Propaganda:
It is Microsoft cloud service telemetry; e.g., Microsoft 365, Outlook, OneDrive, Azure, Xbox, etc.
This is normal: cloud providers monitor abuse, malware uploads, suspicious logins, and compromised accounts.
“Cybersecurity researchers at Microsoft… have access to data, such as computer machine IDs, IP addresses, and malware samples associated with sophisticated cybergroups.”
This is the key line.
Machine IDs here refer to identifiers associated with Microsoft cloud services or malware samples - not a Windows OS‑level “super ID” that tracks all activity. I just wrote recently about Tails OS (Linux) not protecting from these same things! -And it's alleged the most private version of Linux.
Microsoft correlated activity by looking at shared IP addresses -Something any cloud host or server could do. If multiple accounts log in from the same VPN exit node, or the same residential IP, or the same cloud server; they can be linked. It does not imply Microsoft can see through VPN encryption.
The affidavit never states: That Windows sends a universal device ID to Microsoft, that Microsoft can track all web browsing, that Microsoft can deanonymize VPN traffic, or that Microsoft can identify users across unrelated services.