's possible that this situation is somehow being aggravated by the conflicting operation of some other security software installed on the system either currently or in the past which hadn't been completely removed using the manual tools 3rd-party vendors provide for this purpose.

    In any case, this thread should have been locked long ago, since it's become a magnet for these seemingly random and confused posts, few of which have had any relation to the original application or problem for which it was begun.

    Anyone reading this should, as always, begin your own thread stating only your own specific problems and steps already attempted to fix them.  Just because they may sound similar doesn't mean they have anything to do with what's been discussed here, as the confusion above should clearly display.

    Rob

    Was this answer helpful?

    4 people found this answer helpful.
    0 comments No comments