Microsoft Defender for Endpoint
Endpoint protection

Defender Endpoint Demonstration Controlled Folder Access Ransomware

In brief

The instructions now explain that the setup script excludes c:\demo from Microsoft Defender Antivirus. They direct users to run the test file from a nonexcluded folder when testing for a CFA block or detection, and clarify where to run and delete copies afterward.

What Defender admins need to know

Running the test from c:\demo may cause it to be treated as trusted and undermine the test results.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

  • tier2
  • demo ms.topic: how-to ms.custom: msecd-doc-authoring-1015 ms.subservice: asr ms.date: 06/16/08/12/2026 ai-usage: ai-assisted

#customer intent: As a security administrator, I want to use a ransomware test file to confirm that controlled folder access blocks ransomware from encrypting files in a protected folder so that I can verify CFA before I deploy it in my environment. appliesto:

  • Downloads a ransomware test file (ransomware_testfile_unsigned.exe) to c:\demo\CFATestFiles, and a clean test file (testfile_safe.txt) to c:\demo.
  • Turns on CFA in Enabled (block) mode and adds c:\demo to the protected folders list (without affecting your other protected folders).