Windows Recall Explained: What It Does, and How to Turn It Off

Microsoft's AI 'photographic memory' search was rebuilt after 2024's privacy backlash. Here's what Recall does today, who can use it, and how to switch it off.

Windows 11 setup screen showing the Recall opt-in prompt with Yes, save and No, don't save buttons
The Recall opt-in screen introduced after Microsoft's 2024 privacy rework. Image: Microsoft.

Windows Recall is an AI-powered search tool built into Windows 11 that periodically saves encrypted "snapshots" of your screen so you can later find anything you've seen on your PC using natural-language search. After a 2024 privacy backlash forced Microsoft to rebuild it from the ground up, Recall shipped as a general-availability feature on Copilot+ PCs in April 2025 as an opt-in experience — it is not on by default, and Microsoft's current documentation confirms that remains true today. On managed business PCs, it's disabled and completely removed unless an IT administrator turns it on. This guide covers exactly what Recall does, what hardware it needs, and the precise steps to enable, disable, or fully uninstall it.

Quick facts
  • Default state: Opt-in on unmanaged Copilot+ PCs; disabled and removed by default on IT-managed devices.
  • Hardware needed: A Copilot+ PC with a 40+ TOPS NPU, 16 GB RAM, 8 logical processors, and 256 GB+ storage.
  • Security gate: Requires Device Encryption/BitLocker and Windows Hello with a biometric sign-in.
  • To turn off: Settings > Privacy & security > Recall & snapshots > toggle "Save snapshots" off.
  • To remove entirely: "Turn Windows features on or off" > uncheck Recall > restart (deletes saved snapshots).

What is Windows Recall, exactly?

Recall is a Windows 11 feature, part of what Microsoft calls the Windows Copilot Runtime, that takes periodic screenshots of your active screen while you work — roughly every few seconds, whenever the content on screen has changed — and stores them locally in an encrypted, on-device timeline. Windows then uses on-device AI (optical character recognition and image analysis running on the PC's neural processing unit) to index what's in each snapshot: text you read, documents you edited, websites you visited, images you looked at. Later, you can scroll back through that timeline or type a natural-language description of what you remember — Microsoft's marketing shorthand is giving your PC a "photographic memory" — and Recall surfaces the matching snapshots so you can jump straight back to that document, email, or webpage.

A companion feature called Click to Do runs on top of any snapshot you open, letting you copy text, open an image in an editor, or send content to another app directly from the saved screen capture. Recall does not record audio and does not save continuous video; it only captures still images of the screen at intervals, and it skips DRM-protected content and game video when Game Mode is active.

The 2024 privacy controversy, briefly

Microsoft first announced Recall in May 2024 alongside the Copilot+ PC hardware category, originally planning to ship it enabled by default. Within weeks, security researchers — most notably a proof-of-concept tool nicknamed "Total Recall" — showed that the early preview build stored its snapshot database in a local file that wasn't encrypted and could be extracted by any user or piece of malware with local access, undermining Microsoft's claims about the feature's security. Microsoft pulled Recall from the initial Copilot+ PC launch on June 13, 2024, and rebuilt it as a Windows Insider preview instead.

In September 2024, Microsoft published a detailed rework: Recall would ship as an opt-in feature (nothing saved unless a user explicitly turns it on), snapshots and the underlying vector database would be encrypted at all times, encryption keys would be bound to a user's Windows Hello Enhanced Sign-in Security (ESS) identity and protected inside a Virtualization-based Security (VBS) Enclave, and the feature would be fully uninstallable via Windows Optional Features. That architecture — not the original 2024 design — is the one that actually shipped (see Wikipedia's timeline of the Recall rollout for the full sequence of events).

Is Recall on by default in 2026?

No. According to Microsoft's current Recall documentation, on an unmanaged Copilot+ PC (the kind most consumers buy), Recall is available out of the box, but saving snapshots always requires the user to explicitly opt in — either during the Recall setup flow or later in Settings. If you never open Recall or agree to its prompt, no snapshots are ever taken. On commercially managed devices (business PCs joined to a domain or managed via Microsoft Intune or similar tools), Microsoft's documentation states Recall is disabled and its files are removed from the device by default; an IT administrator must deliberately enable the "Allow Recall to be enabled" policy before end users even see the option, and even then, users — not the admin — must individually consent to saving snapshots.

This is a meaningfully different posture from the original 2024 plan, and it has held steady through the April 2025 general-availability release and into 2026: Recall ships as an opt-in, user-consented feature everywhere, with no path for an administrator or Microsoft to switch on snapshot-saving on a user's behalf. Recall isn't tied to a single feature update — it's delivered to eligible Copilot+ PCs through Windows Update on top of either the 24H2 or 25H2 feature update, so upgrading to Windows 11 25H2 doesn't change whether Recall is on; the opt-in requirement travels with the feature itself, not the underlying OS version.

One honest caveat worth flagging: Microsoft's Recall documentation is a living page that gets revised as policies and settings evolve (the IT-admin management article was itself last updated in December 2025), and Microsoft doesn't publish a single dated "current status" statement the way it might for a product launch. The opt-in-by-default behavior described above is what's stated in Microsoft's live support and Learn documentation as of this writing; if you're evaluating Recall for a fleet of managed devices, verify the exact policy defaults against the current version of Microsoft's "Manage Recall for Windows clients" page before you rely on them, since Microsoft can and does adjust default policy states between updates.

Hardware requirements: what counts as a Copilot+ PC

Recall only runs on Copilot+ PCs — it is not available on older Windows 11 hardware, regardless of Windows version. Per Microsoft's official system requirements, a PC needs all of the following to enable Recall:

RequirementMinimum
PC categoryCopilot+ PC meeting the Secured-core standard (Qualcomm, Intel, or AMD silicon; Arm64EC apps not supported)
NPU performance40 TOPS (trillion operations per second) or higher
Memory16 GB RAM
Processor8 logical processors
Storage256 GB capacity; 50 GB free space required to enable; saving pauses below 25 GB free
Disk encryptionDevice Encryption or BitLocker enabled
Identity/authenticationWindows Hello Enhanced Sign-in Security with at least one biometric method (face or fingerprint) enrolled
SoftwareApril 2025 non-security preview update or later

The 40-TOPS NPU floor deliberately excludes most pre-2024 laptops; it's met by chips such as the Qualcomm Snapdragon X series, AMD Ryzen AI 300 series, and Intel Core Ultra 200V series. Recall is also currently optimized for a specific set of languages (English, Chinese Simplified, French, German, Japanese, and Spanish), with content- and storage-based limitations Microsoft documents separately.

How snapshots are protected

Every snapshot and its associated entry in Recall's local vector database is encrypted at all times. The encryption keys are protected by the PC's Trusted Platform Module (TPM) and tied to the signed-in user's Windows Hello Enhanced Sign-in Security identity; keys can only be used inside a Virtualization-based Security Enclave, an isolated, hardware-backed environment that other users, other processes, and Microsoft itself cannot read. Snapshots are never uploaded — all analysis and storage happen locally on the device, with no internet or cloud connection required, and Microsoft's documentation states Microsoft cannot access or view a user's snapshots. Other people signed into the same PC under different accounts cannot see your snapshots either.

A "sensitive information filtering" setting is turned on by default and uses the same on-device classification engine that powers Microsoft Purview to try to skip saving snapshots that contain things like passwords or financial account numbers, though the sensitive content itself always stays on the device whether or not this filter is active. Organizations can also plug in a Data Loss Prevention provider (Microsoft Purview is currently the only supported one) so specific windows flagged as sensitive are excluded from snapshots at the policy level. Recall also automatically skips saving from a handful of remote-desktop clients (Remote Desktop Connection, VMConnect, Azure Virtual Desktop) as long as those clients implement screen-capture protection, and it filters supported browsers' private-browsing sessions by default.

How to turn Recall on

On an eligible, unmanaged Copilot+ PC:

  1. Go to Settings > Privacy & security > Recall & snapshots (or launch Recall directly, which triggers the same setup prompt).
  2. Read the "Unlock your photographic memory with Recall" prompt and select Yes, save to opt in, or No, don't save to decline.
  3. Set up or confirm Windows Hello with a biometric sign-in (face or fingerprint) if you haven't already — Recall won't start saving snapshots without it.
  4. Optionally, use the same Settings page to filter specific apps or websites out of snapshots, review Recall's sensitive-information filtering, and set how much disk space snapshots can use.

Once enabled, a Recall icon sits in the system tray; opening the app or the search box asks you to re-authenticate with Windows Hello first, since even a paused, decrypted look at your own timeline requires proof of presence.

How to turn off or fully remove Recall

There are three levels of "off," and which one you want depends on whether you might use Recall again later.

MethodWhat it doesReversible?
Toggle off in SettingsSettings > Privacy & security > Recall & snapshots > turn "Save snapshots" off. Stops new snapshots immediately; existing ones remain unless you delete them separately.Yes — toggle back on anytime
Pause temporarilySelect the Recall icon in the system tray and choose "Pause until tomorrow." Saving resumes automatically at midnight, or you can resume manually.Yes — resumes automatically or on demand
Uninstall the optional featureSearch "Turn Windows features on or off," uncheck Recall, click OK, and restart. This removes the Recall component entirely and deletes previously saved snapshots.Yes — re-check the box and restart to reinstall
Block via Group Policy (managed/admin PCs)gpedit.msc > Computer Configuration > Administrative Templates > Windows Components > Windows AI > set "Allow Recall to be enabled" to Disabled. Removes the Recall bits and deletes any saved snapshots.Yes — set the policy back to Enabled or Not Configured

For a permanent, whole-PC removal, the "Turn Windows features on or off" route is the one Microsoft documents for consumers: press Start, search for Optional features or "Turn Windows features on or off," scroll to and untick Recall, confirm, and restart when prompted. This deletes any snapshots already stored on the device, not just the app itself.

Group Policy and MDM settings for IT admins

On domain-joined or Intune-managed fleets, Recall ships disabled and removed by default, and individual users cannot enable it on their own unless an administrator opts the organization in. The relevant controls live under Computer Configuration > Administrative Templates > Windows Components > Windows AI in Group Policy, with matching MDM policies under the WindowsAI configuration service provider:

  • Allow Recall to be enabled (CSP: AllowRecallEnablement) — makes the Recall component available for users to opt into. Disabling this removes the Recall bits from the device and deletes any existing snapshots.
  • Turn off saving snapshots for Recall (CSP: DisableAIDataAnalysis) — even with Recall available, this must be left disabled/not configured for end users to be offered the save-snapshots opt-in; admins cannot use this policy to turn saving on for someone else.
  • Set maximum storage/duration for snapshots — caps disk space (10–150 GB) or retention (30–180 days) for snapshots on Enterprise/Education editions.
  • App and website filtering policies — lets admins pre-populate lists of executables or URLs that should never be captured.
  • Data Loss Prevention provider policy — integrates Recall with Microsoft Purview so windows flagged as containing sensitive data are excluded from snapshots.

Administrators who want to deploy Recall in some environments may also need to manually enable the optional feature via PowerShell (Enable-WindowsOptionalFeature -Online -FeatureName "Recall") since the package doesn't always deploy automatically even once policy allows it; the inverse command, Disable-WindowsOptionalFeature -Online -FeatureName "Recall" -Remove, lets a user or admin strip it back off a single machine.

Does 25H2 change anything about Recall?

Not fundamentally. Recall is a Copilot+ PC capability delivered through Windows Update rather than a feature exclusive to one annual release, so it behaves the same whether a device is running 24H2 or the newer 25H2 feature update. If you're managing a rollout and also tracking monthly servicing changes, it's worth checking release notes like the September 2026 preview update for any Recall-adjacent fixes, since Microsoft occasionally ships Recall bug fixes and small policy additions (such as the EEA snapshot-export option) through regular cumulative updates rather than through feature-update-level announcements.

Why Recall leans so heavily on Windows Hello

Recall's entire security model depends on proving it's really you, every time. Before snapshots can even start saving, you must enroll in Windows Hello Enhanced Sign-in Security with a biometric method; before you can open the Recall app or run a search, you must re-authenticate with Windows Hello again, since that authentication event is what unlocks the TPM-protected key needed to decrypt your snapshot database inside the VBS Enclave. If your device doesn't support Windows Hello's enhanced mode, or you never enroll a fingerprint or face, Recall's opt-in prompt won't let you turn saving on in the first place. If you're setting up biometric and passwordless sign-in more broadly across your devices, our guide on setting up passkeys on iPhone, Android, and Windows covers the same Windows Hello foundation Recall relies on.

What's next for Recall

Recall remains a moving target: Microsoft has continued adding controls since the April 2025 GA release, including Data Loss Prevention integration with Purview and, for users in the European Economic Area, the ability to export snapshots to trusted third-party apps under a separate opt-in policy. Expect Microsoft to keep tuning default policies for managed devices and expanding supported languages and browsers over time — if Recall matters to your workflow or your organization's compliance posture, treat Microsoft's own "Manage Recall for Windows clients" and "Privacy and control over your Recall experience" pages as the source of truth, since third-party coverage (including this article) can lag behind policy tweaks Microsoft ships quietly in cumulative updates.

Frequently asked questions

Is Windows Recall on by default?

No. On unmanaged Copilot+ PCs, Recall is available but requires opt-in consent before it saves any snapshots. On IT-managed devices, it's disabled and removed by default until an administrator enables it, and even then users must opt in individually.

What PCs can run Windows Recall?

Only Copilot+ PCs with a 40+ TOPS NPU, 16 GB RAM, 8 logical processors, 256 GB or more storage, Device Encryption or BitLocker, and Windows Hello Enhanced Sign-in Security with a biometric method enrolled.

How do I turn off Windows Recall?

Go to Settings > Privacy & security > Recall & snapshots and toggle 'Save snapshots' off, or select the Recall icon in the system tray and choose 'Pause until tomorrow' for a temporary break.

How do I completely uninstall Recall?

Search 'Turn Windows features on or off,' uncheck Recall, click OK, and restart. This removes the Recall component entirely and deletes any snapshots already saved on the device.

Why does Recall require Windows Hello?

Because the encryption keys protecting your snapshot database are bound to your Windows Hello Enhanced Sign-in Security identity. Without biometric authentication enrolled, Recall can neither save nor decrypt snapshots.

Can Microsoft or my IT department see my Recall snapshots?

No. Snapshots are processed and stored locally and are never uploaded. Microsoft's documentation states Microsoft and IT admins cannot access or view them, and other users signed into the same PC can't see them either.

Sources

More on Windows 11 →Windows RecallWindows 11Copilot+ PCWindows HelloPrivacy
Felix Moreau
Written byFelix Moreau

Felix Moreau writes Pandromeda's software coverage and how-to guides. He covers Windows, macOS and Linux updates, the apps people rely on, emulators and developer tools, and turns official documentation into clear, numbered steps that work on the current version.

More from Software & Guides

See all