CFA ransomware mitigations
CFA is yet another feature in the ASR space that leverages the Defender engine to harden devices against ransomware and other destructive apps or threats. The whole concept of CFA is to control which apps are allowed to access what are marked as protected folders.
Operating modes
CFA has been designed to operate on unfriendly and untrusted processes. These are processes that are not validly signed and, based on Microsoft’s cloud reputation system, not known to be, or not already determined as, clean or friendly processes. CFA provides multiple levels of blocking and auditing for the activities performed by such processes in the form of various operational modes.
Disable (default)
In this mode, the feature is disabled and won’t block any activity from any process. By default, CFA is disabled and needs to be explicitly enabled in one of the non-disabled modes to block or audit the activity.
Enable (block)
In this mode, CFA ensures...