Microsoft confirms that Windows GDID device identifier cannot be disabled, documented in FBI case filing


microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to windows facility, in a federal complaint filed by U.S. prosecutors against an alleged member of the Scattered Spider hacking group.

The ID is generated when Windows is set up with a Microsoft account, persists through Windows updates, and cannot be disabled without affecting the activation of Windows and Microsoft Store apps.

Microsoft briefly mentioned GDID in the Azure Monitor documentation, describing it only as “an identifier used internally by Microsoft.” The complaint quotes a Microsoft representative describing GDID as “a device-level persistent identifier designed to uniquely identify an installation of a Windows operating system on a device, whether a physical device such as a mobile phone or laptop or a virtual machine, in certain Microsoft services and scenarios.”

What is the Windows Global Device Identifier and how the FBI used it

The Global Device Identifier (GDID) is a permanent ID assigned when Windows provisions a Microsoft account. It is generated by a Windows service chain.

The wlidsvc service requests a device PUID from login.live.com, which the Connected Devices Platform then registers with the Microsoft Device Directory Service.

Delivery Optimization reports the GDID to Microsoft when the PC shares or downloads updates. This identifier is stored in the Windows registry at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties and is formatted with a lowercase “g” prefix followed by a decimal number.

It is reported to Microsoft servers and remains persistent across Windows updates, but is not persisted after a clean reinstall. Microsoft has recognized that a user may have multiple GDIDs linked through their account, OneDrive, and their activation history.

The FBI used the GDID to track alleged Scattered Spider member Peter Stokes through VPN connections, proxy servers, and across four countries for approximately eight months.

According to the complaint, the GDID g:6755467234350028 was registered by visiting the ngrok registration page at the same time as creating an account used in the attack through a Tzulo VPN proxy. Three hours later, the same GDID accessed a victim retailer’s website through the same proxy.

The device was cross-referenced with IP addresses linked to Stokes’ accounts at Snapchat, Facebook, Apple and Ubisoft in Estonia, New York, Thailand and elsewhere. Stokes’ public photos on Snapchat matched hotel reservations, locations and travel schedules associated with the GDID.

The persistent nature of the GDID across VPN sessions turned out to be a key asset in the research. While VPN IP addresses change frequently, the underlying Windows installation continued to report the same identifier, which aided researchers in their tracking efforts.

Why privacy researchers care and what users can do

Several security researchers have expressed concerns about the visibility and control that users have over GDID:

  • There is no consent screen when GDID is assigned. Apple Advertising Identifier requires an App Tracking Transparency message with a visible reset. Android provides similar controls. GDID has neither.
  • Activation dependency. Massgrave, the group behind Microsoft Activation Scripts, has observed that Windows Setup sends hardware information to Microsoft and receives identifiers that are then used for Store access and licensing. Blocking GDID assignment breaks both activation and UWP apps.
  • Reinstalling Windows produces a new GDID, but signing back into the same Microsoft account gives Microsoft a clear path to link the new identifier to previous activity.
  • Microsoft’s public documentation on the identifier consists of a sentence in an Azure Monitor reference table for enterprise IT administrators.

Security researcher Matthew Hickey has characterized Windows as “surveillance software” in response to the case. Costin Raiu asked on the Three Buddy Problem podcast how many similar features exist on other platforms.

Users concerned about GDID have limited direct options because the identifier cannot be disabled without interrupting core Windows functionality. Practical steps that reduce related tracking include:

  1. Use a local account instead of a Microsoft account when possible. Windows 11 has made this more difficult in recent versions, but the option is still available during setup for users who know how to access it.
  2. Disable optional diagnostic data via Settings, Privacy & Security, Diagnostics & Feedback.
  3. Disable personalized ads and start tracking in Privacy & security, Recommendations & offers.
  4. Turn off cloud content search in Privacy & Security, Search, to prevent local searches from sending data to Bing.
  5. Review and disable Activity History and other telemetry options in Privacy & Security settings.
  6. For journalism, activism, or domestic abuse situations where identifier persistence poses a threat, use Linux routed through Tor instead of relying on a commercial VPN with a Windows PC.

Users who reinstall Windows to get a new GDID should note that signing back into the same Microsoft account provides Microsoft with data linking the new identifier to previous activity.

What GDID means for Windows users and how widely it is implemented

For the approximately 1.6 billion Windows users worldwide, GDID has been running quietly in the background, without any public disclosure or user controls. The recent complaint revealed the existence of this identifier, but Microsoft has not committed to providing user-facing controls or documentation for regular users.

Users concerned about device-level tracking should note that the identifier is attached to the account, not the device, meaning that reinstalling the operating system does not break the link.

Most major operating systems maintain some form of persistent device identity for purposes such as licensing and security controls, but Windows differs from platforms like Apple and Google in that it does not offer visible controls.

Legal requests, such as subpoenas, can force Microsoft to share GDID activity data with authorities, as exemplified by the Scattered Spider case. GDID is present on all Windows installations linked to a Microsoft account.

Users cannot see their own GDID through standard Windows interfaces; It is stored in the registry at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties under the LID key. Microsoft has not indicated any changes to the way GDID is generated, stored, or reported.

The only public reference outside of the federal complaint is a brief note in the Azure Monitor documentation. Users can monitor privacy updates from Microsoft, but the company has not indicated plans to provide more public information about GDID.

The Scattered Spider case moves forward in the United States federal judicial system. For those interested in the technical details, reviewing Microsoft’s telemetry complaint discussion offers the clearest public explanation of how GDID works to date.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *