Microsoft to Add TPM-Based Attestation to Secure Windows KMS Activation

New hardware-backed verification aims to reduce risks from spoofed activation servers and compromised infrastructure.

Windows 11

Key Takeaways:

  • KMS Hardware-Secured uses TPM attestation to verify trusted activation servers.
  • Windows Server 2025 will begin showing readiness notifications in August 2026.
  • TPM attestation will become mandatory in a future Windows Server LTSC release.

As cyber threats continue to evolve, Microsoft is strengthening Windows activation security by extending protection beyond software and into the hardware layer. The new KMS Hardware-Secured feature uses TPM-based attestation to ensure that activation servers are running on trusted, uncompromised hardware before they can activate Windows devices.

Key Management Service (KMS) is a volume activation technology that allows organizations to activate Windows and other Microsoft products across multiple devices using a centralized activation server instead of activating each device individually. Devices on the organization’s network periodically connect to the KMS host to validate their licenses and remain activated.

Microsoft mentioned that traditional KMS deployments have been vulnerable to spoofed or cloned KMS servers, which creates compliance, licensing, and security risks. Microsoft is addressing these risks by requiring stronger verification of KMS hosts.

How TPM attestation protects KMS activation servers

KMS Hardware-Secured is an enhanced activation model that adds a hardware layer of trust to the Key Management Service. It uses TPM (Trusted Platform Module) attestation to confirm that a KMS host is running on genuine, uncompromised hardware before it can activate Windows devices.

“The cornerstone of this modernization is TPM-based attestation. Starting with upcoming Windows Server releases, KMS hosts must prove they are running on verified, uncompromised hardware before activating clients. This is achieved through TPM – a hardware root of trust that provides cryptographic proof of integrity,” Microsoft explained.

Security benefits of hardware-secured KMS activation

TPM attestation strengthens Windows activation security by ensuring that only trusted and verified KMS servers are allowed to activate devices. It becomes much harder for attackers to tamper with activation systems, steal activation credentials, or create fake KMS hosts. Moreover, this hardware-based approach helps organizations align with Microsoft’s evolving security standards and prepares their activation infrastructure for future compliance and security requirements.

TPM attestation works by allowing a KMS host to prove its identity using the security capabilities built into its Trusted Platform Module (TPM). Microsoft verifies this hardware-backed evidence and checks that the host platform has not been altered. Once verified, the server can securely provide activation services to Windows devices within the organization.

What organizations need to do before the transition?

Microsoft advises organizations to begin preparing for the transition to hardware-secured KMS by reviewing their existing KMS infrastructure and confirming that their servers support TPM. Administrators should verify TPM attestation capabilities, identify any systems that may require hardware upgrades, and start planning for the upcoming security requirements.

Microsoft is also rolling out changes to help organizations prepare for hardware-secured KMS activation. Starting in August 2026, Windows Server 2025 will display readiness notifications that indicate whether a KMS host meets the new TPM-based security requirements. Going forward, TPM attestation will become a mandatory part of KMS Hardware-Secured activation in the next Windows Server Long-Term Servicing Channel (LTSC) release.