Microsoft has spent years turning Windows from a traditional desktop operating system into a deeply connected cloud platform.
Some of those connections are useful. Windows needs internet access for updates, malware definitions, activation, cloud storage, account synchronization, and other services people choose to use.
The problem is everything that comes with them.
A standard Windows 11 installation regularly contacts Microsoft servers for diagnostics, crash reports, feature experiments, cloud configuration, advertising, personalized recommendations, Bing results, MSN content, widgets, location services, account activity, and browser telemetry.
Most people never get a clear explanation of what is being sent, why it is being sent, or how long it is associated with their device.
Microsoft gives users plenty of privacy switches, but those switches are spread across different sections of Settings. Some options are only available through Group Policy. Some settings return after major updates, and others only disable one part of a much larger data collection system.
If you have to use Windows, you probably cannot make it completely private. You can, however, reduce the amount of data it sends by a huge margin.
The GDID case shows why device tracking matters
The GDID case brought attention to a particularly uncomfortable part of modern Windows: persistent device identification.
A global or persistent device identifier allows online activity to be associated with the same Windows installation or physical device over time. Even if the collected records do not contain your real name in every request, a stable identifier makes separate events much easier to connect.
Windows communicates with several device registration and connected-device endpoints, including:
dds.microsoft.com
cs.dds.microsoft.com
aad.cs.dds.microsoft.com
fd.dds.microsoft.com
ztd.dds.microsoft.com
cdpcs.access.microsoft.com
activity.windows.com
assets.activity.windows.com
edge.activity.windows.com
These services have been associated with device registration, connected experiences, Microsoft account integration, Entra ID, activity synchronization, and zero-touch deployment systems such as Windows Autopilot.
Not every request to these domains proves that Microsoft is tracking everything a person does. Some of these services have legitimate enterprise and device-management functions. Public documentation also does not fully explain every internal identifier, endpoint, or data flow.
Still, that does not make the privacy concern disappear.
A persistent device identifier can connect activity across sessions and Microsoft services. For a home computer that does not use Entra ID, Autopilot, cross-device synchronization, or corporate management, it is reasonable to question why so many device registration connections are necessary.
These domains can be blocked, but they should be treated as an aggressive category. Blocking them can interfere with Microsoft accounts, work or school enrollment, device registration, activity synchronization, and other connected experiences.
There are safer privacy changes to make first.
Stop using Microsoft Edge as your primary browser
The easiest place to start is the browser.
Edge is tightly integrated with Microsoft's advertising, search, synchronization, shopping, content, and telemetry systems. Depending on its configuration, Edge can communicate with Microsoft for:
- Search and URL suggestions
- Browsing diagnostics
- Shopping recommendations
- Personalized ads
- Microsoft Rewards
- Copilot features
- Sidebar apps
- MSN news
- New-tab content
- Account synchronization
- Typing and spelling assistance
- Website reputation checks
You can disable many of these features, but there is little reason to make Edge your primary browser if privacy is a priority.
Brave is a practical replacement for people who need Chromium compatibility. It works with almost every website that supports Chrome, has good tracker blocking by default, and requires less initial configuration.
I recommend reviewing Brave's own settings too. Disable Rewards, sponsored content, usage reporting, and any other features you do not need. No browser should receive a free pass just because it markets itself as private.
Firefox is the better choice if you want some distance from the Chromium ecosystem. A reasonable Firefox setup includes:
- Enhanced Tracking Protection set to Strict
- uBlock Origin
- HTTPS-Only Mode
- Disabled telemetry and studies
- Disabled sponsored suggestions
- A trusted DNS-over-HTTPS provider
- Separate browser profiles for different activities
Neither Brave nor Firefox makes you anonymous. Websites can still track visitors through accounts, cookies, fingerprinting, IP addresses, and analytics scripts. They are simply better foundations than a browser deeply connected to the Windows ecosystem.
Remove Microsoft bloatware, AI, widgets, and suggestions
Windows 11 comes with apps, promotional shortcuts, AI integrations, and cloud content that many people never requested.
Open:
Settings > Apps > Installed apps
Remove the applications and components you do not use. What appears on the list depends on your Windows edition, region, hardware, and installation date, but common examples include:
- Clipchamp
- Copilot
- Dev Home
- Family
- Feedback Hub
- Get Help
- Microsoft 365 promotional apps
- Microsoft News
- Microsoft Teams for personal use
- Mixed Reality
- Outlook for Windows
- Phone Link
- Solitaire
- Xbox applications
- Widgets
- Weather
Also open the taskbar settings and disable Widgets, Copilot, Search highlights, and other online features you do not want.
If your computer supports Recall or other Copilot+ features, review those settings separately. Do not assume they are disabled just because you never opened the application.
The same applies to suggested content. Microsoft places recommendations in the Start menu, Settings, notifications, lock screen, and File Explorer.
Turn off as many of these as your Windows version allows:
- Account-related notifications
- Personalized offers
- Recommendations in Start
- Search highlights
- Suggested content in Settings
- Tailored experiences
- Tips and suggestions
- Windows welcome experience
- Ways to get the most out of Windows
Do not blindly run a debloating tool with every option selected. Some tools remove WebView2, codecs, Store dependencies, application installers, and shared frameworks needed by unrelated programs.
Remove things gradually, restart Windows, and test the applications you actually use.
Disable everything you can under Privacy and Security
Open Settings > Privacy & security and inspect every category.
Microsoft changes the wording and location of these controls between Windows releases, but the important options normally include:
- Advertising ID
- Activity history
- App diagnostics
- Automatic file downloads
- Cloud content search
- Diagnostic data
- Feedback frequency
- Inking and typing personalization
- Location
- Online speech recognition
- Personalized offers
- Search permissions
- Suggested content
- Tailored experiences
Set diagnostic data to the lowest level available on your edition.
Disable optional diagnostic data, tailored experiences, advertising personalization, feedback requests, typing personalization, and cloud search if you do not need them.
Then open:
Settings > System > Notifications > Additional settings
Disable options such as:
- Show the Windows welcome experience after updates
- Suggest ways to get the most out of Windows
- Get tips and suggestions when using Windows
You should also inspect permissions for the camera, microphone, location, contacts, calendar, call history, messages, account information, and background applications.
Do not give an application permanent access to something it does not need.
Use a local Windows account when possible
A local account will not stop Windows telemetry, but it reduces the direct connection between your Windows profile and a Microsoft identity.
You can use a local Windows account while signing in separately to individual applications such as OneDrive, Microsoft 365, or Xbox.
That separation is useful. It means the operating system itself does not have to be permanently connected to the same account used for email, cloud storage, subscriptions, and other Microsoft services.
Microsoft keeps making local-account installation more difficult. The available setup methods change between Windows versions, so check which method works with your current release before reinstalling Windows.
Move to Enterprise for better privacy controls
Windows Home and Pro do not expose the same level of telemetry control as Windows Enterprise and Education.
Enterprise gives you access to stricter diagnostic-data policies and a much wider set of Group Policy controls. If privacy matters and you have to remain on Windows, Enterprise is the edition I recommend.
Changing the Windows edition and owning a valid license are not the same thing. Edition conversion changes the installed Windows feature set. Licensing and activation are separate questions.
If you already have a legitimate Enterprise license through work, school, volume licensing, or another channel, use it.
If you do not have another practical option, I recommend looking at Massgrave. It can handle edition changes and related Windows activation tasks in about half a minute.
Use the real site, read what the script does, and understand that changing editions does not automatically give you a legal Enterprise license. That is a separate matter between you, Microsoft, and any organization whose licensing may apply to the device.
The reason to move to Enterprise is access to better policy controls, not the name shown in the System window.
Disable telemetry through Group Policy
On Windows Enterprise, open the Run dialog with Win + R, type:
gpedit.msc
Then go to:
Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds
Look for a policy named Allow Diagnostic Data or Allow Telemetry, depending on your Windows version.
Set diagnostic collection to the lowest level available.
You should also review these Group Policy sections:
- Cloud Content
- Data Collection and Preview Builds
- Microsoft Edge
- OneDrive
- Search
- Store
- Windows AI
- Windows Copilot
- Windows Error Reporting
- Windows Update
- Widgets
Useful policies include those that disable:
- Advertising ID
- Automatic feedback requests
- Cloud consumer accounts
- Consumer experiences
- Diagnostic data collection
- Experimentation
- Online tips
- Personalized content
- Search highlights
- Suggested applications
- Tailored experiences
- Windows Spotlight
- Windows tips
- Widgets
Policy names change over time. Microsoft also removes or replaces policies in newer Windows releases, so review them again after major feature updates.
SmartScreen and cloud protection come with a privacy cost
There is an uncomfortable privacy and security trade-off inside Windows Security.
Open:
Windows Security > App & browser control > Reputation-based protection
Microsoft Defender SmartScreen checks websites, downloads, applications, file reputation, and potentially unwanted software.
To perform those checks, Windows may send Microsoft information such as:
- URLs
- File names
- File hashes
- Download sources
- Certificate information
- Application reputation data
- Security-related metadata
SmartScreen can provide real security benefits. It can stop malicious downloads, phishing pages, and unknown applications before traditional antivirus detection catches up.
It is also a cloud reputation service, which means Microsoft receives information about what the computer is checking.
I personally keep SmartScreen and reputation-based protection disabled because I consider that level of cloud checking too invasive. That is my privacy decision, not a universal recommendation.
The same concern applies to cloud-delivered protection and automatic sample submission in Microsoft Defender.
Cloud-delivered protection allows Defender to send information about suspicious files and behavior to Microsoft for immediate analysis.
Automatic sample submission can send suspicious files or parts of files to Microsoft. Windows may ask before submitting certain files, but I do not want a security product deciding that one of my files should be uploaded to a third party.
I keep both cloud-delivered protection and automatic sample submission disabled.
That reduces Microsoft's access to information about my files and activity, but it can also reduce protection against new malware. Everyone should think about that trade-off and make their own decision.
If you regularly download unknown software, open email attachments, install game mods, use pirated software, or run random scripts, turning off cloud protection may be a bad trade for you.
If you keep these features disabled, compensate with better habits:
- Keep Defender signatures updated
- Keep Windows security updates installed
- Do not run unknown scripts as administrator
- Check digital signatures
- Scan suspicious files with more than one engine when appropriate
- Keep offline backups
- Use a standard account for daily work
- Show file extensions in File Explorer
- Avoid broad Defender exclusions
- Use application isolation or a virtual machine for risky files
Privacy is important, but an information-stealing malware infection is worse than Microsoft telemetry.
Block Microsoft telemetry through the hosts file
After changing Windows settings and Group Policy, the next step is blocking selected Microsoft domains.
The Windows hosts file is located here:
C:\Windows\System32\drivers\etc\hosts
A hosts entry maps a hostname to an address. Mapping it to 0.0.0.0 blocks the IPv4 connection. Mapping it to :: covers IPv6.
For example:
0.0.0.0 telemetry.example.com
:: telemetry.example.com
The hosts file does not support wildcards. Blocking example.com does not automatically block data.example.com.
It also cannot stop applications that use hardcoded IP addresses, another hostname, a proxy, or their own DNS resolver. It is still a useful and transparent layer.
Back up and edit the hosts file
Open Command Prompt as administrator and create a backup:
copy "%SystemRoot%\System32\drivers\etc\hosts" ^
"%USERPROFILE%\Desktop\hosts-backup.txt"
Then edit the file:
- Open the Start menu.
- Search for Notepad.
- Right-click Notepad.
- Select Run as administrator.
- Select File > Open.
- Open
C:\Windows\System32\drivers\etc. - Change the file type from Text Documents to All Files.
- Open the file named
hosts. - Add the entries at the bottom.
- Save the file.
Flush the DNS cache afterward:
ipconfig /flushdns
Restart applications that were already open because they may have cached DNS results.
Level 1: Basic telemetry and event collection
These are the safest entries to start with. They are primarily associated with telemetry, event collection, diagnostics, usage reporting, and test environments.
Blocking them should not disable normal Windows Update downloads, Microsoft account sign-in, or activation.
It may reduce Microsoft's ability to diagnose problems or analyze how Windows features are being used.
0.0.0.0 alpha.telemetry.microsoft.com
:: alpha.telemetry.microsoft.com
0.0.0.0 au-v10.events.data.microsoft.com
:: au-v10.events.data.microsoft.com
0.0.0.0 au-v20.events.data.microsoft.com
:: au-v20.events.data.microsoft.com
0.0.0.0 au.vortex-win.data.microsoft.com
:: au.vortex-win.data.microsoft.com
0.0.0.0 browser.events.data.msn.com
:: browser.events.data.msn.com
0.0.0.0 de-v20.events.data.microsoft.com
:: de-v20.events.data.microsoft.com
0.0.0.0 de.vortex-win.data.microsoft.com
:: de.vortex-win.data.microsoft.com
0.0.0.0 df.telemetry.microsoft.com
:: df.telemetry.microsoft.com
0.0.0.0 eu-v10.events.data.microsoft.com
:: eu-v10.events.data.microsoft.com
0.0.0.0 eu-v10c.events.data.microsoft.com
:: eu-v10c.events.data.microsoft.com
0.0.0.0 eu-v20.events.data.microsoft.com
:: eu-v20.events.data.microsoft.com
0.0.0.0 eu.vortex-win.data.microsoft.com
:: eu.vortex-win.data.microsoft.com
0.0.0.0 events-sandbox.data.microsoft.com
:: events-sandbox.data.microsoft.com
0.0.0.0 events.data.microsoft.com
:: events.data.microsoft.com
0.0.0.0 jp-v10.events.data.microsoft.com
:: jp-v10.events.data.microsoft.com
0.0.0.0 jp-v20.events.data.microsoft.com
:: jp-v20.events.data.microsoft.com
0.0.0.0 onecollector.cloudapp.aria.akadns.net
:: onecollector.cloudapp.aria.akadns.net
0.0.0.0 self.events.data.microsoft.com
:: self.events.data.microsoft.com
0.0.0.0 sqm.df.telemetry.microsoft.com
:: sqm.df.telemetry.microsoft.com
0.0.0.0 sqm.telemetry.microsoft.com
:: sqm.telemetry.microsoft.com
0.0.0.0 tele.trafficmanager.net
:: tele.trafficmanager.net
0.0.0.0 telemetry.appex.bing.net
:: telemetry.appex.bing.net
0.0.0.0 telemetry.microsoft.com
:: telemetry.microsoft.com
0.0.0.0 telemetry.remoteapp.windowsazure.com
:: telemetry.remoteapp.windowsazure.com
0.0.0.0 telemetry.urs.microsoft.com
:: telemetry.urs.microsoft.com
0.0.0.0 uk-v20.events.data.microsoft.com
:: uk-v20.events.data.microsoft.com
0.0.0.0 uk.vortex-win.data.microsoft.com
:: uk.vortex-win.data.microsoft.com
0.0.0.0 us-v10.events.data.microsoft.com
:: us-v10.events.data.microsoft.com
0.0.0.0 us-v10c.events.data.microsoft.com
:: us-v10c.events.data.microsoft.com
0.0.0.0 us-v20.events.data.microsoft.com
:: us-v20.events.data.microsoft.com
0.0.0.0 us.vortex-win.data.microsoft.com
:: us.vortex-win.data.microsoft.com
0.0.0.0 us4-v20.events.data.microsoft.com
:: us4-v20.events.data.microsoft.com
0.0.0.0 us5-v20.events.data.microsoft.com
:: us5-v20.events.data.microsoft.com
0.0.0.0 v10-win.vortex.data.microsoft.com.akadns.net
:: v10-win.vortex.data.microsoft.com.akadns.net
0.0.0.0 v10.events.data.microsoft.com
:: v10.events.data.microsoft.com
0.0.0.0 v10.vortex-win.data.microsoft.com
:: v10.vortex-win.data.microsoft.com
0.0.0.0 v10c.events.data.microsoft.com
:: v10c.events.data.microsoft.com
0.0.0.0 v10c.vortex-win.data.microsoft.com
:: v10c.vortex-win.data.microsoft.com
0.0.0.0 v20.events.data.microsoft.com
:: v20.events.data.microsoft.com
0.0.0.0 v20.vortex-win.data.microsoft.com
:: v20.vortex-win.data.microsoft.com
0.0.0.0 vortex-sandbox.data.microsoft.com
:: vortex-sandbox.data.microsoft.com
0.0.0.0 vortex-win-sandbox.data.microsoft.com
:: vortex-win-sandbox.data.microsoft.com
0.0.0.0 vortex-win.data.microsoft.com
:: vortex-win.data.microsoft.com
0.0.0.0 vortex.data.glbdns2.microsoft.com
:: vortex.data.glbdns2.microsoft.com
0.0.0.0 vortex.data.microsoft.com
:: vortex.data.microsoft.com
Level 2: Crash reporting, Watson, and feedback
Watson is Microsoft's crash-reporting and error-analysis infrastructure. It can collect crash details, diagnostic information, application state, and memory dump data.
Blocking these domains prevents or reduces the submission of crash reports. Windows and applications should still run, but Microsoft will receive less information when something fails.
Feedback Hub and Microsoft's support diagnostics may also stop working correctly.
0.0.0.0 ceuswatcab01.blob.core.windows.net
:: ceuswatcab01.blob.core.windows.net
0.0.0.0 ceuswatcab02.blob.core.windows.net
:: ceuswatcab02.blob.core.windows.net
0.0.0.0 diagnostics.support.microsoft.com
:: diagnostics.support.microsoft.com
0.0.0.0 eaus2watcab01.blob.core.windows.net
:: eaus2watcab01.blob.core.windows.net
0.0.0.0 eaus2watcab02.blob.core.windows.net
:: eaus2watcab02.blob.core.windows.net
0.0.0.0 eu-watsonc.events.data.microsoft.com
:: eu-watsonc.events.data.microsoft.com
0.0.0.0 feedback.microsoft-hohm.com
:: feedback.microsoft-hohm.com
0.0.0.0 feedback.search.microsoft.com
:: feedback.search.microsoft.com
0.0.0.0 feedback.windows.com
:: feedback.windows.com
0.0.0.0 kmwatsonc.events.data.microsoft.com
:: kmwatsonc.events.data.microsoft.com
0.0.0.0 modern.watson.data.microsoft.com
:: modern.watson.data.microsoft.com
0.0.0.0 modern.watson.data.microsoft.com.akadns.net
:: modern.watson.data.microsoft.com.akadns.net
0.0.0.0 oca.microsoft.com
:: oca.microsoft.com
0.0.0.0 oca.telemetry.microsoft.com
:: oca.telemetry.microsoft.com
0.0.0.0 reports.wes.df.telemetry.microsoft.com
:: reports.wes.df.telemetry.microsoft.com
0.0.0.0 services.wes.df.telemetry.microsoft.com
:: services.wes.df.telemetry.microsoft.com
0.0.0.0 survey.watson.microsoft.com
:: survey.watson.microsoft.com
0.0.0.0 umwatson.events.data.microsoft.com
:: umwatson.events.data.microsoft.com
0.0.0.0 umwatsonc.events.data.microsoft.com
:: umwatsonc.events.data.microsoft.com
0.0.0.0 watson.live.com
:: watson.live.com
0.0.0.0 watson.microsoft.com
:: watson.microsoft.com
0.0.0.0 watson.ppe.telemetry.microsoft.com
:: watson.ppe.telemetry.microsoft.com
0.0.0.0 watson.telemetry.microsoft.com
:: watson.telemetry.microsoft.com
0.0.0.0 watsonc.events.data.microsoft.com
:: watsonc.events.data.microsoft.com
0.0.0.0 wes.df.telemetry.microsoft.com
:: wes.df.telemetry.microsoft.com
0.0.0.0 weus2watcab01.blob.core.windows.net
:: weus2watcab01.blob.core.windows.net
0.0.0.0 weus2watcab02.blob.core.windows.net
:: weus2watcab02.blob.core.windows.net
Level 3: MSN, Bing, ads, widgets, and Spotlight
These domains provide MSN feeds, Bing assets, widgets, promotional content, thumbnails, suggested content, and Windows Spotlight material.
They are generally safe to block if you do not use those features.
Possible side effects include blank widgets, missing weather cards, an empty Edge new-tab page, missing thumbnails, and Windows Spotlight falling back to a static background.
0.0.0.0 api.msn.com
:: api.msn.com
0.0.0.0 arc.msn.com
:: arc.msn.com
0.0.0.0 assets.msn.com
:: assets.msn.com
0.0.0.0 business.bing.com
:: business.bing.com
0.0.0.0 c.bing.com
:: c.bing.com
0.0.0.0 c.msn.com
:: c.msn.com
0.0.0.0 choice.microsoft.com
:: choice.microsoft.com
0.0.0.0 creativecdn.com
:: creativecdn.com
0.0.0.0 edgeassetservice.azureedge.net
:: edgeassetservice.azureedge.net
0.0.0.0 evoke-windowsservices-tas.msedge.net
:: evoke-windowsservices-tas.msedge.net
0.0.0.0 fd.api.iris.microsoft.com
:: fd.api.iris.microsoft.com
0.0.0.0 fp-afd-nocache-ccp.azureedge.net
:: fp-afd-nocache-ccp.azureedge.net
0.0.0.0 fp-vs.azureedge.net
:: fp-vs.azureedge.net
0.0.0.0 g.msn.com
:: g.msn.com
0.0.0.0 ntp.msn.com
:: ntp.msn.com
0.0.0.0 prod-azurecdn-akamai-iris.azureedge.net
:: prod-azurecdn-akamai-iris.azureedge.net
0.0.0.0 ris.api.iris.microsoft.com
:: ris.api.iris.microsoft.com
0.0.0.0 srtb.msn.com
:: srtb.msn.com
0.0.0.0 staticview.msn.com
:: staticview.msn.com
0.0.0.0 th.bing.com
:: th.bing.com
0.0.0.0 tse1.mm.bing.net
:: tse1.mm.bing.net
0.0.0.0 widgetcdn.azureedge.net
:: widgetcdn.azureedge.net
0.0.0.0 widgetservice.azurefd.net
:: widgetservice.azurefd.net
0.0.0.0 www.msn.com
:: www.msn.com
Level 4: Location, maps, weather, OneNote, and activity
These domains support real Windows features. They are safe to block only if you do not use those features.
Blocking location services may affect:
- Automatic location detection
- Automatic time-zone detection
- Find My Device
- Maps
- Weather
- Applications that request Windows location data
Blocking OneNote's CDN may cause missing resources or other loading problems inside OneNote.
Blocking activity domains may disable activity synchronization and connected-device features.
0.0.0.0 activity.windows.com
:: activity.windows.com
0.0.0.0 assets.activity.windows.com
:: assets.activity.windows.com
0.0.0.0 cdn.onenote.net
:: cdn.onenote.net
0.0.0.0 ecn.dev.virtualearth.net
:: ecn.dev.virtualearth.net
0.0.0.0 ecn-us.dev.virtualearth.net
:: ecn-us.dev.virtualearth.net
0.0.0.0 edge.activity.windows.com
:: edge.activity.windows.com
0.0.0.0 inference.location.live.net
:: inference.location.live.net
0.0.0.0 location-inference-westus.cloudapp.net
:: location-inference-westus.cloudapp.net
0.0.0.0 maps.windows.com
:: maps.windows.com
0.0.0.0 tile-service.weather.microsoft.com
:: tile-service.weather.microsoft.com
0.0.0.0 weathermapdata.blob.core.windows.net
:: weathermapdata.blob.core.windows.net
Level 5: Edge configuration and feature experiments
These domains appear to be connected to Edge feature rollout rings, configuration, experiments, fallback services, and Microsoft-delivered browser content.
Blocking them makes sense if you do not use Edge and do not want Microsoft remotely changing or testing browser features.
Windows still uses Edge WebView2 for some applications, so test those applications afterward.
0.0.0.0 a-ring-fallback.msedge.net
:: a-ring-fallback.msedge.net
0.0.0.0 c-ring.msedge.net
:: c-ring.msedge.net
0.0.0.0 config.edge.skype.com
:: config.edge.skype.com
0.0.0.0 dual-s-ring.msedge.net
:: dual-s-ring.msedge.net
0.0.0.0 fp.msedge.net
:: fp.msedge.net
0.0.0.0 i-ring.msedge.net
:: i-ring.msedge.net
0.0.0.0 ln-ring.msedge.net
:: ln-ring.msedge.net
0.0.0.0 s-ring.msedge.net
:: s-ring.msedge.net
0.0.0.0 t-ring.msedge.net
:: t-ring.msedge.net
0.0.0.0 t-ring-fdv2.msedge.net
:: t-ring-fdv2.msedge.net
Level 6: Cloud settings, commands, and functional events
These endpoints are more aggressive because they may handle cloud configuration, feature flags, experiments, telemetry instructions, and functional event processing.
Blocking them can reduce Microsoft's remote control over connected Windows features. It may also cause some cloud-managed settings or Microsoft components to behave unexpectedly.
0.0.0.0 asimov-win.settings.data.microsoft.com.akadns.net
:: asimov-win.settings.data.microsoft.com.akadns.net
0.0.0.0 co4.telecommand.telemetry.microsoft.com
:: co4.telecommand.telemetry.microsoft.com
0.0.0.0 cy2.settings.data.microsoft.com.akadns.net
:: cy2.settings.data.microsoft.com.akadns.net
0.0.0.0 cy2.vortex.data.microsoft.com.akadns.net
:: cy2.vortex.data.microsoft.com.akadns.net
0.0.0.0 db5-eap.settings-win.data.microsoft.com.akadns.net
:: db5-eap.settings-win.data.microsoft.com.akadns.net
0.0.0.0 db5.settings-win.data.microsoft.com.akadns.net
:: db5.settings-win.data.microsoft.com.akadns.net
0.0.0.0 db5.vortex.data.microsoft.com.akadns.net
:: db5.vortex.data.microsoft.com.akadns.net
0.0.0.0 functional.events.data.microsoft.com
:: functional.events.data.microsoft.com
0.0.0.0 geo.settings-win.data.microsoft.com.akadns.net
:: geo.settings-win.data.microsoft.com.akadns.net
0.0.0.0 geo.vortex.data.microsoft.com.akadns.net
:: geo.vortex.data.microsoft.com.akadns.net
0.0.0.0 query.prod.cms.rt.microsoft.com
:: query.prod.cms.rt.microsoft.com
0.0.0.0 settings-sandbox.data.microsoft.com
:: settings-sandbox.data.microsoft.com
0.0.0.0 settings-win.data.microsoft.com
:: settings-win.data.microsoft.com
0.0.0.0 settings.data.glbdns2.microsoft.com
:: settings.data.glbdns2.microsoft.com
0.0.0.0 settings.data.microsoft.com
:: settings.data.microsoft.com
0.0.0.0 telecommand.telemetry.microsoft.com
:: telecommand.telemetry.microsoft.com
0.0.0.0 www.telecommandsvc.microsoft.com
:: www.telecommandsvc.microsoft.com
Level 7: Statistics, delivery telemetry, and traffic shaping
These hostnames are associated with statistics, CDN infrastructure, and traffic-management services.
They should not be casually described as the servers that deliver Windows update packages. A name such as statsfe2.update.microsoft.com suggests reporting or statistics related to updates, which is not the same thing as hosting the update payload itself.
Blocking these domains may affect statistics, download coordination, traffic shaping, or reporting around Microsoft services. It should not be presented as equivalent to disabling Windows Update.
0.0.0.0 cs11.wpc.v0cdn.net
:: cs11.wpc.v0cdn.net
0.0.0.0 cs1137.wpc.gammacdn.net
:: cs1137.wpc.gammacdn.net
0.0.0.0 statsfe1.ws.microsoft.com
:: statsfe1.ws.microsoft.com
0.0.0.0 statsfe2.update.microsoft.com.akadns.net
:: statsfe2.update.microsoft.com.akadns.net
0.0.0.0 statsfe2.ws.microsoft.com
:: statsfe2.ws.microsoft.com
0.0.0.0 tsfe.trafficshaping.dsp.mp.microsoft.com
:: tsfe.trafficshaping.dsp.mp.microsoft.com
Level 8: Device registration and GDID-related endpoints
This is the most aggressive privacy category in the list.
These domains can be involved in device registration, connected experiences, Microsoft account integration, Entra ID, Autopilot, and persistent device identification.
Do not block them on a work-managed computer without understanding how the organization manages the device.
Possible side effects include:
- Device registration failures
- Broken work or school enrollment
- Entra ID problems
- Autopilot deployment failures
- Account synchronization errors
- Connected-device features no longer working
- Microsoft account warnings
0.0.0.0 aad.cs.dds.microsoft.com
:: aad.cs.dds.microsoft.com
0.0.0.0 cdpcs.access.microsoft.com
:: cdpcs.access.microsoft.com
0.0.0.0 cs.dds.microsoft.com
:: cs.dds.microsoft.com
0.0.0.0 dds.microsoft.com
:: dds.microsoft.com
0.0.0.0 fd.dds.microsoft.com
:: fd.dds.microsoft.com
0.0.0.0 mucp.api.account.microsoft.com
:: mucp.api.account.microsoft.com
0.0.0.0 ztd.dds.microsoft.com
:: ztd.dds.microsoft.com
Level 9: Microsoft account authentication
The final category contains Microsoft account authentication endpoints.
Blocking these domains is technically possible, but it can stop account-based Microsoft services from working.
If the goal is to prevent Microsoft account use completely and keep Windows local-only, these are the last entries to add.
Possible side effects include problems with:
- Microsoft account sign-in
- Microsoft Store authentication
- Microsoft 365
- OneDrive
- Outlook
- Xbox services
- License checks tied to an account
- Account recovery
- Work or school authentication
0.0.0.0 account.live.com
:: account.live.com
0.0.0.0 login.live.com
:: login.live.com
Test the blocks in stages
Do not add every category at once unless you are prepared to troubleshoot the result.
Start with telemetry and crash reporting. Use the computer normally for a few days. Then add content, widgets, location, cloud settings, and device registration categories one at a time.
After each change, test the features you care about:
- Windows activation
- Windows Update
- Defender signature updates
- Microsoft Store
- Microsoft 365
- OneDrive
- VPN software
- Work or school accounts
- WebView2-based applications
- Your preferred browser
- Any Microsoft application you still use
You can test a blocked domain in PowerShell:
Resolve-DnsName telemetry.microsoft.com
You can also use:
ping telemetry.microsoft.com
A blocked hostname should resolve to 0.0.0.0 or ::, depending on which address Windows chooses.
Some applications cache DNS results. Close and reopen them after changing the hosts file.
If something stops working, remove the entries from the most recently added category and run:
ipconfig /flushdns
To restore the original hosts file from the backup:
copy /y "%USERPROFILE%\Desktop\hosts-backup.txt" ^
"%SystemRoot%\System32\drivers\etc\hosts"
ipconfig /flushdns
Windows privacy requires maintenance
There is no single privacy switch for Windows 11.
The most effective setup combines several layers:
- Use Brave or Firefox instead of Edge
- Use a local Windows account
- Remove Microsoft applications you do not need
- Remove or disable Copilot and other AI features
- Disable Widgets, MSN feeds, suggestions, and personalized content
- Set diagnostic data to the lowest available level
- Use Windows Enterprise for stronger Group Policy controls
- Disable unnecessary cloud integrations
- Decide whether SmartScreen and Defender cloud features fit your threat model
- Block telemetry domains through the hosts file
- Review everything again after major Windows updates
Microsoft changes Windows constantly. New endpoints appear, old hostnames disappear, settings move, and unwanted applications sometimes return after updates.
The goal is not to break Windows or blindly block every Microsoft server. The goal is to remove unnecessary data collection while keeping the specific features and security protections you actually want.
Microsoft designed Windows 11 around cloud connectivity and continuous data collection. If you are required to use it, accepting every default is not your only option.
Top comments (0)