Microsoft’s Global Device Identifier (GDID) Tracks Windows Devices Across Networks

Microsoft uses a Global Device Identifier (GDID) to uniquely identify individual Windows installations across multiple services. The identifier recently drew public attention after FBI investigators used Microsoft records linked to GDID in a cybercrime investigation.

According to a federal court filing, the GDID is a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device. Each Windows installation—whether on a physical computer or virtual machine—receives a separate identifier.

Microsoft generates the identifier on its servers and stores it locally in the Windows registry. Researchers report that the Passport identity service receives the number before the Connected Devices Platform registers it with Microsoft’s Device Directory Service.

The GDID typically remains unchanged during Windows updates and common system changes. However, a full Windows reinstall creates a new GDID, though Microsoft may retain earlier records linked to the previous identifier.

The identifier appears as a 64-bit value beginning with “g:” followed by a long number. Users can view the value stored on their computer through the Windows registry or a PowerShell command.

How GDID Connects Activity Across Microsoft Services

GDID supports several Windows and Microsoft services, including Windows activation, Microsoft Store purchases, app licensing, Phone Link, shared clipboard functions, device telemetry, and diagnostic information. Microsoft Edge can also connect enhanced diagnostic data to the identifier when users enable that setting, potentially including browser activity and browsing history.

Microsoft’s public documentation provides few details about GDID. An Azure Monitor reference describes GlobalDeviceId as “Microsoft global device identifier” used internally by the company. Microsoft has not published a separate support page explaining its creation, retention period, or full use.

Zerotrace Labs examined the system by replacing a device’s existing identifier during a controlled test. Their research found that several Windows components use GDID as part of Microsoft’s wider device identity system.

FBI Uses Microsoft GDID Records in Hacker Case

The identifier gained attention through the case against Peter Stokes, a 19-year-old dual US-Estonian citizen. US authorities accuse him of participating in a May 2025 cyberattack against a luxury jewelry retailer.

Prosecutors claim attackers posed as company employees and contacted the retailer’s help desk, convincing staff to reset account credentials and multi-factor authentication controls. The group allegedly obtained at least 77GB of data and demanded about $8 million in cryptocurrency.

According to the criminal complaint, the FBI obtained GDID records from Microsoft. Investigators said the same identifier accessed an ngrok registration page when the suspected attacker created an account and later connected to the victim’s website through the same VPN proxy.

Authorities also linked the GDID to IP addresses in Tallinn, New York, and Thailand. Travel information and social media posts reportedly placed Stokes in those locations during the relevant periods.

Stokes was arrested in Finland and later extradited to the United States. He faces charges related to conspiracy, computer intrusion, and fraud. The allegations have not been proven, and he is presumed innocent while the court case continues.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *