Record the environment first
Capture the Windows version, installed product version, package hash, service configuration, filter status and test location. Use a test computer or virtual machine with a recovery snapshot. Preserve a separate backup of all test material.
Verify component health
Confirm that the user interface, background service and filesystem protection component agree about status. If any authoritative component is unavailable, stop testing with business data. A healthy dashboard without active enforcement is not sufficient.
Test permitted operations
Create a disposable file, open it, edit it, save repeatedly, close it and reopen it. Rename, move and copy it according to the intended workflow. Repeat with common business applications. Permitted operations should remain dependable after protection is enabled.
Test prohibited operations
Attempt deletion through File Explorer, Command Prompt and PowerShell. Test nested files and folders. For an archived location, also attempt create, overwrite, rename and move. After every denied action, confirm the target physically exists and can still be opened.
Restart and persistence
Restart the service and reboot Windows. Confirm protected locations remain visible, archive state persists and enforcement reconnects. Repeat a disposable delete test and check that a current audit event identifies the correct computer, user and action when that information is available.
Define stop conditions
Stop relying on protection if deletion succeeds, locations disappear, the service or filter is unavailable, normal file saving becomes unreliable or data integrity is uncertain. Preserve logs and exact reproduction steps before making further changes.
