Share via

Windows Defender options

Anonymous
2021-06-03T13:00:06+00:00

when windows defender identifies an app or process which is then blocked by controlled folder access, the only action option it offers is allow on this device. I have noticed that articles about windows defender offer actions such as MANUAL STEPS REQUIRED, REMOVE or QUARANTINE as well as the ALLOW ON DEVICE option. one of the options is chosen and then the user clicks on START ACTIONS.

Why is my version of windows defender only offering the allow on this device option, meaning that if I do not wish to permit the blocked app or process to ALLOW ON THIS DEVICE, the blocked app or process just sits under the Protection History tab in windows defender and I can do nothing with it.

I also note that despite my protection history being set to delete after 30 days, this has not happened. I have tried various methods of clearing the protection history manually but none have worked.

I have only recently started using windows defender as my virus and tthreat protection (around 7 weeks) but I still have blocked apps/processes from April 19th, 23rd and 30th and May 1st. Some of these I have allowed through the controlled folder access as they are trusted apps or processes, but I do not want the history to be cluttered with notification of blocked apps or processes as I already have more notifications for blocked apps and processes covering later in May and one in June.

The system information for my version is as follows: ANTIMALWARE CLIENT VERSION: 4.18.2105.3, ENGINE VERSION: 1.1.18200.4, ANTIVIRUS VERSION: 1.339.1937.0 and ANTI-SPYWARE VERSION: 1.339.1937.0

Any help that can be given, especially dealing with the action options, I would be grateful.

Windows for home | Windows 10 | Security and privacy

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

Answer accepted by question author

  1. _AW_ 67,251 Reputation points Volunteer Moderator
    2021-06-09T08:16:12+00:00

    Definitely remove the windows entry from the list.

    You can right click on the unwanted entry and select cancel. That will remove it from the list.

    3 people found this answer helpful.
    0 comments No comments

8 additional answers

Sort by: Most helpful
  1. _AW_ 67,251 Reputation points Volunteer Moderator
    2021-06-09T03:46:34+00:00

    On the only Virtual Machine that I have running Windows Defender with CFA, Protection History for CFA was still present after 6 months, at which point I manually cleared it. Rob's theory seems in line with my findings.

    To manually remove the CFA history, you need to remove the file:

    C:\ProgramData\Microsoft\Windows Defender\Scans\mpenginedb.db

    This file is locked by the WinDefend service executable, so can't be removed via regular means. The easiest way to delete it is to use a small portable program Delete.On.Reboot

    Just download and unzip the program and double click to run. Press 'Add' then browse to the above file, then press 'Restart the PC now'

    https://www.majorgeeks.com/files/details/delete_on_reboot.html

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2021-06-04T05:51:38+00:00

    Hi,

    Thank you for writing to Microsoft Community Forums.

    In order to get clarity and to assist you accordingly, please reply with the answers to the questions below:

    • What is the Version and Build of Windows 10 installed on the PC? (Type winver in Windows search/Run command)
    • What is the make and model of the PC?
    • Do you have any other security software enabled on the PC?
    • Are you aware of any changes on the PC prior to this issue?

    However, we would like you to post a screenshot of the issue for further investigation. (Please follow the steps mentioned in the screenshot posted by Shawn ‘Cmdr’ Keene on Oct 2, 2015 to post the screenshots.) Do not share any personal information in the screenshots.

    Regards,

    Aditya Roy

    Microsoft Community – Moderator

    1 person found this answer helpful.
    0 comments No comments
  3. Anonymous
    2021-06-08T13:34:59+00:00

    Hello Aditya Roy,

    I replied to your request for information but you have not given me any further information are you able to help?

    Thank You.

    0 comments No comments
  4. Anonymous
    2021-06-04T07:54:24+00:00

    Version and build of window10 is windows 10 Pro 21H1, OS Build 19043.1023. My PC was built for me a few years ago so it is not a purchased off the shelf make and model.

    I also have the free version of Malwarebytes on my PC. and I am not aware of any changes to the PCprior to this issue. Thank you for your help.

    ImageImageImage

    0 comments No comments