📣 Send us your press release
Site updates every 15 minutes
Technology

Microsoft to Use TPM for Windows KMS Activation Security

Microsoft is implementing TPM-based attestation for Windows KMS volume activation to combat illegitimate activations and enhance enterprise security.

25 July 2026
Microsoft to Use TPM for Windows KMS Activation Security
Image is an AI-generated illustration

Microsoft is enhancing the security of its Windows volume activation process by introducing Trusted Platform Module (TPM) based attestation for Key Management Service (KMS). This move aims to prevent misuse of KMS for illegitimate Windows activations and bolster security for enterprise environments.

KMS is the standard method for large organizations to activate Windows devices in bulk. The new TPM-based attestation will leverage the cryptographic capabilities of TPM chips to verify the authenticity and integrity of KMS-hosting servers. This is intended to thwart attackers who have exploited KMS to facilitate pirated software activations.

Under the new system, the KMS host's hardware identity will be verified, confirming it's a Microsoft-certified component. Additionally, checks will be performed to ensure the KMS host has not been tampered with before it can process activation requests. Microsoft plans to make TPM-based attestation a mandatory requirement starting with the next Windows Server version.

The company stated that TPM-based attestation will become a mandatory requirement from the next generation of Windows Server. Enterprises can expect to receive readiness notifications for Windows Server 2025 regarding this feature starting in August 2026, prompting them to update their infrastructure. This development follows Microsoft's efforts in 2025 to block the widely used 'KMS38' activation method, a key tool for pirated Windows copies.

Original source: ithome.com