Microsoft Defender for Endpoint
Endpoint protection

Controlled Folder Access Overview

In brief

The article now points to an updated Windows Security Protection History URL and removes the Microsoft Volume Licensing Reference Guide link.

What Defender admins need to know

No administrator action is required; use the updated links when consulting the article.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

When an app with an unknown reputation triggers CFA, the following events happen:

CFA works best with Microsoft Defender for Endpoint, which provides detailed reporting on events and blocks as part of the usual alert investigation scenarios.

Advanced management capabilities aren't available with other licenses (for example, Windows Professional or Microsoft 365 E3). However, you can develop your own monitoring and reporting tools based on the CFA events generated in Windows Event Viewer on each device (for example, Windows Event Forwarding).

To learn more about Windows licensing, see Windows Licensing and get the Microsoft Volume Licensing Reference Guide.

Supported operating systems for CFA