{
  "id": 216341,
  "title": "VPN provider built a script to block Microsoft's hidden GDID tracking on Windows — Windscribe's \"deGDID\" erases existing identifiers and blocks new ones from being created",
  "url": "https://urgent.news/2026/08/06/vpn-provider-built-a-script-to-block-microsofts-hidden-gdid-tracking",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-06T10:30:00.000Z",
  "source": {
    "name": "Tom's Hardware",
    "slug": "tom-s-hardware",
    "url": "https://www.tomshardware.com/software/windows/vpn-provider-windscribe-has-built-a-script-to-block-microsofts-persistent-gdid-tracking-on-windows-degdid-erases-existing-identifiers-and-blocks-new-ones-from-being-created"
  },
  "original_language": "en",
  "account": "Windscribe, a VPN provider, has developed an open-source script named \"deGDID\" to combat Microsoft's persistent Global Device Identifier (GDID) on Windows operating systems. This identifier, which is built into Windows, has raised concerns over its invasive tracking capabilities, even though it was initially introduced for a positive purpose.\n\nThe deGDID script, which can be accessed on GitHub, is designed to remove existing GDID keys from your PC. However, it comes at the cost of disrupting some Microsoft cloud services. The script can be executed via PowerShell with administrative privileges, offering three main flags: –Status to check if a GDID is active, –Status –Redact to generate logs with the GDID redacted for diagnostic purposes, and –Protect to completely erase the GDID and prevent the creation of new ones. A fourth flag, –Unprotect, allows users to revert to the default state if needed.\n\nThe –Protect flag is the most significant feature of the script, as it identifies and removes server-issued GDID keys from the registry, modifies ACLs and registry permissions to block the OS from retrieving new GDID keys, and sets up a firewall to prevent Microsoft identity services from recognizing the PC. This approach effectively eliminates existing GDIDs and prevents the generation of new ones. However, it's crucial to note that this process cannot remove old keys already stored on Microsoft's servers, and the script only works on unmanaged systems with admin accounts.\n\nThe necessity for deGDID arises from the lack of a native toggle in Windows to disable GDID. As a permanent device ID, GDID can track users across IP addresses, bypassing VPNs and remaining undetected. This feature has led Windscribe to create the script, aiming to protect users from potential invasions of privacy and misuse of this permanent tracking mechanism.\n\nIn testing, the script successfully removed GDID keys on a Windows 11 computer and prevented the creation of new ones. However, connecting to Microsoft's servers and authenticating Windows accounts proved challenging, resulting in connection errors for certain Windows services and online applications. While Windscribe considers deGDID a research project, the implications of blocking core Microsoft services and features could be too disruptive for some users. Nevertheless, it represents a promising step in the ongoing fight against hidden trackers.",
  "summary": "You can run the deGDID script on your computer to delete cached GDID keys and prevent Microsoft's servers from minting new ones in the background. The firewall you put up with this script will break certain Microsoft services and features, however, but you can always reverse it.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "XDA Developers",
        "title": "I do all my Linux work inside Windows now, and I genuinely can't tell if Microsoft won or lost",
        "url": "https://urgent.news/2026/08/06/i-do-all-my-linux-work-inside-windows-now-and-i-genuinely-cant-tell",
        "published": "2026-08-06T15:00:10.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}