Privacy News Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

lokamoka820

Level 51
Thread author
Verified
Top Poster
Well-known
Mar 1, 2024
4,080
3
14,399
4,969
Banana Republic
Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group.

The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.

Microsoft briefly mentioned GDID in the Azure Monitor documentation, describing it only as "an identifier used by Microsoft internally." The complaint cites a Microsoft representative describing GDID as "a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device such as a mobile phone or laptop or a virtual machine, across certain Microsoft services and scenarios."

Why Privacy Researchers Are Concerned and What Users Can Do​

Multiple security researchers have raised concerns about the visibility and control users have over GDID:
  • There is no consent screen when GDID is assigned. Apple's advertising identifier requires an App Tracking Transparency prompt with a visible reset. Android provides similar controls. GDID has neither.
  • Activation dependence. Massgrave, the group behind Microsoft Activation Scripts, has noted that Windows setup sends hardware info to Microsoft and receives identifiers back that are later used for Store access and licensing. Blocking GDID assignment breaks both activation and UWP apps.
  • Reinstalling Windows produces a new GDID, but signing back into the same Microsoft Account gives Microsoft a clear path to link the new identifier to previous activity.
  • Microsoft's public documentation of the identifier consists of one sentence in an Azure Monitor reference table for enterprise IT administrators.
Security researcher Matthew Hickey has characterized Windows as "surveillance software" in response to the case. Costin Raiu asked on the Three Buddy Problem podcast how much similar functionality exists on other platforms.

Users concerned about GDID have limited direct options because the identifier cannot be turned off without breaking core Windows functionality. Practical steps that reduce related tracking include:
  1. Use a local account instead of a Microsoft Account when possible. Windows 11 has made this harder in recent versions, but the option is still available during setup for users who know how to reach it.
  2. Turn off optional diagnostic data through Settings, Privacy and security, Diagnostics and feedback.
  3. Disable personalized ads and launch tracking under Privacy and security, Recommendations and offers.
  4. Turn off Cloud Content Search under Privacy and security, Search, to stop local searches from sending data to Bing.
  5. Review and disable Activity History and other telemetry options in Privacy and security settings.
  6. For journalism, activism, or domestic abuse situations where identifier persistence poses a threat, use Linux routed through Tor rather than relying on a commercial VPN with a Windows PC.
Users who reinstall Windows to obtain a new GDID should be aware that signing back into the same Microsoft Account provides Microsoft with data linking the new identifier to previous activity.
 
Privacy settings in Windows can still reduce some data sharing, but they don't affect system-level identifiers like the GDID described in the article.

I still think it's worth reviewing and adjusting those settings, since they can still reduce some optional data sharing, even if they don't affect identifiers like GDID. This case simply shows that some aspects of Windows operate independently of the privacy options available to users. 🔒✨
 
As the article says "
  1. Use a local account instead of a Microsoft Account when possible. Windows 11 has made this harder in recent versions, but the option is still available during setup for users who know how to reach it. "
Press Shift+F10 in the last bootup during Windows install when it asks for the region, and run:
OOBE\BYPASSNRO
And that will give you the choice saying "I don't have internet" and allow you to make up a local user name, bypassing this sign in to MS account nonsense.

Why is everybody making this so mysterious? ("for users who know how to reach it")

Anyways if this doesn't work, switch to Linux.
 
Last edited:
Anyways if this doesn't work, switch to Linux.
Haha, for OS-level surveillance (Android, Microsoft), this seems likely the surest mitigation.

BTW, Tom's Hardware speculated that:
1. He was using Edge.
2. He had his Windows telemetry set to Optional/Full, as Required/Basic doesn't appear to transmit URLs by default.
3. The FBI got his visited and timestamped URLs (along with the GDID) from Microsoft

So don't use Edge, back down the telemetry to required (and all the ads! to none), and don't piss off the FBI.
 
Last edited:
Here's everything you need to know about Global Device Identifier (GDID), a special identifier Microsoft uses to track every Windows device.
Many people are generally skeptical about their online safety and the privacy of their data. No matter what measures you take, be it using a VPN, leaving minimal online footprint, or using anonymous accounts, it never feels like you’re completely safe. And since you can’t prove that you’re being watched, it’s easy to think of yourself as paranoid. Until a case like Microsoft’s GDID surfaces.
The general public recently became aware that Microsoft has been quietly tracking Windows PCs through a special key that most users have never heard of. Microsoft never publicly detailed it, and it took a federal court filing for the company to fully confirm its existence.

The identifier is called GDID, short for Global Device Identifier, and it recently helped the FBI catch an alleged hacker, who as part of a hacking group, breached the security of a jewelry store. The suspect was using VPNs, proxies, and multiple aliases to stay hidden, but GDID still helped the authorities identify him.

And while GDID helped FBI catch the threat actor, the case also exposed something a lot of ordinary Windows users are uneasy about. It shed light on a tracking mechanism that’s baked into the operating system that runs on around 1.6 billion PCs worldwide.

What GDID actually is
👎
Read more:
 
Windows' GDID can be permanently disabled with a PowerShell script made by a Windscribe developer.

https://www.neowin.net/news/permane...-on-all-windows-11-versions-with-this-script/
Windscribe, however, cautions that disabling GDID generation could affect Microsoft services that depend on device identification. While the company says it has not encountered any issues during testing, it acknowledges there may be edge cases where certain Windows features or Microsoft services behave differently. Regardless, the firm says it should technically work with all Windows 11 versions (21H2 up to 25H2), and Windows 10 version 22H2.
Windows Tracks You With a Hidden ID. So We Built deGDID to Block It.
GitHub - yegors/deGDID: Deletes all instances of Microsoft's GDID and prevents minting of new ones
• Blocks known Microsoft registration paths by managing a region in the Windows hosts file, plus reinforcing the block with Windows Firewall rules.
• Wipes known local GDID-related state across target-user, SYSTEM, and .DEFAULT identity locations, token device IDs, device tickets, Credential Manager entries, ConnectedDevicesPlatform, TokenBroker, WAM broker caches, and matching NegativeCache entries.
It worked here in a Windows 10 VM snapshot.
 
I'm not sure how functional it will be because it relies on Windows Firewall and hosts file. And Microsoft is known for making exceptions for their domains in both.
You can check the status with: .\degdid.ps1 -Status :

Code:
degdid status — 2026-08-11T10:08:59.2667060+02:00

This PC
Windows 10 22H2, build 19045
User:    User-Virtual\User
SID:     S-1-5-21-<REDACTED>
Profile: C:\Users\User
Supported by this tool: YES
Dormant profiles ignored: 1 (not loaded and not active targets)

Registration protection
ACTIVE — Windows DeviceAdd is blocked.
login.live.com: blocked on IPv4 and IPv6; TCP connection failed.
Supplemental wlidsvc firewall rule: enforced

Global Device Identifiers
No real-shaped GDID was found in the known active or cache stores.

VERDICT: PROTECTED — no real GDID found and DeviceAdd is blocked.
No action is required. Re-run Status after major Windows or firewall changes.

For full technical diagnostics: .\degdid.ps1 -Status -Json
 
Why is everybody making this so mysterious? ("for users who know how to reach it")
Exactly, just disconnect your router & WiFi during install. I'm calling bullshit on it though, I imagine MS has some sneaky way of enabling it for non MS accounts.

The ID is generated when Windows is set up with a Microsoft Account,

Yeah so just don't use a MS account, funny :poop: no wonder they are heavily pushing MS accounts on install. Naughty naughty MS got caught with your pants down 👖