Microsoft GDID Tracking Sparks Fresh Windows Privacy Questions

Microsoft GDID Tracking System Raises Fresh Privacy Questions After FBI Investigation Exposes Windows Identifier
Microsoft GDID Tracking Sparks Fresh Windows Privacy Questions
Written By:
Akshita Pidiha
Reviewed By:
Ankitha Phulare
Published on

A little-known Microsoft system that assigns a unique identifier to every Windows installation has come under fresh scrutiny. These details emerged in a federal court filing linked to an FBI cybercrime investigation.

The identifier, known as the Global Device Identifier (GDID), helped investigators trace an alleged hacker despite the use of VPNs, proxy servers, and multiple online identities. The disclosure has also raised broader questions about transparency around Microsoft's data collection practices on Windows devices.

What GDID is and How it Works

GDID is a persistent device-level identifier assigned to every Windows installation. Microsoft generates the identifier on its servers and stores it locally in the Windows registry. Each installation receives a separate identifier, including virtual machines.

According to Microsoft's description in the unsealed complaint in United States v. Peter Stokes, GDID is ‘a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device.’

The identifier is issued when a Windows device is set up with a Microsoft account through the Passport identity service. It continues to exist through regular Windows updates and most hardware or software changes. A fresh Windows installation receives a new GDID, while Microsoft retains records linked to the previous identifier.

Windows installation receives a new GDID

Public documentation on GDID is limited. Microsoft's only publicly available reference describes it as an internal global device identifier without offering further technical details.

Identifier Connects Several Windows Services

Independent researchers who examined the system found that GDID is linked with several Windows features after being registered through Microsoft's Connected Devices Platform and Device Directory Service.

The identifier supports Windows activation, Microsoft Store licensing, Phone Link, clipboard synchronization, and other cross-device services. It also appears in Windows diagnostic data. When Microsoft Edge enhanced diagnostics are enabled, browsing history can also be associated with the same identifier.

Security researchers say the concern is not the existence of a device identifier itself. The debate centres on Microsoft's limited public disclosure of how the identifier operates and how widely it is used across Windows services.

FBI Investigation Highlights GDID's Role

GDID came into the spotlight during the criminal case involving Peter Stokes, a 19-year-old dual US-Estonian citizen who is accused of being part of the Scattered Spider hacking group.

According to the US Department of Justice, investigators obtained Stokes' GDID from Microsoft while investigating the May 2025 cyberattack on a luxury jewellery retailer. Officials said the identifier helped connect activity across different locations and online services, allowing investigators to link the suspect to the alleged cyberattack.

The complaint says the attackers pretended to be company employees and contacted the retailer's help desk. They allegedly persuaded staff to reset account credentials and multi-factor authentication, which gave them access to the company's internal systems.

Here’s the command:

$hex = (Get-ItemProperty 'HKCU:\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties').LID

"g:$([Convert]::ToUInt64($hex,16))"

Here’s the command:

Authorities alleged that around 77 gigabytes of data were stolen before an AED 8 million cryptocurrency ransom was demanded. Stokes has been charged with conspiracy, computer intrusion and fraud, and is presumed innocent while the case continues.

Transparency Takes Centre Stage

Windows users cannot turn off GDID or stop Windows from creating it. They can reduce diagnostic data and activity history to limit the amount of information linked to the identifier in the future. Even then, the GDID already created and stored by Microsoft will continue to exist.

Microsoft says GDID is meant only for its internal use. The company has not presented any evidence that it shares the identifier with advertisers. Law enforcement agencies can access the identifier through legal channels such as court orders or subpoenas.

The disclosure has shifted the discussion from the technology itself to how much users know about it. Privacy experts say many operating systems use device identifiers. They also point out that users are usually informed when such tracking systems are in place. The GDID case has renewed calls for Microsoft to clearly explain how Windows creates, uses and stores device-level identifiers.

Also Read: Microsoft Removes Search Clutter in New Windows 11 Update Test

Analytics Insight UAE: Top Tech News Website in UAE, Dubai & Middle East
www.analyticsinsight.ae