How to Enable Ransomware Protection on Windows 10 and 11
Security
5 min readSeptember 8, 2026

How to Enable Ransomware Protection on Windows 10 and 11

Ransomware can lock you out of your own files in seconds — but Windows has built-in defenses most users never turn on. Learn how to activate and configure ransomware protection before it's too late.

Share

Why Ransomware Is One of the Biggest Threats to Your PC

Ransomware attacks have surged in recent years, targeting not just corporations but everyday home users. Once ransomware infects your system, it encrypts your documents, photos, and other personal files — then demands payment to restore access. Even if you pay, there's no guarantee you'll get your data back.

The good news: Windows 10 and Windows 11 include powerful built-in ransomware defenses that most users have never enabled. Combined with smart habits and a tool like **PC Diagnostic Analyzer**, you can dramatically reduce your risk.

Free AI Diagnosis

Dealing with this on your own PC?

Describe your problem and get a real AI diagnosis in seconds — no account needed.

Step 1: Enable Controlled Folder Access in Windows Security

**Controlled Folder Access** is Microsoft's primary ransomware shield. It blocks unauthorized apps from modifying files in protected folders like Documents, Pictures, and Desktop.

To turn it on:

1

Open **Windows Security** (search for it in the Start menu)

2

Click **Virus & threat protection**

3

Scroll to **Ransomware protection** and click **Manage ransomware protection**

4

Toggle **Controlled folder access** to **On**

Once enabled, only trusted applications can write to your protected folders. If an unknown program tries to modify your files, Windows blocks it and sends you an alert.

Adding Protected Folders

By default, Windows protects your standard user folders. You can add custom folders:

1

Under Controlled folder access, click **Protected folders**

2

Click **Add a protected folder**

3

Browse to any folder you want to safeguard — for example, `C:\Users\YourName\Projects`

Allowing Trusted Apps

Some legitimate programs (like older photo editors or backup tools) may be blocked. To whitelist them:

1

Click **Allow an app through Controlled folder access**

2

Click **Add an allowed app** → **Browse all apps**

3

Select the executable you trust

Step 2: Configure OneDrive for Ransomware Recovery

Even with protection enabled, having a recovery path is essential. **OneDrive** integrates directly with Windows ransomware protection and can restore your files if an attack slips through.

Sign in to OneDrive and enable **Files On-Demand** so your documents sync automatically

OneDrive keeps **version history** for up to 30 days — you can roll back individual files or entire folders

If ransomware strikes, open OneDrive online, click **Restore your OneDrive**, and select a point in time before the attack

To verify OneDrive is protecting your files, run this PowerShell command:

```powershell

Get-Item "$env:USERPROFILE\OneDrive" | Select-Object FullName, LastWriteTime

```

If the folder exists and has a recent timestamp, your sync is active.

Step 3: Keep Windows Defender Up to Date

Ransomware protection is only as strong as your antivirus definitions. Windows Defender updates automatically, but you can force an immediate update:

```powershell

Update-MpSignature

```

Or via the command prompt:

```cmd

"C:\Program Files\Windows Defender\MpCmdRun.exe" -SignatureUpdate

```

Check your current definition version with:

```powershell

Get-MpComputerStatus | Select-Object AntivirusSignatureLastUpdated, AntivirusSignatureVersion

```

Definitions older than 24 hours are a risk — make sure automatic updates are not disabled.

Step 4: Disable Unnecessary Remote Access

Ransomware frequently enters systems through **Remote Desktop Protocol (RDP)**. If you don't use remote desktop, disable it:

1

Right-click **This PC** → **Properties**

2

Click **Remote settings**

3

Under Remote Desktop, select **Don't allow remote connections to this computer**

Alternatively, use PowerShell:

```powershell

Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections -Value 1

```

Also check for open RDP ports using:

```cmd

netstat -an | findstr :3389

```

If port 3389 is listening and you don't need it, block it in Windows Firewall.

Step 5: Audit Startup Programs and Scheduled Tasks

Ransomware often establishes **persistence** by adding itself to startup entries or scheduled tasks. Review these regularly:

Open **Task Manager** → **Startup** tab to see what launches at boot

Run `taskschd.msc` to open Task Scheduler and inspect active tasks

Use the registry path `HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run` to check for suspicious auto-run entries

Any entry you don't recognize warrants investigation before it can cause damage.

Step 6: Run a Full System Diagnostic

Beyond manual checks, **PC Diagnostic Analyzer** gives you a comprehensive security overview in minutes. Upload your Windows diagnostic data and the tool scans for:

Outdated drivers that ransomware exploits as entry points

Misconfigured security settings that leave gaps in your defenses

Suspicious startup entries and scheduled tasks flagged as high-risk

Missing Windows updates that patch known ransomware vulnerabilities

Running **PC Diagnostic Analyzer** regularly means you catch vulnerabilities before attackers do — not after.

What to Do If You're Already Infected

If ransomware has already struck:

1

**Disconnect from the internet immediately** — unplug the Ethernet cable or disable Wi-Fi to stop the spread

2

**Do not pay the ransom** — payment doesn't guarantee file recovery and funds criminal operations

3

**Boot into Safe Mode** and run a full Windows Defender offline scan:

```cmd

MpCmdRun.exe -Scan -ScanType 3

```

4

**Restore from OneDrive or a backup** using the version history feature

5

**Report the attack** to the FBI's Internet Crime Complaint Center (IC3) at ic3.gov

Build a Layered Defense

No single tool stops every threat. The strongest ransomware defense combines:

Controlled Folder Access to block unauthorized file changes

OneDrive sync for automatic cloud backups with version history

Up-to-date Defender definitions to catch known ransomware strains

Disabled RDP to close a common attack vector

Regular diagnostics with PC Diagnostic Analyzer to spot new vulnerabilities

Take five minutes today to enable Controlled Folder Access and verify your OneDrive sync — those two steps alone put you ahead of most home users when it comes to ransomware resilience.

Protect Your PC Before Ransomware Strikes

Don't wait for an attack to take security seriously. Run a free diagnostic with **PC Diagnostic Analyzer** right now to uncover hidden vulnerabilities, outdated drivers, and security misconfigurations that could make your system an easy target. A few minutes of prevention today can save you hours — or days — of recovery tomorrow.

Found this helpful?

Share it with someone who could use it.

Share

DiagnoseMyPC Team

Expert PC diagnostics and troubleshooting guides to help you keep your Windows system running smoothly.

Frequently Asked Questions

How do I know if my PC has malware?

Common signs include sudden slowdowns, pop-ups, unfamiliar programs, high network or CPU usage when idle, and browser changes you didn't make. An AI diagnosis can flag suspicious activity in your system data — run a free scan at diagnosemypc.com to check.

Is Windows Defender enough to protect my PC?

For most home users, Windows Defender plus safe browsing habits and regular updates is solid protection. The bigger risks are outdated software, weak passwords, and clicking malicious links — good habits matter more than any single tool.

What should I do first if I think I've been hacked?

Disconnect from the internet, change important passwords from a different device, run a full security scan, and check for unfamiliar programs or startup entries. A diagnosis helps confirm what changed on your system so you know exactly what to clean up.

Does this tool make changes to my PC without asking?

No. The analyzer only reads the diagnostic data you choose to share and shows you any recommended fixes first. You stay in complete control of what actually runs on your computer.

Free Diagnostic Tool

Having PC Issues? Let AI Diagnose Them

Get an AI-powered analysis of your Windows PC in under 5 minutes — no technical knowledge required, no account to get started.