Windscribe has introduced an innovative open-source script named deGDID, designed to eliminate a persistent tracking identifier from Windows systems. This tool specifically targets Microsoft’s Global Device Identifier (GDID), a permanent marker that operates beneath the network layer, where traditional VPNs typically function. By acting as a firewall against the internal DeviceAdd endpoint, deGDID effectively prevents Microsoft identity services from recognizing the machine as registered.
The script offers a fourth flag, -Unprotect, which allows users to reverse the process and restore default settings if necessary. Testing conducted on a Windows 11 machine confirmed that the script operates as intended, with the -Status flag revealing several cached identifiers prior to their removal. Notably, this tool is designed to work alongside antivirus and endpoint protection, as it addresses tracking rather than malicious software.
Limitations of the workaround
However, Windscribe acknowledges certain limitations inherent in this workaround. For instance, keys that are already stored on Microsoft’s servers cannot be deleted, meaning the company retains indefinite access to previously collected data. Furthermore, the script is unable to run on managed systems or domain-joined accounts, thus restricting its use to individual unmanaged machines. Currently, Windows does not provide a built-in method for disabling GDID, and the identifier persists across IP addresses, regardless of any VPN tunneling applied.
“We tried the script on a Windows 11 computer, and it worked as intended,” the company noted in its documentation regarding the testing process. Windscribe describes deGDID as an ongoing research effort that will continue to evolve as more details about the identifier’s mechanics are uncovered. The broken services resulting from the script’s execution represent a tangible cost for users who must weigh the privacy trade-off against the loss of certain Microsoft account functionalities. Given that server-side keys remain permanently accessible to Microsoft, this script serves as a partial fix rather than a comprehensive solution.