Microsoft making a new feature mandatory requirement for Windows KMS activation

Enhancing Security with KMS Hardware-Secured

In a concerted effort to bolster the security of its Windows operating system and associated products, Microsoft has recently unveiled a series of strategic enhancements. Among these initiatives is a significant update to Entra ID authentication, which now incorporates default passkeys, alongside the introduction of AI-enhanced security updates for Windows. This shift underscores Microsoft’s commitment to evolving its security framework in response to contemporary challenges.

One of the latest advancements involves the Key Management Service (KMS), which is set to undergo a transformation aimed at reinforcing the security of Windows volume activation. The new enhancement, dubbed KMS Hardware-Secured, will leverage Trusted Platform Module (TPM)-based attestation to ensure that KMS hosts operate on trusted hardware before they are permitted to activate Windows devices.

This initiative is a timely response to the increasing complexities surrounding device identity, software licensing, and the potential misuse of activation processes. KMS serves as Microsoft’s volume activation technology, specifically designed for organizations that require the activation of numerous Windows devices within a network. Rather than each device connecting directly to Microsoft’s activation servers, a KMS host within the enterprise environment manages activation requests from eligible client devices, streamlining the deployment process.

According to Microsoft, the introduction of the KMS Hardware-Secured capability aims to mitigate risks associated with counterfeit or cloned KMS servers, which cybercriminals have exploited to circumvent activation controls. By implementing TPM attestation, Microsoft seeks to ensure that only verified KMS hosts, operating on uncompromised hardware, can issue Windows activation licenses.

For those unfamiliar with TPM, it is a dedicated hardware security module that establishes a hardware root of trust. TPM enables devices to generate and safeguard cryptographic keys, thereby ensuring the platform’s integrity. Many essential Windows security features, including Windows Hello, BitLocker, and System Guard, rely on TPM for their functionality.

Under the new activation model, a KMS host will first utilize TPM-backed attestation to confirm its hardware identity. Following this, Microsoft will verify the attestation before granting the server the authority to activate Windows devices. The TPM also plays a crucial role in confirming the platform’s integrity, ensuring that the host remains uncompromised throughout the activation process. Once this verification is successfully completed, the KMS host can securely handle activation requests from Windows devices within the organization.

As a result, businesses utilizing KMS are encouraged to begin evaluating their environments in anticipation of this transition. Microsoft has indicated that further guidance will be provided for virtualized KMS hosts in the near future.

Starting in August 2026, Windows Server 2025 will roll out readiness messaging to assist administrators in determining whether their KMS hosts comply with the new hardware-based security requirements. Status information will be accessible through the slmgr /dlv command, with eligible devices displaying the message, “This device is eligible to serve as a KMS host with hardware-based security,” while non-eligible devices will indicate, “This device does not meet the requirements for using KMS host with hardware-based security.”

Moreover, Microsoft has confirmed that TPM attestation will become a mandatory requirement for KMS Hardware-Secured activation with the forthcoming Windows Server Long-Term Servicing Channel (LTSC) release, anticipated to be Windows Server 2028. Consequently, the company advises organizations to commence preparations for this transition well in advance. Additional details can be found in the official blog post on Microsoft’s Tech Community website.

Winsage
Microsoft making a new feature mandatory requirement for Windows KMS activation