Windows Defender Event 1127 on BdeHdCfg.exe

AndAuf 16 Reputation points
2023-03-22T13:50:27.6733333+00:00

Anybody else seeing more and more warnings with EventID 1127 for conbrolled folder access to BdeHdCfg.exe

The German eventlog is

Der überwachte Ordnerzugriff hat C:\Windows\System32\BdeHdCfg.exe daran gehindert, Änderungen am Speicher durchzuführen.

Erkennungszeit: 2023-03-22T13:16:09.071Z

Benutzer: (unknown user)

Pfad: \Device\HarddiskVolume1

Name des Prozesses: C:\Windows\System32\BdeHdCfg.exe

Sicherheitsversion: 1.385.774.0

Modulversion: 1.1.20100.6

Produktversion: 4.18.2302.6

There is not very much documentation about this. The devices are all bitlocker encrypted, but what is this access attempt?

Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,753 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 43,931 Reputation points
    2023-03-23T16:18:08.07+00:00

    Hello there,

    Controlled Folder Access has blocked an untrusted process from potentially modifying disk sectors.

    For more information about the event record, see the following:

    EventID: <EventID>, for example: 1127

    Version: <Version>, for example: 0

    You can get the detailed description of the Event ID from here https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/troubleshoot-microsoft-defender-antivirus?view=o365-worldwide

    Hope this resolves your Query !!

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments