How to enable ransomware protection in Windows 10 Pro

Ransomware protection in Windows 10 Pro helps prevent suspicious programs from changing, encrypting, or deleting files in important folders. If malicious software reaches your computer, this extra layer can limit access to documents, pictures, spreadsheets, and other personal data.

The main feature is Controlled folder access, which is part of Windows Security and Microsoft Defender Antivirus. It monitors protected locations and blocks unfamiliar applications from making changes unless you approve them. The setting works alongside antivirus scanning, firewall protection, account security, and regular backups.

Before changing security settings, make sure Windows 10 is fully updated and Microsoft Defender is active. If your computer uses another antivirus product, some Defender controls may be hidden or managed by that program. Reviewing the Windows 10 update process can help resolve outdated security definitions or missing Windows Security options.

Find the ransomware protection settings

Open the Start menu, type Windows Security, and select the matching app. You can also reach it through Settings > Update & Security > Windows Security > Open Windows Security. The Windows Security dashboard groups protection tools in one place, including virus scanning, firewall controls, device security, and account protection.

Select Virus & threat protection. Under the protection summary, look for Ransomware protection, then choose Manage ransomware protection. If the option is not visible, expand the Windows Security window or install pending Windows updates. A third-party antivirus application may also have taken control of Microsoft Defender.

The Ransomware protection page contains Controlled folder access, along with links for reviewing blocked applications and recovering files through supported cloud backup services. The feature can be enabled without changing your normal antivirus scan schedule. Microsoft Defender will continue scanning files while Controlled folder access watches protected folders for unauthorized changes.

Turn on controlled folder access

On the Ransomware protection page, switch Controlled folder access to On. Windows immediately begins protecting common locations such as Documents, Pictures, Videos, Music, Desktop, and Favorites. The exact list can vary depending on the Windows version and the folders associated with your user profile.

When an untrusted application tries to save or modify a file in a protected folder, Windows may block the action and display a notification. This does not automatically mean the application is malicious. Older utilities, photo editors, games, accounting tools, and custom programs sometimes need permission because they do not meet Microsoft’s trust criteria.

Use the feature for important data rather than disabling it at the first warning. A blocked program can often be allowed safely after you confirm that it came from a legitimate publisher and behaves as expected. Ransomware protection is most useful when it prevents unexpected file changes while still allowing the software you rely on to work.

Allow trusted applications carefully

Select Allow an app through Controlled folder access, then choose Add an allowed app. Windows provides options to view recently blocked applications or browse to a specific executable file. Select the actual program file that needs access, not a download shortcut, installer, or unknown helper file.

Only allow software obtained from a reputable source. Check the publisher, installation location, and reason the application needs to write inside a protected folder. A program that merely reads a document may not require an exception, while a document editor or backup utility may need permission to save changes.

Avoid adding broad folders such as Downloads or allowing every executable on the computer. A ransomware infection can use an approved application as a route to protected files. If a program stops working after an update, remove its old permission and add the current executable only after verifying the update.

The Block history area can help explain failed saves or missing files. Review the application name and affected location before taking action. If a notification points to an unfamiliar executable, leave it blocked and run a full Microsoft Defender scan rather than approving it.

Protect folders and keep backups

Controlled folder access protects several standard locations by default, but you can add other folders. Select Protected folders, choose Add a protected folder, and browse to a location containing valuable files. Consider adding a separate work folder, a project directory, or a local archive that is not already included.

Do not treat folder protection as a replacement for backups. Ransomware can affect files outside protected locations, damage connected drives, or compromise an account that synchronizes changes. Keep at least one backup disconnected from the computer when it is not being used. An external drive that remains permanently connected may be affected by the same attack.

File History, an external backup program, or a trusted cloud service can provide additional recovery options. Check that backups contain readable copies rather than only placeholders or synchronized deletions. Occasionally restore a test file so you know where recovery options are located before an emergency occurs.

Protection option What it does Best use Important limitation
Controlled folder access Blocks unapproved apps from changing files in protected folders Preventing suspicious encryption or deletion Legitimate apps may need individual approval
Microsoft Defender scans Detects known malware and suspicious behavior Finding threats before they run Detection is not a substitute for backups
File History Stores earlier versions of selected files Recovering changed or deleted personal files The backup drive must be available and healthy
Cloud file recovery Restores files through a supported online service Recovering from widespread local damage Synced ransomware changes may also reach the cloud
Offline backup Keeps a separate copy disconnected from the PC Recovery after a severe infection It requires regular manual or scheduled updates

Adjust settings without weakening security

Windows Security includes additional controls that support ransomware defense. Keep Real-time protection enabled, and allow cloud-delivered protection and automatic sample submission when you are comfortable sending suspicious samples to Microsoft. These features help Defender identify current threats, although they require an active internet connection for some checks.

Tamper Protection can stop unwanted applications from changing important Defender settings. Find it under Virus & threat protection settings > Manage settings, then leave it enabled unless a trusted administrator has a specific reason to change it. Turning off multiple protections to solve a single compatibility problem leaves the computer exposed.

Use Exclusions sparingly. An exclusion tells Defender to skip a file, folder, file type, or process during certain scans. It does not provide the same targeted permission as Controlled folder access, and a wide exclusion can hide malware. Remove temporary exclusions when troubleshooting is complete.

Windows Hello can strengthen account security by reducing dependence on a stolen password. A PIN, fingerprint, or compatible facial sign-in does not directly replace ransomware protection, but it can make unauthorized account access harder. The Windows Hello setup guide explains how to configure these sign-in options in Windows 10 Pro.

Test and troubleshoot blocked file changes

After enabling Controlled folder access, open a trusted application and save a test document in a protected folder. If the save succeeds, normal access is working. If it fails, check the notification area and return to Windows Security > Virus & threat protection > Ransomware protection to review recent activity.

When an essential application is blocked, update it from the developer’s official website first. Modern versions may be recognized automatically after an update. If the problem continues, add only the verified executable through the allowed-apps list. Restart the application after granting permission because some programs do not retry a failed operation automatically.

If the ransomware protection page cannot be opened, restart the computer and install pending quality updates. Confirm that the Security Center service is running and check whether group policies or another antivirus application controls Defender. Work or school computers may have settings managed by an administrator, so local changes may be unavailable.

Persistent warnings, unknown blocked programs, or sudden file-renaming activity deserve immediate attention. Disconnect the computer from the network if you suspect an active infection, avoid opening affected files, and use a separate trusted device to review recovery and support information. Do not pay or communicate with attackers before obtaining professional guidance, since payment does not guarantee file recovery.

Maintain a safer Windows setup

Ransomware protection is strongest when several habits work together. Keep applications updated, use a standard user account for everyday tasks when practical, and avoid opening unexpected attachments or enabling macros in documents from unknown sources. Pirated software and unverified activators are frequent sources of malware and should not be used.

Apply these maintenance practices regularly:

Store recovery information separately from the computer. A printed list of important account details, backup locations, and trusted support contacts can be useful when the affected machine cannot be trusted. Protect cloud accounts with strong, unique passwords and multifactor authentication so attackers cannot simply delete or encrypt synchronized copies.

Enable the protection feature, test a trusted application, and verify a recent backup today. These small checks turn Windows 10 Pro’s built-in security tools into a practical defense against unauthorized file changes and make recovery more manageable if malware reaches the system.