GPO policy: "Allow Diagnostic Data" (formerly "Allow Telemetry") under Computer Configuration > Administrative Templates > Windows Components > Data Collection and Preview Builds. Controls the maximum amount of diagnostic data Windows sends to Microsoft. Registry: HKLM\SOFTWARE\Policies\Microsoft\Windows\DataCollection:AllowTelemetry (REG_DWORD). CIS Benchmark (L1) recommends value 0 (Security/Diagnostic data off) or value 1 (Send required diagnostic data) for enterprise environments. Reference: Configure Windows diagnostic data in your organization
Values
| Enum Value | Description |
|---|---|
|
|
Security-level telemetry only (registry value 0). The minimum data required to keep Windows secure; includes malware-related data. Enterprise/Education editions only; mapped to "Required diagnostic data" on Home/Pro. |
|
|
Basic / Required diagnostic data (registry value 1). Device information and quality data needed to keep Windows up to date, secure, and performing properly. CIS L1 recommended value. |
|
|
Enhanced diagnostic data (registry value 2). Additional data about app usage and device health. Deprecated as a standalone level in Windows 11; mapped to Required on newer builds. |
|
|
Full / Optional diagnostic data (registry value 3). All available diagnostic data, including data that can be used to diagnose and fix device problems. Least privacy-preserving. |
Used by
ComputerAdministrativeTemplatestype: Computer-specific Administrative Templates (ADMX) settings on an Endpoint.
Example
Example
"SECURITY"