What do you suggest on public Wi-Fi & home network with company (ms-windows) laptop

I work from home. My company gives me laptop which is windows-11 and it has VPN and it has many tracking software built-in.

That windows-11 can see other machines at home because of Wi-Fi… How can I prevent this? Is there any simple way to create different sub-networks for each device? will it be over-engineering for a simple person?

When we use public Wi-Fi is it good enough to boot device with Tails and use tor browser inside? Does Tails randomizes MAC by default?

Put that PC on a seperate VLAN.

Depends on your router, maybe try looking up “[router model] guest network”

It’s definently good enough, maybe even overkill, depends on your threat model.

You can put the Windows machine on the guest network of your router so it can’t see other devices. As for public WiFi, Windows can randomize the MAC address.