A suspect hops between countries, routes traffic through VPNs, and switches IPs like burner phones. Still caught — not because the VPN failed, but because Windows itself was the informant. Court filings in the Scattered Spider hacking case reveal Microsoft provided the FBI with a complete IP history tied to something called a Global Device ID, according to reporting by Security Online and WindowsLatest. That GDID mapped the device’s movements across jurisdictions, VPN sessions included. Millions of Windows users run VPNs believing they’re invisible to Microsoft. Based on what those filings show, that assumption needs revisiting — especially for anyone who has read about apps secretly tracking users at the OS and application level.
What GDID Actually Is (And Why You Can’t Delete It)
This persistent identifier is assigned at installation, bound server-side to your hardware and TPM certificate, and survives every workaround short of a full drive wipe.
GDID is a 64-bit identifier assigned when you install Windows. It’s stored locally in the user registry, but the real binding lives on Microsoft’s servers — tied to hardware descriptors and a TPM-backed device certificate, according to technical analysis by ZeroTraceLab. Editing the local registry value is like scratching a VIN off your dashboard while the DMV still has your records on file. No user-facing toggle fully disables it.
Here’s what that means practically:
- GDID persists across OS updates and account changes until a complete drive wipe and clean reinstall
- Microsoft logs VPN exit IPs alongside your GDID, linking sessions from different countries to one device
- Signed-in Microsoft services — OneDrive, Edge sync, Outlook, Bing — amplify the linkage by pairing account data with device identity
- Even setting diagnostic data to minimum does not remove the identifier
Your VPN Still Works – Just Not Against Microsoft
The claim that GDID “negates any value” of a VPN is overstated, but the specific failure point matters enormously depending on your threat model.
A VPN still encrypts traffic from ISPs and sketchy coffee-shop networks. It still masks your IP from third-party websites that have no access to Microsoft’s device logs. The breakdown is specific but significant: if your threat model includes Microsoft — or anyone with legal access to Microsoft’s telemetry — a VPN alone cannot protect you. As privacy researchers have noted, “A VPN does not stop telemetry or data collection by operating systems, apps, or websites.” The Scattered Spider case is the proof of concept, and a surveillance app built to target users across borders illustrates just how layered these tracking architectures can become.
Damage Control Options
You can limit what gets transmitted, but fully neutralizing GDID on Windows requires either serious hardening or switching platforms entirely.
Advanced users can reduce exposure:
- Set Diagnostic data to minimum via Group Policy
- Disable the DiagTrack (Connected User Experiences and Telemetry) service
- Turn off Activity history syncing and the Advertising ID
- Use tools like Wireshark or Pi-hole to audit outbound telemetry traffic
For high-stakes privacy scenarios, a Windows privacy analyst cited in technical reporting on the GDID case put it plainly: “If you genuinely need privacy, do it on an operating system that isn’t built to phone home.” Linux remains the most cited alternative in that context. Readers evaluating their broader exposure may also want to consider physical security systems that experts recommend as part of a layered privacy and protection strategy.
VPNs aren’t broken. They’re solving a different problem than most people assume. GDID is the serial number stamped into the chassis — your VPN only swaps the license plate.





























