Zero Trust DNS Private Preview
techcommunity.microsoft.com
techcommunity.microsoft.com
This would likely be excruciating to use and kinda pointless for general use PCs (given how much stuff will probably break in the short term). Maybe that's an intended use case long-term but it's not there now.
I could see this being useful for task-oriented boxes that have no business connecting to arbitrary destinations. I also like the idea of using this as a method to funnel all DNS traffic into the system resolver and into controlled DNS servers. I like that this also kills the application-layer DNS arms race.
Implementing a 75% solution akin to this on Linux wouldn't be too tremendously hard, either. All the pieces and parts are already there to do it.
Schools and certain kind of enterprises will welcome this feature.
This seems like a good compromise that will enable IT admins to get the control they desire while still giving users access to privacy preserving technologies like HTTPS with ECH.
you cannot disable it on IOS or android. Because it is owned by the APP not the OS.
Even firefox had to disable the setting (and about:config! making firefox on android pretty much garbage unless you install from fdroid) just so google would allow firefox on the play store.
Your comment is like saying that firewalls are disgusting because they can be used to lockdown machines.