
Microsoft is preparing a major update to the Windows activation system. The company will introduce a new security mechanism that leverages the Trusted Platform Module (TPM) to verify the authenticity of Key Management Service (KMS) servers. This technology is designed to make it significantly harder to create fake activation servers. The TPM module is typically installed on the motherboard, meaning Windows would essentially be tied to the computer’s hardware under this setup.
KMS is a corporate tool from Microsoft that enables organizations to centrally activate large numbers of computers running Windows and other company products, eliminating the need to manually enter license keys on each device.
The new mechanism is called TPM-based attestation. Its purpose is to confirm that the activation server is legitimate and operating within a secure environment. To achieve this, the system will rely on TPM hardware capabilities: it will first verify that the server is running on trusted hardware, then analyze the integrity of the software environment, and only after a successful check will it allow activation requests to be processed.
According to Microsoft, the existing KMS architecture has remained a potential attack point for many years. Malicious actors have created fake activation servers that mimic the operation of official KMS infrastructures. Such solutions have been used both to bypass corporate licensing mechanisms and to illegally activate home versions of Windows.
The company states that hardware-based verification will become a mandatory component of the new security model starting with the next generation of Windows Server. Beginning in August 2026, users of Windows Server 2025 will start receiving notifications to prepare their infrastructure for the transition to the updated protection mechanism.
This innovation is primarily aimed at corporate clients, but it could also impact the market for illegal Windows activators. Many popular tools rely on emulating KMS servers or connecting to third-party online activation servers that periodically confirm the system’s license status.