Microsoft is introducing strict controls on pirated KMS activation

Microsoft is preparing a new security measure for KMS, a system for mass activation of Windows devices in the enterprise environment. The company will introduce hardware trust-based verification, which means that the KMS host will have to verify its identity via a TPM chip before it is allowed to activate Windows devices on the local network.

The goal of this change is to suppress pirate activation of Windows via fake or cloned KMS servers. Such servers have been used for years to bypass Microsoft activation controls, because they mimic a legitimate business environment and enable the activation of unauthorized Windows installations.

KMS, i.e. Key Management Service, is intended for large organizations. Instead of each computer contacting Microsoft servers individually, the company activates a single KMS host, and then Windows devices within the local network are activated through it. This simplifies the management of large numbers of computers, but the same mechanism has long been abused by illegal activation tools.

READ ABOUT:  Microsoft is removing Copilot buttons from Windows 11 apps

In the future, Microsoft KMS activation will require hardware confirmation via the TPM chip on the server

The new protection introduces TPM authentication of the KMS host. TPM, or Trusted Platform Module, is a hardware security component that generates and protects cryptographic keys, checks platform integrity, and is used in features such as Windows Hello, BitLocker, and System Guard.

When the new KMS hardware protection is active, the KMS host will first need to generate a cryptographic proof via the TPM chip. Microsoft will then verify that proof and the integrity of the platform. Only if the host is confirmed to be running on trusted and unmodified hardware will it be allowed to process Windows device activation requests.

The introduction will be gradual. From August 2026, Windows Server 2025 first gets a check engine. Administrators will be able to use the slmgr /dlv command to verify that the device is eligible for a KMS host with hardware security.

READ ABOUT:  Microsoft shuts down the old application and introduces a new solution

Mandatory implementation is expected with the next Windows Server LTSC release, most likely Windows Server 2028. From then on, TPM certification should become a requirement for KMS activation, meaning that KMS hosts without hardware proof will no longer be able to issue Windows operating system activation permissions.

For ordinary computer users, this change currently has no direct effect, because it refers to the KMS host side, and not to Windows computers acting as KMS clients. In other words, a standard PC activated via a legitimate business KMS server should not be directly affected.

In the long term, however, the change could seriously affect illegal one-click Windows activation tools. If fake KMS servers will no longer be able to pass the Microsoft check without a valid TPM proof, the threshold for abuse will be significantly higher, and a large part of the previous pirated solutions could cease to function, reports mydrivers.

READ ABOUT:  Zagreb is expanding the system of public bicycles with 1,000 new Bajs and introducing a cargo model

Source link