Telemetry Settings That Actually Matter (and the Ones That Don’t)
Windows 11 contains a bewildering collection of privacy, diagnostic, advertising, personalisation and application-permission settings.
Search online for advice and things quickly become even more confusing.
One guide tells you to disable every telemetry service.
Another recommends blocking dozens of Microsoft addresses.
A YouTube video promises a PowerShell script that will make Windows “completely private”.
For a business, that can cause more problems than it solves.
Some Windows settings genuinely determine how much diagnostic information is sent to Microsoft. Others merely control personalised advertising, recommendations or how often Windows asks for feedback.
And some of the privacy settings that matter most aren't technically telemetry settings at all.
The objective shouldn't be:
“Disable absolutely everything that communicates with Microsoft.”
A much better objective is:
Understand what Windows collects, disable unnecessary optional collection, control application permissions and manage the configuration consistently across your organisation.
Here's what actually deserves your attention.
What Is Windows Telemetry?
Microsoft generally refers to Windows telemetry as diagnostic data.
Windows can send technical information about a device to Microsoft to support areas including:
- Windows Update
- reliability
- hardware compatibility
- driver compatibility
- crashes
- application problems
- device configuration
- Windows performance
On current Windows 11 client devices, the two categories most users need to understand are:
Required diagnostic data
and:
Optional diagnostic data
Microsoft's broader documentation also describes Diagnostic data off/Security and an older Enhanced level, but Enhanced applies to older Windows and Windows Server versions rather than current Windows 11 clients.
That distinction matters because advice written for Windows 10, Windows Server or Enterprise environments can easily become confused with the controls available on an ordinary Windows 11 PC.
Setting That Really Matters: Optional Diagnostic Data
Start here:
Settings > Privacy & security > Diagnostics & feedback
Look for:
Send optional diagnostic data
For most ordinary business PCs, I would leave this off unless there is a defined reason for enabling it.
Required diagnostic data continues to operate.
What you're disabling is the additional layer of information Microsoft can collect.
Microsoft says Optional diagnostic data can include more detailed information about device configuration and health, software usage, device activity, browsing-related information and enhanced error reporting.
Optional data can be useful in certain circumstances.
For example:
- Windows Insider devices
- specific troubleshooting
- compatibility investigations
- support cases
- environments using services that require additional diagnostic information
But on a standard production PC:
If you can't explain why that device needs Optional diagnostic data enabled, it probably doesn't.
What Does “Required Diagnostic Data” Actually Include?
This is worth explaining because the word required sometimes makes people suspicious.
Microsoft publishes detailed documentation showing the events and fields included in Required diagnostic data.
For Windows 11 26H1, Microsoft describes it as a limited set of information necessary to understand the device and its configuration.
It includes categories relating to:
- basic device information
- quality and reliability
- application compatibility
- Microsoft Store
- Windows Update
- hardware and configuration
Microsoft's documentation even exposes the individual diagnostic events and fields used by Windows 11 26H1.
For example, required diagnostics can include technical information about memory, hardware capabilities, update status and device configuration.
That is very different from saying:
“Microsoft is receiving everything I do on the computer.”
It isn't.
But there is another distinction worth understanding.
Required Service Data Is Different Again
Windows Required service data is not the same thing as Required diagnostic data.
Connected Windows services may need certain information simply to perform the service you have asked them to provide.
Microsoft says Windows required service data is separate from Required and Optional Windows diagnostic data, meaning changing the diagnostic-data setting does not necessarily stop information required for connected services from being transmitted.
This is another reason aggressive “block every Microsoft telemetry endpoint” scripts can cause problems.
Not every connection between Windows and Microsoft exists purely for telemetry.
Setting That Matters: Tailored Experiences and Recommendations
Depending on your Windows 11 release, you'll find controls relating to personalised experiences under areas such as:
Diagnostics & feedback
or:
Recommendations & offers
These controls can allow diagnostic information to be used to provide:
- recommendations
- tips
- advertisements
- Microsoft product suggestions
- third-party product suggestions
For a business PC, there is rarely much benefit.
Turning personalisation off does not disable Windows Update, Microsoft Defender or ordinary Required diagnostic data.
It mainly reduces Microsoft's ability to use information to customise recommendations and offers.
For standard company devices:
I'd switch it off.
Setting That Matters: Advertising ID
Windows can provide applications with an advertising identifier associated with the user.
Look under:
Settings > Privacy & security > General
or the relevant Recommendations & offers section on your Windows build.
Turning off personalised advertising through the Windows advertising ID is sensible on a business computer.
A company laptop exists to run business applications—not create a better advertising profile.
But understand what this setting doesn't do.
Disabling the advertising ID does not:
- remove every advert
- disable browser cookies
- prevent websites tracking users
- disable Windows diagnostic data
- make the computer anonymous online
It disables one specific mechanism used for advertising personalisation.
Useful?
Yes.
A complete privacy solution?
No.
Setting That Matters: Improve Inking and Typing
Windows can send additional typing and handwriting information to Microsoft to improve language recognition and suggestions.
For an ordinary desktop or laptop used with a keyboard, there may be little business reason to enable it.
However, some users genuinely benefit from these capabilities.
Examples include employees using:
- digital pens
- handwriting recognition
- touchscreens
- accessibility features
- multilingual input
The sensible approach isn't to declare the setting universally good or bad.
Ask:
Does this user need the functionality?
If not, disable the additional data sharing.
If they do, document the exception.
Stop Obsessing Over Telemetry and Check App Permissions
This is arguably more important than several of the settings people commonly describe as “Windows spying”.
Open:
Settings > Privacy & security > App permissions
Review what applications can access.
Pay particular attention to:
- Location
- Camera
- Microphone
- Contacts
- Account information
- Documents
- Pictures
- Videos
- File system
- Notifications
- App diagnostics
Consider this scenario.
You spend three hours trying to block Windows diagnostic endpoints.
Meanwhile, an unnecessary application has access to:
your microphone, camera and file system.
You've concentrated on the wrong privacy problem.
Application permissions should follow a straightforward rule:
If an application doesn't need access to something, don't give it access.
Teams or another video-conferencing application obviously needs a microphone and camera if employees use video calls.
A basic calculator probably doesn't.
An unknown Store application definitely deserves investigation before receiving broad permissions.
Activity History Deserves a Look
Activity history is separate from Windows diagnostic data.
Depending on the Windows configuration and Microsoft services being used, it can record information relating to applications, files and services used on the computer.
Look under:
Settings > Privacy & security > Activity history
It deserves particular attention on:
- shared PCs
- reception computers
- hot-desk machines
- systems handling confidential work
- devices used by multiple people
Don't confuse Activity history with:
- browser history
- Recent files
- Microsoft 365 audit logs
- Edge synchronisation
- application-specific histories
Those are separate systems.
Feedback Frequency Matters Less Than People Think
Windows may occasionally ask users to provide feedback.
You can reduce or disable these requests.
That's useful if they're annoying employees.
But it isn't a major telemetry control.
Feedback prompts and automatic diagnostic data are different things.
Setting feedback frequency to Never does not mean:
“Windows telemetry is now disabled.”
Adjust it for usability rather than treating it as a major privacy defence.
Device Usage Matters Less Too
Windows may ask whether you use the PC for categories such as:
- business
- gaming
- creativity
- entertainment
- education
This information can influence recommendations, suggestions and promotional experiences.
On a business computer, there is little reason to select unnecessary categories.
Turn them off if you don't want the recommendations.
But again:
Device Usage is not the same thing as diagnostic data.
Don't spend an hour worrying about this while leaving Optional diagnostic data and unnecessary application permissions untouched.
Language-Based Website Content Isn't a Major Risk
Windows can allow websites to access the operating system's language list so they can provide locally relevant content.
Turning that off may provide a small privacy benefit.
It does not stop websites from using other information such as:
- browser language
- cookies
- IP address
- account information
- browser fingerprinting
For a business, browser security, web filtering, authentication and cookie policies deserve considerably more attention.
What About Delete Diagnostic Data?
Under:
Settings > Privacy & security > Diagnostics & feedback
Windows can provide an option to delete diagnostic data associated with the device.
That's useful if you specifically want to remove previously collected diagnostic information.
But it does not mean:
“Never collect diagnostic information again.”
Think of it as:
Delete what's already there
rather than:
Change what happens tomorrow.
If the device continues sending Required or Optional diagnostic data, new information can subsequently be generated.
Diagnostic Data Viewer: Useful for Transparency
If you want to see what Windows is actually producing rather than relying on somebody's alarming Reddit post, Microsoft provides the Diagnostic Data Viewer.
You can access the option through:
Settings > Privacy & security > Diagnostics & feedback > View diagnostic data
The viewer can help IT teams understand what diagnostic information a particular Windows configuration is generating.
It is useful for:
- privacy reviews
- troubleshooting
- testing configuration changes
- understanding Windows diagnostic events
It is a visibility tool, not a privacy control.
Opening the viewer doesn't itself reduce diagnostic collection.
Don't Use “Disable All Telemetry” Scripts on Business PCs
There are countless scripts online promising:
ZERO WINDOWS TELEMETRY!
Some modify the Registry.
Others disable Windows services.
Some edit the hosts file or firewall rules.
Others block huge lists of Microsoft addresses.
That may make an impressive YouTube thumbnail.
It isn't necessarily good IT management.
Aggressive telemetry scripts can potentially:
- disable required Windows services
- interfere with Windows Update
- affect Microsoft Store applications
- break error reporting
- interfere with device management
- affect legitimate monitoring
- apply undocumented Registry settings
- create inconsistent PCs
- be partially undone by the next Windows feature update
There is another problem.
A Microsoft endpoint may support more than one Windows function.
Something labelled “telemetry” in somebody's blocklist may also be involved in reliability, licensing, device management or another connected experience.
For a business:
Consistency, security and supportability are more valuable than achieving an unrealistic “zero telemetry” badge.
Don't Configure 50 PCs by Hand
This is where the discussion becomes much more important for businesses.
If your company has 5 computers, manually checking each one might be manageable.
If you have:
20
50
100
or:
500
you shouldn't be asking employees to configure Windows privacy settings individually.
Define a company standard.
Then deploy and enforce it centrally using tools such as:
- Microsoft Intune
- Group Policy
- another appropriate device-management platform
Microsoft exposes Windows diagnostic configuration through administrative policy controls, including MDM Policy CSP settings.
Central management gives you:
Consistency
Every appropriate PC receives the same baseline.
Documentation
You know what the organisation has decided and why.
Control
Employees don't need to understand every Windows privacy setting.
Scalability
A configuration change can be applied across the organisation.
Auditability
IT can demonstrate that privacy controls are deliberately managed rather than left to chance.
Maintainability
You can review the baseline after Windows feature updates.
That's a much stronger approach than sending employees an email saying:
“Please go into Settings and turn these seven switches off.”
Create a Windows Privacy Baseline
A business should define what a normal company PC looks like.
For example, a reasonable starting baseline might be:
- Required diagnostic data — Enabled
- Optional diagnostic data — Disabled unless justified
- Personalised recommendations/offers — Disabled
- Advertising ID — Disabled
- Improve inking and typing — Disabled unless required
- Activity history — Reviewed according to device use
- Application permissions — Restricted to genuine requirements
- Feedback requests — Limited where unnecessary
- Settings centrally managed where practical
- Exceptions documented
The exact configuration depends on the organisation.
A graphic designer using a pen-enabled Surface may legitimately have different requirements from somebody working on a finance desktop.
The goal is not to make every device identical regardless of purpose.
The goal is to make every difference intentional.
Review the Baseline After Windows Feature Updates
Windows evolves.
Settings move.
Names change.
New controls appear.
Old controls disappear.
Microsoft may also change the underlying policies available to administrators.
That's why privacy configuration should not be:
Set once in 2024 and never looked at again.
Review it periodically and after significant Windows releases.
As of Windows 11 26H1, Microsoft continues to publish detailed documentation describing its Required diagnostic events and fields.
Use Microsoft's current documentation rather than relying indefinitely on a privacy guide written for an older Windows release.
Privacy and Security Are Not the Same Thing
This distinction matters.
Turning off advertising personalisation improves privacy.
It does not protect you from ransomware.
Disabling Optional diagnostic data reduces information shared with Microsoft.
It does not stop phishing.
Disabling Activity history doesn't replace endpoint security.
A business still needs appropriate controls including:
- multi-factor or phishing-resistant authentication
- endpoint protection
- patch management
- backups
- email security
- least privilege
- Conditional Access where appropriate
- user awareness
- incident response
Privacy configuration should be part of your wider IT security strategy—not mistaken for the entire strategy.
The Settings I Would Actually Prioritise
If you don't want to spend hours examining every Windows privacy toggle, concentrate on the things that make a meaningful difference.
For a typical business Windows 11 device:
Keep Required diagnostic data enabled.
Disable Optional diagnostic data unless there is a defined requirement.
Disable unnecessary personalised offers and advertising.
Review application permissions carefully.
Review Activity history where relevant.
Avoid aggressive telemetry-blocking scripts.
Manage important settings centrally.
Document exceptions.
Review the configuration after major Windows changes.
That's a much more useful privacy strategy than indiscriminately disabling every Windows service containing the words diagnostic, connected or telemetry.
How Hamilton Group Can Help
Hamilton Group helps businesses configure Windows around their actual security, privacy and operational requirements rather than applying random “debloat” or “disable telemetry” scripts downloaded from the internet.
We can help with:
- Windows 11 configuration
- Microsoft Intune
- Group Policy
- Microsoft 365
- Windows privacy baselines
- application permissions
- endpoint security
- device management
- patch management
- cybersecurity
- IT audits
- Windows troubleshooting
For businesses managing multiple computers, the biggest improvement is often not finding another privacy switch.
It's moving from:
“We think everybody's PC is configured correctly.”
to:
“We have a documented standard, deploy it centrally and know which devices comply with it.”
Visit or call 0330 043 0069 to discuss Windows 11 management and business IT support.