< Back to all clusters
[TECHNOLOGY] · United States · 6 sources

Microsoft's Global Device ID and TPM‑Based Activation Raise Privacy and Security Concerns

Microsoft has confirmed that Windows installs include a permanent Global Device Identifier (GDID), a 64‑bit value that uniquely tags each operating‑system instance. The identifier is generated on Microsoft’s servers, stored in the registry at HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties, and persists across system updates, changing only when Windows is reinstalled. The FBI obtained GDID data from Microsoft to link a 19‑year‑old suspect involved with the Scattered Spider hacking group to multiple attacks, highlighting the identifier’s use in law‑enforcement investigations. Microsoft estimates roughly 1.6 billion Windows PCs worldwide carry the GDID, prompting privacy‑rights debates.

Separately, Microsoft announced a new “KMS Hardware‑Secured” feature for enterprise activation. The update requires Key Management Service (KMS) hosts to prove their hardware integrity using a Trusted Platform Module (TPM) before issuing mass activations. The TPM‑based attestation will be introduced with Windows Server 2025, with readiness messaging starting in August 2026, and will eventually become mandatory. This shift moves activation verification from purely software checks to a hardware‑rooted trust model, aiming to curb piracy and strengthen corporate security.

Entities: Federal Bureau of Investigation (FBI) · Global Device Identifier (GDID) · Key Management Service (KMS) · Microsoft Corporation · Trusted Platform Module (TPM)

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] Approximately 1.6 billion Windows PCs are affected by GDID. (Microsoft estimate)
  • [● 2 SOURCES] GDID is stored in the Windows registry under HKCU → SOFTWARE → Microsoft → IdentityCRL → ExtendedProperties. (Microsoft documentation)
  • [● 2 SOURCES] The FBI obtained GDID data from Microsoft to link a suspect to a hack by the Scattered Spider group. (FBI / court documents)
  • [● 2 SOURCES] The new KMS requirement shifts activation verification from software checks to a hardware‑rooted trust model. (Microsoft description)
  • [● 2 SOURCES] TPM‑based attestation for KMS will be introduced with Windows Server 2025, with readiness messaging starting August 2026. (Microsoft roadmap)
  • [● 2 SOURCES] GDID persists across Windows updates and changes only when the operating system is reinstalled. (Microsoft statements)
  • [● 2 SOURCES] Microsoft implements a Global Device Identifier (GDID) that uniquely identifies each Windows installation. (Microsoft)
  • [● 2 SOURCES] Microsoft announced KMS Hardware‑Secured, requiring TPM attestation for enterprise Windows activation. (Microsoft press release)