Microsoft GDID: The Windows Tracker That Can’t Be Turned Off

Client
Microsoft
Role
OS telemetry / device tracking
Stack
Windows 10/11, Microsoft Account, wlidsvc, Connected Devices Platform

In July 2026 the world learned that every Windows installation carries a permanent, invisible serial number – a device fingerprint that Microsoft assigns, reports, and cannot be turned off. It isn’t new. It isn’t a bug. It has been running on Windows for years, quietly identifying your machine across Microsoft services, and it is only now public because the FBI leaned on it to catch a hacker. This is the story of the Global Device Identifier, GDID.

Quick overview: this short walks through Windows 11’s GDID.

What GDID is

The Global Device Identifier is a persistent, device-level ID that Microsoft assigns to an installation of Windows – physical laptop, desktop, phone, or virtual machine. In Microsoft’s own words, quoted in a federal complaint, it is designed to “uniquely identify an installation of a Windows operating system on a device … across certain Microsoft services and scenarios.”

It is generated when Windows is provisioned against a Microsoft Account, by a chain of services. The wlidsvc service requests a Device PUID from login.live.com, which is then registered into Microsoft’s Device Directory Service by the Connected Devices Platform. Delivery Optimization reports the GDID back to Microsoft whenever the PC shares or downloads updates.

It is stored in the Windows registry under HKCUSOFTWAREMicrosoftIdentityCRLExtendedProperties, formatted with a lowercase g prefix followed by a decimal number – for example g:6755467234350028. It survives Windows updates. It is not retained across a clean reinstall, and one user can have multiple GDIDs linked through their account, OneDrive, and activation history.

The case that exposed it

GDID only became public because US prosecutors used it to track Peter Stokes, an alleged member of the Scattered Spider hacking group, in a federal complaint. Stokes is accused of stealing at least 77GB of data and demanding roughly $8 million in cryptocurrency ransom.

Stokes did everything right to hide – a VPN, proxy servers, travel across four countries over eight months. It didn’t matter. The FBI obtained his GDID from Microsoft, and the persistent identifier cut straight through the VPN. The complaint describes a GDID g:6755467234350028 recorded visiting the ngrok signup page at the same moment the attack account was created through a Tzulo VPN proxy. Three hours later, the same GDID accessed a victim retailer’s website through the same proxy. The same device ID was linked to IP addresses in Estonia, New York, and Thailand. Stokes’s own public Snapchat photos matched hotel bookings and travel timelines associated with the GDID.

While VPN IP addresses rotate constantly, the underlying Windows installation kept reporting the same identifier. The GDID is a tracking needle that no tunnel can hide.

Why it’s rot

The problem isn’t that Microsoft can identify a device – every OS has hardware IDs. The problem is how it was done: silently, without consent, without user-facing control, and without meaningful documentation.

  • No consent screen. Apple’s advertising identifier requires an App Tracking Transparency prompt and offers a visible reset. Android provides similar controls. GDID has neither – there is no prompt when it is assigned, and no switch to turn it off.
  • No off switch. Microsoft confirmed GDID cannot be disabled without breaking Windows activation and Microsoft Store (UWP) apps. Blocking the identifier assignment breaks core functionality.
  • Deliberately under-documented. For years, Microsoft’s public documentation of GDID consisted of exactly one sentence in an Azure Monitor reference table for enterprise IT administrators – a column described only as “Microsoft global device identifier.” Independent researchers had to reverse-engineer it.
  • It outlives your “privacy” choices. Reinstalling Windows generates a new GDID, but signing back into the same Microsoft Account gives Microsoft the link to connect the new identifier to everything the old one did.

Security researcher Matthew Hickey has characterized Windows as “surveillance software” in response to the case. It’s a fair charge: ~1.6 billion Windows devices have been carrying a permanent, non-consented, non-disabled tracking ID that Microsoft only publicly acknowledged once a court filing forced the issue.

What you can do

GDID can’t be turned off cleanly, but you can reduce how much related tracking Microsoft gets:

  1. Use a local account instead of a Microsoft Account where possible (Windows 11 has made this harder, but the option still exists during setup).
  2. Turn off optional diagnostic data: Settings → Privacy & security → Diagnostics & feedback.
  3. Disable personalized ads and launch tracking under Privacy & security → Recommendations & offers.
  4. Turn off Cloud Content Search under Privacy & security → Search so local searches stop pinging Bing.
  5. Review and disable Activity History and other telemetry options.
  6. For anyone whose safety genuinely depends on avoiding device correlation – journalism, activism, domestic-abuse situations – don’t rely on a commercial VPN on a Windows PC. Use Linux routed through Tor.

Watch the coverage

Want the full breakdown? Here’s the deep dive.

The GDID Controversy: Is Microsoft Tracking Your Every Move? – deep dive:

The bottom line: a VPN protects your IP, not your Windows installation. Your machine has been wearing a nametag to Microsoft this whole time, and now you know its name.