Resource icon

Allow a trusted app through Controlled Folder Access without opening every folder

Controlled Folder Access prevents untrusted apps from changing protected folders such as Documents and Desktop. A legitimate editor may therefore fail to save a file, prompting users to turn the entire feature off. Microsoft's guidance supports allowing a specific trusted app, but warns that a compromised allowed app can access protected files. The useful sequence is to identify the actual blocked executable, check its publisher and give only that app access.

Before you start​

Save the work to a temporary nonprotected location if possible. Read the Windows Security notification and record the blocked process path. Confirm the program was intentionally installed from its real vendor. Back up important protected files before changing permissions. If the app is a script host or general shell, an allow rule may be too broad.

Do it step by step​

  1. Open Windows Security > Virus & threat protection > Ransomware protection > Manage ransomware protection. Confirm Controlled Folder Access is the feature blocking the save.
  2. Inspect Protection history or the notification to find the exact executable path and time. Beware of a lookalike executable in a temporary or user-writable folder.
  3. Update the trusted app from its official source and retry saving once. Some vendors have corrected compatibility issues without an exception.
  4. If still necessary, choose Allow an app through Controlled Folder Access and add only the confirmed executable. Do not exempt an entire folder from antivirus scanning.
  5. Save a harmless test file in the intended protected folder and reopen it. Check that the app works while another untrusted program remains blocked.
  6. Review the allowed-app list later and remove obsolete entries. Keep protected files backed up separately because ransomware defense cannot replace versioned backups.

Check the result​

The named app can save to the protected folder, the feature remains On and the exception list contains no broader unreviewed entry.

If something goes wrong​

If the program updates into a new path, verify its new executable rather than adding every version blindly. If a script host is blocked, resolve the underlying workflow instead of broadly allowing PowerShell or a browser to write all protected data.

Know the limit​

An allowed app can reach protected folders even if it is later compromised. Controlled Folder Access reduces one class of unauthorized modification; it does not block every data theft route. Microsoft ransomware protection

Decision checkpoint​

A narrowly allowed app is still trusted with valuable files. If the app is rarely used, saving to a staging folder and manually moving output may be safer than a permanent exception. Review what process actually saves the file; some editors launch helpers under a different executable. If the alert points at an unexpected helper, verify its installation path and signature before authorizing it. The goal is a working workflow with protection on, not a quiet dashboard.

Aftercare​

Audit the allowed-app list after the vendor ships a fixed version. Remove temporary exceptions that are no longer necessary and confirm normal saves still work.
Posted by
Jack
Views
1
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack