Windows 11 tracks more than most users realise — and much of that tracking is enabled by default. Location data is one of the most sensitive categories, but it’s part of a broader ecosystem of activity tracking that Microsoft uses for personalisation, advertising, and diagnostics. Understanding exactly how Windows 11 location tracking works, what data it collects, and how to configure the privacy settings at every layer allows you to make informed decisions rather than accepting defaults that serve Microsoft’s data interests over yours. This fits into the wider topic we cover in our Complete Guide to Security and Privacy.
Location tracking in Windows 11 operates at multiple layers — the OS location service, individual app permissions, system services, Microsoft account activity, and network-based location inference — each requiring separate configuration. Changing one location setting without addressing the others leaves significant data collection still active.
How the location system works
Windows 11 uses a combination of methods to determine the device’s physical location:
- GPS (on devices with GPS hardware) — metre-level precision
- WiFi positioning (identifying networks in range and looking up their known positions) — neighbourhood-level
- IP-based geolocation (approximate location from the internet connection’s IP address) — city-level
- Cellular triangulation (on devices with cellular modems)
The location system has two distinct parts: the platform location service (managing location data for the entire OS and apps) and individual app permissions. Both must be configured. The platform service being “on” but all app permissions being “off” still allows certain OS processes to use location. The platform service being “off” blocks location entirely but prevents automatic time zone adjustment and emergency services calling.
Location history is a separate feature that stores recent location data on the device, allowing apps with history permission to see where the device has been — even for periods when those apps didn’t have active location permission. Review and configure it separately from the active location permission.
The complete configuration — all layers
1. Master location service: Settings → Privacy & Security → Location → Location services toggle. Leave on if you use any location-based apps; manage per-app permissions instead of disabling entirely. Turn off entirely only if you want zero location data collection and are willing to set the time zone manually.
2. Per-app location permissions: Settings → Privacy & Security → Location → “Let apps access your location” → the individual app list. Set each app:
- Should have location: maps, weather, navigation, delivery tracking apps
- Should NOT have location: social media apps, most productivity apps, games, news apps, most utilities
3. Desktop app location: Settings → Privacy & Security → Location → “Let desktop apps access your location.” This covers traditional Windows desktop applications (as opposed to Store apps). Most users can leave this on but should be aware it applies to any installed desktop software, not just Store apps.
4. Location history: Settings → Privacy & Security → Location → Location history. Clear the existing history and disable “Let apps access your location history on this device” unless you actively use apps that require movement history (delivery tracking, location-based reminders).
5. System services: Settings → Privacy & Security → Location → scroll to “Location services used by Windows.” This shows which system processes currently have location access. Most system services have legitimate reasons for location (automatic time zone, emergency calling) — review rather than blanket-disable.
Microsoft account — the cloud-side location data
Device settings control what gets collected and sent to Microsoft. The Microsoft account privacy dashboard (privacy.microsoft.com) controls what Microsoft does with data already collected. These are separate controls — you need to address both.
At privacy.microsoft.com → Location Activity: review location data associated with the Microsoft account (from Edge searches with location enabled, Cortana queries, Maps usage). Delete this history through “Clear Location activity” and disable future collection through the activity settings. This account-level data persists independently of device settings until explicitly addressed through the online dashboard.
Cortana: Settings → Cortana → Permissions → Location. Disabling Cortana’s location access moves local results to IP-based geolocation — less precise, but eliminates GPS/WiFi positioning data from Cortana’s collection.
All location settings — quick reference
| Setting | Where to find it | Recommended action |
| Location services (master) | Settings → Privacy & Security → Location | On (manage per-app instead of disabling) |
| Per-app location permissions | Same → app list below master toggle | Off for most apps; On only for maps/weather/navigation |
| Desktop app location | Same → “Let desktop apps access your location” | On (applies only to deliberately installed desktop software) |
| Location history | Same → Location history section | Clear and disable unless specifically needed |
| System services location | Same → “Location services used by Windows” at bottom | Review; keep time zone service; disable others if not needed |
| Microsoft account location activity | privacy.microsoft.com → Location Activity | Clear existing; disable future collection |
| Cortana location | Settings → Cortana → Permissions → Location | Off (degrades to IP-based location for Cortana) |
| Browser location permissions | Chrome: Settings → Privacy → Site settings → Location | “Ask before accessing” rather than persistent grants |
Additional privacy layers — beyond the OS settings
Network-based location inference: the IP address of the internet connection provides city-level location to every website and service contacted through Windows, regardless of OS location settings. This is not configurable within Windows. A VPN masks the real IP with the VPN server’s IP, changing the apparent location. Our guide on setting up a VPN on Windows 11 covers this.
Browser location access: browsers have their own location permission system independent of Windows location settings. A browser that has been granted “allow location access” for a website provides GPS-level location regardless of Windows OS settings. Review browser location permissions:
- Chrome: Settings → Privacy and security → Site settings → Location
- Firefox: Settings → Privacy & Security → Permissions → Location
- Edge: Settings → Cookies and site permissions → Location
Set to “Ask before accessing” rather than granting persistent access to specific sites.
WiFi probe requests: Windows periodically broadcasts probe requests to find known WiFi networks. These probes can reveal location history by revealing the names of networks the device has connected to in different places. Windows 11 enables randomised MAC addresses for WiFi probing by default, which partially addresses this. Clearing the list of remembered networks periodically (Settings → Network & Internet → WiFi → Manage known networks) further reduces this passive location disclosure.
Our guide on Windows privacy settings covers the complementary privacy controls beyond location tracking. For Microsoft’s technical documentation on location data use and the privacy dashboard controls, privacy.microsoft.com provides both the data management interface and the privacy policy that governs what each setting controls.
Practical scenarios — configuring for different use cases
Location configuration isn’t one-size-fits-all:
- Fixed home desktop that never changes location: disable the location service entirely. Automatic time zone needs manual updating only twice a year when clocks change — a trivial inconvenience to eliminate all location tracking.
- Travelling laptop for work and personal use: keep the location service on with per-app permissions carefully audited, enable automatic time zone, and configure a VPN for travel to mask network-level location on untrusted networks.
- Shared or family computer: each user account has its own location settings — changes in one account don’t affect others. Review the location settings in each user account independently, applying appropriate configuration for each user’s apps and needs. This per-account architecture allows mixed privacy requirements in the same household.
One nuance worth understanding: location access and location history are two different controls. Location access controls whether apps can query the current location in real time. Location history controls whether recent location data is stored and made available to apps with history permission. An app with “While using” access never stores history unless history storage is separately enabled. For maximum restriction, address both: per-app location access at the minimum necessary level, and location history disabled or cleared.
Windows 11 location tracking, configured layer by layer, produces a device with substantially less location data flowing out than the factory defaults — without losing the legitimate location-dependent functionality (automatic time zone, maps, weather) that makes the location system valuable for normal use.
Windows Hello and location tracking — a clarification
Windows Hello — the biometric authentication system using facial recognition or fingerprint — stores biometric data locally in the Trusted Platform Module (TPM) chip. It does not send facial geometry or fingerprint data to Microsoft’s servers. Windows Hello itself doesn’t contribute to location tracking.
The nuance: Windows Hello accounts linked to Microsoft accounts do sync sign-in security data (account security events, not biometrics) to the Microsoft cloud, tying device activity to the account profile. For users with maximum privacy requirements who want to prevent any association between device biometric sign-ins and cloud account activity: local accounts without Microsoft account integration avoid this specific data linkage while still allowing Windows Hello biometric authentication to function normally.
Corporate and managed device considerations
On domain-joined corporate machines, Windows 11 location tracking may be managed by Group Policy or Microsoft Intune. Administrators can configure location settings system-wide in a way that overrides user-level settings. On managed devices:
- Some location settings may be greyed out and inaccessible — these are controlled by the organisational policy
- Corporate IT may use location tracking for asset management or security purposes (locating lost or stolen devices)
- The same controls available to personal device users (per-app permissions, location history) may be available within the scope the policy allows, even when system-level settings are managed
For administrators managing Windows 11 location tracking across multiple devices: Group Policy (Computer Configuration → Administrative Templates → Windows Components → Location and Sensors) provides system-wide controls that override user settings, ensuring consistent location privacy configuration regardless of individual user choices. The Group Policy settings allow disabling the location platform service entirely, restricting location history, and limiting which system services can access location — all configurable through domain policy rather than requiring per-device manual configuration.
Windows 11’s location tracking system is more configurable than most users know — the controls exist, they’re accessible through the Settings app and privacy dashboard, and addressing each layer individually takes about 15 minutes. The per-app location permission audit consistently turns up apps with location access that have no legitimate location-dependent function; removing those permissions is the highest-impact single step and the one that produces the most immediate, tangible reduction in location data collection.
Post-update maintenance — settings that reset
Major Windows feature updates (the semi-annual updates that change the OS version) occasionally reset specific privacy settings, including location permissions. After any major Windows update (the orange “Updated” banner on the Settings icon), check:
- Per-app location permissions — new apps installed during updates may have received default permissions
- Location history toggle — occasionally reset to default
- Cortana location access
- Any apps that were previously set to “off” for location that now show “on” after the update
The Windows 11 Privacy Dashboard indicator in Settings shows a summary of which apps have accessed sensitive permissions recently — a quick review of this after major updates confirms whether any permissions were changed during the update process. This post-update check takes about five minutes and ensures that the deliberate privacy configuration established during the initial setup isn’t silently reversed by update-side defaults. If this sounds familiar, Privacy by Design is worth a look.
For a systematic approach to all Windows privacy settings beyond location, the Windows privacy settings guide covers every category including diagnostics, app permissions, advertising ID, and activity history in the same layered configuration approach. Location tracking is one of the most sensitive categories but not the only one that requires attention for a comprehensive Windows 11 privacy configuration. Our guide on iPhone Privacy Settings covers an adjacent issue.






