Access to folders under control in Windows 10
Access to folders under control in Windows 10
CFA operational logs appear in the event log under Applications and Services > Microsoft > Windows > Windows Defender > Operational. For blocked accesses, focus on Event ID 1123 to view all blocked entries. ID 5007 indicates changes to settings and lists the registry path for permitted programs—HKLM\SOFTWARE\Microsoft\Windows Defender\Windows Defender Exploit Guard\Controlled Folder Access\AllowedApplications\*. Setting up a custom view can help you quickly monitor these logs.