Enable Controlled Folder Access blocks Onedrive.exe

IMK 421 Reputation points
2023-02-21T17:20:12.31+00:00

Hi

I have Enabled Controlled Folder Access (Endpoint Manager -> Endpoint security -> Attack surface reduction -> Attack Surface Reduction Rules (policy) -> Enable Controlled Folder Access).

In Windows 11 device, this resulted onedrive.exe to be blocked and Known Folder Move didn't work for Documents and Pictures folders, which are default folders in Controlled Folder Access.

This haven't been a problem before and I noticed with this one new device, which happened to be Windows 11. All other devices are Windows 10.

Why Controlled Folder Access now started to block onedrive.exe? Is this some Win 10/11 difference?

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,788 questions
Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
370 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Pavel yannara Mirochnitchenko 12,391 Reputation points MVP
    2023-02-21T21:15:40.32+00:00

    Have you tried add Onedrive to allowed app list in Controlled Folders?


  2. IMK 421 Reputation points
    2023-02-22T15:14:44.0466667+00:00

    This was a new device.

    Could it be possible that the onedrive started in user profile after OOBE but changed to machine-wide installation of onedrive?

    What I have understood, if OneDrive.exe resides in user profile, Defender is not considering as safe. But if it is a machine-wide installation, OneDrive.exe is in Program Files -folder, it is considered as safe.

    0 comments No comments

  3. Limitless Technology 44,081 Reputation points
    2023-02-23T09:46:45.6866667+00:00

    Hi. Thank you for your question and reaching out. I’d be more than happy to help you with your query

    When you enable Controlled Folder Access (CFA) in Windows Defender Security [1], Onedrive.exe will be blocked from modifying or creating files in certain folders. CFA is designed to help protect your files from ransomware and other malicious software by restricting access to protected folders and their subfolders. To enable CFA, open the Windows Security app, and select Virus & Threat Protection > Manage Settings > Controlled Folder Access > On. You can then select the folders you want to protect and add them to the protected list.

    If the reply was helpful, please don’t forget to upvote or accept as answer, thank you.

    0 comments No comments