Microsoft Defender for Endpoint
Endpoint protection

Controlled Folder Access Configure

In brief

The article now lists the Intune navigation path, policy type, platform, profile, CFA settings, and Add/Import examples for protected folders and allowed applications.

What Defender admins need to know

No action is required. Use the revised steps when creating or modifying CFA policies.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • m365-security
  • tier3
  • mde-asr ms.date: 07/01/08/31/2026 ai-usage: ai-assisted

#customer intent: As a security administrator, I want to enable controlled folder access on devices so that I can protect important files and folders from ransomware and other malicious apps. appliesto:

[!INCLUDE Intune is recommended but is a separate product]

In Intune, endpoint security policies are the recommended method to deploy CFA.

To configure CFA using ain Microsoft Intune Endpoint SecurityIntune, use an endpoint security Attack surface reduction policy,policy. For detailed instructions, see Create endpoint security policies (opens in aor Modify existing policies (links open new tabtabs in the Intune documentation).

When creatingyou create the policy, use these specific settings:

  • Policy type: Select Manage > Attack surface reduction on the Endpoint security | Overview page.
  • Platform: Select Windows.
  • Profile: Select Attack Surface Reduction Rules.
  • Configuration settings: After

When you create or modify the policy, after you configure the attack surface reduction (ASR) rules settings, configureuse these specific CFA settings on the following CFA settings:Configuration settings tab:

  • Enable controlled folder access: Select an available mode value. After you assess the effect of CFA in Audit Mode, you can set it to Enabled.

  • Controlled folder access protected folders: To add more folders that get CFA protection, use either of the following methods:

    • Select :::image type="icon" source="media/defender-portal-icon-create.png" border="false"::: Add. In the box that appears, enter the path to include. For example:

      • C:\Data\Reports
      • C:\Data\Finance
    • Select :::image type="icon" source="media/intune-icon-import.png" border="false"::: Import to import a CSV file that contains the paths to include. The CSV file uses the following format:

      ControlledFolderAccessProtectedFolders
      "C:\folder1"
      "C:\folder2"
      ...
      
  • Controlled folder access allowed applications: To specify apps that are allowed to make changes to files in protected folders, use the same :::image type="icon" source="media/defender-portal-icon-create.png" border="false"::: Add or :::image type="icon" source="media/intune-icon-import.png" border="false"::: Import methods described for Controlled folder access protected folders, specifying the path and file name of each app.

    The CSV file uses the following format:

    ControlledFolderAccessAllowedApplications
    "C:\Apps\app1.exe"
    "%ProgramFiles%\Fabrikam\DriveManager\*\DriveService.exe"
    ...
    

    The path of each app can include environment variables and wildcards, as described in Allow apps to modify files in protected folders.

For more information about attack surface reduction profiles in Microsoft Intune, see Manage attack surface reduction settings with Microsoft Intune.

If your organization manages endpoint security policies in the Microsoft Defender portal, you can configure CFA with the same endpoint security policies that Intune uses.

OnFor detailed instructions, see Create an endpoint security policy or Edit an endpoint security policy (links open new tabs).

When you create the policy on the Windows policies tab of the Endpoint security policies page ofin the Defender portal at https://security.microsoft.com/policy-inventoryhttps://security.microsoft.com/policy-inventory?osPlatform=Windows, select :::image type="icon" source="media/defender-portal-icon-create.png" border="false"::use these specific settings:

  • Select platform: Select Create new policyWindows and then create an.
  • Select template: Select Attack surface reduction rules policy. For.

When you create or modify the full procedure, see Create an endpoint security policy.

Usepolicy, use the sameAttack Surface Reduction Rules profile and CFA settings described in Configure CFA in Intune using endpoint security policies. on the Configuration settings tab.

When you assign the policy, note that assignment group limitations apply to devices managed through security settings management. For details, see the Assignments step.

Configure CFA in the Windows Security app

You can use the Windows Security appWindows Security app on individual devices to configure CFA. This method is useful for testing or for configuring a single device. To configure CFA on many devices, use one of the enterprise management methods described earlier in this article.