Win11 Privacy Guide

Field guide · en-GB · Updated 28 August 2026

The Windows 11 Privacy Handbook: switch off telemetry, strip the bloatware, block the tracking

Microsoft has spent years reshaping Windows from a conventional desktop operating system into a platform that is permanently tied to its cloud.

Some of that connectivity is genuinely helpful. Windows relies on internet access for updates, malware definitions, activation, cloud storage, account synchronisation and a range of other services that people actively choose to use.

The difficulty lies in everything that accompanies those conveniences.

A default Windows 11 installation regularly phones home to Microsoft servers for diagnostics, crash reports, feature experiments, cloud-based configuration, advertising, personalised recommendations, Bing results, MSN content, widgets, location data, account activity and browser telemetry.

For most users, nobody ever clearly explains what is transmitted, why it is transmitted, or how long it remains linked to their device.

Microsoft does provide a generous number of privacy toggles, but they are scattered across multiple areas of Settings. Some options exist only in Group Policy, some reappear after major updates, and others merely switch off one small part of a much wider data-collection machine.

If you are obliged to use Windows, total privacy is probably out of reach. What you can do is cut the volume of data leaving your machine by a very large margin.

Why device tracking matters: the GDID case

The GDID case shone a light on one of the more unsettling aspects of modern Windows: persistent device identification.

A persistent, global device identifier means online activity can be tied to the same Windows installation — or the same physical machine — over long periods. Even when individual records do not carry your real name, a stable identifier makes it far easier to join separate events together.

Windows talks to a range of device-registration and connected-device endpoints, including:

dds.microsoft.com
cs.dds.microsoft.com
aad.cs.dds.microsoft.com
fd.dds.microsoft.com
ztd.dds.microsoft.com
cdpcs.access.microsoft.com
activity.windows.com
assets.activity.windows.com
edge.activity.windows.com

These services are linked to device registration, connected experiences, Microsoft account integration, Entra ID, activity synchronisation and zero-touch deployment systems such as Windows Autopilot.

Not every request to these domains is proof that Microsoft is monitoring everything you do. Several of the services have legitimate enterprise and device-management roles, and public documentation does not fully explain every internal identifier, endpoint or data flow.

Even so, the privacy concern does not go away.

A long-lived device identifier can stitch together activity across sessions and across Microsoft services. On a home PC that never touches Entra ID, Autopilot, cross-device sync or corporate management, it is fair to ask why so many device-registration connections are needed.

It is possible to block these domains, but treat them as the most aggressive category on this list. Blocking them can disrupt Microsoft accounts, work or school enrolment, device registration, activity sync and other connected experiences.

There are safer privacy improvements to make first.

Dethrone Edge as your default browser

The browser is the easiest place to begin.

Edge is woven deeply into Microsoft's advertising, search, sync, shopping, content and telemetry systems. Depending on how it is configured, Edge may communicate with Microsoft about:

Many of these features can be switched off, but if privacy is a priority there is little reason to keep Edge as your everyday browser.

Brave is a sensible substitute for anyone who needs Chromium compatibility. It works on nearly every site that supports Chrome, blocks a good deal of tracking by default and needs less initial tuning.

It is still worth reviewing Brave's own settings. Switch off Rewards, sponsored content, usage reporting and anything else you do not need. No browser deserves a free pass simply because it markets itself as private.

Firefox is the stronger choice if you would rather step away from the Chromium ecosystem altogether. A sensible Firefox setup includes:

Neither Brave nor Firefox makes you anonymous. Sites can still track visitors via accounts, cookies, fingerprinting, IP addresses and analytics scripts. They are simply far better foundations than a browser welded into the Windows ecosystem.

Strip out bloatware, AI, widgets and suggestions

Windows 11 ships with apps, promotional shortcuts, AI integrations and cloud content that most people never asked for.

Open: Settings > Apps > Installed apps

Uninstall the applications and components you do not use. Exactly what appears in the list depends on your edition of Windows, region, hardware and installation date, but frequent candidates include:

Also visit the taskbar settings and turn off Widgets, Copilot, search highlights and any other online features you do not want.

If your machine supports Recall or other Copilot+ capabilities, check those settings separately. Never assume they are off merely because you have never opened the app.

The same logic applies to suggested content. Microsoft sprinkles recommendations through the Start menu, Settings, notifications, the lock screen and File Explorer. Disable as many of the following as your version of Windows permits:

Avoid blindly running a debloating tool with every box ticked. Some of these utilities remove WebView2, codecs, Store dependencies, application installers and shared frameworks that unrelated programs rely on.

Remove items gradually, reboot Windows, and test the applications you actually use.

Turn off everything under Privacy & security

Open Settings > Privacy & security and work through each category.

Microsoft rearranges the wording and placement of these controls between releases, but the significant options usually include:

Set diagnostic data to the lowest level your edition allows.

Switch off optional diagnostic data, tailored experiences, ad personalisation, feedback requests, typing personalisation and cloud content search if you have no need of them.

Next, open: Settings > System > Notifications > Additional settings

Disable options such as:

It is also worth reviewing permissions for the camera, microphone, location, contacts, calendar, call history, messages, account information and background apps.

Do not grant any application permanent access to something it does not need.

Prefer a local account wherever possible

A local account will not stop Windows telemetry, but it weakens the direct link between your Windows profile and a Microsoft identity.

You can run a local Windows account whilst still signing into individual applications such as OneDrive, Microsoft 365 or Xbox separately.

That separation is valuable: the operating system itself no longer has to be permanently chained to the same account that handles your email, cloud storage, subscriptions and other Microsoft services.

Microsoft keeps making local-account installation harder. The available workarounds change between Windows versions, so verify which method works on your current release before reinstalling.

Move to Enterprise for stronger controls

Windows Home and Pro do not expose the same depth of telemetry control as Windows Enterprise and Education.

Enterprise unlocks stricter diagnostic-data policies and a far wider set of Group Policy controls. If privacy matters and you must stay on Windows, Enterprise is the edition I would recommend.

Note that converting your Windows edition and holding a valid licence are two different things. An edition conversion changes the feature set installed on the machine; licensing and activation are separate questions.

If you already hold a legitimate Enterprise licence through work, education, volume licensing or another channel, use it.

If you have no other practical route, I suggest looking at Massgrave. It can handle edition changes and related Windows activation tasks in around half a minute.

Use the genuine site, read what the scripts actually do, and understand that switching editions does not automatically grant you a legal Enterprise licence. That remains a matter between you, Microsoft and any organisation whose licensing may cover the device.

The reason to move to Enterprise is access to better policy controls — not the label shown in the System window.

Suppress telemetry with Group Policy

On Windows Enterprise, open the Run dialog with Win + R and type:

gpedit.msc

Then navigate to: Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds

Find the policy called Allow Diagnostic Data or Allow Telemetry, depending on your Windows version. Set diagnostic collection to the lowest available level.

You should also review the following Group Policy areas:

Useful policies include those that disable:

Policy names drift over time, and Microsoft removes or replaces policies in newer releases, so re-check them after major feature updates.

SmartScreen and cloud protection: the privacy price

Windows Security contains an awkward trade-off between privacy and security.

Open: Windows Security > App & browser control > Reputation-based protection

Microsoft Defender SmartScreen inspects websites, downloads, applications, file reputation and potentially unwanted software. To carry out those checks, Windows may send Microsoft information such as:

SmartScreen delivers real security benefits. It can block malicious downloads, phishing pages and unknown applications before traditional antivirus signatures catch up. It is also a cloud reputation service, which means Microsoft receives details of what your computer is inspecting.

Personally, I keep SmartScreen and reputation-based protection switched off because I regard that level of cloud checking as too intrusive. That is my privacy judgement, not a universal recommendation.

The same concern applies to cloud-delivered protection and automatic sample submission in Microsoft Defender.

Cloud-delivered protection lets Defender send details of suspicious files and behaviour to Microsoft for instant analysis. Automatic sample submission can transmit suspicious files — or portions of them — to Microsoft. Windows may ask before sending certain files, but I do not want a security product deciding that one of my files should be uploaded to a third party.

I keep both cloud-delivered protection and automatic sample submission disabled.

That reduces Microsoft's visibility of my files and activity, but it can also weaken protection against brand-new malware. Everybody should weigh that balance and decide for themselves.

If you regularly download unknown software, open email attachments, install game mods, use pirated software or run random scripts, switching off cloud protection may be a poor trade for you.

If you do keep these features off, compensate with stronger habits:

Privacy matters, but an information-stealing malware infection is worse than Microsoft telemetry.

Block telemetry with the hosts file

Once Settings and Group Policy are tightened, the next step is blocking selected Microsoft domains. The Windows hosts file lives at:

C:\Windows\System32\drivers\etc\hosts

A hosts entry maps a hostname to an address. Mapping it to 0.0.0.0 blocks the IPv4 connection; mapping it to :: covers IPv6. For example:

0.0.0.0 telemetry.example.com
:: telemetry.example.com

The hosts file does not understand wildcards: blocking example.com does not automatically block data.example.com.

Nor can it stop applications that use hardcoded IP addresses, alternative hostnames, proxies or their own DNS resolvers. Even so, it remains a useful and transparent layer.

Back up and edit the hosts file

Open an administrator Command Prompt and create a backup:

copy "%SystemRoot%\System32\drivers\etc\hosts" ^
"%USERPROFILE%\Desktop\hosts-backup.txt"

Then edit the file:

  1. Open the Start menu.
  2. Search for Notepad.
  3. Right-click Notepad.
  4. Choose Run as administrator.
  5. Choose File > Open.
  6. Browse to C:\Windows\System32\drivers\etc.
  7. Switch the file type from Text Documents to All Files.
  8. Open the file named hosts.
  9. Append the entries at the bottom.
  10. Save the file.

Afterwards, flush the DNS cache:

ipconfig /flushdns

Restart any applications that were already open, as they may be holding cached DNS results.

The nine blocking levels

Work from the safest category towards the most aggressive, testing as you go.

LevelCoversRisk if blocked
1Basic telemetry and event collectionLow
2Crash reporting, Watson, feedbackLow
3MSN, Bing, ads, widgets, SpotlightLow to medium
4Location, maps, weather, OneNote, activityMedium
5Edge configuration and experimentsMedium
6Cloud settings, commands, functional eventsMedium to high
7Statistics, delivery telemetry, traffic shapingMedium
8Device registration, GDID-related endpointsHigh
9Microsoft account authenticationVery high

Level 1Basic telemetry and event collection

These are the safest entries to begin with. They relate chiefly to telemetry, event collection, diagnostics, usage reporting and test environments. Blocking them should not interfere with normal Windows Update downloads, Microsoft account sign-in or activation. It may reduce Microsoft's ability to diagnose faults or analyse how Windows features are used.

0.0.0.0 alpha.telemetry.microsoft.com
:: alpha.telemetry.microsoft.com
0.0.0.0 au-v10.events.data.microsoft.com
:: au-v10.events.data.microsoft.com
0.0.0.0 au-v20.events.data.microsoft.com
:: au-v20.events.data.microsoft.com
0.0.0.0 au.vortex-win.data.microsoft.com
:: au.vortex-win.data.microsoft.com
0.0.0.0 browser.events.data.msn.com
:: browser.events.data.msn.com
0.0.0.0 de-v20.events.data.microsoft.com
:: de-v20.events.data.microsoft.com
0.0.0.0 de.vortex-win.data.microsoft.com
:: de.vortex-win.data.microsoft.com
0.0.0.0 df.telemetry.microsoft.com
:: df.telemetry.microsoft.com
0.0.0.0 eu-v10.events.data.microsoft.com
:: eu-v10.events.data.microsoft.com
0.0.0.0 eu-v10c.events.data.microsoft.com
:: eu-v10c.events.data.microsoft.com
0.0.0.0 eu-v20.events.data.microsoft.com
:: eu-v20.events.data.microsoft.com
0.0.0.0 eu.vortex-win.data.microsoft.com
:: eu.vortex-win.data.microsoft.com
0.0.0.0 events-sandbox.data.microsoft.com
:: events-sandbox.data.microsoft.com
0.0.0.0 events.data.microsoft.com
:: events.data.microsoft.com
0.0.0.0 jp-v10.events.data.microsoft.com
:: jp-v10.events.data.microsoft.com
0.0.0.0 jp-v20.events.data.microsoft.com
:: jp-v20.events.data.microsoft.com
0.0.0.0 onecollector.cloudapp.aria.akadns.net
:: onecollector.cloudapp.aria.akadns.net
0.0.0.0 self.events.data.microsoft.com
:: self.events.data.microsoft.com
0.0.0.0 sqm.df.telemetry.microsoft.com
:: sqm.df.telemetry.microsoft.com
0.0.0.0 sqm.telemetry.microsoft.com
:: sqm.telemetry.microsoft.com
0.0.0.0 tele.trafficmanager.net
:: tele.trafficmanager.net
0.0.0.0 telemetry.appex.bing.net
:: telemetry.appex.bing.net
0.0.0.0 telemetry.microsoft.com
:: telemetry.microsoft.com
0.0.0.0 telemetry.remoteapp.windowsazure.com
:: telemetry.remoteapp.windowsazure.com
0.0.0.0 telemetry.urs.microsoft.com
:: telemetry.urs.microsoft.com
0.0.0.0 uk-v20.events.data.microsoft.com
:: uk-v20.events.data.microsoft.com
0.0.0.0 uk.vortex-win.data.microsoft.com
:: uk.vortex-win.data.microsoft.com
0.0.0.0 us-v10.events.data.microsoft.com
:: us-v10.events.data.microsoft.com
0.0.0.0 us-v10c.events.data.microsoft.com
:: us-v10c.events.data.microsoft.com
0.0.0.0 us-v20.events.data.microsoft.com
:: us-v20.events.data.microsoft.com
0.0.0.0 us.vortex-win.data.microsoft.com
:: us.vortex-win.data.microsoft.com
0.0.0.0 us4-v20.events.data.microsoft.com
:: us4-v20.events.data.microsoft.com
0.0.0.0 us5-v20.events.data.microsoft.com
:: us5-v20.events.data.microsoft.com
0.0.0.0 v10-win.vortex.data.microsoft.com.akadns.net
:: v10-win.vortex.data.microsoft.com.akadns.net
0.0.0.0 v10.events.data.microsoft.com
:: v10.events.data.microsoft.com
0.0.0.0 v10.vortex-win.data.microsoft.com
:: v10.vortex-win.data.microsoft.com
0.0.0.0 v10c.events.data.microsoft.com
:: v10c.events.data.microsoft.com
0.0.0.0 v10c.vortex-win.data.microsoft.com
:: v10c.vortex-win.data.microsoft.com
0.0.0.0 v20.events.data.microsoft.com
:: v20.events.data.microsoft.com
0.0.0.0 v20.vortex-win.data.microsoft.com
:: v20.vortex-win.data.microsoft.com
0.0.0.0 vortex-sandbox.data.microsoft.com
:: vortex-sandbox.data.microsoft.com
0.0.0.0 vortex-win-sandbox.data.microsoft.com
:: vortex-win-sandbox.data.microsoft.com
0.0.0.0 vortex-win.data.microsoft.com
:: vortex-win.data.microsoft.com
0.0.0.0 vortex.data.glbdns2.microsoft.com
:: vortex.data.glbdns2.microsoft.com
0.0.0.0 vortex.data.microsoft.com
:: vortex.data.microsoft.com

Level 2Crash reporting, Watson and feedback

Watson is Microsoft's crash-reporting and error-analysis infrastructure. It can gather crash details, diagnostic information, application state and memory dump data. Blocking these domains prevents or curtails the submission of crash reports. Windows and your applications should keep running, but Microsoft will receive less information when something goes wrong. Feedback Hub and Microsoft's support diagnostics may also misbehave.

0.0.0.0 ceuswatcab01.blob.core.windows.net
:: ceuswatcab01.blob.core.windows.net
0.0.0.0 ceuswatcab02.blob.core.windows.net
:: ceuswatcab02.blob.core.windows.net
0.0.0.0 diagnostics.support.microsoft.com
:: diagnostics.support.microsoft.com
0.0.0.0 eaus2watcab01.blob.core.windows.net
:: eaus2watcab01.blob.core.windows.net
0.0.0.0 eaus2watcab02.blob.core.windows.net
:: eaus2watcab02.blob.core.windows.net
0.0.0.0 eu-watsonc.events.data.microsoft.com
:: eu-watsonc.events.data.microsoft.com
0.0.0.0 feedback.microsoft-hohm.com
:: feedback.microsoft-hohm.com
0.0.0.0 feedback.search.microsoft.com
:: feedback.search.microsoft.com
0.0.0.0 feedback.windows.com
:: feedback.windows.com
0.0.0.0 kmwatsonc.events.data.microsoft.com
:: kmwatsonc.events.data.microsoft.com
0.0.0.0 modern.watson.data.microsoft.com
:: modern.watson.data.microsoft.com
0.0.0.0 modern.watson.data.microsoft.com.akadns.net
:: modern.watson.data.microsoft.com.akadns.net
0.0.0.0 oca.microsoft.com
:: oca.microsoft.com
0.0.0.0 oca.telemetry.microsoft.com
:: oca.telemetry.microsoft.com
0.0.0.0 reports.wes.df.telemetry.microsoft.com
:: reports.wes.df.telemetry.microsoft.com
0.0.0.0 services.wes.df.telemetry.microsoft.com
:: services.wes.df.telemetry.microsoft.com
0.0.0.0 survey.watson.microsoft.com
:: survey.watson.microsoft.com
0.0.0.0 umwatson.events.data.microsoft.com
:: umwatson.events.data.microsoft.com
0.0.0.0 umwatsonc.events.data.microsoft.com
:: umwatsonc.events.data.microsoft.com
0.0.0.0 watson.live.com
:: watson.live.com
0.0.0.0 watson.microsoft.com
:: watson.microsoft.com
0.0.0.0 watson.ppe.telemetry.microsoft.com
:: watson.ppe.telemetry.microsoft.com
0.0.0.0 watson.telemetry.microsoft.com
:: watson.telemetry.microsoft.com
0.0.0.0 watsonc.events.data.microsoft.com
:: watsonc.events.data.microsoft.com
0.0.0.0 wes.df.telemetry.microsoft.com
:: wes.df.telemetry.microsoft.com
0.0.0.0 weus2watcab01.blob.core.windows.net
:: weus2watcab01.blob.core.windows.net
0.0.0.0 weus2watcab02.blob.core.windows.net
:: weus2watcab02.blob.core.windows.net

Level 3MSN, Bing, ads, widgets and Spotlight

These domains serve MSN feeds, Bing assets, widgets, promotional content, thumbnails, suggested content and Windows Spotlight material. They are generally safe to block if you do not use those features. Possible side effects include empty widgets, missing weather cards, a blank Edge new-tab page, absent thumbnails and Windows Spotlight falling back to a static background.

0.0.0.0 api.msn.com
:: api.msn.com
0.0.0.0 arc.msn.com
:: arc.msn.com
0.0.0.0 assets.msn.com
:: assets.msn.com
0.0.0.0 business.bing.com
:: business.bing.com
0.0.0.0 c.bing.com
:: c.bing.com
0.0.0.0 c.msn.com
:: c.msn.com
0.0.0.0 choice.microsoft.com
:: choice.microsoft.com
0.0.0.0 creativecdn.com
:: creativecdn.com
0.0.0.0 edgeassetservice.azureedge.net
:: edgeassetservice.azureedge.net
0.0.0.0 evoke-windowsservices-tas.msedge.net
:: evoke-windowsservices-tas.msedge.net
0.0.0.0 fd.api.iris.microsoft.com
:: fd.api.iris.microsoft.com
0.0.0.0 fp-afd-nocache-ccp.azureedge.net
:: fp-afd-nocache-ccp.azureedge.net
0.0.0.0 fp-vs.azureedge.net
:: fp-vs.azureedge.net
0.0.0.0 g.msn.com
:: g.msn.com
0.0.0.0 ntp.msn.com
:: ntp.msn.com
0.0.0.0 prod-azurecdn-akamai-iris.azureedge.net
:: prod-azurecdn-akamai-iris.azureedge.net
0.0.0.0 ris.api.iris.microsoft.com
:: ris.api.iris.microsoft.com
0.0.0.0 srtb.msn.com
:: srtb.msn.com
0.0.0.0 staticview.msn.com
:: staticview.msn.com
0.0.0.0 th.bing.com
:: th.bing.com
0.0.0.0 tse1.mm.bing.net
:: tse1.mm.bing.net
0.0.0.0 widgetcdn.azureedge.net
:: widgetcdn.azureedge.net
0.0.0.0 widgetservice.azurefd.net
:: widgetservice.azurefd.net
0.0.0.0 www.msn.com
:: www.msn.com

Level 4Location, maps, weather, OneNote and activity

These domains underpin genuine Windows features, so block them only if you do not use those features. Blocking location services may affect:

Blocking OneNote's CDN can cause missing resources or other loading issues inside OneNote. Blocking the activity domains may disable activity sync and connected-device features.

0.0.0.0 activity.windows.com
:: activity.windows.com
0.0.0.0 assets.activity.windows.com
:: assets.activity.windows.com
0.0.0.0 cdn.onenote.net
:: cdn.onenote.net
0.0.0.0 ecn.dev.virtualearth.net
:: ecn.dev.virtualearth.net
0.0.0.0 ecn-us.dev.virtualearth.net
:: ecn-us.dev.virtualearth.net
0.0.0.0 edge.activity.windows.com
:: edge.activity.windows.com
0.0.0.0 inference.location.live.net
:: inference.location.live.net
0.0.0.0 location-inference-westus.cloudapp.net
:: location-inference-westus.cloudapp.net
0.0.0.0 maps.windows.com
:: maps.windows.com
0.0.0.0 tile-service.weather.microsoft.com
:: tile-service.weather.microsoft.com
0.0.0.0 weathermapdata.blob.core.windows.net
:: weathermapdata.blob.core.windows.net

Level 5Edge configuration and feature experiments

These domains appear to be tied to Edge feature rollout rings, configuration, experiments, fallback services and browser content delivered by Microsoft. Blocking them makes sense if you do not use Edge and do not want Microsoft remotely altering or testing browser features. Windows still uses Edge WebView2 for some applications, so test those applications afterwards.

0.0.0.0 a-ring-fallback.msedge.net
:: a-ring-fallback.msedge.net
0.0.0.0 c-ring.msedge.net
:: c-ring.msedge.net
0.0.0.0 config.edge.skype.com
:: config.edge.skype.com
0.0.0.0 dual-s-ring.msedge.net
:: dual-s-ring.msedge.net
0.0.0.0 fp.msedge.net
:: fp.msedge.net
0.0.0.0 i-ring.msedge.net
:: i-ring.msedge.net
0.0.0.0 ln-ring.msedge.net
:: ln-ring.msedge.net
0.0.0.0 s-ring.msedge.net
:: s-ring.msedge.net
0.0.0.0 t-ring.msedge.net
:: t-ring.msedge.net
0.0.0.0 t-ring-fdv2.msedge.net
:: t-ring-fdv2.msedge.net

Level 6Cloud settings, commands and functional events

These endpoints are more aggressive because they may handle cloud configuration, feature flags, experiments, telemetry instructions and functional event processing. Blocking them can curb Microsoft's remote control over connected Windows features. It may also cause some cloud-managed settings or Microsoft components to behave unpredictably.

0.0.0.0 asimov-win.settings.data.microsoft.com.akadns.net
:: asimov-win.settings.data.microsoft.com.akadns.net
0.0.0.0 co4.telecommand.telemetry.microsoft.com
:: co4.telecommand.telemetry.microsoft.com
0.0.0.0 cy2.settings.data.microsoft.com.akadns.net
:: cy2.settings.data.microsoft.com.akadns.net
0.0.0.0 cy2.vortex.data.microsoft.com.akadns.net
:: cy2.vortex.data.microsoft.com.akadns.net
0.0.0.0 db5-eap.settings-win.data.microsoft.com.akadns.net
:: db5-eap.settings-win.data.microsoft.com.akadns.net
0.0.0.0 db5.settings-win.data.microsoft.com.akadns.net
:: db5.settings-win.data.microsoft.com.akadns.net
0.0.0.0 db5.vortex.data.microsoft.com.akadns.net
:: db5.vortex.data.microsoft.com.akadns.net
0.0.0.0 functional.events.data.microsoft.com
:: functional.events.data.microsoft.com
0.0.0.0 geo.settings-win.data.microsoft.com.akadns.net
:: geo.settings-win.data.microsoft.com.akadns.net
0.0.0.0 geo.vortex.data.microsoft.com.akadns.net
:: geo.vortex.data.microsoft.com.akadns.net
0.0.0.0 query.prod.cms.rt.microsoft.com
:: query.prod.cms.rt.microsoft.com
0.0.0.0 settings-sandbox.data.microsoft.com
:: settings-sandbox.data.microsoft.com
0.0.0.0 settings-win.data.microsoft.com
:: settings-win.data.microsoft.com
0.0.0.0 settings.data.glbdns2.microsoft.com
:: settings.data.glbdns2.microsoft.com
0.0.0.0 settings.data.microsoft.com
:: settings.data.microsoft.com
0.0.0.0 telecommand.telemetry.microsoft.com
:: telecommand.telemetry.microsoft.com
0.0.0.0 www.telecommandsvc.microsoft.com
:: www.telecommandsvc.microsoft.com

Level 7Statistics, delivery telemetry and traffic shaping

These hostnames are associated with statistics, CDN infrastructure and traffic-management services. They should not be casually described as the servers that deliver Windows update packages. A name such as statsfe2.update.microsoft.com suggests reporting or statistics about updates, which is not the same as hosting the update payload itself. Blocking these domains may affect statistics, download coordination, traffic shaping or reporting around Microsoft services. It should not be presented as equivalent to disabling Windows Update.

0.0.0.0 cs11.wpc.v0cdn.net
:: cs11.wpc.v0cdn.net
0.0.0.0 cs1137.wpc.gammacdn.net
:: cs1137.wpc.gammacdn.net
0.0.0.0 statsfe1.ws.microsoft.com
:: statsfe1.ws.microsoft.com
0.0.0.0 statsfe2.update.microsoft.com.akadns.net
:: statsfe2.update.microsoft.com.akadns.net
0.0.0.0 statsfe2.ws.microsoft.com
:: statsfe2.ws.microsoft.com
0.0.0.0 tsfe.trafficshaping.dsp.mp.microsoft.com
:: tsfe.trafficshaping.dsp.mp.microsoft.com

Level 8Device registration and GDID-related endpoints

This is the most aggressive privacy category on the list. These domains can be involved in device registration, connected experiences, Microsoft account integration, Entra ID, Autopilot and persistent device identification. Do not block them on a work-managed machine without understanding how the organisation manages the device. Possible side effects include:

0.0.0.0 aad.cs.dds.microsoft.com
:: aad.cs.dds.microsoft.com
0.0.0.0 cdpcs.access.microsoft.com
:: cdpcs.access.microsoft.com
0.0.0.0 cs.dds.microsoft.com
:: cs.dds.microsoft.com
0.0.0.0 dds.microsoft.com
:: dds.microsoft.com
0.0.0.0 fd.dds.microsoft.com
:: fd.dds.microsoft.com
0.0.0.0 mucp.api.account.microsoft.com
:: mucp.api.account.microsoft.com
0.0.0.0 ztd.dds.microsoft.com
:: ztd.dds.microsoft.com

Level 9Microsoft account authentication

The final category contains Microsoft account authentication endpoints. Blocking these domains is technically possible, but it can stop account-based Microsoft services from working. If your goal is to prevent Microsoft account use entirely and keep Windows strictly local, these are the last entries to add. Possible side effects include problems with:

0.0.0.0 account.live.com
:: account.live.com
0.0.0.0 login.live.com
:: login.live.com

Test the blocks in stages

Do not add every category at once unless you are ready to troubleshoot the consequences.

Begin with telemetry and crash reporting. Use the computer normally for a few days. Then add the content, widgets, location, cloud settings and device registration categories one at a time.

After each change, test the features you care about:

You can check a blocked domain in PowerShell:

Resolve-DnsName telemetry.microsoft.com

Or use:

ping telemetry.microsoft.com

A blocked hostname should resolve to 0.0.0.0 or ::, depending on which address Windows picks. Some applications cache DNS results; close and reopen them after editing the hosts file.

If something breaks, remove the entries from the most recently added category and run:

ipconfig /flushdns

To restore the original hosts file from your backup:

copy /y "%USERPROFILE%\Desktop\hosts-backup.txt" ^
"%SystemRoot%\System32\drivers\etc\hosts"

ipconfig /flushdns

Windows privacy needs ongoing maintenance

There is no single privacy switch for Windows 11. The most effective setup combines several layers:

Microsoft alters Windows constantly. New endpoints appear, old hostnames vanish, settings move, and unwanted applications sometimes return after updates.

The aim is not to break Windows or blindly block every Microsoft server. The aim is to strip out unnecessary data collection whilst keeping the specific features and security protections you actually want.

Microsoft designed Windows 11 around cloud connectivity and continuous data collection. If you are required to use it, accepting every default is not your only option.