Thursday, October 8, 2026
AI desk
/
/
Windows 11 Has a Hidden Device Tracker VPNs Can’t Block: What Is GDID and How to Stop It

Windows 11 Has a Hidden Device Tracker VPNs Can’t Block: What Is GDID and How to Stop It

Windows 11’s Global Device Identifier persists across VPNs and IP changes. Learn what GDID is, how the FBI used it, and what Windscribe’s deGDID script
Last updated
August 9, 2026
11 min read
Fact-checked

Photo: TechJournal

Share

Quick Answer

Windows 11’s Global Device Identifier (GDID) is a persistent, server-assigned tracking code that follows your Windows installation across IP addresses, VPNs, and reboots. There is no built-in off switch. Windscribe’s free, open-source deGDID script, released July 27, 2026, can remove and block it, but doing so breaks Xbox, Outlook, the Microsoft Store, and other cloud services.

Key Takeaways

  • GDID is a 64-bit server-assigned identifier tied to your Windows installation and stored locally in the registry; it survives OS updates but resets on a full reinstall.
  • VPNs, proxy servers, and IP rotation cannot hide GDID because the identifier operates below the network layer where those tools work.
  • The identifier became publicly known after a July 2026 federal complaint showed the FBI used it to trace an alleged Scattered Spider hacker across three countries.
  • Windscribe’s open-source deGDID PowerShell script (released July 27, 2026) removes and blocks GDID, but breaks account sign-in for Xbox, Outlook, OneDrive, the Microsoft Store, Windows Hello, and passkeys.
  • Microsoft has not added a consumer-facing toggle to view, reset, or disable GDID, and has not publicly responded to the deGDID tool as of August 9, 2026.

What exactly is the Windows 11 GDID, and where did it come from?

The Windows 11 Global Device Identifier, or GDID, is a persistent, device-level identifier that Microsoft assigns to each Windows installation to uniquely identify it across services. The DOJ complaint describes GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device.” It survives OS updates but resets on a full reinstall. That reset is not a clean break, however. Reinstall Windows and a new number is assigned, but Microsoft’s own records give every reason to link the new one back to the old, through the same account, OneDrive, and activation history.

The identifier is generated externally, not on the device itself. The Microsoft Account service, wlidsvc, talks to login.live.com and receives a Device PUID back in the server’s response, and that value gets written to the registry in plain text at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties. The Connected Devices Platform, the background service that powers Phone Link and Nearby Share, reads it and registers it into Microsoft’s Device Directory Service. Delivery Optimization then reports that value back to Microsoft as UCDOStatus.GlobalDeviceId whenever a PC shares or downloads update data peer-to-peer.

For most of its existence, GDID had no consumer-facing documentation. Before this case surfaced it publicly, Microsoft had documented GDID in exactly one obscure Azure Monitor schema reference, not in any consumer-facing privacy material. Microsoft has confirmed the existence of a persistent Windows device identifier called GDID, first publicly detailed in an FBI federal complaint against an alleged hacker.

How did the FBI use GDID to track a hacker across three countries?

The GDID identifier entered public awareness through a federal criminal complaint unsealed in July 2026 in the Northern District of Illinois. Finnish police stopped a 19-year-old on an Interpol Red Notice in April 2026, and by July, US prosecutors had unsealed a federal complaint identifying him as Peter Stokes, an alleged member of the Scattered Spider hacking group, wanted over a May 2025 breach of a US luxury jewelry retailer that ended in an $8 million ransom demand.

Stokes had taken significant steps to conceal his online activity. He allegedly used VPNs, ngrok tunnels, and rotating IPs across Estonia, New York, and Thailand to cover his tracks during the breach. None of it mattered. The FBI subpoenaed Microsoft’s telemetry and found a single 64-bit string, g:6755467234350028, that followed his Windows installation everywhere, according to PCMag’s reporting on the DOJ complaint.

The mechanism that made those evasion tools irrelevant is straightforward. The GDID exists as a permanent device ID that can track activity without user consent. It works across IP addresses because it sits beneath the layer where VPNs operate, so no amount of network tunneling can obscure it. Stokes was caught because he used the same Windows device for everything, and the GDID stitched all of it back together after the fact.

Why can’t users simply turn GDID off through Windows Settings?

Windows 11 provides no built-in control for the GDID. Microsoft documents the existence of the identifier in technical and legal filings, but there is currently no built-in Windows setting that allows users to disable or regenerate it manually. Attempting to delete the registry value that stores the identifier does not solve the problem, either. Windscribe tested whether deleting the registry value that stores the identifier would remove it for good. After the deletion, a related identifier reappeared following a reboot, even with one Microsoft registration domain still blocked.

That test led Windscribe to trace identifier-related data into Credential Manager entries, ConnectedDevicesPlatform records, TokenBroker caches, WAM broker data, and matching entries inside the SYSTEM and .DEFAULT registry hives. The identifier is embedded across several distinct Windows subsystems rather than sitting in a single removable location, which is why a manual registry deletion is insufficient.

For context on how this compares to other platforms: Apple and Google at least expose user-facing resets for advertising identifiers. Windows offers nothing equivalent for GDID. This means the 3 standard mitigations available to users, described in the next section, reduce what data gets linked to GDID rather than eliminating the identifier itself.

What settings can limit GDID data collection without the deGDID script?

Three built-in Windows 11 settings reduce the amount of data tied to GDID, though none of them disable the identifier. Users who want to reduce exposure without running a third-party script should apply all 3.

  1. Use a local account instead of a Microsoft Account during setup. You cannot remove the fingerprint, but you can reduce what gets tied to it by skipping the Microsoft Account login during setup. Signing into a Microsoft Account enriches the identity graph connecting GDID to OneDrive, Outlook, Xbox, and more.
  2. Minimize diagnostic telemetry. Turn off optional diagnostic data under Settings > Privacy & security > Diagnostics & feedback. Block Advertising IDs by toggling off personalized ads and launch tracking under Privacy & security > Recommendations & offers. Note that the Settings toggle under Privacy & Security > Diagnostics & feedback only deals with the optional tier. When toggled to Off, the PC will stop sending the richer telemetry, but required diagnostic data continues to flow.
  3. Disable Activity History and Cloud Search. Disable Cloud Search by turning off Cloud Content Search from Privacy & security > Search to stop local searches from sending data to Bing. Turn off Activity History under Privacy & security; Phone Link and cloud clipboard stop working, but cross-device timeline logging drops with them.

These steps narrow the data surface that GDID connects to Microsoft services, but they do not prevent GDID from being assigned, stored, or reported. For users with a higher privacy requirement, the deGDID script described below is the more complete option, with significant trade-offs.

What is Windscribe’s deGDID script and how does it work?

VPN provider Windscribe released deGDID on July 27, 2026, a free, open-source PowerShell script that strips Microsoft’s Global Device Identifier from a Windows installation and stops the operating system from generating a new one. The company built the tool after a federal complaint unsealed July 1 in the Northern District of Illinois showed Microsoft had used the identifier to help investigators tie online activity to a single Windows machine.

The script addresses the GDID problem in 2 stages. Windscribe’s deGDID uses hosts file modifications and firewall rules to block the registration paths Windows uses to fetch a GDID, and wipes known local identity artifacts. Since the identifier is generated server-side, Windscribe notes that the tool cannot erase any historical records Microsoft may already have associated with a device. Instead, its purpose is to stop future issuance of a new GDID after the existing one has been removed.

The script operates through 3 main execution flags, which users choose based on their goal. Use .\degdid.ps1 -Status for read-only inspection, .\degdid.ps1 -Status -Redact before sharing output, and .\degdid.ps1 -Protect for the normal protection flow: block first, verify the block, wipe known local state, wait, re-inventory, then report a verdict. Reversing the change is also possible: reversing the change requires a single command, .\degdid.ps1 -Unblock, run from an elevated PowerShell prompt. That command removes only the network controls deGDID installed, after which Windows can request and receive a new GDID again.

deGDID runs on Windows 10 version 22H2 or Windows 11 build 22000 and later. Windows 11 25H2, build 26200, is the fully lab-validated version. Other accepted builds run but produce a warning. The tool deliberately refuses to run on managed, domain-joined, or corporate machines.

What are the real trade-offs of running deGDID?

Running deGDID is not a clean, consequence-free privacy fix. The most significant trade-off involves Microsoft account-linked services. Blocking Microsoft identity and device graph paths can break or degrade Microsoft features like account sign-in flows, Microsoft Store, Xbox, OneDrive, device sync, passkeys, and Windows Hello sign-in tied to a Microsoft account. Users who rely on any of those services for work, gaming, or productivity should weigh that cost carefully before running the protection command.

The script also carries uncertainty about its completeness. Windscribe’s own research and testing may not have found every instance of the GDID system, and the tool may not block them all. It does not erase records Microsoft already holds or make the user anonymous. Windscribe’s disclaimer describes the script as experimental and states that running it is done at the user’s own risk.

Windscribe says deGDID is a research project, and it will continue to evolve as more information about how GDID works is uncovered. Microsoft has so far provided no comment on the release of the program or the criticism over the inability to disable the identifier in Windows. Back up your system before running the script. The combination of firewall rule changes, hosts file modifications, and registry edits means a failed or interrupted run could require a manual reversal using the -Unblock flag, and anyone unfamiliar with elevated PowerShell should stop and consult a technically experienced person before proceeding.

How to run deGDID safely, step by step

Before running deGDID, back up your PC using Windows Backup or a full system image. The script modifies the Windows hosts file, firewall rules, and multiple registry hives. A backup ensures you can restore to a working state if anything goes wrong. Do not run deGDID on a work PC, a domain-joined machine, or any device managed by an organization’s IT department. The tool refuses managed, domain-joined, Entra-joined, MDM-enrolled, or ambiguous multi-profile systems.

  1. Open a browser and navigate to the deGDID repository on GitHub under Windscribe CEO Yegor Sak’s account (github.com/yegors/deGDID). Download the degdid.ps1 file.
  2. Right-click the downloaded file, select Properties, and check whether Windows has flagged it with a security block. If so, check the Unblock box and click OK before continuing. If Windows marks the downloaded script as Internet-origin, inspect it and remove that file marker once.
  3. Open the Start menu, search for PowerShell, right-click the result, and select Run as administrator.
  4. Navigate to the folder where you saved degdid.ps1 using the cd command. For example: cd C:\Users\YourName\Downloads
  5. Run a read-only status check first: .\degdid.ps1 -Status. Review the output to confirm a real GDID is present before making any changes.
  6. Run .\degdid.ps1 -Protect to apply the full block, verify the block, and wipe known local GDID state. The script backs up what it touches and supports undo using .\degdid.ps1 -Unprotect.
  7. Confirm the final output reads ProtectedNoRealGdid, which is the only complete canonical success result.

Stop and do not proceed if the script reports an UnsupportedEnvironment error. That result means the tool has detected a configuration it cannot safely modify, such as a corporate enrollment or an ambiguous account profile. Contact a technically experienced person or your IT support team in that situation.

GDID Mitigation Options: Comparison of Available Approaches
ApproachWhat It DoesWhat It Does Not DoService ImpactBest For
Use a local account (no Microsoft Account)Reduces data linked to GDID; limits identity graph enrichmentDoes not remove or block GDID generationLoses OneDrive, Xbox, Outlook, Microsoft Store sign-inUsers setting up a new PC who want minimal Microsoft account linkage
Disable optional diagnostic data in SettingsStops richer telemetry from being sent; disables optional data tierRequired diagnostic data still flows; GDID still reported via Delivery OptimizationNo significant service lossAll users as a baseline privacy step
Disable Activity History and Cloud SearchStops cross-device timeline logging and Bing data from local searchesDoes not remove or block GDIDPhone Link and cloud clipboard stop workingUsers who do not use Microsoft cross-device features
Windscribe deGDID script (-Protect)Removes GDID from known local locations; blocks future GDID issuance via firewall and hosts rulesCannot erase records already on Microsoft’s servers; may not catch every GDID pathwayBreaks Xbox, Outlook, Microsoft Store, OneDrive, Windows Hello, and passkeysPrivacy-focused users comfortable losing Microsoft cloud service access
VPN or proxyHides public IP address from websites and some servicesCannot block GDID; identifier operates below the network layerNone for Microsoft servicesIP-level privacy only; ineffective against OS-level identifiers

FAQ

Does GDID affect Windows 10 users, or only Windows 11?

GDID affects both Windows 10 and Windows 11 users. The deGDID script runs on Windows 10 version 22H2 or Windows 11 build 22000 and later, which indicates the identifier is present across both versions. The Global Device Identifier is a persistent key tied to every Windows installation, whether it is a physical PC or a virtual machine.

Is running the deGDID script safe?

Running deGDID carries real risk, and Windscribe is explicit about this. Running the script can break Microsoft account features. Use it at your own risk, on systems you are authorized to modify. Neither Windscribe nor Yegor Sak is liable for any damage or loss that results. Back up your system before running the protection command, and review the source code before executing it.

Does a fresh Windows reinstall remove GDID permanently?

A fresh reinstall resets the GDID, but does not remove it permanently. The only way to clear the existing GDID is a fresh Windows install, but that install receives its own new GDID, and Microsoft can still tie it to the existing machine because the hardware will not have changed. Signing back into the same Microsoft Account re-links the new identifier to the old device history.

Can running deGDID break Windows Update or Windows Defender?

Windows Update and Windows Defender should continue working after running deGDID. Testing on a Windows 11 machine confirmed a loss of sign-in access to Xbox, Outlook, and the Microsoft Store after running the script. Core desktop functions kept working in that same test, and Windscribe reported that Windows Update scans and Windows Defender signature updates also continued working during its own lab testing. That said, Windscribe labels deGDID as experimental, so edge cases are possible.

Has Microsoft responded to the GDID privacy concerns or announced a fix?

Microsoft has not responded publicly to the GDID privacy debate or announced a consumer-facing control. As of this report, Microsoft has not issued a public response to deGDID and has not said whether it plans to add a setting that lets users view, reset, or disable their GDID. The company confirmed the identifier’s existence in legal filings but has not changed its consumer privacy documentation to address the gap.

For more context on Windows 11 update behavior and privacy settings, see Installed the Windows 11 Update but Don’t See the New Features? Here’s Why and Windows 11 August 2026 Update (KB5101684): New Features and How to Get It. For related coverage on OS-level data practices and security risks, see Is Microsoft Secretly Installing a Facial-Recognition Photos App on Your Windows 11 PC?, The Fake CAPTCHA Scam: How ‘Verify You’re Human’ Installs Malware, and How to Uninstall a Windows 11 Update and Roll Back a Bad One.

Share this guide
Facebook
X
LinkedIn
Written by
Alex Morgan is a technology writer and IT support specialist with 8+ years of experience helping people solve everyday tech problems. He specializes in Windows troubleshooting, PC optimization, and hardware guides. When he’s not debugging Windows errors, he’s testing the latest gadgets.

In this article

The AI Brief

Guides like this, every Friday.

One email. No hype cycle.

Keep reading