Microsoft is preparing to require TPM-backed attestation on KMS activation hosts in a future Windows Server Long-Term Servicing Channel release, but the change does not disable existing KMS activation today and does not impose a new TPM check on every Windows PC. The immediate August 2026 change is a readiness-warning phase in Windows Server 2025, according to Microsoft’s Windows IT Pro Blog; it is meant to tell administrators whether a KMS host can support the company’s forthcoming “KMS Hardware-Secured” model.
That narrower scope gets lost in 36Kr’s framing of the announcement as a broad clampdown on “pirated software users.” Microsoft is plainly targeting a weakness exploited by cloned and fraudulent KMS servers, but its published plan is about the server that supplies volume activation, not about individually inspecting home Windows installations or suddenly invalidating the activation state of existing PCs. Windows Latest and Neowin both reached the same practical reading: the TPM proof is performed by the KMS host before it is allowed to activate clients.
For enterprise administrators, this is still significant. KMS may be a small Windows Server role, but it can underpin activation for a large fleet of Windows desktops, servers, and volume-licensed Office installations. A host that misses the future hardware requirements could become an unexpected licensing-infrastructure migration project — particularly where KMS has been left on aging hardware or in a virtual machine that no one has revisited for years.
Key Management Service was built for volume licensing. Instead of every eligible Windows device independently reaching Microsoft’s activation servers, an organization runs an internal KMS host, installs and activates its volume-license host key, and lets managed clients discover the host through DNS.
Microsoft’s current KMS documentation says a host can run on supported Windows Server or Windows client systems, including virtual systems. The host publishes its service through DNS by default, listens on TCP port 1688 by default, and activates qualifying devices after the environment reaches the necessary thresholds: 25 Windows client systems or five Windows Server or volume-licensed Office systems.
The weakness Microsoft is addressing is the trust placed in that host. If a machine can successfully imitate the expected KMS activation behavior, a client may treat it as an activation authority. That has enabled unauthorized local and network-hosted KMS emulators for years, but it also creates a more conventional enterprise risk: a cloned host or stolen activation material can blur the line between an authorized activation server and an impostor.
Microsoft’s proposed answer is hardware-rooted trust. Under KMS Hardware-Secured, the KMS host must use its Trusted Platform Module to attest to its identity and platform state before Microsoft permits it to serve Windows activation requests. A TPM is not magic anti-piracy silicon, as some coverage implies. It is a hardware or firmware security processor that can protect cryptographic keys and record measurements about the platform’s boot state, making a key or host identity harder to copy wholesale from one server image to another.
The security logic is sound: a copied KMS configuration should no longer be enough. The activation authority would be tied to cryptographic evidence from a particular, verified host environment.
But Microsoft has not said that an August 2026 Windows Server 2025 update will turn off conventional KMS hosts, revoke currently activated Windows clients, or force a TPM check on consumer PCs. Those are important distinctions, and none is a minor technicality.
Administrators will see the status in the output of
Microsoft’s published preflight guidance for a physical KMS host is straightforward:
The distinction between a warning and a block matters operationally. A Windows Server 2025 KMS host that shows an ineligible warning in August should continue running its existing activation arrangement; it is a signal to inventory and plan. PC Gamer’s report correctly notes that the company is giving administrators lead time, although Microsoft has not disclosed the particular cumulative update, OS build number, KB article, or exact August rollout date that will carry the readiness check.
That missing specificity means IT teams should watch the Windows Server 2025 update history and their KMS event logs rather than assume the message will arrive on a particular Patch Tuesday.
Several outlets have speculated that the target could be a Windows Server 2028 generation, but that is not a Microsoft commitment. Administrators should not build a compliance plan around an unannounced product name or a presumed release calendar.
More consequentially, Microsoft’s public language leaves one implementation question unresolved. It states that attestation will become mandatory for “KMS Hardware-Secured activation,” while elsewhere describing an upcoming environment in which KMS hosts must prove they are operating on verified, uncompromised hardware before activating clients. That direction strongly suggests that hardware verification will become the supported activation standard, but Microsoft has not yet published a technical statement that explicitly spells out the retirement behavior for every legacy KMS configuration.
That ambiguity is not academic. An organization needs to know whether it will be able to retain an existing conventional KMS host indefinitely for older clients, whether it must replace the host before deploying the next server generation, and whether Windows clients will require any servicing changes. Microsoft’s announcement answers none of those questions.
The largest immediate gap concerns virtualized KMS hosts. Microsoft acknowledges that separate guidance for virtualized environments will arrive in future blog posts. That leaves administrators running KMS in Hyper-V, VMware, Azure Stack HCI, or other private-cloud platforms without a definitive answer on whether a virtual TPM, a particular hypervisor chain of trust, Secure Boot, migration controls, or host-level attestation will satisfy the rule.
A vTPM checkbox should therefore not be mistaken for a compatibility guarantee. In virtual environments, cloning, live migration, disaster recovery, host replacement, and image templates are normal operations — precisely the activities that become more sensitive when an activation role is bound to a hardware-backed identity.
What the report overstates is the immediacy and breadth of the result. The TPM is attached to the KMS host’s authorization process, not newly required from every Windows client seeking activation. A personal Windows 10 or Windows 11 PC is not being newly assessed under this KMS-host readiness program merely because it has — or lacks — a TPM.
Nor does Microsoft say that every unauthorized activation technique stops working when the next Server LTSC release arrives. KMS emulation is only one category of unauthorized activation, and Microsoft’s announcement is specifically about strengthening its own KMS host trust model. Claims that this will conclusively “end” Windows piracy go beyond what the company has announced.
There is also no indication that temporary Windows bugs are exempted from a new anti-piracy enforcement mechanism, because Microsoft has announced no such mechanism. The relevant temporary condition is instead the transition period: current KMS deployments are being warned and assessed before a future enforcement point. A server that is not ready in August is not, based on Microsoft’s published description, supposed to cause an organization’s Windows estate to lose activation that month.
The harder cases will be environments where volume activation is treated as set-and-forget infrastructure. A KMS host can run quietly for years, especially if it was installed on an old physical server, folded into another server role, or deployed as a lightly managed virtual machine. Those installations may have incomplete licensing records, unknown recovery procedures, disabled TPM firmware settings, or no clear owner.
Administrators should record the host operating system and build, physical-versus-virtual status, Windows Server certification, TPM state, key-attestation result, current KMS activation count, DNS publication method, firewall configuration, and recovery or failover arrangement. The count matters because a replacement KMS host still needs enough qualifying client contacts before it can activate clients.
Microsoft has supplied the warning light but not the final road map. In August 2026, the practical consequence is not a mass deactivation event or a consumer-PC crackdown. It is a notice that volume-activation infrastructure is moving from a copyable software configuration toward an identity that has to be proven by the server hardware — and that organizations with neglected KMS hosts now have time to find them before the next Windows Server LTSC release makes that preparation unavoidable.
For enterprise administrators, this is still significant. KMS may be a small Windows Server role, but it can underpin activation for a large fleet of Windows desktops, servers, and volume-licensed Office installations. A host that misses the future hardware requirements could become an unexpected licensing-infrastructure migration project — particularly where KMS has been left on aging hardware or in a virtual machine that no one has revisited for years.
Microsoft Is Changing the Trust Anchor, Not Windows Activation Overnight
Key Management Service was built for volume licensing. Instead of every eligible Windows device independently reaching Microsoft’s activation servers, an organization runs an internal KMS host, installs and activates its volume-license host key, and lets managed clients discover the host through DNS.Microsoft’s current KMS documentation says a host can run on supported Windows Server or Windows client systems, including virtual systems. The host publishes its service through DNS by default, listens on TCP port 1688 by default, and activates qualifying devices after the environment reaches the necessary thresholds: 25 Windows client systems or five Windows Server or volume-licensed Office systems.
The weakness Microsoft is addressing is the trust placed in that host. If a machine can successfully imitate the expected KMS activation behavior, a client may treat it as an activation authority. That has enabled unauthorized local and network-hosted KMS emulators for years, but it also creates a more conventional enterprise risk: a cloned host or stolen activation material can blur the line between an authorized activation server and an impostor.
Microsoft’s proposed answer is hardware-rooted trust. Under KMS Hardware-Secured, the KMS host must use its Trusted Platform Module to attest to its identity and platform state before Microsoft permits it to serve Windows activation requests. A TPM is not magic anti-piracy silicon, as some coverage implies. It is a hardware or firmware security processor that can protect cryptographic keys and record measurements about the platform’s boot state, making a key or host identity harder to copy wholesale from one server image to another.
The security logic is sound: a copied KMS configuration should no longer be enough. The activation authority would be tied to cryptographic evidence from a particular, verified host environment.
But Microsoft has not said that an August 2026 Windows Server 2025 update will turn off conventional KMS hosts, revoke currently activated Windows clients, or force a TPM check on consumer PCs. Those are important distinctions, and none is a minor technicality.
August 2026 Brings Readiness Messages, Not Enforcement
The first visible phase begins this month. Microsoft says Windows Server 2025 will surface readiness messaging so administrators can determine whether a KMS host is capable of supporting hardware-based security before enforcement begins.Administrators will see the status in the output of
slmgr /dlv, the familiar Software Licensing Management Tool command used for detailed activation information. Servers that qualify will report that they are eligible to serve as a KMS host with hardware-based security; systems that do not will state that they do not meet the requirements. Windows will also record warning entries under Applications and Services Logs > Key Management Service in Event Viewer.Microsoft’s published preflight guidance for a physical KMS host is straightforward:
- The server should be certified for Windows Server in the Windows Server Catalog.
- TPM hardware must be installed and enabled.
- The TPM must support key attestation, which Microsoft says administrators can test with
Get-TpmSupportedFeature -FeatureList "Key Attestation"in an elevated PowerShell session.
The distinction between a warning and a block matters operationally. A Windows Server 2025 KMS host that shows an ineligible warning in August should continue running its existing activation arrangement; it is a signal to inventory and plan. PC Gamer’s report correctly notes that the company is giving administrators lead time, although Microsoft has not disclosed the particular cumulative update, OS build number, KB article, or exact August rollout date that will carry the readiness check.
That missing specificity means IT teams should watch the Windows Server 2025 update history and their KMS event logs rather than assume the message will arrive on a particular Patch Tuesday.
The Future LTSC Deadline Is Real but Still Incomplete
Microsoft says TPM attestation becomes mandatory with the next Windows Server LTSC release for KMS Hardware-Secured activation. It has not named that release, provided a shipping date, or published final virtual-host requirements.Several outlets have speculated that the target could be a Windows Server 2028 generation, but that is not a Microsoft commitment. Administrators should not build a compliance plan around an unannounced product name or a presumed release calendar.
More consequentially, Microsoft’s public language leaves one implementation question unresolved. It states that attestation will become mandatory for “KMS Hardware-Secured activation,” while elsewhere describing an upcoming environment in which KMS hosts must prove they are operating on verified, uncompromised hardware before activating clients. That direction strongly suggests that hardware verification will become the supported activation standard, but Microsoft has not yet published a technical statement that explicitly spells out the retirement behavior for every legacy KMS configuration.
That ambiguity is not academic. An organization needs to know whether it will be able to retain an existing conventional KMS host indefinitely for older clients, whether it must replace the host before deploying the next server generation, and whether Windows clients will require any servicing changes. Microsoft’s announcement answers none of those questions.
The largest immediate gap concerns virtualized KMS hosts. Microsoft acknowledges that separate guidance for virtualized environments will arrive in future blog posts. That leaves administrators running KMS in Hyper-V, VMware, Azure Stack HCI, or other private-cloud platforms without a definitive answer on whether a virtual TPM, a particular hypervisor chain of trust, Secure Boot, migration controls, or host-level attestation will satisfy the rule.
A vTPM checkbox should therefore not be mistaken for a compatibility guarantee. In virtual environments, cloning, live migration, disaster recovery, host replacement, and image templates are normal operations — precisely the activities that become more sensitive when an activation role is bound to a hardware-backed identity.
Why the Piracy Headline Overstates the Immediate Impact
36Kr is correct on the essential history: KMS was created for organization-scale volume activation and has been abused by software that mimics an internal KMS host. Microsoft’s new design directly raises the cost of that imitation by requiring a trusted hardware attestation before a real KMS host can activate clients.What the report overstates is the immediacy and breadth of the result. The TPM is attached to the KMS host’s authorization process, not newly required from every Windows client seeking activation. A personal Windows 10 or Windows 11 PC is not being newly assessed under this KMS-host readiness program merely because it has — or lacks — a TPM.
Nor does Microsoft say that every unauthorized activation technique stops working when the next Server LTSC release arrives. KMS emulation is only one category of unauthorized activation, and Microsoft’s announcement is specifically about strengthening its own KMS host trust model. Claims that this will conclusively “end” Windows piracy go beyond what the company has announced.
There is also no indication that temporary Windows bugs are exempted from a new anti-piracy enforcement mechanism, because Microsoft has announced no such mechanism. The relevant temporary condition is instead the transition period: current KMS deployments are being warned and assessed before a future enforcement point. A server that is not ready in August is not, based on Microsoft’s published description, supposed to cause an organization’s Windows estate to lose activation that month.
KMS Owners Should Treat This as an Asset-Inventory Project
For organizations with a documented, modern KMS deployment, the first response is modest: check the host, capture its readiness status, confirm TPM support, and put the host on the normal hardware-refresh and server-upgrade plan. Microsoft’s own KMS guidance recommends at least two hosts where more than 50 clients depend on the service, so redundancy should be considered when planning any replacement work.The harder cases will be environments where volume activation is treated as set-and-forget infrastructure. A KMS host can run quietly for years, especially if it was installed on an old physical server, folded into another server role, or deployed as a lightly managed virtual machine. Those installations may have incomplete licensing records, unknown recovery procedures, disabled TPM firmware settings, or no clear owner.
Administrators should record the host operating system and build, physical-versus-virtual status, Windows Server certification, TPM state, key-attestation result, current KMS activation count, DNS publication method, firewall configuration, and recovery or failover arrangement. The count matters because a replacement KMS host still needs enough qualifying client contacts before it can activate clients.
Microsoft has supplied the warning light but not the final road map. In August 2026, the practical consequence is not a mass deactivation event or a consumer-PC crackdown. It is a notice that volume-activation infrastructure is moving from a copyable software configuration toward an identity that has to be proven by the server hardware — and that organizations with neglected KMS hosts now have time to find them before the next Windows Server LTSC release makes that preparation unavoidable.
References
- Primary source: 36 Kr
Published: Tue, 04 Aug 2026 02:34:33 GMT
Loading…
eu.36kr.com - Related coverage: pcgamer.com
Microsoft reportedly using TPM chips to weed out Windows piracy | PC Gamer
Spare a thought for the system administrators.www.pcgamer.com - Related coverage: learn.microsoft.com
Loading…
learn.microsoft.com - Related coverage: learn.microsoft.com
Loading…
learn.microsoft.com - Related coverage: techcommunity.microsoft.com
Loading…
techcommunity.microsoft.com - Related coverage: microsoft.com
Loading…
www.microsoft.com - Related coverage: support.microsoft.com
Loading…
support.microsoft.com - Related coverage: techcommunity.microsoft.com
- Related coverage: cdn-dynmedia-1.microsoft.com
- Related coverage: cdn-dynmedia-1.microsoft.com
- Related coverage: download.microsoft.com
- Related coverage: windowscentral.com
Microsoft fixes annoying BitLocker lockout — but only for Windows 11, leaving Windows 10 stuck | Windows Central
Windows 11 25H2 users get a BitLocker bug fix, while Windows 10 remains stuck with recovery headaches until Microsoft rolls out a broader solution.www.windowscentral.com - Related coverage: windowscentral.com
Loading…
www.windowscentral.com - Related coverage: neowin.net
Microsoft making a new feature mandatory requirement for Windows KMS activation - Neowin
Microsoft is introducing a new feature as a mandatory requirement for Windows KMS activation soon. The company has shared the details.www.neowin.net
- Related coverage: cybernews.com
Loading…
cybernews.com