Microsoft is preparing to require TPM attestation for servers that manage Windows Key Management Service activation, a move that could block many fake Windows KMS activators used for software piracy.
The company says future KMS hosts will need to prove that they are running on verified and uncompromised hardware before they can activate Windows client devices.
Windows Server 2025 will begin showing readiness messages to administrators from August 2026.
TPM attestation adds a hardware check to KMS activation
Key Management Service, or KMS, lets organisations activate Windows across many company devices without entering a separate product key on every machine.
Until now, KMS activation has relied largely on software-based checks. That approach allowed attackers and piracy groups to create cloned or fake KMS servers that appeared legitimate to Windows devices.
Microsoft now plans to require TPM attestation for KMS hosts using hardware-secured activation.
A Trusted Platform Module is a hardware security component that stores cryptographic keys and performs cryptographic operations. Most modern computers include TPM hardware, and TPM 2.0 is already required for Windows 11.
KMS hosts must prove they are genuine
Each TPM includes a unique Endorsement Key, which can help verify a device’s identity.
Under Microsoft’s new approach, a KMS host will need to provide TPM-backed proof that it is genuine and has not been tampered with. Microsoft will verify that proof before allowing the server to activate Windows clients.
The aim is to stop fake KMS infrastructure from being copied, spoofed or deployed as an unauthorised activation service.
Windows Server 2025 will show readiness warnings
From August 2026, Windows Server 2025 will begin displaying readiness information for the transition.
Administrators will be able to check the status through the slmgr /dlv command, which provides detailed licence information. The messages will also appear in KMS service logs.
Servers without an accessible TPM will receive a warning that the device does not meet the requirements for hardware-secured KMS hosting. Compatible systems will show that they are eligible to serve as a KMS host with hardware-based security.
Microsoft has advised organisations to identify any necessary hardware upgrades before the requirement takes effect.
Windows KMS activators face a major obstacle
Fake Windows KMS activators have long been used to bypass Windows licensing.
These tools typically emulate a KMS service locally or direct a computer to an unauthorised KMS server online. The device then receives what appears to be a valid activation without a legitimate licence.
TPM-backed attestation should make this approach far more difficult because the fake server would need to prove it is running on verified hardware.
However, the change will not necessarily stop every Windows activation bypass. Other techniques, including methods that target different parts of Microsoft’s licensing system, may still exist.
Microsoft has not yet provided detailed guidance for virtualised KMS hosts but said further information will follow.


0 responses to “Microsoft TPM Attestation Will Block Many Windows KMS Activators”