What is the SM cookie?
Synchronizes the MUID (Microsoft User ID) across Microsoft domains to ensure consistent user tracking.
Table of Contents
About SM
| Vendor | Microsoft |
|---|---|
| Cookie Domain | clarity.ms,microsoft.com,msn.com,office.com |
| Category Category The functional category of the technology, such as Web Analytics or Social Media. Learn more | Heatmap & Recording |
| Consent Category Consent Category The consent category this cookie most commonly falls under across sites we scan, normalized into four standard categories. Learn more | Targeting & Advertising |
| Prevalence | Very Common |
| Popularity Popularity Popularity is calculated from our dataset of 4.5B+ cookies analyzed across hundreds of millions of web pages. Learn more | Found on 11.4% of scanned pages |
| Expiration Type | Session |
| Party Type Party Type Whether the cookie is first-party or third-party. Learn more | 3rd-Party |
| Risk Level Risk Level Rates how sensitive the data stored by this cookie is (High, Medium, or Low) based on data classification and distribution. Learn more | Medium |
| Vendor Privacy Policy | https://privacy.microsoft.com/en-us/privacystatement |
| Vendor Website | https://www.microsoft.com |
What is the purpose of SM?
The SM cookie is a third-party tracking cookie set by Microsoft Clarity and other Microsoft services. Its primary function is to synchronize the MUID (Microsoft Unique Identifier) across various Microsoft domains. By ensuring that the same unique identifier is recognized across different sites, Microsoft can reliably track a user's browsing session and interactions. This facilitates aggregated analytics, heatmaps, and session recordings through Microsoft Clarity, while also supporting Microsoft's advertising network by maintaining a consistent behavioral profile of the user across the web.
What are the Privacy Risks of SM?
Risk Level: Medium
The SM cookie facilitates cross-domain tracking by synchronizing the user's MUID (Microsoft User ID) across different Microsoft properties. While it does not contain direct Personally Identifiable Information (PII) like names or email addresses, the synchronized unique identifier allows Microsoft to construct detailed behavioral profiles based on the user's interactions across multiple websites. Because this data is used both for detailed session analytics (via Clarity) and potentially for targeted advertising by Microsoft's ad network, it presents a medium privacy risk regarding cross-site profiling and behavioral tracking.
How to Remove SM from a Website
To remove the SM cookie, a website administrator must stop deploying the technology that sets it. The most direct approach is to remove the Microsoft Clarity tracking script from the site's source code (or delete the Clarity tag from the tag management system such as Google Tag Manager). Alternatively, without fully removing Clarity, a site operator can log in to the Clarity project and, under Settings > Setup > Advanced settings, toggle off the 'Cookies' option so that Clarity no longer writes cookies automatically. Note that disabling this setting or removing the script also disables Clarity's ability to link page views into cohesive multi-page sessions. In short, the SM cookie cannot be removed independently: it is set as part of Clarity's cookie mechanism, so removal requires either turning off Clarity's cookie functionality or removing the Clarity service from the site.