How to Allow Apps in Windows 11 Controlled Folder Access
Controlled Folder Access in Windows 11 protects your personal files from ransomware and other untrusted programs by locking down folders like Documents and Pictures. This built-in security tool stops apps from changing or deleting your files until you give them permission to pass.
You can let your favorite games and work tools run normally by adding them to the allowed list in the Windows Security app. Open Windows Security, click Virus & threat protection, and pick Manage ransomware protection to get started.
To allow an app through Windows 11 Controlled Folder Access, open Windows Security, go to Virus & threat protection, then Ransomware protection. Click “Allow an app through Controlled folder access,” select “Add an allowed app,” and browse to the program you wish to permit.
Understanding 🪟 Windows 11 Controlled Folder Access
Windows 11 controlled folder access is a security tool that protects your important files from unwanted changes, especially from ransomware that tries to lock up your data.
Why do this?
Sometimes, Windows 11 blocks a safe app because it thinks the app is a threat. By adding that app to your allowed list, you tell Windows that the program is safe to use. This keeps your files protected while letting your trusted apps work normally.
What happens when done?
Once you add an app to the list, it can read and write to your protected folders without being blocked. Ransomware will still be blocked by default, keeping your data safe from being locked by hackers.
Allowing apps through Controlled folder access
Windows 11 controlled folder access protects your files from unauthorized changes, but it can sometimes block trusted programs. You can fix this by adding the blocked app to your allowed apps list through the Windows Security app, which lets the program run normally while keeping your computer secure.
- Click the search box on your taskbar, type Windows Security, and click Windows Security.

open windows security app - Click Virus & threat protection.

open windows virus and protection - Look for Ransomware protection and click Manage ransomware protection.

windows 11 controlled folder access turn on - Make sure Controlled folder access is turned On.

windows 11 turn on controlled access folder - Click the link that says Allow an app through Controlled folder access.

windows 11 allow app through protected folders - Click Add an allowed app. Find the program you want to allow on your computer and click Open.

windows 11 allow app through protected folder button
Managing access with PowerShell (Admin)
PowerShell (a command-line tool for advanced tasks) lets you manage Windows 11 controlled folder access quickly using text commands instead of clicking through settings menus. You can run a specific command with administrator rights to add an app to your allowed list instantly.
You can use PowerShell to quickly whitelist applications for Controlled Folder Access in Windows 11. Open PowerShell as an administrator, which gives you special permissions, and use the following command to add an application to the allowed list.
The command you use adds the specified executable to the whitelist. This action allows the executable to bypass the Controlled Folder Access restriction immediately. This bypass is crucial for applications like photo editors that need to save files to protected folders on your Windows 11 device.
Managing access with Registry (Admin)
Navigate to HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications. You can add a new string value here with the full path of your application.
Troubleshooting and Event Viewer
When Windows 11 controlled folder access blocks an app, you can check the Event Viewer to see exactly which program was stopped, helping you troubleshoot the issue.
Enterprise and MDM Deployment
In a business environment, IT administrators use Microsoft Defender for Endpoint and Attack Surface Reduction (ASR) rules to manage these settings across many computers. Using Intune or Group Policy, admins can push a centralized list of allowed applications to ensure consistent threat prevention across the entire organization.
Summary
Controlled folder access is a vital layer of data security. By managing your allowed apps through the GUI, PowerShell, or Registry, you ensure that legitimate software functions correctly while keeping ransomware at bay. Always check the Event Viewer if you suspect a legitimate app is being blocked.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
No comments yet — be the first to share your thoughts!