Flamingo Raises $4.5M Seed Round

Skip to content

Windows Security has one page that a lot of support tickets pass through. It shows whether the PC is scanned, current and protected from ransomware, and it is also where the switches live. This guide walks through virus and threat protection in Windows Security, what each section does, how Controlled Folder Access fits in, and why the page is sometimes greyed out.

What the Page Shows

Microsoft's support page for the app splits virus and threat protection into four areas (Microsoft Support, 2026). Current threats lists what Windows found, the last scan with its duration and file count, and anything you chose to allow. Virus & threat protection settings holds the switches. Virus & threat protection updates shows the security intelligence version, the files that tell Defender what the latest threats look like. Ransomware protection holds Controlled Folder Access and the OneDrive recovery link.

Four scan types sit under Scan options. A quick scan skips the time cost of a full one. A full scan reads every file and program. A custom scan reads only the folders you pick. The fourth, Microsoft Defender Antivirus (offline scan), restarts the PC into the Windows Recovery Environment and scans before Windows loads, so persistent malware has a harder time hiding. Save open work first, because it reboots the machine, and read the result under Protection history.

NetworkChuck Academy's video above walks through changing these settings in Windows, which helps when you are talking a user through the page by phone.

The Settings Worth Knowing

Real-time protection scans files as they are opened or run. If you switch it off, it turns itself back on after a short while, and scheduled scans keep running in the meantime. Cloud-delivered protection lets Defender pull the newest detections while the PC is online. Automatic sample submission sends suspicious files to Microsoft for checking, and the app tells you before it asks for a file that might hold personal data.

Tamper protection stops other apps from changing settings such as real-time and cloud protection. An administrator can still change them in the app, but nothing else can. When tamper protection is on, you must turn it off before real-time protection will go off. Our guide to turning Defender off temporarily covers that trap and the cleaner alternatives, so this page stays on what each setting does.

Exclusions skip a file, folder, file type or process in real-time scanning only. Scheduled scans can still read them. Microsoft's advice for a process exclusion is to use the full path and file name, because a bare name gives malware a way to impersonate the excluded process. Dev Drive protection adds a performance mode that defers scans until after a file operation finishes, which matters to developers on Windows 11 and does not exist on Windows 10.

Controlled Folder Access, Explained

Controlled Folder Access blocks untrusted apps from changing files in protected folders. Defender checks every executable and trusts most apps by prevalence and reputation. Anything with an unknown reputation that tries to write to a protected folder is blocked, and you get a notification and a Protection history entry. The default folders are Documents, Favorites, Music, Pictures and Videos under each user profile, and the public equivalents. Microsoft's documentation says the default list cannot be changed, but you can add more folders, and when OneDrive Known Folder Move redirects a folder, CFA protects the redirected location.

It is off by default. It also needs Microsoft Defender Antivirus in Active mode with real-time protection on, so it does nothing on a PC where a third-party product has put Defender in passive mode. Microsoft's CFA documentation (updated July 2026) lists five modes.

ModeCodeWhat happens
Disabled0Off. All apps can change protected files
Enabled (Block)1Untrusted apps are blocked and logged
Audit Mode2Nothing is blocked, attempts are logged
Block disk modification only3Blocks writes to boot sectors, not folders
Audit disk modification only4Logs boot sector writes only

An r/sysadmin thread from November 2025 shows the usual surprise. An admin turned CFA on and found Word and Excel autosave failing for a few staff, because Defender blocked winword.exe and excel.exe from the Documents and OneDrive folders. The question was how Defender decides which apps are friendly, since nothing shows up in Get-MpPreference. The answer in Microsoft's documentation is reputation and prevalence, and it is not a list you can read on the device.

Roll It Out in Audit Mode First

Microsoft recommends audit mode before block mode, and the thread above shows why. In audit mode nothing is blocked, and every attempt lands in the Windows Defender Operational log. Event 1124 is an audited CFA event, 1123 is a blocked one, 1127 and 1128 are the blocked and audited boot sector writes, and 5007 records a settings change. Read a week of 1124 events, allow the apps your users need, then switch to Enabled.

powershell
# Turn on audit mode, then add an allowed app without touching the existing list
Set-MpPreference -EnableControlledFolderAccess AuditMode
Add-MpPreference -ControlledFolderAccessAllowedApplications "C:\Apps\app1.exe"

# After a week of events, move to block mode
Set-MpPreference -EnableControlledFolderAccess Enabled

Allowed-app paths can use environment variables and wildcards, and a newly allowed app must be restarted before the change applies. A second r/sysadmin thread, from August 2025, hits the classic edge. An admin needs PowerShell 7 allowed, but the Store version installs into a WindowsApps folder whose name changes with each update. The replies offered three routes: use the MSI install, run an Intune remediation script that rewrites the path, or add a certificate-based indicator in the Defender portal.

For a fleet, Microsoft names Intune endpoint security policies as the recommended route, with Group Policy, the Policy CSP, Configuration Manager and PowerShell as alternatives. Block events do not appear in the Defender alerts queue, so you read them from advanced hunting, the device timeline or forwarded events. Our post on log management covers collecting events like these centrally. OpenFrame can run Get-MpPreference and Get-MpComputerStatus across a client's devices and collect the output, which shows the CFA mode and the protection state of every machine in one list.

When the Page Is Greyed Out

Three situations make the page look wrong. If the settings are deployed by Group Policy, they are greyed out on each endpoint until the policy applies, and users cannot change them. If a compatible non-Microsoft antivirus is installed and current, Defender turns itself off or goes passive, and the page reflects that product. And if tamper protection is on, a change pushed through a management tool, Group Policy included, can look as though it worked while tamper protection blocks it.

Do not disable the Windows Security app to fix any of this. Microsoft says doing so does not turn off Defender Antivirus or the firewall, can leave the app showing stale information about installed products, and can stop Defender from re-enabling when you remove a third-party product. For a closer look at where Defender stops and a business tool starts, read our guide to business antivirus.

The Short Version

The page has four jobs: show current threats, hold the settings, keep intelligence updates current, and run ransomware protection. Leave real-time, cloud, sample submission and tamper protection on. Turn Controlled Folder Access on in audit mode, read the 1124 events for a week, allow the apps your users need, then block. A greyed-out page points to Group Policy, a third-party antivirus or tamper protection before it points to a broken PC. For a managed estate that needs reporting across devices, the Defender XDR review covers what the paid layer adds.

FAQ

What is Virus and Threat Protection in Windows Security?

It is the Windows Security page that shows current threats, scan options, protection settings, security intelligence updates and ransomware protection. It controls Microsoft Defender Antivirus, or reports on a third-party antivirus product when one is installed.

Is Controlled Folder Access on by default?

No. It is off by default and has to be turned on, then set to a mode. It needs Microsoft Defender Antivirus in Active mode with real-time protection on, so it does not work when a third-party antivirus has Defender in passive mode.

Why is Virus and Threat Protection greyed out or managed by my organization?

Usually a Group Policy or Intune policy sets those options and locks them on each device. A third-party antivirus can also take over, which turns Defender off or passive. Check the policy first.

How do I see what Controlled Folder Access blocked?

Open Protection history in the Windows Security app, or read events 1123 (blocked) and 1124 (audited) in the Windows Defender Operational log. Block events do not raise alerts in the Defender portal, so use advanced hunting or the device timeline there.

"Fae" Grace Meadows

"Fae" Grace Meadows

Lead AI Fairy

Some things defy easy explanation: magic dust, the northern lights… and Flamingo’s AI Angels. Think Charlie’s Angels, reimagined with automation brains and serious RMM (Remote Monitoring & Management) chops. Weird? A little. Effective? Absolutely. That’s the job.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Virus and Threat Protection

It is the Windows Security page that shows current threats, scan options, protection settings, security intelligence updates and ransomware protection. It controls Microsoft Defender Antivirus, or reports on a third-party antivirus product when one is installed.
No. It is off by default and has to be turned on, then set to a mode. It needs Microsoft Defender Antivirus in Active mode with real-time protection on, so it does not work when a third-party antivirus has Defender in passive mode.
Usually a Group Policy or Intune policy sets those options and locks them on each device. A third-party antivirus can also take over, which turns Defender off or passive. Check the policy first.
Open Protection history in the Windows Security app, or read events 1123 (blocked) and 1124 (audited) in the Windows Defender Operational log. Block events do not raise alerts in the Defender portal, so use advanced hunting or the device timeline there.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.