Microsoft Court Filing Reveals Windows Has a Device ID That Can Follow a PC Across Services
A court filing details how Microsoft linked a Windows installation through its Global Device ID.

A little-known Windows identifier that can uniquely follow a PC across Microsoft services has come under renewed scrutiny after a US court filing revealed it helped investigators trace an alleged member of the Scattered Spider cybercrime group, raising fresh questions about privacy and device tracking.
The identifier, known as the Global Device ID (GDID), surfaced in Microsoft's complaint against the suspected hacker, where the company described it as 'a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device ... across certain Microsoft services and scenarios.'
Researchers say the identifier cannot be fully disabled through Windows settings, although Microsoft has not described it as a consumer tracking feature.
Court Filing Brings Windows Identifier Into Public View
The Global Device ID attracted attention after Microsoft's legal complaint explained how the company linked activity associated with an alleged Scattered Spider member to a specific Windows installation.
According to the filing, the GDID is assigned to a Windows installation and is designed to persist across Microsoft's ecosystem, allowing the company to distinguish one Windows installation from another across supported services.
The identifier became a focus of discussion after reports said Microsoft used historical records associated with the GDID to assist investigators examining the suspect's online activity.
The complaint did not suggest the identifier bypasses encryption or virtual private networks, nor did it describe the technology as a mechanism for monitoring everything users do on their PCs.
Researchers Say Users Cannot Fully Disable GDID
Privacy researchers examining Windows said the identifier is generated during Windows setup and stored locally while remaining associated with Microsoft's backend systems.
According to Windows Latest, users can reduce some diagnostic data collected by Windows but cannot completely disable the Global Device ID through standard Windows settings.
ZeroTraceLab, which analysed the feature after the court filing became public, said modifying or deleting the locally stored identifier does not necessarily remove Microsoft's server-side association with the Windows installation.
The researchers said reinstalling Windows generates a new GDID, although previous identifiers may still remain associated with historical Microsoft records.
Different From Windows' Advertising ID
Researchers noted that the Global Device ID should not be confused with Windows' advertising identifier, which users can disable through privacy settings.
Instead, GDID appears to function as a persistent installation identifier used internally across Microsoft services.
Microsoft has not published detailed consumer documentation explaining every scenario in which the identifier is used.
The company has not indicated that GDID is used for targeted advertising.
Security Experts Say Context Matters
The disclosure has prompted debate among privacy researchers because the identifier reportedly allowed investigators to associate activity across multiple Microsoft services with a single Windows installation.
However, researchers also cautioned against interpreting the court filing as evidence that Microsoft can track all user activity regardless of security tools.
Virtual private networks continue to conceal users' IP addresses from internet service providers and websites. The discussion surrounding GDID instead centres on Microsoft's ability to recognise a Windows installation within its own ecosystem.
Microsoft Has Not Announced Any Changes
Microsoft has not announced plans to remove or make the identifier optional following publication of the court filing.
The company has also not characterised GDID as a newly introduced feature, suggesting it has existed within Windows before attracting public attention through the legal proceedings.
The disclosure nevertheless marks one of the clearest public acknowledgements of how Microsoft identifies Windows installations across its services, prompting renewed discussion among cybersecurity researchers and privacy advocates over how persistent device identifiers should be disclosed to users.
As of publication, Microsoft had not issued additional public guidance addressing questions raised after the court filing, beyond the description contained in the legal complaint.
© Copyright IBTimes 2025. All rights reserved.

























