Microsoft announces hardware-secured KMS to better protect Windows activation
Microsoft has announced KMS Hardware-Secured, a major upgrade that links Windows activation to trusted hardware instead of software alone. The change targets cloned and spoofed Key Management Service (KMS) servers, which have become a growing security and licensing concern for organizations.
Windows activation will soon require trusted hardware
Rather than relying only on software, Microsoft will use the Trusted Platform Module (TPM) to verify a KMS host before it can activate Windows devices. The TPM acts as a hardware root of trust. It proves the server is genuine and hasn’t been tampered with.
According to Microsoft, this brings stronger protection against activation spoofing while keeping activation secrets tied to verified hardware. The company says the new approach offers:
- Better protection against fake KMS servers.
- Stronger resistance to tampering.
- Improved readiness for future security requirements.
Unlike the legacy KMS model, the new system requires TPM-enabled hardware before activation requests are processed.
Windows Server 2025 will begin checking compatibility next month
Microsoft says administrators should start preparing now. Organizations should inventory existing KMS hosts, confirm TPM is installed and enabled, and verify Key Attestation support using PowerShell.
Starting in August 2026, Windows Server 2025 will begin displaying readiness messages through slmgr /dlv and Event Viewer. These alerts will tell admins whether a KMS host is eligible for hardware-based activation.
Microsoft also confirmed that guidance for virtual KMS hosts will arrive in a future update. The company plans to make TPM attestation mandatory with the next Windows Server LTSC release, giving IT teams time to upgrade their infrastructure before enforcement begins.
In other security news, Microsoft is investigating an Exchange Online issue affecting quarantined mailboxes, while also outlining new recommendations for hardening Windows Server against modern cyberattacks.
The company has also confirmed that Microsoft Entra will retire SMS and voice-based MFA in February 2027.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages