3. Cortana & Search
By default Cortana data privacy will transfer all data to Microsoft services, including location, browsing, voice, and search data. Disable.
Danger
After every major windows update, verify these settings.
Manually disable Cortana
Most settings are managed via GPO; not needed if applying Registry/GPO policies.
⌘ + r › ms-settings:cortana
Disable all options.
Clear all data.
Disable Cortana
Disable Cortana & Search access to location
GPO
Computer Configuration › Administrative Templates › Windows Components › Search › Allow search and Cortana to use location
☑
DISABLED
Updated: 2021-02-19
Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search
AllowSearchToUseLocation
DWORD
0
Updated: 2021-02-19
Disable web search from windows desktop & Cortana
GPO
Computer Configuration › Administrative Templates › Windows Components › Search › Do not allow web search
☑
ENABLED
Updated: 2021-02-19
GPO
Computer Configuration › Administrative Templates › Windows Components › Search › Don’t search the web or display web results in Search
☑
ENABLED
Updated: 2021-02-19
Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search
DisableWebSearch
DWORD
1
Updated: 2021-02-19
Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\Windows Search
ConnectedSearchUseWeb
DWORD
0
Updated: 2021-02-19
Disable Cortana & Search indexing
Computer Configuration › Administrative Templates › Windows Components › Search
Prevent automatically adding shared folders to the Windows Search index
ENABLED
Enable indexing of online delegate mailboxes
DISABLED
Allow indexing of encrypted files
DISABLED
Prevent indexing when running on battery power to conserve energy
ENABLED
Prevent indexing e-mail attachments
ENABLED
Prevent indexing files in offline files cache
ENABLED
Prevent indexing Microsoft Office Outlook
ENABLED
Prevent indexing public folders
ENABLED
Enable indexing uncached Exchange folders
DISABLED
Prevent clients from querying the index remotely
ENABLED
Prevent adding UNC locations to index from Control Panel
ENABLED
Updated: 2021-02-19
Disable Cortana on lock screen
GPO
Computer Configuration › Administrative Templates › Windows Components › Search › Allow Cortana above lock screen
☑
DISABLED
Updated: 2021-02-19
Registry
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech_OneCore\Preferences
VoiceActivationEnableAboveLockscreen
DWORD
0
Updated: 2021-02-19
Disable web search over metered connections
Computer Configuration › Administrative Templates › Windows Components › Search › Don’t search the web or display web results in Search over metered connections
☑
ENABLED
Updated: 2021-02-19
3.1. Firewall
Cortana Endpoints to Microsoft Services may change. Peridiocally verify these have not changed. See references for additional documentation.
Warning
These endpoints should be blocked or routed to a blackhole. See Pi-Hole and DNAT for Captive DNS.
Block outbound Cortana Connections
GPO
Computer Configuration › Windows Settings › Security Settings › Windows Defender Firewall with Advanced Security › Windows Defender Firewall with Advanced Security - Local Group Policy Object › Outbound Rules › New Rule
Rule Type
Program
This program path
%windir%\systemapps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
Action
Block the connection
Profile
› Domain
☑
› Private
☑
› Public
☑
Name
Block outbound Cortana
Protocols and Ports
Protocol Type
TCP
Local port
All Ports
Remote port
All Ports
Updated: 2021-02-19
Registry
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\FirewallRules
{0DE40C8E-C126-4A27-9371-A27DAB1039F7}
SZ
v2.25|Action=Block|Active=TRUE|Dir=Out|Protocol=6|App=%windir%\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\searchUI.exe|Name=Block outbound Cortana|
Updated: 2021-02-19
Cortana and Search endpoints
Service |
Endpoint |
---|---|
Cortana, Greetings, Tips, Live Tiles |
|
› |
|
› |
|
› |
|
› |
|
› |
|
› |
|
› |
|
› |
References