A privacy review that only checks the list of individually toggled apps can miss traditional desktop software. Microsoft says the Privacy page does not list every desktop app or control every capability such apps can use. Some Windows controls are broad gates, while a browser also has site-level permissions. An effective audit maps each sensitive capability to the app that needs it, tests a denial, and checks whether an installed app still has a legitimate reason to remain.
Before you start
List the apps that should use camera, microphone, location, files and notifications. Note any work or accessibility tool that genuinely needs a capability. Use a normal user account for testing, but keep an administrator available to change device-wide controls. Managed devices may lock settings; record the policy rather than circumventing it.Do it step by step
- Open Settings > Privacy & security and review App permissions category by category. For each one, note the device-wide access state, the user-level gate and the Store apps individually allowed.
- Identify desktop apps separately. Microsoft warns they may not appear as individual switches under the same category. Review each app's own settings, product permissions and whether it still needs to be installed.
- For camera and microphone, inspect the broader Let desktop apps access control and browser site permissions. A Windows-level grant does not mean every website should receive access.
- Deny one nonessential permission and test the app's actual task. If its core function breaks, decide whether to grant a narrower permission or replace the app. Avoid flipping every switch at once.
- Remove unused software through Settings > Apps after checking its data and license, especially software with broad file access. A permission toggle is not a substitute for uninstalling an app you do not trust.
- Revisit permissions after a major app or Windows update. Keep a short note of exceptions so a future prompt can be judged against your original purpose.