1. Home
  2. Windows Tips
  3. Enable ransomware protection in windows 10

How To Enable Ransomware Protection In Windows 10

Ransomware is a nasty, evolved form of computer viruses. As the name implies, it’s going to cost you money to undo the damage it does. Ransomware basically locks your files and asks you to send money if you want them back. If you’re a victim of ransomware, you have two choices; pay up, or pay someone to get rid of the ransomware. There’s no option that doesn’t cost you money and neither one guarantees that you will get your files back, which is why it’s a good idea to enable ransomware protection before an attack occurs. Windows Defender has a built-in feature that, if set up, will enable ransomware protection on your PC. Here’s how it works.

You must have Windows Defender enabled for this to work. You cannot just opt to use some features of Windows Defender and not use others. Ransomware protection in Windows Defender doesn’t go by that name. It’s more what the feature does that makes it useful for staying safe from ransomware. Windows Defender lets you lock down folders so that unauthorized apps cannot make changes to them. You will need administrative rights to enable ransomware protection in Windows 10.

Requirements and Limitations

Before you enable ransomware protection, there are a few conditions to be aware of:

  • Controlled Folder Access is available on Windows 10 version 1709 (Fall Creators Update) or later, and on Windows 11.
  • The feature depends on Microsoft Defender Antivirus (also called Windows Security) being active on your system.
  • If you have a third-party antivirus installed, the Controlled Folder Access toggle may be missing or greyed out, because the third-party tool has taken over real-time protection from Microsoft Defender.
  • You will need administrative rights to turn the feature on or off.

If you cannot find the option, check that Microsoft Defender is your active antivirus and that Windows is fully up to date. Installing pending updates or removing a conflicting third-party antivirus is usually enough to make the setting appear.

How to Enable Ransomware Protection in Windows 10 and Windows 11

Controlled Folder Access is turned off by default, so you will need to enable it manually. The quickest way to get there is to open the Start menu and search for Controlled folder access, then click the result that appears. Alternatively, follow these steps:

  1. Open Windows Security (search for it from the Start menu, or go to Settings > Privacy & security > Windows Security on Windows 11, or Settings > Update & Security > Windows Security on Windows 10).
  2. Click Virus & threat protection.
  3. Scroll down to the Ransomware protection section and click Manage ransomware protection.
  4. Toggle Controlled folder access to On.
steps to enable ransomware protection in Windows Security

Once the feature is on, you can add protected folders by clicking Protected folders on the same screen.

You can add any folder you like. All nested folders inside a folder will be protected.

Adding Protected Folders

Click Protected folders, then click Add a protected folder and browse to the folder you want to shield. Any subfolders inside it are automatically covered as well. You can add as many folders as you need and remove them at any time from the same list.

Reviewing Blocked Actions and Allowing Apps

When Controlled Folder Access blocks an app, Windows Security sends a notification letting you know what was denied. You can also review the full history of blocked events by going to Windows Security > Protection history and filtering for Controlled Folder Access blocks. From within Protection history, you can select a blocked event and choose to allow the app that was denied, which is the most reliable way to add an exception based on something that actually happened.

To allow a trusted app without waiting for a block to occur, click Allow an app through Controlled folder access on the Manage ransomware protection screen, click Add an allowed app, and browse to the app’s EXE file.

How Enable Ransomware Protection Works

When Controlled Folder Access is enabled, Windows Security blocks untrusted or unauthorized apps from making any changes inside your protected folders. It does not matter what the app is ordinarily used for — if it has not been explicitly trusted, it cannot write to, modify, or delete files inside those folders.

By default, Windows automatically protects several common locations, including Desktop, Documents, Pictures, Videos, Music, and Favorites, as well as the equivalent Public folders on your system. Any folder you add manually is protected on top of these defaults. According to Microsoft’s official documentation on Controlled Folder Access, this feature is specifically designed to protect valuable data from ransomware and other malicious apps.

A practical example: if you try to save a file to your Desktop via IrfanView and the action is blocked, it is because Desktop is one of the default protected folders — not because IrfanView is restricted to a particular folder by design. The same block would apply to any untrusted app attempting to write there.

When a block occurs, you will see a notification from Windows Security. You can click that notification to go directly to Protection history, where you can review the blocked event and, if the app is one you trust, allow it from that same screen.

This might make you wonder whether your system will be usable if your trusted apps don’t have free reign. Fortunately, controlled folder access has a whitelisting feature that lets you add safe apps to it. These safe apps will be able to access whichever folder it is they want or need to.

To whitelist an app, click the ‘Allow an app through controlled folder access’ option under the ‘Protected folders’ link. Click Add App and select the EXE of the app you want to give full access to.

It’s worth taking the time to add your trusted apps and keep Controlled Access turned on. Once you enable ransomware protection and configure your protected folders, you significantly reduce the risk of losing important files to a ransomware attack.

2 Comments

  1. Hello, since the 20H2 update to windows (2020) the process for activating the anti-ransomware has changed. IOW, this page needs some updating. Thanks.

  2. While this is a good idea, it’s not a simple set and forget. The number of notifications that I received after changing this setting was interesting to say the least, Kindle, my webcam (which was interesting because I don’t use it) etc.
    Seeing as some software – such as Kindle – is run from the AppData directory structure, so you get notifications when you run them.

    This may also disrupt software/web developers so will require a lot of setup to get your packages to update. This will take a lot of time to sort out and is probably not worth the effort for most people.

    The other option is to just turn it on/off when needed, this will require a little more effort, but is probably the easiest option for those in this situation.