Record the environment first

Capture the Windows version, installed product version, package hash, service configuration, filter status and test location. Use a test computer or virtual machine with a recovery snapshot. Preserve a separate backup of all test material.

Verify component health

Confirm that the user interface, background service and filesystem protection component agree about status. If any authoritative component is unavailable, stop testing with business data. A healthy dashboard without active enforcement is not sufficient.

Test permitted operations

Create a disposable file, open it, edit it, save repeatedly, close it and reopen it. Rename, move and copy it according to the intended workflow. Repeat with common business applications. Permitted operations should remain dependable after protection is enabled.

Test prohibited operations

Attempt deletion through File Explorer, Command Prompt and PowerShell. Test nested files and folders. For an archived location, also attempt create, overwrite, rename and move. After every denied action, confirm the target physically exists and can still be opened.

Restart and persistence

Restart the service and reboot Windows. Confirm protected locations remain visible, archive state persists and enforcement reconnects. Repeat a disposable delete test and check that a current audit event identifies the correct computer, user and action when that information is available.

Define stop conditions

Stop relying on protection if deletion succeeds, locations disappear, the service or filter is unavailable, normal file saving becomes unreliable or data integrity is uncertain. Preserve logs and exact reproduction steps before making further changes.