← Back to Blog

Troubleshooting | Aug 3, 2026 | 8 min read

Is Your Antivirus Blocking the Clipboard? How to Check

By Mohit Sehrawat

Is Your Antivirus Blocking the Clipboard? How to Check — Edge Drop Guide

A clipboard manager that launches but captures nothing is rarely broken. The more common cause is a security suite — Windows Defender, a third-party antivirus, or an enterprise endpoint-protection agent — hooking the clipboard and blocking the manager from reading it. This guide covers the typical suspects, the Microsoft-side controls (Controlled Folder Access, Windows Information Protection), and a clean test for whether a security product is the cause before adding exclusions.

For related problems, see Windows Sandbox has no lasting history for the disposable-VM case, corrupt clipboard cache after Insider builds for flighting-side breakage, and the general Win+V not working on Windows 11: 9 fixes and Win+V Says 'Nothing Here'? How to Fix Clipboard History on Windows 11 references.

How antivirus hooks the clipboard

Security products intercept clipboard operations for two reasons: anti-ransomware (detecting mass file-list copies) and data-loss prevention (detecting sensitive content leaving the device). The hook is implemented as a filter driver, a notification handler, or both. When a clipboard manager running on the same machine tries to read the clipboard, the security product can intervene in three ways:

  • Block the read entirely. The manager sees an empty clipboard even when content is present.
  • Allow the read but strip formats. The manager sees plain text but not HTML or bitmap.
  • Allow the read but quarantine the content. The manager sees the content briefly, then it disappears.

The first is the most common and the one users notice. The third is rare and is usually tied to a DLP rule that flagged the content.

Microsoft-side controls to check first

Before blaming a third-party suite, check the controls built into Windows. These are the ones most likely to interfere with clipboard managers.

Controlled Folder Access

Controlled Folder Access is the ransomware-protection feature of Microsoft Defender. It blocks unrecognised apps from writing to protected folders (Documents, Pictures, etc.). It does not block clipboard reads directly, but if a clipboard manager writes its history database into a protected folder, the write is blocked and the manager behaves as if the clipboard is empty.

The fix is to add the manager's executable to the Controlled Folder Access allow list. Settings → Privacy & security → Windows Security → Virus & threat protection → Manage ransomware protection → Allow an app through Controlled Folder Access.

Windows Information Protection (WIP)

WIP is an enterprise data-protection feature that classifies apps as "work" or "personal" and restricts what can move between them. A clipboard copy from a work-enlightened app to a personal app can be silently blocked. If the device is enrolled in WIP (typical for Intune-managed devices), this is a likely cause.

WIP configuration is at the tenant level; the user cannot simply toggle it off. The diagnostic is to copy from an obviously personal app (Notepad) and see whether the manager captures it; if yes, WIP is likely blocking work-context copies. For more on the enterprise angle, see enterprise controls for Windows clipboard history and clipboard history grayed out by organization.

Microsoft Defender Exploit Protection

Exploit Protection includes per-application mitigations that can block clipboard access for hardened apps. Settings → Privacy & security → Windows Security → App & browser control → Exploit protection settings. Check the per-application overrides for the clipboard manager's executable; "Validate heap integrity" and "Export address filtering" do not affect clipboard, but "Block low-IL images" and similar integrity controls can.

Third-party suites

Common third-party suites that hook the clipboard include Kaspersky, Bitdefender, ESET, Sophos, CrowdStrike Falcon, SentinelOne, and Symantec/Broadcom. Each has its own exclusion mechanism; the steps below are the general pattern.

Kaspersky

Kaspersky's "Application Privilege Control" and "Data Encryption" modules can block clipboard reads by unrecognised apps. The exclusion path is Settings → Additional → Threats and Exclusions → Exclusions → Add the manager's executable. Kaspersky also has a "Clipboard data protection" toggle in some product tiers; turning that off temporarily is the fastest diagnostic.

Bitdefender

Bitdefender's "Advanced Threat Defense" and "Anti-Ransomware" modules hook clipboard for behavioural detection. Settings → Protection → Advanced Threat Defense → Settings → Exceptions → Add the manager's executable. The Anti-Ransomware module has its own separate allow-list under Protection → Anti-Ransomware → Allowed apps.

ESET

ESET's "Anti-Theft" and "Network Connection Inspector" do not affect clipboard, but "Real-time file system protection" can block writes to the manager's database. Settings → Advanced setup → Antivirus → Exclusions → Performance exclusions → Add the manager's executable and its data folder.

Sophos and CrowdStrike

These are enterprise-managed agents. The user cannot add exclusions locally; the exclusion must be added to the policy in Sophos Central or Falcon. The diagnostic is the same — copy from Notepad, see if the manager captures — but the fix requires an IT ticket. For the broader policy picture, see enterprise controls for Windows clipboard history.

A clean diagnostic test

Before adjusting any setting, run this 30-second test to confirm whether a security product is the cause:

  • Open Notepad on the host. Type a short string and copy it with Ctrl+C.
  • Open the clipboard manager. If it shows the string, the manager is reading the OS clipboard correctly.
  • If the manager does not show the string, copy the same string from a different app (WordPad, a browser address bar, PowerShell). If none of them appear, the manager is blocked from reading the clipboard.
  • Temporarily disable the third-party antivirus (or, on Defender, temporarily turn off Real-time protection). Re-test.
  • If the manager captures content with AV off but not with AV on, AV is the cause. Add the exclusion; do not leave AV off.

Microsoft Defender can be paused for a short period from Settings → Privacy & security → Windows Security → Virus & threat protection → Manage settings → Turn off Real-time protection. The pause is time-limited and reverses automatically.

What to whitelist

The exclusion target is the manager's main executable. Common paths:

  • Ditto: C:\Program Files\Ditto\Ditto.exe
  • CopyQ: C:\Program Files\CopyQ\copyq.exe
  • Edge-Drop: the install path chosen at setup, typically C:\Users\username\AppData\Local\Programs\edge-drop\Edge-Drop.exe for the per-user install or C:\Program Files\Edge-Drop\Edge-Drop.exe for the per-machine install
  • Windows native clipboard: no exclusion needed; the Clipboard User Service is part of the OS

Excluding a single executable is the right granularity. Do not exclude the entire Program Files directory or the user profile; that is too broad.

Edge-Drop's position

Edge-Drop, the Windows clipboard shelf, is one of the managers that can be blocked. It reads the clipboard via the same OS API as Ditto and CopyQ, so the same exclusion pattern applies. Edge-Drop does not require any special AV integration; the standard per-executable exclusion is sufficient.

Edge-Drop does not ship cloud sync, scripting, or capture features; it does not attempt to bypass security products. If a security suite blocks it, the answer is the same exclusion path as for any other manager.

Symptom patterns that point to AV

Several user-reported patterns are characteristic of AV interference rather than a manager bug:

  • Manager captures some content but not other content. Plain text from Notepad is captured; HTML from Outlook is not. This points to format stripping, which is typical of DLP rules that target rich formats.
  • Manager captures for an hour, then stops. The capture works after a reboot or AV service restart, then degrades. This points to a behavioural rule that has learned to flag the manager after observing repeated clipboard reads.
  • Manager works for one user on the device but not another. This is almost always WIP or AppLocker policy scoped per user, not a global AV block.
  • Manager works with AV paused, fails with AV running, with no other change. Direct confirmation that AV is the cause.
  • Win+V also fails to save new items. When Win+V itself is affected, the cause is usually the Clipboard User Service being blocked by a driver filter, not the third-party manager. For that case, see Win+V Says 'Nothing Here'? How to Fix Clipboard History on Windows 11.

Recognising the pattern shortens the diagnostic significantly. A manager that captures some content is not broken; it is being selectively filtered.

What gets flagged

DLP rules in enterprise suites typically flag clipboard content that matches patterns for:

  • Credit card numbers (16-digit patterns matching issuer ranges)
  • Social Security numbers (US-style 9-digit patterns)
  • IBAN and SWIFT codes
  • Email addresses combined with specific sender domains
  • Strings matching a custom keyword list (project codenames, internal system names)

When the clipboard contains such a string and the manager tries to read it, the DLP rule can block the read silently. The user sees the string in the source app, copies it, and the manager captures nothing. This is the intended behaviour of the DLP rule, not a bug in either the manager or the source app.

For the broader enterprise picture of what gets blocked and why, see enterprise controls for Windows clipboard history.

Recovery after a false positive

When a DLP rule blocks content that should not have been blocked, the recovery path is policy-side, not device-side. The user cannot whitelist content locally. The IT admin adjusts the policy in the suite's management console (Defender for Endpoint, Symantec Cloud Console, etc.) and the block clears on the next policy refresh.

The user-facing workaround in the meantime is to copy the content in a slightly different form — for example, splitting a long string across two copies, or removing the characters that triggered the pattern match. This is not a fix; it is a stopgap until the policy is corrected.

Troubleshooting checklist

  • Run the clean diagnostic test with Notepad before changing any settings.
  • Check Controlled Folder Access allow list for the manager's executable.
  • Check whether the device is WIP-enrolled (typical for Intune-managed devices) and test with personal-context content.
  • Check Exploit Protection per-app overrides for the manager's executable.
  • Add a per-executable exclusion in the third-party suite's settings.
  • For enterprise-managed suites (Sophos, CrowdStrike, SentinelOne), file an IT ticket with the diagnostic test results.
  • Re-enable AV after testing. Do not leave Real-time protection off as a "fix".

What to avoid

  • Disabling antivirus entirely as a fix. A short pause for diagnosis is fine; a permanent disable is not. The correct fix is an exclusion, not a shutdown.
  • Excluding the entire user profile or Program Files. Exclusions should be per-executable.
  • Blaming the clipboard manager first. Most managers behave correctly when no security product is interfering. Test the manager with AV paused before deciding the manager is broken.
  • Inventing a registry key or hidden setting. Microsoft Defender's controls are listed in the Microsoft Learn documentation; do not invent controls that are not there.

Related reading

Sources

Mohit Sehrawat
Written by Mohit Sehrawat · Author & Software Tester

Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.

GitHub · LinkedIn

Copy. Stack. Drop.

Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.

Download for Windows Get from Microsoft Store

How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support

Free · Lightweight · Privacy First
Find us on CodeHype