Microsoft has confirmed that Windows devices are assigned a Global Device Identifier (GDID), a persistent identifier that uniquely identifies a Windows installation across certain Microsoft services. The revelation has sparked widespread privacy discussions after court documents showed the identifier played a key role in helping investigators trace the activities of an alleged cybercriminal despite the use of VPN services.
Privacy advocates are now questioning why the identifier cannot be disabled through standard Windows settings.

What Is The Global Device ID?
The Global Device Identifier (GDID) is a unique identifier assigned to a Windows installation when a device is set up or registered. According to Microsoft, it is designed to identify a Windows installation across specific Microsoft services and scenarios.
The identifier generally remains unchanged through regular Windows updates but changes after a clean reinstallation of the operating system, creating a new GDID for the fresh installation.
Why It Has Triggered Privacy Concerns
The issue came to public attention after legal documents revealed that Microsoft’s records linked a suspect’s online activities to a specific GDID. Investigators reportedly used the identifier, together with other evidence, to connect activity performed through VPNs and third-party services to a particular Windows installation.
The case has raised concerns among privacy experts because users currently have no simple option to disable or opt out of the identifier within Windows settings.
How Microsoft Says It Is Used
Microsoft describes the GDID as an internal device-level identifier used across certain Microsoft services rather than a general consumer tracking feature. The company says it helps manage device identity in various scenarios involving Windows installations.
However, security researchers argue that the existence of a persistent identifier capable of linking activity across services deserves greater transparency and clearer user controls.
Can Users Remove The Identifier?
Reports indicate that the GDID survives operating system updates but is replaced only after performing a complete Windows reinstallation. Simply modifying registry entries or changing account settings does not remove Microsoft’s server-side association with the Windows installation.
Privacy experts recommend limiting optional diagnostic data, reviewing privacy settings and using local accounts where appropriate, although these measures do not eliminate the GDID itself.
Broader Debate Around Digital Privacy
The disclosure has reignited discussions about digital privacy, operating system telemetry and how technology companies manage device identifiers. As operating systems become increasingly connected to cloud services, regulators and privacy advocates are calling for greater transparency, clearer disclosure and more user control over persistent device identifiers.
The development also highlights the ongoing challenge of balancing cybersecurity, device management and law enforcement requirements with individual privacy expectations.
Summary
Microsoft has confirmed that Windows assigns every installation a persistent Global Device Identifier (GDID) that cannot be disabled through normal settings. The identifier came into focus after it helped investigators trace an alleged cybercriminal, prompting fresh debate over user privacy, transparency and the need for greater control over device-level tracking mechanisms.
