Privacy and Security Settings Windows 11: The Complete 2026 Guide (Every Setting Explained)

To access privacy and security settings in Windows 11, go to Settings > Privacy and Security. The page covers two areas: Privacy settings (advertising ID, diagnostic data, app permissions, Recall) and Security settings (Windows Defender, BitLocker, Core Isolation, Smart App Control). The single most impactful actions are turning off optional diagnostic data, enabling Controlled folder access, and turning on Memory Integrity.

Windows 11 ships with dozens of privacy and security toggles buried across two dozen subpages. Most guides cover seven of them. This Axeetech guide covers all of them. The Settings > Privacy and Security page controls everything from which apps can see your location, to whether Microsoft records your keystrokes, to whether an AI feature screenshots everything on your screen. You do not need to change every setting.

Privacy and security settings Windows 11 complete guide 2026 every setting.
The complete guide to Windows 11 Privacy and Security settings in 2026, covering every subsection from app permissions and diagnostic data to BitLocker, Core Isolation, and Windows Recall.

But you do need to know what each one does. This guide gives you every path, every recommended action, and the quick-start checklist to harden your PC in under 15 minutes.

Also Read: COM Surrogate Delete File Error

Quick-Start: The 14 Most Important Settings to Change Right Now

Use the table below if you want results fast. Come back to the detailed sections to understand why each setting matters.

PrioritySettingPathAction
CriticalMemory IntegrityWindows Security > Device Security > Core IsolationON
CriticalTamper ProtectionWindows Security > Virus and threat protection > SettingsON
CriticalRansomware protectionWindows Security > Virus and threat protection > Ransomware protectionON
CriticalAdvertising IDSettings > Privacy and Security > GeneralOFF
CriticalOptional diagnostic dataSettings > Privacy and Security > Diagnostics and feedbackOFF
CriticalTailored experiencesSettings > Privacy and Security > Diagnostics and feedbackOFF
CriticalActivity historySettings > Privacy and Security > Activity historyOFF
HighBitLocker/Device EncryptionSettings > Privacy and Security > Device encryptionON
HighSmartScreen (all toggles)Windows Security > App and browser controlON
HighFirewall (all networks)Windows Security > Firewall and network protectionON
HighApp permissions auditSettings > Privacy and Security > App permissionsReview each
MediumDNS over HTTPSSettings > Network and Internet > Wi-Fi > [Network] > DNSON
MediumWindows HelloSettings > Accounts > Sign-in optionsEnable
MediumRecall snapshotsSettings > Privacy and Security > Recall and snapshotsOFF (Copilot+ PCs)
Windows 11 privacy security quick start checklist 2026 most important settings.
The 14 most critical privacy and security settings to change in Windows 11, organized by Critical, High, and Medium priority with exact navigation paths.

How to Open Privacy and Security Settings in Windows 11

The main path is the same in Windows 11 and Windows 10:

Settings > Privacy and Security

The fastest shortcut is Win+I to open Settings, then click Privacy and Security in the left panel. For direct access to specific subsections, press Win+R and use the following Run commands:

Privacy General page:

ms-settings:privacy-general

Diagnostics and feedback page:

ms-settings:privacy-feedback

The Settings > Privacy and Security page has three logical groups. Security at the top covers Windows Security, Device encryption, Find my device, and For developers. Privacy in the middle covers General, Speech, Inking and typing personalization, Diagnostics and feedback, Activity history, Search permissions, Searching Windows, and Presence sensing. App permissions at the bottom lists every hardware and data access permission Windows manages on behalf of installed apps.

Privacy Settings: General (Advertising ID and Tracking)

The General page controls how Windows collects behavioral data to serve personalized content and ads. Every toggle here is a form of tracking that provides zero benefit to your PC performance or stability.

Navigate to:

Settings > Privacy and Security > General

Turn off all four toggles:

  1. Let apps show me personalized ads using my advertising ID (turns off the unique cross-app tracking identifier Windows assigns to your device)
  2. Let websites show me locally relevant content by accessing my language list (stops websites from using your language preferences to infer location)
  3. Let Windows improve Start and search results by tracking app launches (stops Windows from monitoring which apps you open and when)
  4. Show me suggested content in the Settings app (stops ads and promotional content inside the Settings app itself)

The advertising ID is the most important of these four. It functions like a browser cookie but for apps. Turning it off prevents every installed app from sharing a single tracking identifier to build a cross-app profile of your behavior.

Privacy Settings: Diagnostics, Feedback, and Activity History

This group of settings controls the volume of data Windows sends to Microsoft and how long it stores behavioral data on your device.

Diagnostics and Feedback

Settings > Privacy and Security > Diagnostics and feedback

Required diagnostic data cannot be disabled. It covers basic hardware information, crash reports, and the data Windows needs to stay updated and stable. This is a reasonable trade-off and not a privacy concern for most users.

Optional diagnostic data covers browsing patterns, typing input, app usage details, and device configuration data. Turn this OFF. It provides no benefit to your PC and feeds into Microsoft’s personalization and advertising systems.

Turn off Improve inking and typing. This sends samples of handwriting and keystrokes to Microsoft for recognition improvement. Turn off Tailored experiences. This uses your diagnostic data to show personalized tips, advertisements, and product recommendations inside Windows.

Tip: To delete all diagnostic data Microsoft has already collected from your device, go to Settings > Privacy and Security > Diagnostics and feedback and click the Delete button under the Diagnostic data section. This clears the stored telemetry from Microsoft’s servers. Required data collection continues going forward but the historical record is removed.

Speech

Settings > Privacy and Security > Speech

Turn off Online speech recognition unless you actively use Cortana, voice typing in Word, or other voice-assistant features. When on, Windows sends voice samples to Microsoft’s cloud for processing and model improvement.

Inking and Typing Personalization

Settings > Privacy and Security > Inking and typing personalization

Turn off the custom inking and typing dictionary. When on, Windows builds a local profile of your typing patterns and handwriting and may share samples with Microsoft for model training.

Activity History

Settings > Privacy and Security > Activity history

Turn off both toggles: Store my activity history on this device, and Send my activity history to Microsoft. Activity history records which apps, files, and websites you interact with. It feeds Windows Timeline and Microsoft 365 activity features. Disabling it does not break any Windows function.

Search Permissions

Settings > Privacy and Security > Search permissions

Set SafeSearch to Moderate or Strict on any shared or family PC. Turn off Cloud content search for both Microsoft account and Work or School account to stop Bing from indexing your account files and calendar as part of Windows search. Turn off Search history and clear the existing record.

Presence Sensing

Settings > Privacy and Security > Presence sensing

Presence sensing is new in Windows 11 24H2 and only appears on hardware that includes a presence detection sensor. The feature lets apps detect when you are physically near the PC to trigger behaviors like Wake on approach, adaptive brightness, and auto-lock.

Review the app list and restrict access. No app needs this permission unless you are intentionally using attention-based display features. For related display behavior controls, the AxeeTech guide on display and power settings covers the adaptive brightness configuration that connects to Presence Sensing on supported hardware.

Privacy Settings: App Permissions (The Complete Permission Guide)

App permissions are the most overlooked section of Privacy and Security settings. Windows grants apps access to hardware and personal data through a system that most users have never reviewed.

The Three-Layer Permission Framework

Every permission category in Windows 11 has three separate levels of control:

Level 1 is the master device toggle at the top of each permission page. Turning this off blocks every app on the system from accessing that feature. This is a sledgehammer, not a scalpel.

Level 2 is the Desktop apps toggle in the middle of each page. This controls access specifically for traditional .exe applications installed outside the Microsoft Store.

Level 3 is the per-app toggle list at the bottom of the page. This shows every installed app with its own individual on/off switch. This is where most users should be making changes.

The correct approach for most permissions is to leave the Level 1 master toggle ON, leave the Level 2 desktop toggle ON, and turn off individual apps at Level 3 that have no legitimate reason to access the feature.

Warning: Turning off the master toggle for Camera or Microphone at the top of the permission page blocks ALL apps from accessing that hardware, including Teams, Zoom, and video calling apps. Leave the master toggle ON and restrict access at the individual Level 3 app list instead.

Key App Permissions to Review

Navigate to each permission at:

Settings > Privacy and Security > App permissions > [Permission name]
PermissionRecommended ActionApps That Legitimately Need It
LocationON master, restrict per-appMaps, Weather, Find My Device
CameraON master, restrict per-appTeams, Zoom, Camera app
MicrophoneON master, restrict per-appTeams, Zoom, voice assistants
Account infoReview per-appApps needing your name or profile picture
ContactsReview per-appMail app, Phone Link
CalendarReview per-appCalendar apps, productivity tools
Phone callsReview per-appPhone Link only
EmailReview per-appMail app only
Documents libraryReview per-appRestrict to apps that need document access
Downloads folderReview per-appBrowsers and download managers
Pictures libraryReview per-appPhoto editors and gallery apps
Videos libraryReview per-appVideo players and editors
File systemRestrict carefullyBroad system-wide access; limit to trusted apps
ScreenshotsRestrict carefullyScreen capture tools only
Windows 11 app permissions three layer framework camera microphone location 2026.
Windows 11 app permissions use a three-layer structure with a master device toggle, a desktop apps toggle, and individual per-app controls for Camera, Microphone, and Location.

Work through each permission category once per quarter. Newly installed apps sometimes request permissions without making it obvious during setup. The AxeeTech guide on change default app settings covers the related default app and file-type assignment settings that complement the app permissions framework.

Privacy Settings: Windows Recall and Snapshots (Copilot+ PCs)

Windows Recall is an AI feature available exclusively on Copilot+ PCs that include a Neural Processing Unit (NPU). It takes continuous periodic screenshots of your screen and uses AI to make everything you have ever seen on the PC searchable.

The setting appears in:

Settings > Privacy and Security > Recall and snapshots

This page only appears on Copilot+ PC hardware. If you do not see it, your PC does not have Recall.

Warning: Windows Recall captures screenshots of everything on your screen, including banking websites, login credentials typed into browsers, private messages, confidential work documents, and medical records. On any Copilot+ PC, go to Settings > Privacy and Security > Recall and snapshots and confirm Save snapshots is set to Off unless you have made a deliberate choice to use this feature.

To disable Recall completely, set Save snapshots to Off. To delete all screenshots already stored, click the Delete snapshots button on the same page. To exclude specific applications from being captured, use Filter apps and websites to add them to the exclusion list. DRM-protected content and InPrivate or private browsing sessions are excluded from Recall automatically.

Recall stores its screenshot database locally on the device, encrypted using BitLocker or Device Encryption. If you disable Device Encryption, Recall also stops working. Both features share the same encryption dependency.

Activity History and Recall are separate features, but disabling both together provides the most thorough baseline privacy posture on Copilot+ hardware.

Security Settings: Windows Defender (Virus, Firewall, and SmartScreen)

The Windows Security app is the central console for the security features built into Windows 11. Open it from:

Settings > Privacy and Security > Windows Security > Open Windows Security

Virus and Threat Protection

Keep Real-time protection ON at all times. This is Microsoft Defender’s active scanning engine. Disabling it leaves the PC entirely unprotected from active threats.

Keep Cloud-delivered protection ON. It connects Defender to Microsoft’s threat intelligence cloud and provides faster response to new malware that has not yet been added to local signature databases.

Keep Tamper protection ON. This setting prevents malware and unauthorized software from modifying or disabling Defender’s settings. If a threat disables this first, every other Defender protection becomes ineffective.

Controlled Folder Access (Ransomware Protection)

Controlled folder access prevents unauthorized applications from modifying files in protected folders. Enable it at:

Windows Security > Virus and threat protection > Ransomware protection > Controlled folder access > On

After enabling, add additional folders to the protected list. The default protection covers Documents, Desktop, Pictures, and Videos. Add any folder that contains files you cannot afford to lose.

If a legitimate application gets blocked after enabling Controlled folder access, add it to the allowed app list through:

Windows Security > Virus and threat protection > Ransomware protection > Allow an app through Controlled folder access

Firewall

Windows Security > Firewall and network protection

Keep the firewall enabled for all three network profiles: Domain, Private, and Public. The Public network profile is the most critical. It protects against threats on coffee shop, hotel, airport, and other untrusted Wi-Fi networks where other devices may be hostile.

Audit the allowed apps list periodically. Remove entries for applications you no longer use.

Reputation-Based Protection (SmartScreen)

Windows Security > App and browser control > Reputation-based protection

Turn on all four SmartScreen toggles:

  1. Check apps and files (warns before running downloaded files with poor reputation)
  2. SmartScreen for Microsoft Edge (warns before visiting malicious sites)
  3. Potentially unwanted app blocking (blocks adware, browser hijackers, and PUPs)
  4. SmartScreen for Microsoft Store apps (screens Store apps against reputation data)

Potentially unwanted app (PUA) blocking is frequently missed. It does not block full malware but stops the grey-area software that hijacks browser settings, installs toolbars, and adds startup programs without clear user consent.

Exploit Protection

Windows Security > App and browser control > Exploit protection

Leave the default settings in place. The system settings control CFG (Control Flow Guard), DEP (Data Execution Prevention), ASLR (Address Space Layout Randomization), and SEHOP (Structured Exception Handling Overwrite Protection). These protect against memory exploitation techniques used in targeted attacks. Only change these settings if a specific legacy application explicitly requires it.

If any of the Windows Security features above trigger issues after a system update, the AxeeTech guide on how to fix Windows Update issues easily covers every repair method for update-related security tool conflicts.

Security Settings: Smart App Control

Smart App Control (SAC) is Windows 11’s most aggressive application protection layer. It evaluates every app before allowing it to run using Microsoft’s cloud intelligence database.

Windows Security > App and browser control > Smart App Control settings

Warning: Smart App Control only works on a clean installation of Windows 11. If you upgraded from Windows 10 or from an earlier Windows 11 build, the feature shows as Off with no option to enable it. The only way to activate SAC on an upgraded system is a full, clean reinstall of Windows 11. Check your status now. If it shows Off, that is your current state permanently until a fresh install.

For clean installations where SAC is available, start on Evaluation mode. In Evaluation, SAC monitors app reputation quietly without blocking anything. After one to two weeks of normal use, switch to On. This allows SAC to build accurate context about which apps you actually use before it starts enforcing restrictions.

Once switched from On to Off, SAC cannot be re-enabled without reinstalling Windows. Treat the Off setting as permanent before clicking it.

Tip: To check your Smart App Control status, go to Windows Security > App and browser control > Smart App Control settings. If it shows Evaluation or On, your system supports it and protection is active. If it shows Off with a grayed-out toggle and no option to change it, your only path to SAC is a clean Windows reinstall.

Security Settings: Core Isolation and Memory Integrity

Core Isolation uses virtualization-based security (VBS) to isolate critical Windows processes in a separate virtualized memory environment. Memory Integrity is the component within Core Isolation that prevents malicious code from being injected into those protected processes.

Windows Security > Device security > Core isolation > Core isolation details > Memory integrity: On
Windows 11 Core Isolation Memory Integrity enable Device Security path 2026.
Enabling Memory Integrity in Windows 11 Device Security protects core system processes from malware injection using virtualization-based security.

Enable Memory Integrity and restart when prompted. The restart is required to activate the virtualization layer.

Warning: If the Memory Integrity toggle is grayed out and unavailable, an incompatible driver installed on your PC is blocking virtualization. Open Device Manager (Win+X > Device Manager), look for any entry marked with a yellow warning triangle, and update or remove that driver. After resolving the driver conflict, return to Core Isolation and enable Memory Integrity. The AxeeTech guide on how to manually update device drivers in Windows covers every method for finding and installing the correct driver version for your hardware.

After enabling Memory Integrity, if Windows enters a repair loop on the next restart, the AxeeTech guide on what to do when your system is repairing itself covers the exact sequence of what Windows is doing and when it is safe to intervene.

Security Settings: BitLocker and Device Encryption

Drive encryption protects your data if the physical device is stolen. Without encryption, anyone with physical access to the drive can read every file on it, bypassing the Windows login screen entirely.

Windows 11 Home:

Settings > Privacy and Security > Device encryption > On

Home edition uses Device Encryption, a simplified version of BitLocker that activates automatically when a Microsoft account is linked. The recovery key is stored in your Microsoft account at account.microsoft.com.

Windows 11 Pro and Enterprise:

Control Panel > BitLocker Drive Encryption

Or search “Manage BitLocker” in the Start menu.

Pro gives you full BitLocker with choices of TPM-only unlocking, TPM plus PIN, or USB key. Choose “Encrypt entire drive” for complete protection including free space. Use XTS-AES encryption mode for drives that stay inside the PC.

Warning: Save your BitLocker recovery key in two places: your Microsoft account AND a printed physical copy stored somewhere separate from the PC. If the TPM chip resets after a firmware update, the recovery key is the only way back in. Losing both copies means permanent, irrecoverable data loss. There is no backdoor, not even for Microsoft support.

For gamers or users concerned about performance: encryption overhead on an NVMe SSD is negligible during normal use. Theoretical storage-intensive benchmark impacts top out at 2-5%. At 1080p and above on modern hardware, no difference in game load times is measurable.

Windows 11 Home users who want the full BitLocker feature set including removable drive encryption can use Hasleo BitLocker Anywhere as a third-party solution with the same encryption standard.

Sign-In Security (Windows Hello, PIN, and Dynamic Lock)

The most common entry point for PC compromises is not a software exploit. It is physical access through an unattended unlocked machine or a weak login credential. These settings close that gap.

Settings > Accounts > Sign-in options

Enable Windows Hello Face if your PC has an infrared camera. Facial recognition through Windows Hello is phishing-resistant because the authentication happens locally on the device using a camera hash, not a transmittable password. Enable Windows Hello Fingerprint if your PC has a fingerprint reader.

Use a PIN instead of a traditional password for everyday sign-in. A Windows PIN is stored locally on the device and is never transmitted over the network, unlike a Microsoft account password which travels through servers. A PIN breach only compromises one physical device, not your entire Microsoft account.

Enable Dynamic lock. This feature pairs your Windows PC with your smartphone via Bluetooth and locks the screen automatically when the phone moves out of range. Set it up at Settings > Accounts > Sign-in options > Dynamic lock > Allow Windows to automatically lock your device when you are away.

Set Require sign-in to Every time. Disable automatic login so every restart requires a password or PIN.

The most important security habit in Windows is a keyboard shortcut. Press Win+L from any screen to lock the PC instantly. Use it every time you walk away from your desk.

DNS over HTTPS (Encrypt Your Web Queries)

Every website you visit begins with a DNS query that converts the domain name into an IP address. Without DNS over HTTPS (DoH), these queries travel in plain text and are visible to your ISP, network administrator, and anyone monitoring the connection. Enabling DoH encrypts every DNS query.

Settings > Network and Internet > Wi-Fi > [Your network name] > Hardware properties > DNS server assignment > Edit > Manual

Set Preferred DNS to your chosen provider’s IP address, then change the DNS over HTTPS dropdown from Off to On (automatic template). Repeat for Alternate DNS if desired.

DNS ProviderIPv4 AddressPrivacy FocusExtra Features
Cloudflare1.1.1.1HighFastest global resolution; 1.1.1.2 adds malware blocking
Quad99.9.9.9HighBlocks malware and phishing domains at DNS level
Google8.8.8.8Low-moderateHighly reliable; Google collects query data
NextDNSCustom IPVery highConfigurable filtering and logging; free tier available
Windows 11 DNS over HTTPS Cloudflare Quad9 network settings 2026.
Enabling DNS over HTTPS in Windows 11 network settings encrypts DNS queries so ISPs and network observers cannot see which websites you visit.

Cloudflare 1.1.1.1 is the fastest globally and privacy-focused. Cloudflare 1.1.1.2 adds malware blocking without configuration. Quad9 9.9.9.9 blocks DNS requests to known malware and phishing domains automatically, adding a free network-level protection layer.

Windows 11 Home vs Pro: Security Feature Differences

Not every security feature described in this guide is available on Windows 11 Home. The table below shows every security feature that differs between editions.

FeatureWindows 11 HomeWindows 11 Pro
BitLockerDevice Encryption (limited)Full BitLocker + removable drives
Smart App ControlYes (clean install only)Yes (clean install only)
Core Isolation and Memory IntegrityYesYes
Windows Defender Antivirus and FirewallYesYes
Group Policy EditorNoYes
Windows SandboxNoYes
Hyper-VNoYes
Windows Defender Application GuardNoYes
Remote Desktop (host)NoYes
Domain joinNoYes
Credential GuardNoYes (enterprise deployment)

Group Policy is the most significant Pro-only feature for privacy. It gives granular control over telemetry, cloud sync, and app access at a policy level rather than through individual settings toggles. Advanced users on Pro should explore Group Policy as a cleaner alternative to third-party privacy tools.

O&O ShutUp10++ and Advanced Privacy Tools

O&O ShutUp10++ provides toggles for privacy settings that are buried in the Windows Registry and Group Policy, inaccessible through the normal Settings interface. It is free and available at oo-software.com.

Warning: Create a System Restore point before using O&O ShutUp10++ or any registry-based privacy tool. Open Control Panel > System > System Protection > Create and name it before making any changes. ShutUp10++ is safe when used carefully with individual toggles reviewed one at a time. Use the Recommended settings option for a conservative starting point.

ShutUp10++ does not edit host files or firewall rules aggressively, which means it does not break Windows Update, the Microsoft Store, or account sign-in. Avoid third-party Windows privacy tools that do edit the hosts file or add aggressive firewall outbound rules. These tools regularly break Windows Update delivery and Microsoft Store authentication in ways that are difficult to diagnose and reverse.

For Windows 11 Pro users, Group Policy (gpedit.msc) provides the same control without any third-party software and is fully reversible through the same interface.

A general Windows troubleshooter covers the built-in automated diagnostic tools that identify which settings changes have caused functionality problems and can suggest reversals before a manual restore point is needed.

Frequently Asked Questions

How do I open Privacy and Security settings in Windows 11?

Press Win+I to open Settings and click Privacy and Security in the left panel. Alternatively, press Win+R and type ms-settings:privacy-general to go directly to the General privacy page. The full Settings path is Settings > Privacy and Security. The page is divided into three groups: Security at the top, Privacy in the middle, and App permissions at the bottom. Each group contains multiple subsections covering individual features and permissions.

What privacy settings should I turn off in Windows 11?

The highest-priority privacy settings to turn off are the Advertising ID (Settings > Privacy and Security > General), Optional diagnostic data (Settings > Privacy and Security > Diagnostics and feedback), Tailored experiences (same page), and both Activity history toggles (Settings > Privacy and Security > Activity history). Additionally, turn off Online speech recognition, Inking and typing personalization, cloud content search for your Microsoft account, and review every permission in the App permissions section to remove access from apps that have no legitimate reason to hold it.

How do I disable the advertising ID in Windows 11?

Go to Settings > Privacy and Security > General. The first toggle is “Let apps show me personalized ads using my advertising ID.” Turn it Off. This disables the cross-app tracking identifier that Windows assigns to your device. Apps will still show ads, but they will not be able to share a common identifier to build a behavioral profile across multiple applications. This is the single most impactful General privacy setting to change.

What is the difference between required and optional diagnostic data?

Required diagnostic data is the baseline information Windows sends to Microsoft to keep the operating system stable, secure, and updated. It includes hardware configuration, error reports, and crash data. It cannot be disabled. Optional diagnostic data goes further and includes browsing patterns, app usage details, typing samples, and device configuration information used for Microsoft’s personalization, advertising, and product improvement systems. Optional diagnostic data can be turned off at Settings > Privacy and Security > Diagnostics and feedback. Turn it off. Required data continues regardless.

How do I enable BitLocker on Windows 11 Home?

On Windows 11 Home, the feature is called Device Encryption rather than BitLocker. Go to Settings > Privacy and Security > Device encryption and turn it On. Device Encryption requires a Microsoft account to be signed in so the recovery key can be saved automatically. After enabling, verify your recovery key is stored at account.microsoft.com under Devices > BitLocker recovery keys. Home users who want the full BitLocker feature set including removable drive encryption can use Hasleo BitLocker Anywhere as a third-party alternative.

What is Memory Integrity and should I turn it on?

Memory Integrity is a component of Core Isolation that uses virtualization-based security (VBS) to prevent malicious code from being injected into high-security Windows processes. It should be turned on for almost every user. Access it at Windows Security > Device security > Core isolation details > Memory integrity. If the toggle is grayed out, an incompatible driver on your system is blocking virtualization. Open Device Manager, find the driver marked with a yellow warning triangle, and update or remove it. After resolving the conflict, Memory Integrity becomes available.

What is Smart App Control and why can I not enable it?

Smart App Control uses Microsoft’s cloud intelligence to evaluate app reputation before allowing execution, blocking untrusted and unsigned applications. It is only available on a clean installation of Windows 11. If you upgraded from Windows 10 or from a previous Windows 11 version, Smart App Control shows as Off with no toggle to enable it. This is permanent until you perform a fresh clean install of Windows 11. Check your status at Windows Security > App and browser control > Smart App Control settings. Evaluation mode is the correct starting point on clean installs.

How do I disable Windows Recall on a Copilot+ PC?

On Copilot+ PCs, go to Settings > Privacy and Security > Recall and snapshots. Set Save snapshots to Off to stop Recall from taking further screenshots. Click Delete snapshots to remove all screenshots already stored on the device. Use Filter apps and websites to exclude specific applications from capture if you choose to leave Recall partially active. If this page does not appear in your Settings, your PC does not have Recall because it is not Copilot+ hardware with an NPU.

How do I turn on ransomware protection in Windows 11?

Open Windows Security and go to Virus and threat protection. Scroll down to Ransomware protection and click Manage ransomware protection. Turn on Controlled folder access. After enabling it, click Protected folders to add any folder containing important files beyond the default set (Documents, Desktop, Pictures, Videos). If a legitimate application such as a photo editor or document manager gets blocked after this, go back to Ransomware protection and click Allow an app through Controlled folder access to add it to the trusted list.

Is DNS over HTTPS worth enabling on Windows 11?

Yes for most users, especially on public or shared Wi-Fi networks. Without DNS over HTTPS, every website you visit begins with a plain-text DNS query that your ISP, network operator, and anyone monitoring the connection can read. Enabling DoH encrypts these queries and prevents that surveillance. The performance impact is negligible, often under 10 milliseconds per query. Cloudflare 1.1.1.1 and Quad9 9.9.9.9 are the best choices for privacy-focused users, with Quad9 adding free malware domain blocking at the DNS level. Enable DoH at Settings > Network and Internet > Wi-Fi > your network > Hardware properties > DNS server assignment > Edit.

Leave a Reply

Your email address will not be published. Required fields are marked *