

A federal court filing has revealed new details about a Windows identifier that Microsoft uses to recognize individual operating system installations. The identifier, known as the Global Device Identifier or GDID, appears across several Microsoft services.
Microsoft has provided little public information about the system. However, court records and independent research show that GDID can connect activity from one Windows installation across different networks, locations, and Microsoft products.
The identifier recently became public after US investigators used Microsoft records in a criminal case linked to the Scattered Spider hacking group. The case showed how GDID data can support an investigation even when a user relies on VPNs, proxy servers, and several online identities.
Microsoft describes GDID as ‘a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device.’ Each Windows installation receives a separate identifier, including installations on physical computers and virtual machines.
Microsoft generates the identifier on its servers. Windows then stores it locally in the system registry. Researchers say the Passport identity service receives the number before the Connected Devices Platform registers it with Microsoft’s Device Directory Service.
The identifier usually stays unchanged during Windows updates and common system changes. A full Windows reinstall creates a new GDID. However, Microsoft may retain earlier records connected to the previous identifier.
GDID appears as a 64-bit value beginning with “g:” followed by a long number. Users can view the value stored on their computer through the Windows registry or a PowerShell command.
GDID supports several Windows and Microsoft services. Researchers have linked it to Windows activation, Microsoft Store purchases, app licensing, Phone Link, shared clipboard functions, device telemetry, and diagnostic information.
Microsoft Edge can also connect enhanced diagnostic data to the identifier when users enable that setting. Such data may include browser activity and browsing history sent to Microsoft under the selected diagnostic options.
Microsoft’s public documentation gives few details about GDID. An Azure Monitor reference describes GlobalDeviceId as ‘Microsoft global device identifier’ used internally by the company. Microsoft has not published a separate support page explaining its creation, retention period, or full use.
Zerotrace Labs examined the system by replacing a device’s existing identifier during a controlled test. Its research found that several Windows components use GDID as part of Microsoft’s wider device identity system.
The identifier gained attention through the case against Peter Stokes, a 19-year-old dual US-Estonian citizen. US authorities accuse him of taking part in a May 2025 cyberattack against a luxury jewellery retailer.
Prosecutors claim attackers posed as company employees and contacted the retailer’s help desk. They allegedly convinced staff to reset account credentials and multi-factor authentication controls. The group later obtained at least 77GB of data and demanded about $8 million in cryptocurrency.
According to the criminal complaint, the FBI obtained GDID records from Microsoft. Investigators said the same identifier accessed an ngrok registration page when the suspected attacker created an account. It later connected to the victim’s website through the same VPN proxy.
Authorities also linked the GDID to IP addresses in Tallinn, New York, and Thailand. Travel information and social media posts reportedly placed Stokes in those locations during the relevant periods.
Stokes was arrested in Finland and later extradited to the United States. He faces charges related to conspiracy, computer intrusion, and fraud. The allegations have not been proven, and he is presumed innocent while the court case continues.