Military Disables Advertising IDs: Lawmakers Ask If It’s Enough
Privacy & Compliance

Military Disables Advertising IDs: Lawmakers Ask If It’s Enough

Four memos on military advertising IDs, released September 4, confirm that the Army, the Air Force, the Department of the Navy and U.S. Special Operations Command disable the mobile advertising identifier on government-issued devices. Sen. Ron Wyden and Rep. Pat Harrigan released the memos alongside a letter to the Department of Defense Inspector General, asking whether the practice is enough to stop foreign adversaries from buying commercial location data tied to U.S. troops. They want a response by October 2, 2026.

Which Military Components Disabled Advertising IDs?

In memos dated between July 8 and August 18, the Army, the Air Force, the Department of the Navy, which covers both the Navy and the Marine Corps, and U.S. Special Operations Command each told Sen. Wyden’s office that they disable the mobile advertising identifier, or MAID, on government-issued devices. The Army, the Navy and SOCOM all call it a standard security protocol, the Navy’s word being “cybersecurity,” while the Air Force describes an actively enforced configuration. The lawmakers’ letter asks the DoD Inspector General to review the effectiveness of existing DoD policies, technical controls and OPSEC guidelines against the sale of commercial location data.

The Same Control, Only One Document With Dates

The Army and SOCOM name Microsoft Intune’s Mobile Application Management; the Navy names MAM configurations without naming a vendor; the Air Force names Group Policy Objects and MDM baselines. Three of the four give no start date: the Army and Navy name none, and SOCOM says only “recently.” Only the Air Force’s August 18 letter names days: enforcement on Windows and Android “initiated July 23, 2026” and reached “enterprise-wide compliance” on July 27, while the same letter says MAID is “actively enforced at the tenant level” on iOS with no date attached. Wyden’s letter flags that timing directly: the Air Force policy “was implemented in July, after the congressional request for the memo.”

Document & date Date the document gives What it says is disabled
Army memo, July 8, 2026 (Gabriel Chiulli) None given MAID within Intune MAM, applied to Windows, Android and Apple GFE
Air Force letter, August 18, 2026 (Ashley N. Devoto) Windows & Android: July 23–27, 2026. iOS: none given. MAID tenant-wide on iOS; tracking/ad identifiers on Windows and Android via GPOs
Department of the Navy letter, July 22, 2026 (M. Barry Tanner); the department covers the Navy and Marine Corps None given MAID within secure application/MAM environment
SOCOM RFI response, July 28, 2026 Mobile: “actively enforced,” no date. Windows: “recently,” no date. MAID via Intune MAM on Android and iOS; ad ID also disabled on Windows
USCENTCOM RFI answer, April 14, 2026 (attached to the May 28 letter; not one of the four memos) New MDM server, full location disable, estimated May 6, 2026 “Personalized Advertising setting” off by group policy; “Ad Targeting Information” still user-editable

What Did CENTCOM’s April Answer Show?

CENTCOM’s answer predates the other four by months and reads differently. Attached to the lawmakers’ May 28 letter to DoD CIO Kirsten Davies, the CENTCOM response, dated April 14, says “the Personalized Advertising setting is disabled by group policy on the Mobile Device Management Server. However, Ad Targeting Information is not disabled and can be edited by a user.” CENTCOM said DISA was testing a fix and that a new MDM server, letting location services be “completely disabled,” had an estimated completion date of May 6. The May letter summarized that answer more bluntly: “the advertising ID is still not disabled on government-issued smartphones.”

Why Lawmakers Say Disabling MAID May Not Be Enough

Wyden’s September 4 letter defines the identifier’s role before it questions the fix: MAIDs “serve as the primary bridge linking advertising bidstream data and Software Development Kit location points to a single persistent profile, allowing data brokers to aggregate precise location trails and sell them to third parties.” It then offers three explanations for why commercial location data tied to DoD facilities keeps surfacing anyway: some components may not have “fully disabled the advertising IDs,” disabling MAID may be “no longer a sufficient defense on its own, as data brokers can still capture, correlate, and monetize unique location data using other information collected from phones,” or, “particularly alarming,” the data for sale “originates entirely from personal devices brought into DoD facilities and operational areas by service members and government contractors.” The Inspector General is asked to run purchased location datasets against DoD bases to see which explanation holds.

What a Zeroed MAID Does to the Ad Join

Wyden’s own language is the useful part for marketers, not just OPSEC officers: MAID is the join key between bidstream auction data and SDK-reported location. That’s the same key MAID-based audience segments, location vendors and measurement reports lean on outside the military too, and every managed device where it reads null drops out of that join. The letters don’t quantify how large that drop is; they describe a mechanism, not a volume. It’s a reminder that campaign attribution carried in a structured URL, not a device ID, keeps working once a device stops broadcasting one, unlike ChatGPT Ads turning identifier matching on by default for existing pixels.

What Reuters Added, and the October 2 Deadline

Reuters, which reviewed the letters and took its own statements, reported detail the memos don’t contain: the Army said ad IDs on Windows have been blocked “since before 2021,” and Android and Apple devices off by default “since at least February 2026,” dates absent from the Army’s memo itself. Wyden said in a statement quoted by Reuters that the military’s efforts “have not been effective at neutralizing this threat,” and Harrigan said U.S. enemies “should not be able to pull out a credit card and buy information that helps them track American troops.” The Pentagon said in an email it would respond to the lawmakers directly. The Inspector General’s answer is due October 2. The full letter and memos are posted by Wyden’s office; the Reuters account, syndicated by the Spokesman-Review, carries the statements in full.

Alex Savich

Digital marketing journalist covering MarTech, AI, SEO, and analytics for Elsop Insights.