Microsoft Defender for Endpoint
Endpoint protection

Test controlled folder access with an untrusted app

In brief

The documentation warns that the setup script excludes `c:\demo` from Microsoft Defender Antivirus. Testers must copy and run `CFAtool.exe` from a folder that is not excluded so the expected CFA block or detection occurs.

What Defender admins need to know

Administrators running this test should use a non-excluded folder for `CFAtool.exe`.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Demonstrate howTest controlled folder access (CFA) blockswith an untrusted app description: Use the controlled folder access (CFA) test tool to see how Microsoft Defender Antivirus blocks an untrusted app from writing to a protected folder. ms.service: defender-endpoint ms.author: chrisda

  • tier2
  • demo ms.topic: how-to ms.custom: msecd-doc-authoring-1015 ms.subservice: asr ms.date: 06/16/08/03/2026 ai-usage: ai-assisted

#customer intent: As a security administrator, I want to use the CFA test tool to confirm that controlled folder access blocks an untrusted app from writing to a protected folder so that I can verify CFA before I deploy it in my environment. appliesto: