Skip to main content

Microsoft outlines Recall security: ‘The user is always in control’

Recall promotional image.
Microsoft

Microsoft just released an update regarding the security and privacy protection in Recall. The blog post outlines the measures Microsoft is taking to prevent a data privacy disaster, including security architecture and technical controls. A lot of the features highlight that Recall is optional, and that’s despite the fact that Microsoft recently confirmed that it cannot be uninstalled.

Recommended Videos

Microsoft’s post is lengthy and covers just about every aspect of the security challenges that its new AI assistant has to face. One of the key design principles is that “the user is always in control.” Users will be given the choice of whether they want to opt in and use Recall when setting up their new Copilot+ PC.

Microsoft also notes that Recall will only run on PCs that are eligible for Copilot+, and that comes with a hefty set of hardware requirements that bolster the security. This includes Trusted Platform Module (TPM) 2.0, System Guard Secure Launch, and Kernel DMA Protection.

Setting up Microsoft Recall.
Microsoft

Let’s circle back to the user being in control of what Recall can or cannot access. During setup, you can choose to use it or not; if you don’t choose to use it, it’ll be off by default. Microsoft now also says that you can remove Recall entirely in Windows settings, although it’s unclear whether that means it’ll be completely uninstalled from the PC.

If you choose to opt in, you can filter out certain apps or websites and not allow Recall to save data related to them. Incognito mode browsing is never saved either. You’ll be able to control how long Recall will save your data for, and how much disk space you’re willing to spare for those snapshots. And if you ever want to delete something, you can get rid of snapshots from a certain time range or all content from a specific website or app. To summarize, everything that’s found in Recall can be deleted at any given time.

Microsoft is also adding an icon to the system tray. This will indicate whether Recall is currently collecting snapshots, and you’ll be able to pause this whenever you want. Moreover, you won’t be able to access Recall content without biometric credentials, meaning the use of Windows Hello.

A screenshot of the Recall feature in Windows.
Microsoft

Microsoft promises that sensitive data in Recall is always encrypted and protected via the TPM and tied to your Windows Hello identity. Other users on the same PC won’t be able to access your Recall data; it’ll only be accessible within the Virtualization-based Security Enclave (VBS Enclave). That’s where all the Recall data resides, and only select bits of it are allowed to leave the VBS when requested.

Microsoft also described the Recall architecture in greater detail, saying: “Processes outside the VBS Enclaves never directly receive access to snapshots or encryption keys and only receive data returned from the enclave after authorization.” Sensitive content filtering is also in place to filter out things like passwords, ID numbers, and credit card details from what Recall can remember.

Lastly, Microsoft says that it’s working with a third-party security vendor to run a penetration test and confirm that Recall is secure. All in all, it sounds like the company did its homework here, but we’ll have to wait and see how it all pans out when Recall is widely available.

Will these new measures be enough to alleviate the worries of those who have been boycotting Recall from day one? It’s hard to say, but it’s clear that Microsoft is aware of the controversies and is taking steps to prove that its AI assistant can be trusted.

Monica J. White
Monica is a computing writer at Digital Trends, focusing on PC hardware. Since joining the team in 2021, Monica has written…
Copilot is Microsoft’s cue to redeem Windows and edge past macOS
The new Surface Laptop 13 on a white table.

There is always going to be a big divide between macOS and Windows. Much of it has to do with the functional disparities that are deeply ingrained at an OS-level. Or if you dive into the heated community debates, you will see it broadly as a battle between seamlessness and flexibility. 

Gaming remains the guiding star for Windows adherents. A handful of highly specialized niche industry tools also remain locked to the Microsoft platform. On the other hand, macOS fans swear by the fluid software, plenty of firepower options in the M-series silicon era, and fantastic hardware. 

Read more
Windows 11’s controversial AI Recall feature is coming to your Copilot+ PC very soon
The Surface Pro 11 on a white table in front of a window.

As AI strides on, it inevitably finds its way onto our personal devices, with tech giants announcing new features that rely on accessing our private information and media to serve us better. While some might find this useful, others are bound to find it creepy, and one such feature is Microsoft's controversial AI Recall, which takes screenshots of everything you do on a Copilot+ PC so it's easier to trace back your steps and find something specific later. After being announced last year, and then witnessing a few delays, Recall is finally rolling out to a broader group of Windows 11.

Microsoft recently announced Recall is coming to Windows 11 with the latest Release channel update with build 26100.3902 (KB5055627). The feature's availability in the Windows 11 Release Preview channel, which succeeds the Beta channel in the Windows Insider program, means it is in the initial phases of being available to a wider audience of folks who own Copilot+ PC. This category of PCs currently includes a whole wide range of laptops with specialized hardware in the form of a neural processing unit (NPU) dedicatedly for running AI tasks, though we might see desktops joining the club soon.

Read more
Windows 11 and 10 users find new inetpub folder after April update
Shutdown menu in Windows 11.

Windows 11 and 10 users have reported a mysterious 'inetpub' folder after installing Microsoft's April 2025 updates, as Bleeping Computer reports. Although the folder is typically associated with the Internet Information Services (IIS) web server, it's now appearing on systems without it installed. Microsoft has confirmed that the behavior is intentional but has not fully explained why.

The unexpected folder is empty, and you can find it in the root of the C: drive even if you don't have IIS installed. If you had IIS installed (web server platform by Microsoft), it would use the inetpub folder to save logs, website content, and server-related files. So, it's weird you have one without the other after installing Windows 11 KB5055523 update or Windows 10 KB5055518. The SYSTEM account owns the new inetpub folder, meaning an elevated process made it.

Read more