Skip to content
Global Device Identifier: How Microsoft tracks your behaviour

Global Device Identifier: How Microsoft tracks your behaviour

Computing July 24, 2026

A US court filing has revealed an obscure Windows tool tracking user behaviour around Microsoft services including Edge, clipboard and the app store.

The Global Device Identifier (GDID) is a persistent key tied to every Windows installation since Vista, whether it’s a physical PC or virtual machine. The only way to clear it is a fresh Windows install – but that install will gets its own GDID, and Microsoft can still tie it to your existing machine because the hardware won’t have changed.

Microsoft says the GDID is “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device,” which sounds harmless enough. But independent researchers have worked out that Windows installs aren’t the only thing being tracked.

Because Microsoft has not publicised any information GDID (short of a single-line reference in the Azure Monitor reference table ), Zerotrace Labs reverse-engineered it.

The GDID is generated externally, on Microsoft’s servers, and stored locally in the registry. Windows’ Connected Devices Platform then registers it in Microsoft's Device Directory Service.

The key is embedded into many Windows services. Not just Windows activation but your diagnostic data; Edge’s enhanced diagnostics (if switched on), which includes your browsing history; purchases, licenses and installs on the Microsoft Store; device telemetry; and more.

Back in May 2025, the Scattered Spider hacking group breached a jewellery retailer via social engineering. They posed as employees, called the company’s helpdesk and managed to access internal systems. They then stole at least 77GB of data and demanded $8 million in cryptocurrency as a ransom.

The FBI traced the attack to at least one individual - a 19-year-old dual US-Estonian citizen called Peter Stokes – using GDID.

The FBI obtained Stokes’ GDID from Microsoft, whose records showed it connected to a signup page for developer infrastructure platform ngrok at the same time the attacker created their ngrok account. The GDID reached the victim's site a few hours later, through the same VPN proxy.

The same GDID was linked to IP addresses in Tallinn, New York, and Thailand at the same time Stokes was visiting those places.

Stokes was arrested in April this year and extradited to the USA from Finland. Details GDID were first revealed in the FBI’s criminal complaint against him this month.

While GDID did help to catch the alleged attacker, and is far from the only OS-level tracking mechanism, the lack of transparency around it has drawn complaints from both security experts and Windows users.

Extracted Entities

Attack Types (1)

Tools (1)