Why Windows privacy is complicated
Windows has developed from a largely self-contained desktop operating system into a platform that depends heavily on internet-connected services.
Some of those connections are necessary or beneficial. Windows uses the internet for security updates, malware definitions, activation, certificate checks, cloud storage, account synchronisation and services that the user has deliberately enabled.
The difficulty is separating those useful connections from diagnostics, advertising, experimentation, personalised recommendations, cloud-delivered content, Bing integration, widgets, browser reporting, location services and other forms of data collection.
Windows 11 provides numerous privacy controls, but they are distributed across several areas of Settings. More advanced options may require Group Policy, and feature updates can alter, reset or replace existing controls. Switching off one option may also address only a small part of a wider connected service.
A Windows computer cannot realistically be made entirely private while it continues to use Microsoft services. Nevertheless, careful configuration can substantially reduce the information it sends.
Why persistent device identifiers deserve attention
Public discussion about global or persistent device identifiers has highlighted an important privacy issue: separate events become easier to associate when they repeatedly contain an identifier linked to the same installation or physical device.
Individual requests do not necessarily contain a person's real name. However, a stable identifier can make it possible to connect activity across different sessions, applications and Microsoft services.
Windows communicates with endpoints associated with device registration, connected experiences, Microsoft accounts, Entra ID, activity synchronisation and deployment systems such as Windows Autopilot. Examples include:
dds.microsoft.com
cs.dds.microsoft.com
aad.cs.dds.microsoft.com
fd.dds.microsoft.com
ztd.dds.microsoft.com
cdpcs.access.microsoft.com
activity.windows.com
assets.activity.windows.com
edge.activity.windows.com
A connection to one of these domains does not, by itself, prove that Microsoft is recording everything a user does. Several endpoints have legitimate enterprise, authentication and device-management purposes. Public documentation also does not describe every internal identifier or data flow in full.
Even so, it is reasonable for a home user who does not use Entra ID, Autopilot, corporate management or cross-device synchronisation to question whether every device registration connection is required.
Choose a different primary browser
The browser is one of the simplest places to reduce routine data collection. Microsoft Edge is closely integrated with Microsoft's search, advertising, shopping, content, synchronisation and telemetry systems.
Depending on its configuration, Edge may contact Microsoft for:
- Search and address-bar suggestions
- Browsing diagnostics and usage reports
- Website reputation and download checks
- Shopping recommendations and price tracking
- Personalised advertising
- Microsoft Rewards
- Copilot and sidebar services
- MSN feeds and new-tab content
- Account and settings synchronisation
- Cloud-based spelling and writing assistance
Brave
Brave is a convenient alternative for users who require compatibility with Chromium-based websites and extensions. It blocks many common trackers by default and usually requires less initial configuration than a standard Chromium installation.
Brave still has optional connected features. Review its settings and disable Rewards, sponsored images, usage reporting, promotional content and any other services you do not use.
Firefox
Firefox is a suitable choice for anyone who wants to avoid relying entirely on the Chromium browser ecosystem. A privacy-focused Firefox configuration may include:
- Enhanced Tracking Protection set to Strict
- uBlock Origin installed and kept up to date
- HTTPS-Only Mode enabled
- Telemetry and studies disabled
- Sponsored suggestions switched off
- A trustworthy DNS-over-HTTPS provider
- Separate profiles for unrelated activities
Neither browser provides anonymity. Websites can still identify or follow visitors through account logins, cookies, browser fingerprinting, IP addresses and analytics scripts. They simply provide a more independent starting point than a browser deeply integrated into Windows.
Remove unwanted apps, AI features and suggestions
Windows 11 commonly includes applications, promotional shortcuts, online content and AI-related components that many users do not need.
Settings > Apps > Installed apps
Examine the list and uninstall only the items you recognise and do not use. The available software varies according to the Windows edition, region, hardware manufacturer and installation date. Possible examples include:
- Clipchamp
- Copilot
- Dev Home
- Family
- Feedback Hub
- Get Help
- Microsoft 365 promotional applications
- Microsoft News
- Microsoft Teams for personal use
- Mixed Reality components
- Outlook for Windows
- Phone Link
- Solitaire
- Weather
- Widgets
- Xbox applications
Open Taskbar settings and switch off Widgets, Copilot, Search highlights and any other internet-connected elements you do not want.
If the computer supports Recall or other Copilot+ features, inspect their controls separately. Do not assume that an AI feature is inactive merely because you have never opened its application.
Windows also displays recommendations in the Start menu, Settings, File Explorer, notifications and on the lock screen. Disable the following where your version of Windows provides the option:
- Account-related notifications
- Personalised offers
- Recommendations in Start
- Search highlights
- Suggested content in Settings
- Tailored experiences
- Tips and suggestions
- The Windows welcome experience
- Suggestions for getting more from Windows
Review every Privacy and security category
Settings > Privacy & security
Microsoft changes the wording and position of privacy controls between Windows releases. Inspect every category rather than relying on an old list of menu paths.
Important areas usually include:
- Advertising ID
- Activity history
- App diagnostics
- Automatic file downloads
- Cloud content search
- Diagnostic data
- Feedback frequency
- Inking and typing personalisation
- Location
- Online speech recognition
- Personalised offers
- Search permissions
- Suggested content
- Tailored experiences
Set diagnostic data to the lowest level available for your Windows edition. Disable optional diagnostics, tailored experiences, advertising personalisation, feedback requests, cloud search and typing personalisation if you do not need them.
Settings > System > Notifications > Additional settings
Consider disabling options that:
- Show the Windows welcome experience after updates
- Suggest ways to get more from Windows
- Provide tips and suggestions while using Windows
Review access to the camera, microphone, location, contacts, calendar, messages, account information and background activity. Applications should not receive permanent access to information or hardware they do not genuinely require.
Use a local Windows account where possible
A local account does not stop operating-system telemetry, but it weakens the direct connection between the Windows profile and a Microsoft identity.
You can use a local Windows account and sign in separately to individual applications such as Microsoft 365, OneDrive or Xbox. This allows the operating system account to remain separate from email, cloud storage, subscriptions and other Microsoft services.
Microsoft regularly changes the account options shown during Windows installation. If you intend to reinstall Windows, check the legitimate setup methods supported by your current release before beginning.
Consider Enterprise for stronger policy controls
Windows Home and Pro do not provide the same range of diagnostic and policy controls as Windows Enterprise and Education.
Enterprise editions expose stricter diagnostic-data policies and a broader set of Group Policy settings. This can make Enterprise more appropriate for privacy-sensitive systems that must continue to run Windows.
The practical reason for choosing Enterprise is access to more administrative controls, not merely the edition name displayed in System settings.
Reduce telemetry through Group Policy
On a supported Windows edition, press Win + R, enter the following command and press Enter:
gpedit.msc
Navigate to:
Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds
Find Allow Diagnostic Data or Allow Telemetry. The exact name depends on the Windows build. Select the lowest diagnostic level permitted by your edition and environment.
Also inspect policy sections relating to:
- Cloud Content
- Data Collection and Preview Builds
- Microsoft Edge
- OneDrive
- Search
- Store
- Windows AI
- Windows Copilot
- Windows Error Reporting
- Windows Update
- Widgets
Useful policies may allow you to disable:
- Advertising ID
- Automatic feedback requests
- Cloud consumer accounts
- Consumer experiences
- Diagnostic data collection
- Feature experimentation
- Online tips
- Personalised content
- Search highlights
- Suggested applications
- Tailored experiences
- Windows Spotlight
- Windows tips
- Widgets
Policy names and availability change. Review these settings again after every major Windows feature update.
Understand the security and privacy trade-offs
Windows Security > App & browser control > Reputation-based protection
Microsoft Defender SmartScreen checks websites, downloads, files, applications and potentially unwanted software against Microsoft's cloud reputation systems.
Those checks may transmit information such as:
- URLs and download sources
- File names and cryptographic hashes
- Certificate details
- Application reputation information
- Security-related metadata
SmartScreen can prevent phishing, malicious downloads and unknown applications before conventional antivirus signatures detect them. The privacy cost is that Microsoft receives information about the content being checked.
Similar considerations apply to Defender's cloud-delivered protection and automatic sample submission. Cloud protection can submit information about suspicious activity for rapid analysis. Automatic sample submission may upload suspicious files or portions of files.
Disabling cloud protection is especially risky if you frequently download unfamiliar software, open unexpected attachments, install game modifications, use untrusted software sources or run scripts from the internet.
If you deliberately disable any cloud-based security feature, compensate with careful security practices:
- Keep Defender signatures and Windows updates current
- Do not run unknown scripts with administrator rights
- Check software publishers and digital signatures
- Use more than one scanner for genuinely suspicious files
- Maintain tested offline backups
- Use a standard account for ordinary work
- Show file extensions in File Explorer
- Avoid broad Defender exclusions
- Use a sandbox or virtual machine for risky files
Privacy matters, but malware that steals documents, passwords and session cookies is a more serious privacy failure than routine operating-system telemetry.
Block selected domains through the hosts file
Once Windows settings and policies have been configured, the hosts file can provide another transparent layer of control.
The Windows hosts file is located at:
C:\Windows\System32\drivers\etc\hosts
A hosts entry maps a hostname to a chosen address. Mapping
a domain to 0.0.0.0 prevents the usual IPv4
connection. Adding a corresponding :: entry
covers IPv6 resolution.
0.0.0.0 telemetry.example.com
:: telemetry.example.com
The hosts file does not support wildcards. Blocking
example.com does not automatically block
data.example.com.
It also cannot stop software that uses a hard-coded IP address, a different hostname, a proxy, encrypted DNS or its own resolver. It is therefore one useful layer rather than a complete network-control system.
Back up the hosts file
Open Command Prompt as administrator and create a backup:
copy "%SystemRoot%\System32\drivers\etc\hosts" ^
"%USERPROFILE%\Desktop\hosts-backup.txt"
Edit the file safely
- Open the Start menu.
- Search for Notepad.
- Right-click Notepad.
- Select Run as administrator.
- Choose File > Open.
-
Browse to
C:\Windows\System32\drivers\etc. - Change the file filter from Text Documents to All Files.
- Open the file named
hosts. - Add the required entries at the bottom.
- Save the file.
Clear the DNS cache afterwards:
ipconfig /flushdns
Restart applications that were already running because they may have cached earlier DNS results.
Staged Microsoft domain lists
Each list below contains hostnames only. Use the associated
button to generate and copy both the
0.0.0.0 and :: hosts entries.
The generated text is copied to your clipboard.
Level 1: Basic telemetry and event collection
These endpoints are primarily associated with diagnostics, telemetry, event collection, usage reporting and test environments.
Blocking them should not normally prevent activation, Microsoft account sign-in or ordinary Windows Update downloads. It may reduce Microsoft's ability to diagnose faults and measure feature usage.
alpha.telemetry.microsoft.com
au-v10.events.data.microsoft.com
au-v20.events.data.microsoft.com
au.vortex-win.data.microsoft.com
browser.events.data.msn.com
de-v20.events.data.microsoft.com
de.vortex-win.data.microsoft.com
df.telemetry.microsoft.com
eu-v10.events.data.microsoft.com
eu-v10c.events.data.microsoft.com
eu-v20.events.data.microsoft.com
eu.vortex-win.data.microsoft.com
events-sandbox.data.microsoft.com
events.data.microsoft.com
jp-v10.events.data.microsoft.com
jp-v20.events.data.microsoft.com
onecollector.cloudapp.aria.akadns.net
self.events.data.microsoft.com
sqm.df.telemetry.microsoft.com
sqm.telemetry.microsoft.com
tele.trafficmanager.net
telemetry.appex.bing.net
telemetry.microsoft.com
telemetry.remoteapp.windowsazure.com
telemetry.urs.microsoft.com
uk-v20.events.data.microsoft.com
uk.vortex-win.data.microsoft.com
us-v10.events.data.microsoft.com
us-v10c.events.data.microsoft.com
us-v20.events.data.microsoft.com
us.vortex-win.data.microsoft.com
us4-v20.events.data.microsoft.com
us5-v20.events.data.microsoft.com
v10-win.vortex.data.microsoft.com.akadns.net
v10.events.data.microsoft.com
v10.vortex-win.data.microsoft.com
v10c.events.data.microsoft.com
v10c.vortex-win.data.microsoft.com
v20.events.data.microsoft.com
v20.vortex-win.data.microsoft.com
vortex-sandbox.data.microsoft.com
vortex-win-sandbox.data.microsoft.com
vortex-win.data.microsoft.com
vortex.data.glbdns2.microsoft.com
vortex.data.microsoft.com
Level 2: Crash reports, Watson and feedback
Microsoft Watson is used for crash analysis and error reporting. Reports may contain diagnostic details, application state and memory-dump information.
Blocking these domains should not prevent Windows or ordinary applications from running, but crash reports, Feedback Hub and support diagnostics may fail.
ceuswatcab01.blob.core.windows.net
ceuswatcab02.blob.core.windows.net
diagnostics.support.microsoft.com
eaus2watcab01.blob.core.windows.net
eaus2watcab02.blob.core.windows.net
eu-watsonc.events.data.microsoft.com
feedback.microsoft-hohm.com
feedback.search.microsoft.com
feedback.windows.com
kmwatsonc.events.data.microsoft.com
modern.watson.data.microsoft.com
modern.watson.data.microsoft.com.akadns.net
oca.microsoft.com
oca.telemetry.microsoft.com
reports.wes.df.telemetry.microsoft.com
services.wes.df.telemetry.microsoft.com
survey.watson.microsoft.com
umwatson.events.data.microsoft.com
umwatsonc.events.data.microsoft.com
watson.live.com
watson.microsoft.com
watson.ppe.telemetry.microsoft.com
watson.telemetry.microsoft.com
watsonc.events.data.microsoft.com
wes.df.telemetry.microsoft.com
weus2watcab01.blob.core.windows.net
weus2watcab02.blob.core.windows.net
Level 3: MSN, Bing, advertising and Widgets
These domains provide MSN feeds, Bing resources, promotional material, thumbnails, Widgets and Windows Spotlight content.
Possible effects include empty Widgets, missing weather cards, an incomplete Edge new-tab page, absent thumbnails and a static lock-screen background.
api.msn.com
arc.msn.com
assets.msn.com
business.bing.com
c.bing.com
c.msn.com
choice.microsoft.com
creativecdn.com
edgeassetservice.azureedge.net
evoke-windowsservices-tas.msedge.net
fd.api.iris.microsoft.com
fp-afd-nocache-ccp.azureedge.net
fp-vs.azureedge.net
g.msn.com
ntp.msn.com
prod-azurecdn-akamai-iris.azureedge.net
ris.api.iris.microsoft.com
srtb.msn.com
staticview.msn.com
th.bing.com
tse1.mm.bing.net
widgetcdn.azureedge.net
widgetservice.azurefd.net
www.msn.com
Level 4: Location, Maps, Weather and activity
These endpoints support genuine Windows functions. Block them only if you do not use the corresponding features.
Possible effects include problems with:
- Automatic location detection
- Automatic time-zone selection
- Find My Device
- Maps and Weather
- Applications requesting Windows location data
- OneNote resources
- Activity and connected-device synchronisation
activity.windows.com
assets.activity.windows.com
cdn.onenote.net
ecn.dev.virtualearth.net
ecn-us.dev.virtualearth.net
edge.activity.windows.com
inference.location.live.net
location-inference-westus.cloudapp.net
maps.windows.com
tile-service.weather.microsoft.com
weathermapdata.blob.core.windows.net
Level 5: Edge configuration and experiments
These endpoints appear to support Edge configuration, staged feature deployment, experiments, fallback services and Microsoft-delivered browser content.
Blocking them is most appropriate when Edge is not your primary browser. Windows applications may still use Edge WebView2, so test those applications afterwards.
a-ring-fallback.msedge.net
c-ring.msedge.net
config.edge.skype.com
dual-s-ring.msedge.net
fp.msedge.net
i-ring.msedge.net
ln-ring.msedge.net
s-ring.msedge.net
t-ring.msedge.net
t-ring-fdv2.msedge.net
Level 6: Cloud settings and functional events
These endpoints may be involved in remote configuration, feature flags, experiments, telemetry instructions and functional-event processing.
Blocking them may reduce remote configuration activity, but it can also make cloud-managed Windows components behave unpredictably.
asimov-win.settings.data.microsoft.com.akadns.net
co4.telecommand.telemetry.microsoft.com
cy2.settings.data.microsoft.com.akadns.net
cy2.vortex.data.microsoft.com.akadns.net
db5-eap.settings-win.data.microsoft.com.akadns.net
db5.settings-win.data.microsoft.com.akadns.net
db5.vortex.data.microsoft.com.akadns.net
functional.events.data.microsoft.com
geo.settings-win.data.microsoft.com.akadns.net
geo.vortex.data.microsoft.com.akadns.net
query.prod.cms.rt.microsoft.com
settings-sandbox.data.microsoft.com
settings-win.data.microsoft.com
settings.data.glbdns2.microsoft.com
settings.data.microsoft.com
telecommand.telemetry.microsoft.com
www.telecommandsvc.microsoft.com
Level 7: Statistics and traffic management
These hostnames are associated with statistics, content delivery and traffic-management infrastructure.
A hostname such as
statsfe2.update.microsoft.com is more
likely to support reporting around updates than to host
the update packages themselves. Blocking it should not
be described as equivalent to disabling Windows
Update.
Nevertheless, these blocks may affect download coordination, traffic shaping or service reporting.
cs11.wpc.v0cdn.net
cs1137.wpc.gammacdn.net
statsfe1.ws.microsoft.com
statsfe2.update.microsoft.com.akadns.net
statsfe2.ws.microsoft.com
tsfe.trafficshaping.dsp.mp.microsoft.com
Level 8: Device registration endpoints
This is one of the most aggressive categories. These domains may support device registration, Microsoft account integration, Entra ID, Autopilot, connected experiences and persistent device identification.
Possible effects include:
- Device-registration failures
- Broken work or school enrolment
- Entra ID errors
- Autopilot deployment failures
- Account synchronisation problems
- Microsoft account warnings
- Unavailable connected-device features
aad.cs.dds.microsoft.com
cdpcs.access.microsoft.com
cs.dds.microsoft.com
dds.microsoft.com
fd.dds.microsoft.com
mucp.api.account.microsoft.com
ztd.dds.microsoft.com
Level 9: Microsoft account authentication
These are Microsoft account authentication endpoints. Blocking them may be appropriate only for a deliberately local-only system on which Microsoft account services are not required.
Blocking them can interfere with:
- Microsoft account sign-in
- Microsoft Store authentication
- Microsoft 365
- OneDrive
- Outlook
- Xbox services
- Account-based licence checks
- Account recovery
- Work or school authentication
account.live.com
login.live.com
Test each block before continuing
Add one category at a time. Begin with basic telemetry and crash reporting, then use the computer normally for several days before adding another category.
After every change, test:
- Windows activation
- Windows Update
- Defender security intelligence updates
- Microsoft Store
- Microsoft 365
- OneDrive
- VPN software
- Work or school accounts
- WebView2-based applications
- Your preferred browser
- Any Microsoft application you still use
Test DNS resolution from PowerShell:
Resolve-DnsName telemetry.microsoft.com
You can also try:
ping telemetry.microsoft.com
A hostname blocked through the hosts file should resolve
to 0.0.0.0 or ::, depending on
the address family selected by Windows.
If a required feature stops working, remove the entries from the most recently added category and clear the DNS cache:
ipconfig /flushdns
Restore the original hosts file
If you created the suggested desktop backup, open Command Prompt as administrator and run:
copy /y "%USERPROFILE%\Desktop\hosts-backup.txt" ^
"%SystemRoot%\System32\drivers\etc\hosts"
ipconfig /flushdns
Windows privacy requires regular maintenance
Windows 11 does not provide one master switch that disables every unnecessary form of data collection. An effective configuration uses several layers.
- Use Brave or Firefox instead of Edge where practical
- Use a local Windows account where possible
- Remove applications you do not require
- Disable unwanted Copilot and AI features
- Turn off Widgets, MSN feeds and personalised content
- Choose the lowest available diagnostic-data level
- Use Group Policy for stronger administrative control
- Disable cloud integrations you do not use
- Evaluate cloud security features using your threat model
- Block selected telemetry domains in controlled stages
- Review the entire configuration after major updates
Microsoft continually changes Windows. New endpoints appear, old domains disappear, settings move and removed applications may return after feature updates.
The objective is not to block every Microsoft server or to damage useful Windows functions. It is to remove unnecessary data collection while preserving the services and security protections you genuinely need.
Windows 11 is designed around cloud connectivity and continuous communication. If you must use it, however, accepting every default setting is not your only option.
Frequently asked questions
Can Windows 11 be made completely private?
Not realistically while it remains connected to Microsoft services. Privacy settings, Group Policy and network blocking can substantially reduce data collection, but they cannot guarantee that no data leaves the computer.
Will these hosts entries disable Windows Update?
The lower-level lists are not intended to block normal update payloads. More aggressive lists can still affect related configuration, reporting or account services. Always test Windows Update after making changes.
Is a local account enough to stop telemetry?
No. A local account reduces the direct association between the Windows profile and a Microsoft identity, but the operating system can continue to send diagnostic and service data.
Should SmartScreen be disabled for privacy?
Most users should retain SmartScreen because it provides meaningful protection against malicious websites, downloads and unfamiliar applications. Disabling it is an individual privacy and security trade-off, not a general recommendation.
Can these changes be reversed?
Yes. Re-enable the relevant Windows settings or policies, remove the hosts entries and flush the DNS cache. Keeping a backup of the original hosts file makes recovery much easier.