Testing Controlled Folder Access

IMK 421 Reputation points
2023-02-22T15:21:40.4933333+00:00

Hi

I was testing CFA with instructions in below URL.

https://demo.wd.microsoft.com/Page/CFA2

I was following the scenario 1.

I downloaded the CFA test tool, opened it, used it to create a file to different controlled folders and every time this tool was able to create a test file to all controlled folders.

What I understood was that this tool is not suppose to be able to create test files to any controlled folders but it can.

Controlled Folder Access is enabled and this is checked via Defender app. Also checked the controlled folders via Defender app.

What am I missing??

Microsoft Intune Security
Microsoft Intune Security
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
371 questions
Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,785 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,669 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Fiona Matu 86 Reputation points Microsoft Employee
    2024-02-18T12:17:49.8833333+00:00

    The CFA test tool from Microsoft is designed to test the functionality of the Controlled Folder Access feature in Windows Defender. The tool doesn't bypass the CFA but rather, it is automatically allowed by CFA. It's whitelisted by Microsoft to test the functionality of CFA. The CFA feature in Windows Defender is designed to protect against unauthorized applications from making changes to files in protected folders. If an unauthorized application tries to modify or delete a file in a protected folder, the user is notified about the attempt. If the CFA test tool could not create files in the controlled folders, then it would not be able to effectively test the functionality of the CFA feature. The CFA test tool is designed to demonstrate what would happen if an unauthorized application tried to make changes to files in a protected folder. However, if you want to test the CFA feature with an unauthorized application, you could try using a different application that is not whitelisted by Microsoft. If the CFA feature is functioning correctly, you should receive a notification that the application attempted to make changes to a file in a protected folder. Please note that the "Controlled folder access" feature is meant to help protect your files from being changed by suspicious or malicious apps. It's not designed to prevent all changes to files in protected folders. Some apps that are safe and trusted by Microsoft might still be allowed to make changes to files in protected folders. Refer to this page for more information about the Controlled Folder Access feature.

    0 comments No comments