Controlled Folder Access: default Allowed Programs list

fra.pc 136 Reputation points
2021-05-26T17:07:10.607+00:00

Hi, I have tried to learn about Controlled Folder Access in Defender by looking at Microsoft Learn and I can't find anything about which are the programs allowed by default by Windows. I could not find anything even in the Tenforums tutorials about Controlled Folder Access; it looks like that, for example, even in the Registry the default allowed programs are hidden.

Is it possible to find the actual list of the default allowed programs and modify it?
I am trying to prevent Defender from scanning some folders in a more effective way compared to Exclusions in Defender settings, but if Defender itself is whitelisted for Controlled Folder Access it would be useless. Also, I don't know if Controlled Folder Access would prevent any program trying to access a folder located on a sleeping drive from spinning said drive up yet.

Thanks a lot to anyone that will help :D

Windows for business Windows Client for IT Pros Devices and deployment Configure application groups
Windows for business Windows Client for IT Pros User experience Other
0 comments No comments
{count} votes

Accepted answer
  1. Jenny Feng 14,241 Reputation points
    2021-05-27T02:32:03.047+00:00

    @fra.pc
    Hi,
    As far as I know, the default protected folders include Windows system files and the built-in, common default document and content folders.
    I'm afraid you can't modify the default allowed programs. That's by design, to protect your operating system from something malicious that tries to do the same thing.
    Please refer to the following information:
    Controlled folder access applies to many system folders and default locations, including folders such as Documents, Pictures, and Movies. You can add other folders to be protected, but you cannot remove the default folders in the default list.
    https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/customize-controlled-folders?view=o365-worldwide

    For folder located on a sleeping drive, there is no clear information, but you can check the Windows event logs under the Windows Defender source to verify it.

    Hope above information can help you.

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.