When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.
This means most PCs won’t even be eligible to use Recall.
In fact, their identity is what releases the [encryption] keys."

An attacker is unable to infiltrate Recall’s services that handle snapshots and data.
They’re never released outside of the enclave, the keys are all protected inside of the enclave.
Recall operates entirely on-rig.
“We’re not sending any of this information anywhere"Weston tells me.

An attacker is unable to infiltrate Recall’s services that handle snapshots and data.
“Microsoft could never even decrypt this [data] even if we wanted to.
The only thing we send back is basic diagnostic usage to fix bugs and user-controlled feedback.
Weston also confirmed to me that Windows Recall is actually not installed by default on Windows 11 Enterprise.

Windows Hello is now a key part of the Recall encryption process.
“On the Enterprise SKU the bits for Recall are not there at all.
It’s an optional component you have to install.
It’s actually not on the machine by default.”

This is where you can choose to enable or disable Recall during setup.
“No, an employer cannot see that information.
It’s fully encrypted, [accessible] only to the logged in user.”
Copilot+ PCs with Intel- and AMD-based processors will be able to join the Recall preview soon after.

We’ll have to wait and see how this plays out.












