Microsoft is right about one narrow point in the latest Windows 11 privacy dispute: the Global Device Identifier, or GDID, is not a newly deployed tracking service. But the denial leaves untouched the reason the issue exploded in the first place: a federal court filing shows Microsoft has long maintained a persistent identifier for individual Windows installations and can correlate activity recorded under it across certain Microsoft services.
TechPowerUp reported on August 3 that Microsoft rejected claims of a newly added Windows tracking mechanism. The primary record supports that correction. In a July 2026 superseding criminal complaint against alleged Scattered Spider participant Peter Stokes, the U.S. Department of Justice documented Microsoft’s description of GDID as a persistent, device-level identifier for a Windows installation on a physical PC or virtual machine. The filing concerns activity alleged to have occurred in May 2025—more than a year before this week’s argument.
That means “new service” is the wrong diagnosis. It does not mean the public concern is baseless. Microsoft’s response appears to rebut a claim about when the identifier was introduced, while leaving major questions about its assignment, transmission, retention, service coverage, and consumer controls unanswered.
The Stokes complaint provides the clearest public description yet of what Microsoft calls a Global Device Identifier. According to a Microsoft representative quoted in the filing, the GDID uniquely identifies a Windows installation across “certain Microsoft services and scenarios.” It remains the same through normal Windows updates, but a Windows reinstall receives a new identifier—even if performed on the same hardware.
That lifecycle matters. GDID is not proven to be an immutable motherboard serial number, a TPM identifier, or a deterministic hardware hash. A clean Windows installation producing a new value points instead to an installation identity: a durable identity associated with the operating-system instance that Microsoft services can recognize over time.
In the case described by prosecutors, Microsoft records associated one GDID with an ngrok account registration made through a VPN-proxy IP address. Investigators then used the same identifier alongside timestamps, IP records, account activity, travel evidence, and other provider data to build their attribution case. The GDID did not identify a person by itself; it became useful because it linked events that would otherwise have been split across IP addresses and networks.
That is a more precise—and more consequential—description than saying Windows “tracks every keystroke” or that a new spyware service suddenly appeared. A stable identifier does not need to collect content on its own to become powerful. It gives Microsoft a way to join records produced by other services and diagnostic systems.
That documentation is significant for two reasons. First, it independently confirms that the term is real and not an invention of the criminal complaint. Second, it shows why users were caught off guard: the public-facing explanation is exceptionally thin for an identifier that, by Microsoft’s own description to federal investigators, can persist across Windows updates and be used across multiple services.
Microsoft has detailed privacy controls for advertising IDs, location access, app permissions, diagnostic-data levels, tailored experiences, and account-connected features. GDID has no comparable consumer-facing setting. There is no documented toggle labeled “Global Device Identifier,” no published dashboard explaining which Windows and Microsoft services receive it, and no ordinary control for rotating it without reinstalling Windows.
The missing information is not a semantic complaint. Administrators need to know whether an identifier is generated on devices using local accounts, Microsoft accounts, Entra ID, domain join, Microsoft Store access, Delivery Optimization, Xbox services, or any combination of those conditions. They also need to know whether it is transmitted with required diagnostics, optional diagnostics, service-specific traffic, or only under particular connected experiences.
Microsoft has not publicly answered those questions in the material available so far. Calling the system old does not fill in those blanks.
Windows sends Required diagnostic data automatically to keep the operating system secure, updated, reliable, and functioning as expected. Microsoft says this data is stored alongside one or more unique identifiers that help it recognize a user on an individual device and understand service issues and usage patterns. Required diagnostics are distinct from the Feedback Hub workflow, which is user initiated.
Optional diagnostic data expands the scope. Microsoft says it can include more detailed device health information, application usage, enhanced error reporting, and—in relevant circumstances—websites a user browses. The company’s Edge policy documentation is even more specific: when Edge optional diagnostics are enabled, visited URLs and per-page usage can be reported to Microsoft. Administrators can disable that URL-reporting policy, but it applies only when optional browser diagnostics are in use.
The Stokes filing does not disclose the exact Windows component or telemetry pathway that provided the browsing records cited by investigators. Tom’s Hardware likewise noted that the complaint does not identify the specific collection mechanism. It would be wrong to claim the filing proves every Windows 11 machine routinely uploads every URL a user visits.
But it is equally wrong to claim that Windows data leaves the machine only after a user manually opens Feedback Hub and submits a report. Microsoft documents automatic diagnostic collection, recognizes that diagnostic events carry device identifiers and correlation values, and documents optional browsing-related collection under defined conditions.
A persistent Windows installation identity can make a sequence of otherwise separate events easier to associate inside Microsoft’s systems. If the same GDID appears when a device uses a home connection, a hotel network, a VPN endpoint, a Microsoft account, a service login, or optional browser diagnostics, Microsoft may be able to relate those records. Law enforcement access is a separate legal process, but the technical correlation happens because the platform maintains continuity.
For enterprise IT, this is familiar territory. Device identifiers are useful for update compliance, anti-fraud controls, software entitlements, security investigations, Intune administration, and account protection. The operational value is real. A managed fleet cannot be serviced reliably if every client becomes anonymous after an update or a network change.
The consumer privacy issue is that a device-management identifier can also function as a correlation key outside the administrator’s view. Microsoft’s public material has concentrated on the usefulness of diagnostic data and connected experiences while offering very little explanation of the particular identity layer that makes cross-service correlation possible.
The controls that do exist are narrower but meaningful:
Microsoft’s larger problem is transparency. It has now been publicly established that Windows installations have a durable global identifier that can bridge Microsoft records across services, yet the company still has not published the plain-language technical documentation, retention details, service map, and user controls that such an identifier warrants.
That means “new service” is the wrong diagnosis. It does not mean the public concern is baseless. Microsoft’s response appears to rebut a claim about when the identifier was introduced, while leaving major questions about its assignment, transmission, retention, service coverage, and consumer controls unanswered.
The court filing establishes that GDID existed before the controversy
The Stokes complaint provides the clearest public description yet of what Microsoft calls a Global Device Identifier. According to a Microsoft representative quoted in the filing, the GDID uniquely identifies a Windows installation across “certain Microsoft services and scenarios.” It remains the same through normal Windows updates, but a Windows reinstall receives a new identifier—even if performed on the same hardware.That lifecycle matters. GDID is not proven to be an immutable motherboard serial number, a TPM identifier, or a deterministic hardware hash. A clean Windows installation producing a new value points instead to an installation identity: a durable identity associated with the operating-system instance that Microsoft services can recognize over time.
In the case described by prosecutors, Microsoft records associated one GDID with an ngrok account registration made through a VPN-proxy IP address. Investigators then used the same identifier alongside timestamps, IP records, account activity, travel evidence, and other provider data to build their attribution case. The GDID did not identify a person by itself; it became useful because it linked events that would otherwise have been split across IP addresses and networks.
That is a more precise—and more consequential—description than saying Windows “tracks every keystroke” or that a new spyware service suddenly appeared. A stable identifier does not need to collect content on its own to become powerful. It gives Microsoft a way to join records produced by other services and diagnostic systems.
Microsoft’s own documentation confirms the identifier, but barely explains it
Microsoft Learn documentation for Windows Update for Business reporting includes aGlobalDeviceId field in the Delivery Optimization status schema. Microsoft describes it in one sentence: a global device identifier used internally by Microsoft.That documentation is significant for two reasons. First, it independently confirms that the term is real and not an invention of the criminal complaint. Second, it shows why users were caught off guard: the public-facing explanation is exceptionally thin for an identifier that, by Microsoft’s own description to federal investigators, can persist across Windows updates and be used across multiple services.
Microsoft has detailed privacy controls for advertising IDs, location access, app permissions, diagnostic-data levels, tailored experiences, and account-connected features. GDID has no comparable consumer-facing setting. There is no documented toggle labeled “Global Device Identifier,” no published dashboard explaining which Windows and Microsoft services receive it, and no ordinary control for rotating it without reinstalling Windows.
The missing information is not a semantic complaint. Administrators need to know whether an identifier is generated on devices using local accounts, Microsoft accounts, Entra ID, domain join, Microsoft Store access, Delivery Optimization, Xbox services, or any combination of those conditions. They also need to know whether it is transmitted with required diagnostics, optional diagnostics, service-specific traffic, or only under particular connected experiences.
Microsoft has not publicly answered those questions in the material available so far. Calling the system old does not fill in those blanks.
“Manual feedback only” is contradicted by Windows diagnostic documentation
Some discussion surrounding the TechPowerUp report has framed the disputed activity as feedback data that is uploaded only when a user manually files a report. Microsoft’s own privacy documentation does not support such a broad claim.Windows sends Required diagnostic data automatically to keep the operating system secure, updated, reliable, and functioning as expected. Microsoft says this data is stored alongside one or more unique identifiers that help it recognize a user on an individual device and understand service issues and usage patterns. Required diagnostics are distinct from the Feedback Hub workflow, which is user initiated.
Optional diagnostic data expands the scope. Microsoft says it can include more detailed device health information, application usage, enhanced error reporting, and—in relevant circumstances—websites a user browses. The company’s Edge policy documentation is even more specific: when Edge optional diagnostics are enabled, visited URLs and per-page usage can be reported to Microsoft. Administrators can disable that URL-reporting policy, but it applies only when optional browser diagnostics are in use.
The Stokes filing does not disclose the exact Windows component or telemetry pathway that provided the browsing records cited by investigators. Tom’s Hardware likewise noted that the complaint does not identify the specific collection mechanism. It would be wrong to claim the filing proves every Windows 11 machine routinely uploads every URL a user visits.
But it is equally wrong to claim that Windows data leaves the machine only after a user manually opens Feedback Hub and submits a report. Microsoft documents automatic diagnostic collection, recognizes that diagnostic events carry device identifiers and correlation values, and documents optional browsing-related collection under defined conditions.
A VPN changes network attribution, not Microsoft’s view of a device
The practical lesson from the court record is not that a VPN is useless. A VPN can still conceal a user’s public IP address from websites and network observers, subject to its own privacy and logging practices. It does not promise anonymity from services where the user signs in, uses a persistent identifier, or voluntarily sends application telemetry.A persistent Windows installation identity can make a sequence of otherwise separate events easier to associate inside Microsoft’s systems. If the same GDID appears when a device uses a home connection, a hotel network, a VPN endpoint, a Microsoft account, a service login, or optional browser diagnostics, Microsoft may be able to relate those records. Law enforcement access is a separate legal process, but the technical correlation happens because the platform maintains continuity.
For enterprise IT, this is familiar territory. Device identifiers are useful for update compliance, anti-fraud controls, software entitlements, security investigations, Intune administration, and account protection. The operational value is real. A managed fleet cannot be serviced reliably if every client becomes anonymous after an update or a network change.
The consumer privacy issue is that a device-management identifier can also function as a correlation key outside the administrator’s view. Microsoft’s public material has concentrated on the usefulness of diagnostic data and connected experiences while offering very little explanation of the particular identity layer that makes cross-service correlation possible.
What Windows 11 users and administrators can actually control
There is no supported, documented GDID switch in Windows 11 Privacy & security settings. Removing random services, registry values, or identity files based on scripts circulating online is a poor substitute for a vendor-supported control; it can break Microsoft Store, account sign-in, Xbox, sync, update delivery, or other connected features without establishing what data has stopped flowing.The controls that do exist are narrower but meaningful:
- Set Windows diagnostic data to Required rather than Optional where policy and product requirements allow it.
- Review Microsoft Edge diagnostic settings and, in managed environments, use the
UrlDiagnosticDataEnabledpolicy to disable URL reporting in optional Edge diagnostics. - Turn off optional connected experiences that a device or organization does not need, recognizing that this does not disable all required service data.
- Use Diagnostic Data Viewer to inspect the diagnostic events Windows makes visible locally, while recognizing that it is not a complete inventory of every Microsoft service interaction.
- Treat a VPN as network privacy tooling, not as a mechanism that prevents Microsoft-connected software from recognizing a signed-in or persistently identified Windows installation.
Microsoft’s larger problem is transparency. It has now been publicly established that Windows installations have a durable global identifier that can bridge Microsoft records across services, yet the company still has not published the plain-language technical documentation, retention details, service map, and user controls that such an identifier warrants.
References
- Primary source: TechPowerUp
Published: 2026-08-03T16:22:41+00:00
Loading…
www.techpowerup.com - Related coverage: learn.microsoft.com
Win32CompatibilityAppraiser CSP | Microsoft Learn
Learn how the Win32CompatibilityAppraiser configuration service provider enables the IT admin to query the current status of the Appraiser and UTC telemetry health.learn.microsoft.com - Related coverage: learn.microsoft.com
Troubleshooting WNS push notifications - Windows apps | Microsoft Learn
How to troubleshoot common errors with push notificationslearn.microsoft.com - Related coverage: support.microsoft.com
August 26, 2025—KB5064080 (OS Build 22631.5840) Preview | Microsoft Support
August 26, 2025—KB5064080 (OS Build 22631.5840) Previewsupport.microsoft.com - Related coverage: pcworld.com
Microsoft VP hints at ending Windows 11's Microsoft Account requirement | PCWorld
A Microsoft VP says he's "working on" removing the mandatory Microsoft account requirement in Windows 11, a truly controversial "feature."www.pcworld.com - Related coverage: community.bitdefender.com
Offical Windows 10 support?? - Expert Community
Last i heard BD free still dont support windows 10 official and is randomly cause people bsod and other issue is this still the case?? and if does, does free verison have exclude functions on real time scans and manual scans? I Looking to replace Avast free cause ever since windows 10 th2 avast...community.bitdefender.com - Related coverage: support.mozilla.org
- Related coverage: windowsreport.com
Windows GDID Raises Privacy Concerns Over Persistent Device Tracking
Microsoft’s persistent Windows GDID can identify an installation across networks, raising questions about privacy, consent, and user control.
windowsreport.com
- Related coverage: support.microsoft.com
July 14, 2026—KB5101649 (OS Build 28000.2525) | Microsoft Support
July 14, 2026—KB5101649 (OS Build 28000.2525)support.microsoft.com - Related coverage: keelcrux.com
Windows GDID: Microsoft confirms an unremovable hardware identifier | KEEL CRUX
A Microsoft confirmation, revealed in an FBI court case, describes a persistent machine identifier across reinstallations and without opt-out. The political surwww.keelcrux.com
- Related coverage: windowsforum.com
Windows GDID: Why a VPN Cannot Hide Persistent Device Tracking | Windows Forum
Microsoft’s Windows operating system uses a persistent Global Device Identifier, or GDID, that can distinguish one Windows installation from another across...windowsforum.com - Related coverage: zerotracelab.com
GDID: The Windows Global Device Identifier · ZeroTrace Lab
Where the Windows Global Device Identifier lives, how Microsoft issues it, how it is used to track installs across services, and how far you can actually patch it.www.zerotracelab.com - Related coverage: pchardwarepro.com
What is Windows GDID and how does it affect your privacy?
Discover what Windows GDID is, the persistent tracker the FBI used to locate hackers. Learn how it works and how to limit its reach!www.pchardwarepro.com - Related coverage: neowin.net
Microsoft tracks every Windows PC through a secret key, here's everything you need to know - Neowin
Have you heard of GDID? It's a special identifier that Microsoft uses to track your Windows PC. Learn more about it.www.neowin.net
- Related coverage: xela.au
Full Writeup of the Windows GDID · Xela
Article URL: Comments URL: Points: 11 # Comments: 5www.xela.au
- Related coverage: modemguides.com
The Microsoft Tracker Your VPN Can't Hide URL Slug: windows-gdid-tracking-vpn
Microsoft's GDID tracked a hacker through every VPN he used. What the Windows identifier is, what it records, and how to limit it at the network level.
www.modemguides.com
- Related coverage: cipheryou.com
Windows GDID: How Microsoft Can Track You Even Behind a VPN | CipherYou Blog
Windows GDID is a unique device identifier that can link your physical device to your online activity, even when you use a VPN. Learn how it works, why it matters for privacy, and what you can do about it.
cipheryou.com
- Related coverage: cdn-dynmedia-1.microsoft.com
- Related coverage: cdn-dynmedia-1.microsoft.com
- Related coverage: tomshardware.com
Arrest and extradition of Scattered Spider hacker shines light on how Windows telemetry GDIDs can identify and track users — Microsoft device identifier is just one digital fingerprint in a software world rife with them | Tom's Hardware
A harsh lesson on Windows telemetry, protecting online anonymity, and misinformation about defensive measures.www.tomshardware.com - Related coverage: tomshardware.com
Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI — 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group | Tom's Hardware
DOJ claims the group stole over $100 million across various attacks.www.tomshardware.com - Related coverage: pcgamer.com
An alleged member of a hacking group was caught, thanks to one hated Windows feature | PC Gamer
Good news and bad news then?www.pcgamer.com - Related coverage: bleepingcomputer.com
Microsoft rejects critical Azure vulnerability report, no CVE issued
A security researcher claims Microsoft quietly fixed an Azure Backup for AKS vulnerability after rejecting his report, and without issuing a CVE. Microsoft disputes the claim, telling BleepingComputer the behavior was expected and thatwww.bleepingcomputer.com
- Related coverage: techradar.com
Microsoft denies Chinese hackers could have cracked its cloud services too | TechRadar
Claims of Azure cloud hacks are unfounded, Microsoft sayswww.techradar.com - Related coverage: azure.status.microsoft
Azure status history | Microsoft Azure
Check the status history of Microsoft Azure services here.azure.status.microsoft
- Related coverage: bleepingcomputer.com
- Related coverage: windowscentral.com
"An insanely myopic move": Microsoft backs off legal threats against Windows security researchers after BitLocker backlash | Windows Central
Microsoft says it no longer intends to pursue legal action against security researchers who conduct or publish their findings.www.windowscentral.com - Related coverage: thehackernews.com
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
Microsoft disrupted Fox Tempest’s MSaaS using 72-hour certificates, cutting signed malware delivery worldwide.thehackernews.com
- Related coverage: appliedantitrust.com
- Related coverage: appliedantitrust.com
Microsoft Word - FTC v. Microsft-Activision - CA9 Motion for Stay Pending Appeal (Draft 2023-07-13 2100)
PDF documentappliedantitrust.com
- Related coverage: techcommunity.microsoft.com
- Related coverage: learn-attachment.microsoft.com