diff --git a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md index da3a63cae7..08d11df095 100644 --- a/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md +++ b/windows/security/threat-protection/windows-defender-exploit-guard/evaluate-controlled-folder-access.md @@ -49,7 +49,7 @@ You can also use Group Policy, Intune, MDM, or System Center Configuration Manag ## Review controlled folder access events in Windows Event Viewer -The following controlled folder access events appear in Windows Event Viewer. +The following controlled folder access events appear in Windows Event Viewer under Microsoft/Windows/Windows Defender/Operational folder. | Event ID | Description | | --- | --- |