Some of that connectivity is genuinely helpful. Windows relies on internet access for updates, malware definitions, activation, cloud storage, account synchronisation and a range of other services that people actively choose to use.
The difficulty lies in everything that accompanies those conveniences.
A default Windows 11 installation regularly phones home to Microsoft servers for diagnostics, crash reports, feature experiments, cloud-based configuration, advertising, personalised recommendations, Bing results, MSN content, widgets, location data, account activity and browser telemetry.
For most users, nobody ever clearly explains what is transmitted, why it is transmitted, or how long it remains linked to their device.
Microsoft does provide a generous number of privacy toggles, but they are scattered across multiple areas of Settings. Some options exist only in Group Policy, some reappear after major updates, and others merely switch off one small part of a much wider data-collection machine.
If you are obliged to use Windows, total privacy is probably out of reach. What you can do is cut the volume of data leaving your machine by a very large margin.
Why device tracking matters: the GDID case
The GDID case shone a light on one of the more unsettling aspects of modern Windows: persistent device identification.
A persistent, global device identifier means online activity can be tied to the same Windows installation — or the same physical machine — over long periods. Even when individual records do not carry your real name, a stable identifier makes it far easier to join separate events together.
Windows talks to a range of device-registration and connected-device endpoints, including:
dds.microsoft.com
cs.dds.microsoft.com
aad.cs.dds.microsoft.com
fd.dds.microsoft.com
ztd.dds.microsoft.com
cdpcs.access.microsoft.com
activity.windows.com
assets.activity.windows.com
edge.activity.windows.comThese services are linked to device registration, connected experiences, Microsoft account integration, Entra ID, activity synchronisation and zero-touch deployment systems such as Windows Autopilot.
Not every request to these domains is proof that Microsoft is monitoring everything you do. Several of the services have legitimate enterprise and device-management roles, and public documentation does not fully explain every internal identifier, endpoint or data flow.
Even so, the privacy concern does not go away.
A long-lived device identifier can stitch together activity across sessions and across Microsoft services. On a home PC that never touches Entra ID, Autopilot, cross-device sync or corporate management, it is fair to ask why so many device-registration connections are needed.
It is possible to block these domains, but treat them as the most aggressive category on this list. Blocking them can disrupt Microsoft accounts, work or school enrolment, device registration, activity sync and other connected experiences.
There are safer privacy improvements to make first.
Dethrone Edge as your default browser
The browser is the easiest place to begin.
Edge is woven deeply into Microsoft's advertising, search, sync, shopping, content and telemetry systems. Depending on how it is configured, Edge may communicate with Microsoft about:
- Search and URL suggestions
- Browsing diagnostics
- Shopping recommendations
- Personalised ads
- Microsoft Rewards
- Copilot features
- Sidebar apps
- MSN news
- New-tab content
- Account synchronisation
- Typing and spelling assistance
- Website reputation checks
Many of these features can be switched off, but if privacy is a priority there is little reason to keep Edge as your everyday browser.
Brave is a sensible substitute for anyone who needs Chromium compatibility. It works on nearly every site that supports Chrome, blocks a good deal of tracking by default and needs less initial tuning.
It is still worth reviewing Brave's own settings. Switch off Rewards, sponsored content, usage reporting and anything else you do not need. No browser deserves a free pass simply because it markets itself as private.
Firefox is the stronger choice if you would rather step away from the Chromium ecosystem altogether. A sensible Firefox setup includes:
- Enhanced Tracking Protection set to Strict
- uBlock Origin
- HTTPS-Only Mode
- Disabled telemetry and studies
- Disabled sponsored suggestions
- A trusted DNS-over-HTTPS provider
- Separate browser profiles for different activities
Neither Brave nor Firefox makes you anonymous. Sites can still track visitors via accounts, cookies, fingerprinting, IP addresses and analytics scripts. They are simply far better foundations than a browser welded into the Windows ecosystem.
Strip out bloatware, AI, widgets and suggestions
Windows 11 ships with apps, promotional shortcuts, AI integrations and cloud content that most people never asked for.
Open: Settings > Apps > Installed apps
Uninstall the applications and components you do not use. Exactly what appears in the list depends on your edition of Windows, region, hardware and installation date, but frequent candidates include:
- Clipchamp
- Copilot
- Dev Home
- Family
- Feedback Hub
- Get Help
- Microsoft 365 promotional apps
- Microsoft News
- Microsoft Teams for personal use
- Mixed Reality
- Outlook for Windows
- Phone Link
- Solitaire
- Xbox applications
- Widgets
- Weather
Also visit the taskbar settings and turn off Widgets, Copilot, search highlights and any other online features you do not want.
If your machine supports Recall or other Copilot+ capabilities, check those settings separately. Never assume they are off merely because you have never opened the app.
The same logic applies to suggested content. Microsoft sprinkles recommendations through the Start menu, Settings, notifications, the lock screen and File Explorer. Disable as many of the following as your version of Windows permits:
- Account-related notifications
- Personalised offers
- Recommendations in Start
- Search highlights
- Suggested content in Settings
- Tailored experiences
- Tips and suggestions
- The Windows welcome experience
- "Ways to get the most out of Windows"
Avoid blindly running a debloating tool with every box ticked. Some of these utilities remove WebView2, codecs, Store dependencies, application installers and shared frameworks that unrelated programs rely on.
Remove items gradually, reboot Windows, and test the applications you actually use.
Turn off everything under Privacy & security
Open Settings > Privacy & security and work through each category.
Microsoft rearranges the wording and placement of these controls between releases, but the significant options usually include:
- Advertising ID
- Activity history
- App diagnostics
- Automatic file downloads
- Cloud content search
- Diagnostic data
- Feedback frequency
- Inking and typing personalisation
- Location
- Online speech recognition
- Personalised offers
- Search permissions
- Suggested content
- Tailored experiences
Set diagnostic data to the lowest level your edition allows.
Switch off optional diagnostic data, tailored experiences, ad personalisation, feedback requests, typing personalisation and cloud content search if you have no need of them.
Next, open: Settings > System > Notifications > Additional settings
Disable options such as:
- Show the Windows welcome experience after updates
- Suggest ways to get the most out of Windows
- Get tips and suggestions when using Windows
It is also worth reviewing permissions for the camera, microphone, location, contacts, calendar, call history, messages, account information and background apps.
Do not grant any application permanent access to something it does not need.
Prefer a local account wherever possible
A local account will not stop Windows telemetry, but it weakens the direct link between your Windows profile and a Microsoft identity.
You can run a local Windows account whilst still signing into individual applications such as OneDrive, Microsoft 365 or Xbox separately.
That separation is valuable: the operating system itself no longer has to be permanently chained to the same account that handles your email, cloud storage, subscriptions and other Microsoft services.
Microsoft keeps making local-account installation harder. The available workarounds change between Windows versions, so verify which method works on your current release before reinstalling.
Move to Enterprise for stronger controls
Windows Home and Pro do not expose the same depth of telemetry control as Windows Enterprise and Education.
Enterprise unlocks stricter diagnostic-data policies and a far wider set of Group Policy controls. If privacy matters and you must stay on Windows, Enterprise is the edition I would recommend.
Note that converting your Windows edition and holding a valid licence are two different things. An edition conversion changes the feature set installed on the machine; licensing and activation are separate questions.
If you already hold a legitimate Enterprise licence through work, education, volume licensing or another channel, use it.
If you have no other practical route, I suggest looking at Massgrave. It can handle edition changes and related Windows activation tasks in around half a minute.
Use the genuine site, read what the scripts actually do, and understand that switching editions does not automatically grant you a legal Enterprise licence. That remains a matter between you, Microsoft and any organisation whose licensing may cover the device.
The reason to move to Enterprise is access to better policy controls — not the label shown in the System window.
Suppress telemetry with Group Policy
On Windows Enterprise, open the Run dialog with Win + R and type:
gpedit.mscThen navigate to: Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds
Find the policy called Allow Diagnostic Data or Allow Telemetry, depending on your Windows version. Set diagnostic collection to the lowest available level.
You should also review the following Group Policy areas:
- Cloud Content
- Data Collection and Preview Builds
- Microsoft Edge
- OneDrive
- Search
- Store
- Windows AI
- Windows Copilot
- Windows Error Reporting
- Windows Update
- Widgets
Useful policies include those that disable:
- Advertising ID
- Automatic feedback requests
- Cloud consumer accounts
- Consumer experiences
- Diagnostic data collection
- Experimentation
- Online tips
- Personalised content
- Search highlights
- Suggested applications
- Tailored experiences
- Windows Spotlight
- Windows tips
- Widgets
Policy names drift over time, and Microsoft removes or replaces policies in newer releases, so re-check them after major feature updates.
SmartScreen and cloud protection: the privacy price
Windows Security contains an awkward trade-off between privacy and security.
Open: Windows Security > App & browser control > Reputation-based protection
Microsoft Defender SmartScreen inspects websites, downloads, applications, file reputation and potentially unwanted software. To carry out those checks, Windows may send Microsoft information such as:
- URLs
- File names
- File hashes
- Download sources
- Certificate information
- Application reputation data
- Security-related metadata
SmartScreen delivers real security benefits. It can block malicious downloads, phishing pages and unknown applications before traditional antivirus signatures catch up. It is also a cloud reputation service, which means Microsoft receives details of what your computer is inspecting.
Personally, I keep SmartScreen and reputation-based protection switched off because I regard that level of cloud checking as too intrusive. That is my privacy judgement, not a universal recommendation.
The same concern applies to cloud-delivered protection and automatic sample submission in Microsoft Defender.
Cloud-delivered protection lets Defender send details of suspicious files and behaviour to Microsoft for instant analysis. Automatic sample submission can transmit suspicious files — or portions of them — to Microsoft. Windows may ask before sending certain files, but I do not want a security product deciding that one of my files should be uploaded to a third party.
I keep both cloud-delivered protection and automatic sample submission disabled.
That reduces Microsoft's visibility of my files and activity, but it can also weaken protection against brand-new malware. Everybody should weigh that balance and decide for themselves.
If you regularly download unknown software, open email attachments, install game mods, use pirated software or run random scripts, switching off cloud protection may be a poor trade for you.
If you do keep these features off, compensate with stronger habits:
- Keep Defender signatures updated
- Keep Windows security updates installed
- Do not run unknown scripts as administrator
- Check digital signatures
- Scan suspicious files with more than one engine when appropriate
- Keep offline backups
- Use a standard account for daily work
- Show file extensions in File Explorer
- Avoid broad Defender exclusions
- Use application isolation or a virtual machine for risky files
Privacy matters, but an information-stealing malware infection is worse than Microsoft telemetry.
Block telemetry with the hosts file
Once Settings and Group Policy are tightened, the next step is blocking selected Microsoft domains. The Windows hosts file lives at:
C:\Windows\System32\drivers\etc\hostsA hosts entry maps a hostname to an address. Mapping it to 0.0.0.0
blocks the IPv4 connection; mapping it to :: covers IPv6. For example:
0.0.0.0 telemetry.example.com
:: telemetry.example.comThe hosts file does not understand wildcards: blocking example.com does
not automatically block data.example.com.
Nor can it stop applications that use hardcoded IP addresses, alternative hostnames, proxies or their own DNS resolvers. Even so, it remains a useful and transparent layer.
Back up and edit the hosts file
Open an administrator Command Prompt and create a backup:
copy "%SystemRoot%\System32\drivers\etc\hosts" ^
"%USERPROFILE%\Desktop\hosts-backup.txt"Then edit the file:
- Open the Start menu.
- Search for Notepad.
- Right-click Notepad.
- Choose Run as administrator.
- Choose File > Open.
- Browse to
C:\Windows\System32\drivers\etc. - Switch the file type from Text Documents to All Files.
- Open the file named
hosts. - Append the entries at the bottom.
- Save the file.
Afterwards, flush the DNS cache:
ipconfig /flushdnsRestart any applications that were already open, as they may be holding cached DNS results.
The nine blocking levels
Work from the safest category towards the most aggressive, testing as you go.
| Level | Covers | Risk if blocked |
|---|---|---|
| 1 | Basic telemetry and event collection | Low |
| 2 | Crash reporting, Watson, feedback | Low |
| 3 | MSN, Bing, ads, widgets, Spotlight | Low to medium |
| 4 | Location, maps, weather, OneNote, activity | Medium |
| 5 | Edge configuration and experiments | Medium |
| 6 | Cloud settings, commands, functional events | Medium to high |
| 7 | Statistics, delivery telemetry, traffic shaping | Medium |
| 8 | Device registration, GDID-related endpoints | High |
| 9 | Microsoft account authentication | Very high |
Level 1Basic telemetry and event collection
These are the safest entries to begin with. They relate chiefly to telemetry, event collection, diagnostics, usage reporting and test environments. Blocking them should not interfere with normal Windows Update downloads, Microsoft account sign-in or activation. It may reduce Microsoft's ability to diagnose faults or analyse how Windows features are used.
0.0.0.0 alpha.telemetry.microsoft.com
:: alpha.telemetry.microsoft.com
0.0.0.0 au-v10.events.data.microsoft.com
:: au-v10.events.data.microsoft.com
0.0.0.0 au-v20.events.data.microsoft.com
:: au-v20.events.data.microsoft.com
0.0.0.0 au.vortex-win.data.microsoft.com
:: au.vortex-win.data.microsoft.com
0.0.0.0 browser.events.data.msn.com
:: browser.events.data.msn.com
0.0.0.0 de-v20.events.data.microsoft.com
:: de-v20.events.data.microsoft.com
0.0.0.0 de.vortex-win.data.microsoft.com
:: de.vortex-win.data.microsoft.com
0.0.0.0 df.telemetry.microsoft.com
:: df.telemetry.microsoft.com
0.0.0.0 eu-v10.events.data.microsoft.com
:: eu-v10.events.data.microsoft.com
0.0.0.0 eu-v10c.events.data.microsoft.com
:: eu-v10c.events.data.microsoft.com
0.0.0.0 eu-v20.events.data.microsoft.com
:: eu-v20.events.data.microsoft.com
0.0.0.0 eu.vortex-win.data.microsoft.com
:: eu.vortex-win.data.microsoft.com
0.0.0.0 events-sandbox.data.microsoft.com
:: events-sandbox.data.microsoft.com
0.0.0.0 events.data.microsoft.com
:: events.data.microsoft.com
0.0.0.0 jp-v10.events.data.microsoft.com
:: jp-v10.events.data.microsoft.com
0.0.0.0 jp-v20.events.data.microsoft.com
:: jp-v20.events.data.microsoft.com
0.0.0.0 onecollector.cloudapp.aria.akadns.net
:: onecollector.cloudapp.aria.akadns.net
0.0.0.0 self.events.data.microsoft.com
:: self.events.data.microsoft.com
0.0.0.0 sqm.df.telemetry.microsoft.com
:: sqm.df.telemetry.microsoft.com
0.0.0.0 sqm.telemetry.microsoft.com
:: sqm.telemetry.microsoft.com
0.0.0.0 tele.trafficmanager.net
:: tele.trafficmanager.net
0.0.0.0 telemetry.appex.bing.net
:: telemetry.appex.bing.net
0.0.0.0 telemetry.microsoft.com
:: telemetry.microsoft.com
0.0.0.0 telemetry.remoteapp.windowsazure.com
:: telemetry.remoteapp.windowsazure.com
0.0.0.0 telemetry.urs.microsoft.com
:: telemetry.urs.microsoft.com
0.0.0.0 uk-v20.events.data.microsoft.com
:: uk-v20.events.data.microsoft.com
0.0.0.0 uk.vortex-win.data.microsoft.com
:: uk.vortex-win.data.microsoft.com
0.0.0.0 us-v10.events.data.microsoft.com
:: us-v10.events.data.microsoft.com
0.0.0.0 us-v10c.events.data.microsoft.com
:: us-v10c.events.data.microsoft.com
0.0.0.0 us-v20.events.data.microsoft.com
:: us-v20.events.data.microsoft.com
0.0.0.0 us.vortex-win.data.microsoft.com
:: us.vortex-win.data.microsoft.com
0.0.0.0 us4-v20.events.data.microsoft.com
:: us4-v20.events.data.microsoft.com
0.0.0.0 us5-v20.events.data.microsoft.com
:: us5-v20.events.data.microsoft.com
0.0.0.0 v10-win.vortex.data.microsoft.com.akadns.net
:: v10-win.vortex.data.microsoft.com.akadns.net
0.0.0.0 v10.events.data.microsoft.com
:: v10.events.data.microsoft.com
0.0.0.0 v10.vortex-win.data.microsoft.com
:: v10.vortex-win.data.microsoft.com
0.0.0.0 v10c.events.data.microsoft.com
:: v10c.events.data.microsoft.com
0.0.0.0 v10c.vortex-win.data.microsoft.com
:: v10c.vortex-win.data.microsoft.com
0.0.0.0 v20.events.data.microsoft.com
:: v20.events.data.microsoft.com
0.0.0.0 v20.vortex-win.data.microsoft.com
:: v20.vortex-win.data.microsoft.com
0.0.0.0 vortex-sandbox.data.microsoft.com
:: vortex-sandbox.data.microsoft.com
0.0.0.0 vortex-win-sandbox.data.microsoft.com
:: vortex-win-sandbox.data.microsoft.com
0.0.0.0 vortex-win.data.microsoft.com
:: vortex-win.data.microsoft.com
0.0.0.0 vortex.data.glbdns2.microsoft.com
:: vortex.data.glbdns2.microsoft.com
0.0.0.0 vortex.data.microsoft.com
:: vortex.data.microsoft.comLevel 2Crash reporting, Watson and feedback
Watson is Microsoft's crash-reporting and error-analysis infrastructure. It can gather crash details, diagnostic information, application state and memory dump data. Blocking these domains prevents or curtails the submission of crash reports. Windows and your applications should keep running, but Microsoft will receive less information when something goes wrong. Feedback Hub and Microsoft's support diagnostics may also misbehave.
0.0.0.0 ceuswatcab01.blob.core.windows.net
:: ceuswatcab01.blob.core.windows.net
0.0.0.0 ceuswatcab02.blob.core.windows.net
:: ceuswatcab02.blob.core.windows.net
0.0.0.0 diagnostics.support.microsoft.com
:: diagnostics.support.microsoft.com
0.0.0.0 eaus2watcab01.blob.core.windows.net
:: eaus2watcab01.blob.core.windows.net
0.0.0.0 eaus2watcab02.blob.core.windows.net
:: eaus2watcab02.blob.core.windows.net
0.0.0.0 eu-watsonc.events.data.microsoft.com
:: eu-watsonc.events.data.microsoft.com
0.0.0.0 feedback.microsoft-hohm.com
:: feedback.microsoft-hohm.com
0.0.0.0 feedback.search.microsoft.com
:: feedback.search.microsoft.com
0.0.0.0 feedback.windows.com
:: feedback.windows.com
0.0.0.0 kmwatsonc.events.data.microsoft.com
:: kmwatsonc.events.data.microsoft.com
0.0.0.0 modern.watson.data.microsoft.com
:: modern.watson.data.microsoft.com
0.0.0.0 modern.watson.data.microsoft.com.akadns.net
:: modern.watson.data.microsoft.com.akadns.net
0.0.0.0 oca.microsoft.com
:: oca.microsoft.com
0.0.0.0 oca.telemetry.microsoft.com
:: oca.telemetry.microsoft.com
0.0.0.0 reports.wes.df.telemetry.microsoft.com
:: reports.wes.df.telemetry.microsoft.com
0.0.0.0 services.wes.df.telemetry.microsoft.com
:: services.wes.df.telemetry.microsoft.com
0.0.0.0 survey.watson.microsoft.com
:: survey.watson.microsoft.com
0.0.0.0 umwatson.events.data.microsoft.com
:: umwatson.events.data.microsoft.com
0.0.0.0 umwatsonc.events.data.microsoft.com
:: umwatsonc.events.data.microsoft.com
0.0.0.0 watson.live.com
:: watson.live.com
0.0.0.0 watson.microsoft.com
:: watson.microsoft.com
0.0.0.0 watson.ppe.telemetry.microsoft.com
:: watson.ppe.telemetry.microsoft.com
0.0.0.0 watson.telemetry.microsoft.com
:: watson.telemetry.microsoft.com
0.0.0.0 watsonc.events.data.microsoft.com
:: watsonc.events.data.microsoft.com
0.0.0.0 wes.df.telemetry.microsoft.com
:: wes.df.telemetry.microsoft.com
0.0.0.0 weus2watcab01.blob.core.windows.net
:: weus2watcab01.blob.core.windows.net
0.0.0.0 weus2watcab02.blob.core.windows.net
:: weus2watcab02.blob.core.windows.netLevel 3MSN, Bing, ads, widgets and Spotlight
These domains serve MSN feeds, Bing assets, widgets, promotional content, thumbnails, suggested content and Windows Spotlight material. They are generally safe to block if you do not use those features. Possible side effects include empty widgets, missing weather cards, a blank Edge new-tab page, absent thumbnails and Windows Spotlight falling back to a static background.
0.0.0.0 api.msn.com
:: api.msn.com
0.0.0.0 arc.msn.com
:: arc.msn.com
0.0.0.0 assets.msn.com
:: assets.msn.com
0.0.0.0 business.bing.com
:: business.bing.com
0.0.0.0 c.bing.com
:: c.bing.com
0.0.0.0 c.msn.com
:: c.msn.com
0.0.0.0 choice.microsoft.com
:: choice.microsoft.com
0.0.0.0 creativecdn.com
:: creativecdn.com
0.0.0.0 edgeassetservice.azureedge.net
:: edgeassetservice.azureedge.net
0.0.0.0 evoke-windowsservices-tas.msedge.net
:: evoke-windowsservices-tas.msedge.net
0.0.0.0 fd.api.iris.microsoft.com
:: fd.api.iris.microsoft.com
0.0.0.0 fp-afd-nocache-ccp.azureedge.net
:: fp-afd-nocache-ccp.azureedge.net
0.0.0.0 fp-vs.azureedge.net
:: fp-vs.azureedge.net
0.0.0.0 g.msn.com
:: g.msn.com
0.0.0.0 ntp.msn.com
:: ntp.msn.com
0.0.0.0 prod-azurecdn-akamai-iris.azureedge.net
:: prod-azurecdn-akamai-iris.azureedge.net
0.0.0.0 ris.api.iris.microsoft.com
:: ris.api.iris.microsoft.com
0.0.0.0 srtb.msn.com
:: srtb.msn.com
0.0.0.0 staticview.msn.com
:: staticview.msn.com
0.0.0.0 th.bing.com
:: th.bing.com
0.0.0.0 tse1.mm.bing.net
:: tse1.mm.bing.net
0.0.0.0 widgetcdn.azureedge.net
:: widgetcdn.azureedge.net
0.0.0.0 widgetservice.azurefd.net
:: widgetservice.azurefd.net
0.0.0.0 www.msn.com
:: www.msn.comLevel 4Location, maps, weather, OneNote and activity
These domains underpin genuine Windows features, so block them only if you do not use those features. Blocking location services may affect:
- Automatic location detection
- Automatic time-zone detection
- Find My Device
- Maps
- Weather
- Applications that request Windows location data
Blocking OneNote's CDN can cause missing resources or other loading issues inside OneNote. Blocking the activity domains may disable activity sync and connected-device features.
0.0.0.0 activity.windows.com
:: activity.windows.com
0.0.0.0 assets.activity.windows.com
:: assets.activity.windows.com
0.0.0.0 cdn.onenote.net
:: cdn.onenote.net
0.0.0.0 ecn.dev.virtualearth.net
:: ecn.dev.virtualearth.net
0.0.0.0 ecn-us.dev.virtualearth.net
:: ecn-us.dev.virtualearth.net
0.0.0.0 edge.activity.windows.com
:: edge.activity.windows.com
0.0.0.0 inference.location.live.net
:: inference.location.live.net
0.0.0.0 location-inference-westus.cloudapp.net
:: location-inference-westus.cloudapp.net
0.0.0.0 maps.windows.com
:: maps.windows.com
0.0.0.0 tile-service.weather.microsoft.com
:: tile-service.weather.microsoft.com
0.0.0.0 weathermapdata.blob.core.windows.net
:: weathermapdata.blob.core.windows.netLevel 5Edge configuration and feature experiments
These domains appear to be tied to Edge feature rollout rings, configuration, experiments, fallback services and browser content delivered by Microsoft. Blocking them makes sense if you do not use Edge and do not want Microsoft remotely altering or testing browser features. Windows still uses Edge WebView2 for some applications, so test those applications afterwards.
0.0.0.0 a-ring-fallback.msedge.net
:: a-ring-fallback.msedge.net
0.0.0.0 c-ring.msedge.net
:: c-ring.msedge.net
0.0.0.0 config.edge.skype.com
:: config.edge.skype.com
0.0.0.0 dual-s-ring.msedge.net
:: dual-s-ring.msedge.net
0.0.0.0 fp.msedge.net
:: fp.msedge.net
0.0.0.0 i-ring.msedge.net
:: i-ring.msedge.net
0.0.0.0 ln-ring.msedge.net
:: ln-ring.msedge.net
0.0.0.0 s-ring.msedge.net
:: s-ring.msedge.net
0.0.0.0 t-ring.msedge.net
:: t-ring.msedge.net
0.0.0.0 t-ring-fdv2.msedge.net
:: t-ring-fdv2.msedge.netLevel 6Cloud settings, commands and functional events
These endpoints are more aggressive because they may handle cloud configuration, feature flags, experiments, telemetry instructions and functional event processing. Blocking them can curb Microsoft's remote control over connected Windows features. It may also cause some cloud-managed settings or Microsoft components to behave unpredictably.
0.0.0.0 asimov-win.settings.data.microsoft.com.akadns.net
:: asimov-win.settings.data.microsoft.com.akadns.net
0.0.0.0 co4.telecommand.telemetry.microsoft.com
:: co4.telecommand.telemetry.microsoft.com
0.0.0.0 cy2.settings.data.microsoft.com.akadns.net
:: cy2.settings.data.microsoft.com.akadns.net
0.0.0.0 cy2.vortex.data.microsoft.com.akadns.net
:: cy2.vortex.data.microsoft.com.akadns.net
0.0.0.0 db5-eap.settings-win.data.microsoft.com.akadns.net
:: db5-eap.settings-win.data.microsoft.com.akadns.net
0.0.0.0 db5.settings-win.data.microsoft.com.akadns.net
:: db5.settings-win.data.microsoft.com.akadns.net
0.0.0.0 db5.vortex.data.microsoft.com.akadns.net
:: db5.vortex.data.microsoft.com.akadns.net
0.0.0.0 functional.events.data.microsoft.com
:: functional.events.data.microsoft.com
0.0.0.0 geo.settings-win.data.microsoft.com.akadns.net
:: geo.settings-win.data.microsoft.com.akadns.net
0.0.0.0 geo.vortex.data.microsoft.com.akadns.net
:: geo.vortex.data.microsoft.com.akadns.net
0.0.0.0 query.prod.cms.rt.microsoft.com
:: query.prod.cms.rt.microsoft.com
0.0.0.0 settings-sandbox.data.microsoft.com
:: settings-sandbox.data.microsoft.com
0.0.0.0 settings-win.data.microsoft.com
:: settings-win.data.microsoft.com
0.0.0.0 settings.data.glbdns2.microsoft.com
:: settings.data.glbdns2.microsoft.com
0.0.0.0 settings.data.microsoft.com
:: settings.data.microsoft.com
0.0.0.0 telecommand.telemetry.microsoft.com
:: telecommand.telemetry.microsoft.com
0.0.0.0 www.telecommandsvc.microsoft.com
:: www.telecommandsvc.microsoft.comLevel 7Statistics, delivery telemetry and traffic shaping
These hostnames are associated with statistics, CDN infrastructure and
traffic-management services. They should not be casually described as the servers
that deliver Windows update packages. A name such as
statsfe2.update.microsoft.com suggests reporting or statistics about
updates, which is not the same as hosting the update payload itself. Blocking these
domains may affect statistics, download coordination, traffic shaping or reporting
around Microsoft services. It should not be presented as equivalent to disabling
Windows Update.
0.0.0.0 cs11.wpc.v0cdn.net
:: cs11.wpc.v0cdn.net
0.0.0.0 cs1137.wpc.gammacdn.net
:: cs1137.wpc.gammacdn.net
0.0.0.0 statsfe1.ws.microsoft.com
:: statsfe1.ws.microsoft.com
0.0.0.0 statsfe2.update.microsoft.com.akadns.net
:: statsfe2.update.microsoft.com.akadns.net
0.0.0.0 statsfe2.ws.microsoft.com
:: statsfe2.ws.microsoft.com
0.0.0.0 tsfe.trafficshaping.dsp.mp.microsoft.com
:: tsfe.trafficshaping.dsp.mp.microsoft.comLevel 8Device registration and GDID-related endpoints
This is the most aggressive privacy category on the list. These domains can be involved in device registration, connected experiences, Microsoft account integration, Entra ID, Autopilot and persistent device identification. Do not block them on a work-managed machine without understanding how the organisation manages the device. Possible side effects include:
- Device registration failures
- Broken work or school enrolment
- Entra ID problems
- Autopilot deployment failures
- Account synchronisation errors
- Connected-device features no longer working
- Microsoft account warnings
0.0.0.0 aad.cs.dds.microsoft.com
:: aad.cs.dds.microsoft.com
0.0.0.0 cdpcs.access.microsoft.com
:: cdpcs.access.microsoft.com
0.0.0.0 cs.dds.microsoft.com
:: cs.dds.microsoft.com
0.0.0.0 dds.microsoft.com
:: dds.microsoft.com
0.0.0.0 fd.dds.microsoft.com
:: fd.dds.microsoft.com
0.0.0.0 mucp.api.account.microsoft.com
:: mucp.api.account.microsoft.com
0.0.0.0 ztd.dds.microsoft.com
:: ztd.dds.microsoft.comLevel 9Microsoft account authentication
The final category contains Microsoft account authentication endpoints. Blocking these domains is technically possible, but it can stop account-based Microsoft services from working. If your goal is to prevent Microsoft account use entirely and keep Windows strictly local, these are the last entries to add. Possible side effects include problems with:
- Microsoft account sign-in
- Microsoft Store authentication
- Microsoft 365
- OneDrive
- Outlook
- Xbox services
- Licence checks tied to an account
- Account recovery
- Work or school authentication
0.0.0.0 account.live.com
:: account.live.com
0.0.0.0 login.live.com
:: login.live.comTest the blocks in stages
Do not add every category at once unless you are ready to troubleshoot the consequences.
Begin with telemetry and crash reporting. Use the computer normally for a few days. Then add the content, widgets, location, cloud settings and device registration categories one at a time.
After each change, test the features you care about:
- Windows activation
- Windows Update
- Defender signature updates
- Microsoft Store
- Microsoft 365
- OneDrive
- VPN software
- Work or school accounts
- WebView2-based applications
- Your preferred browser
- Any Microsoft application you still use
You can check a blocked domain in PowerShell:
Resolve-DnsName telemetry.microsoft.comOr use:
ping telemetry.microsoft.comA blocked hostname should resolve to 0.0.0.0 or ::,
depending on which address Windows picks. Some applications cache DNS results;
close and reopen them after editing the hosts file.
If something breaks, remove the entries from the most recently added category and run:
ipconfig /flushdnsTo restore the original hosts file from your backup:
copy /y "%USERPROFILE%\Desktop\hosts-backup.txt" ^
"%SystemRoot%\System32\drivers\etc\hosts"
ipconfig /flushdnsWindows privacy needs ongoing maintenance
There is no single privacy switch for Windows 11. The most effective setup combines several layers:
- Use Brave or Firefox instead of Edge
- Use a local Windows account
- Remove Microsoft applications you do not need
- Remove or disable Copilot and other AI features
- Disable Widgets, MSN feeds, suggestions and personalised content
- Set diagnostic data to the lowest available level
- Use Windows Enterprise for stronger Group Policy controls
- Disable unnecessary cloud integrations
- Decide whether SmartScreen and Defender cloud features fit your threat model
- Block telemetry domains through the hosts file
- Review everything again after major Windows updates
Microsoft alters Windows constantly. New endpoints appear, old hostnames vanish, settings move, and unwanted applications sometimes return after updates.
The aim is not to break Windows or blindly block every Microsoft server. The aim is to strip out unnecessary data collection whilst keeping the specific features and security protections you actually want.
Microsoft designed Windows 11 around cloud connectivity and continuous data collection. If you are required to use it, accepting every default is not your only option.