In the case of the alleged hacker, he had used the same device for all his online activities, so even if his identity was hidden through other means, Microsoft was able to tie all those activities together. When Microsoft was able to spot patterns in behavior that matched those of a particular GDID it held on account, it was able to coordinate with authorities to tie the activities to the hacker in question, giving up his identity and leading to his eventual arrest and charges brought against him.
This has raised concerns among privacy advocates about Microsoft not providing an opt-out option for this level of tracking.
From Google/AI (the usual caveats about AI info apply):
The Windows Global Device ID (GDID) is a persistent, permanent digital identifier assigned to a Windows installation. It was introduced with the initial release of Windows 10 in 2015 as part of Microsoft's core telemetry infrastructure.
The GDID gained intense public attention in July 2026 after a leaked FBI criminal complaint revealed that Microsoft provided a suspect's GDID and associated IP log history to law enforcement, bypassing the anonymity of a VPN.
What is the GDID used for?
Microsoft utilizes the identifier for several internal operating system and cloud-related functionalities:
Licensing & Activations: It binds a specific Windows license to a precise machine configuration, ensuring compliance with activation rules.
Core App Management: It manages application state and installations through the Microsoft Store and Universal Windows Platform (UWP).
System Optimization: The wlidsvc (Windows Live ID) service requests a Device PUID from Microsoft login servers, which the Connected Devices Platform registers. Services like Delivery Optimization report this ID back when sharing or downloading Windows updates.
Telemetry & Tracking: It links a massive pipeline of user data—such as web browsing habits, search history, error logs, and app usage—to a singular identity, tracking your device across different networks.
Where is it located, and can you turn it off?
The identifier cannot be turned off or disabled through normal Windows privacy settings, as doing so would break core OS functions like app downloads and software activation.
Registry Location: You can find your specific identifier stored locally on your PC under HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties (formatted with a lowercase "g" prefix followed by a decimal number).
Persistence: The GDID survives basic Windows updates, browser resets, and account modifications. It does not survive a complete, clean wipe and reinstallation of the operating system, which forces the creation of a brand new GDID (though Microsoft maintains logs of the historical ID).
I’m going to try to verify the Google/AI info and report back here.
Is this part of Win 10 as well?
This is another reason why Microsoft requires that you have a Microsoft Account for your Windows computer.
They tie your computer's Windows GDID to your Microsoft Account, and this ties to YOU as an individual.
Everything you do with your computer, regardless of VPN, IP anonymizing, etc. is directly traceable to you.
Of course, if you're not doing anything bad (*), there's no need to be concerned. Right? /s
(*) Bad: Counter to the approved narrative.
This jibes with what a MS employee relative told me about ten years ago. At the time, I didn’t believe him. I do now.
Wondering if this is true of Windows running on a Linux VirtualBox.
MSFT, GOOG, META should all have been broken up years ago.
I am currently in the process of getting rid of Outlook in order to create more room in the VM which is crowding my GPU (an RTX 3050) for running PowerPoint on a VM. Ran Outlook 2007 for a very long time, but had to install Outlook Classic as part of the conversion to Ubuntu running a virtual machine. So far, only about 50% of the backup emails I kept have run successfully through readpst (a mere 350,000 files over 20 years). Got them translated to eml. The Import to Thunderbird bombed about 3/4 of the way through. So I’m down to drag and drop a folder at a time. It’s awful.
I have probably 3,500pp of published PDFs from PowerPoint and another 2,000 from Word which I MUST maintain and update upon occasion. Those are published in pdf. The Master PDF Editor is the best I’ve found in Linux, but they aren’t up to the editorial needs I have. I have been in contact with their development people and they’re looking into how it is I accomplish revisions in 100pp+ PowerPoint files containing links on every page. In Acrobat it’s a simple swap of a “printed” file under the links of a whole chapter in one operation. I’m so sick of Adobe screwing me for 15yo software I’d already bought I’m ready to dive into the morass anyway.
LibreOffice Impress is just not there yet in terms of graphical quality. So far, it looks like LibreOffice Writer may be sufficient to replace Word (haven’t tested their footnoting). Nor does it record video. I have three 120pp PowerPoint presentations yet to record with the soundtrack from Audacity in Ubuntu to be integrated in Kdenlive. PowerPoint’s recording capability sucks, big time.
Indian scammers now work for Microsoft
So MS decided the MAC wasn’t cool enough and made their own.
I hope Rufus the burning software is working on it ,you can turn a lot of Microsoft’s crap off now but if you try to download a new window ISO using a computer with a Rufus burned windows ISO it stops you , LOL
bookmark
To paraphrase Ninotchka, their type will soon be extinct. Organizations have lifespans and MS is arriving at its natural end.
When non-techy people (like me) start transitioning to Linux, you know the big guy has become utterly insufferable.
Reinstall Windows and Use a Local Account
Never sign into a Microsoft Account (MSA).
Disable wlidsvc and DiagTrack
Turn Off Advertising ID
Block Microsoft Servers via Hosts File or DNSPrevent
//microsoft.com://microsoft.com://live.com
This little tid bit of knowledge should hasten everyone’s exit to Linux.
I wonder if Windows 11 also uses the Endorsement Key (EK) burned into the TPM chip; Win11 requires TPM.
As explained in “https://en.wikipedia.org/wiki/Trusted_Platform_Module“:
“Computer programs can use a TPM for the authentication of hardware devices, since each TPM chip has a unique and secret Endorsement Key (EK) burned in as it is produced.”
It sounds like the EK is read-only, and thus would require changing the hardware — perhaps the entire CPU — to change it.
What happens if I delete the registry key?
Well it’s a good thing I’ve been using Linux for over 2 years now.