← all articles

How to lock down a Windows laptop for privacy

A fresh Windows 11 install nudges you toward a Microsoft account, ships with an advertising ID turned on, and sends required diagnostic data to Microsoft whether you agree or not. None of that is a scandal. It is the default, and the default is tuned for Microsoft’s convenience.

This is for anyone with a personal or work laptop who wants the boring, high-value fixes done properly. Think freelancers on coworking wifi, or anyone who has wondered what happens if the bag gets lifted at a cafe. It is not an anonymity guide. If a state agency is your threat model, start with the EFF’s Surveillance Self-Defense and look at a different operating system.

By the end you will have an encrypted disk with the recovery key stored somewhere sane, a daily account without admin rights, diagnostic data and ad tracking trimmed as far as Windows allows, encrypted DNS, and no inbound services you did not choose. Budget about 90 minutes. Steps are written for Windows 11 24H2 and 25H2, with notes where Windows 10 22H2 differs.

what you need

  • Windows 11 24H2 or 25H2 (Windows 10 22H2 works for most steps, see step 1)
  • an administrator login and about 90 minutes
  • Windows 11 Pro if you want BitLocker with a local account. Home to Pro is US$99 in the Microsoft Store, and you can skip it if Home’s device encryption is enough for you
  • a USB stick or a sheet of paper for the recovery key, kept away from the laptop
  • Terminal (Admin), which is already installed
  • Firefox with uBlock Origin, both free, or whatever you pick after the private browsers comparison
  • Quad9 or Cloudflare 1.1.1.1 for DNS, both free

Total cost: US$0, or US$99 with Pro.

step by step

1. Check your version and update

Open Terminal (Admin), run the command below, then go to Settings > Windows Update, install everything and reboot.

Get-ComputerInfo | Select-Object WindowsProductName, WindowsVersion, OsBuildNumber

Expected output: a product name, then 24H2 and build 26100 (25H2 shows 26200). Windows 10 22H2 shows 19045.

Windows 10 lost regular updates on 14 October 2025, and the one-year consumer extension Microsoft offered ends on 13 October 2026. Most of what follows still helps, but an unpatched OS undoes a lot of it, so plan the move to 11.

If it breaks: Get-ComputerInfo can sit for a minute, so wait. If updates fail, run Settings > System > Troubleshoot > Other troubleshooters > Windows Update, reboot and retry.

2. Turn on disk encryption and save the recovery key

On Home, go to Settings > Privacy & security > Device encryption and switch it on. On Pro, open Control Panel > BitLocker Drive Encryption and turn it on for C:. Then check it:

manage-bde -status C:
manage-bde -protectors -get C: -Type RecoveryPassword

Expected output: Conversion Status “Fully Encrypted”, Protection Status “Protection On”, and a 48-digit recovery password. Write that number on paper or copy it to the USB stick. A Microsoft account also holds a copy at aka.ms/myrecoverykey.

This is the call some readers will dislike. On Home, device encryption only switches on when you sign in with a Microsoft account, and I would take an encrypted disk tied to that account over a plain one with a local login. Microsoft’s BitLocker overview covers what it protects: a powered-off laptop. Someone who knows your Windows password still gets in.

If it breaks: no Device encryption entry usually means no TPM 2.0 or no Modern Standby. Check with tpm.msc, or go Pro and use BitLocker.

3. Sort out sign-in and admin rights

Go to Settings > Accounts > Your info, choose “Sign in with a local account instead” and follow the prompts. Set a PIN under Sign-in options. Then create a standard account for daily use and keep the admin one for installs:

net user daily * /add
net localgroup Administrators

Expected output: the first command asks for a password, the second lists only accounts you recognise. Rerun manage-bde -status C: and confirm protection is still on. I have not tested every hardware combination, so check.

If it breaks: the local account option is missing on work or school accounts, or when “only allow Windows Hello sign-in for Microsoft accounts” is on. Turn that off in Sign-in options.

4. Trim diagnostic data and ad tracking

Go to Settings > Privacy & security > Diagnostics & feedback. Turn off “Send optional diagnostic data”, “Improve inking and typing” and “Tailored experiences”, then click “Delete diagnostic data”. Under Privacy & security > General, turn off the advertising ID and the app-launch tracking option. Then set the policy value:

$k = "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection"
New-Item -Path $k -Force | Out-Null
Set-ItemProperty -Path $k -Name AllowTelemetry -Value 0 -Type DWord

Expected output: the toggles read Off. Now the limit. Per Microsoft’s diagnostic data documentation, the value 0 (“off”) is honoured only on Enterprise, Education and a few other editions. On Home and Pro it counts as required data, the minimum. This step cuts optional data and ad tailoring.

It does not stop Windows talking to Microsoft.

If it breaks: greyed toggles that say “managed by your organization” mean a work policy owns them. Leave those alone.

5. Review app permissions, Recall and OneDrive backup

Open Settings > Privacy & security and go through Location, Camera and Microphone. Turn off any app you do not recognise, or Location services entirely if you never need it. Then open OneDrive from the tray, go to Settings > Sync and backup > Manage backup, and switch off Desktop, Documents and Pictures if you do not want them copied to Microsoft’s cloud. Alternatives are in the secure cloud storage roundup. On a Copilot+ PC, also run:

Get-WindowsOptionalFeature -Online -FeatureName Recall
Disable-WindowsOptionalFeature -Online -FeatureName Recall

Expected output: State reads Disabled after the second command and a reboot. On other laptops PowerShell says the feature is unknown, which is fine. I have not tested this on Copilot+ hardware, so also look under Settings > Privacy & security > Recall & snapshots.

If it breaks: switching Location services off also greys out Find my device. That is the trade.

6. Switch to encrypted DNS

On Windows 11, open Settings > Network & internet > Wi-Fi > your network’s Properties. Next to DNS server assignment click Edit, choose Manual, turn on IPv4, enter 9.9.9.9 as preferred DNS and 149.112.112.112 as alternate, and set DNS over HTTPS to “On (automatic template)” for both. Save, then repeat for Ethernet if you use it. Verify with:

Get-DnsClientDohServerAddress

Expected output: the Properties page shows both addresses tagged “(Encrypted)”, and the cmdlet lists the DoH templates Windows knows, Quad9’s among them. Windows 10 has no DoH setting, so skip this and turn it on inside Firefox under Settings > Privacy & Security.

What this buys you: your router and the wifi operator can no longer read your DNS lookups. Quad9 can, and the IP addresses you connect to stay visible, so this is not a VPN. See VPN vs proxy and what your router sees.

If it breaks: hotel and airport login pages often refuse to load. Set DNS assignment back to Automatic (DHCP), log in to the portal, then switch back.

7. Close the inbound doors

Check the firewall, SMB1 and Remote Desktop:

Get-NetFirewallProfile | Select-Object Name, Enabled, DefaultInboundAction
Get-WindowsOptionalFeature -Online -FeatureName SMB1Protocol | Select-Object State
Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server" | Select-Object fDenyTSConnections

Expected output: Enabled True on Domain, Private and Public, inbound action Block or NotConfigured (which behaves as block), SMB1Protocol Disabled and fDenyTSConnections 1, meaning Remote Desktop is off. If anything differs, fix it:

Set-NetFirewallProfile -Profile Domain,Private,Public -Enabled True -DefaultInboundAction Block
Set-NetConnectionProfile -InterfaceAlias "Wi-Fi" -NetworkCategory Public

The Public profile stops your laptop advertising itself to other machines on the same wifi. Also open Settings > Windows Update > Advanced options > Delivery Optimization and turn off downloads from other PCs.

If it breaks: printer and file share discovery stop working on Public. Use Private only on your home network.

8. Clean out apps and pick a browser

Remove the preinstalled apps you will never open. Drop the last line if you use Phone Link:

Get-AppxPackage -Name Microsoft.BingNews | Remove-AppxPackage
Get-AppxPackage -Name Microsoft.WindowsFeedbackHub | Remove-AppxPackage
Get-AppxPackage -Name Microsoft.MicrosoftSolitaireCollection | Remove-AppxPackage
Get-AppxPackage -Name Microsoft.YourPhone | Remove-AppxPackage

Then open Task Manager > Startup apps and disable what you do not need, and install Firefox with uBlock Origin. The multi-profile antidetect browsers agencies use are a separate topic, reviewed at antidetectreview.org.

Expected output: rerunning Get-AppxPackage -Name Microsoft.BingNews returns nothing.

If it breaks: an “in use” error means the app is open, so close it and rerun.

9. Reboot and re-audit

Reboot. You should see your PIN prompt and no recovery screen. Then run the audit and save the output next to your recovery key:

manage-bde -status C: | Select-String "Protection Status"
net localgroup Administrators
Get-NetFirewallProfile | Select-Object Name, Enabled
(Get-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DataCollection").AllowTelemetry
Get-DnsClientServerAddress -InterfaceAlias "Wi-Fi" -AddressFamily IPv4 | Select-Object ServerAddresses

Expected output: Protection On, only admins you know, three profiles True, 0, and Quad9’s two addresses.

If it breaks: Windows feature updates have a history of resetting privacy toggles, so rerun this after each one and redo whatever drifted.

common pitfalls

  • Losing the recovery key. BitLocker asks for it after firmware updates and some hardware changes, and without the 48 digits the data is gone. Print it before you need it.
  • Reading “diagnostic data off” as “nothing leaves the laptop”. Windows Update, Defender cloud lookups and the Store still talk to Microsoft, which is the price of a patched system.
  • Pasting a GitHub “privacy debloat” script into an admin prompt. I do not run them. They rewrite services, the hosts file and the registry in bulk, can break Windows Update, and you are trusting an author you cannot name. The registry line in step 4 is short enough to read in ten seconds.
  • Treating a VPN as the fix for all of this. It hides traffic from the local network and does nothing for telemetry or a stolen disk.
  • Handing the laptop on without a proper wipe, see wiping a device before it leaves your hands.

scaling this

From one laptop to 10: put the PowerShell blocks in one .ps1 file on a USB stick and run it per machine. The GUI toggles are the slow part, and I would guess 30 minutes a laptop once the script exists. Decide up front where recovery keys live, since a shared spreadsheet full of them is a leak of its own.

At 100 laptops, hand work stops scaling. You want Windows Pro or Enterprise, Microsoft Intune for the policies (diagnostic data, BitLocker, firewall), recovery keys escrowed to Microsoft Entra ID, and Windows Autopilot so new machines arrive configured. Local accounts mostly go away, because devices join Entra.

At 1000, you are running a program. Enterprise licences unlock the true diagnostic data off level from step 4, and you need staged policy rollouts, a help desk process for BitLocker recovery, and a way to prove settings stayed applied. I have not run a fleet this size, so this part is Microsoft’s documentation, not experience.

where to go next

The full index is at /blog/. Three follow-ups that fit this one:

Written by Xavier Fok

disclosure: this article may contain affiliate links. if you buy through them we may earn a commission at no extra cost to you. verdicts are independent of payouts. last reviewed by Xavier Fok on 2026-09-27.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →