Microsoft is preparing to make Windows activation much stricter by introducing a new security system that checks whether activation servers are running on genuine, trusted hardware. The change is expected to make it much harder to use fake activation servers that have often been used for pirated Windows activations.

The company is adding a new feature called KMS Hardware-Secured, which uses the computer’s Trusted Platform Module (TPM), a built-in security chip found in most modern PCs, to verify that a Windows activation server is running on legitimate hardware before it can activate other computers.

KMS is a Windows activation system mainly used by businesses and large organizations. It allows companies to activate many Windows PCs without each computer needing to connect directly to Microsoft.

However, fake versions of these activation servers have also been used to activate pirated copies of Windows. Microsoft says these fake servers create security, licensing, and compliance risks.

Under the new system, Microsoft will require activation servers to prove they are running on genuine hardware before they can activate Windows devices.

Instead of trusting only software settings, the company will use the PC’s TPM security chip to confirm that the activation server is authentic and has not been modified.

If the server passes these security checks, it will be allowed to activate Windows computers within the organization.

This means simply copying the software from a real activation server will no longer be enough to make it work.

Microsoft says this approach will better protect Windows activation and make fake activation servers much more difficult to use.

Microsoft will begin preparing businesses for the new requirements in August 2026.

Windows Server 2025 will start showing notifications that let IT administrators know whether their activation servers are ready for the upcoming changes.

Microsoft also recommends that organizations check their activation servers, make sure TPM support is available and turned on, and confirm that their hardware supports the new security checks. Separate guidance for virtual servers will be released later.

Microsoft says these hardware security checks will become mandatory with the next Windows Server Long-Term Servicing Channel (LTSC) release.

The company is giving businesses advance notice so they have time to upgrade any servers that do not meet the new requirements before enforcement begins.

Microsoft has been expanding the use of TPM across Windows in recent years. For example, Windows 11 already requires TPM 2.0 on officially supported PCs because it helps protect the system against security threats.

The update is important because fake KMS servers have also been used outside businesses to activate pirated copies of Windows.

One of the most well-known projects offering KMS-based activation methods is Microsoft Activation Scripts (Massgrave). Microsoft had already blocked one of its activation methods, known as KMS38, on newer Windows versions in 2025 after removing the feature it relied on. Massgrave later removed KMS38 from its tool.

Traditional KMS activation is different, and Microsoft’s earlier change did not disable it.

With the upcoming hardware verification requirement, running fake KMS activation servers could become much more difficult because Microsoft’s activation system will require proof that the server is running on genuine hardware.

However, it is still unclear whether the change will completely stop pirated Windows activations. Some unofficial activation tools use different methods that do not rely on fake KMS servers.

The biggest change is that Microsoft is moving Windows activation from software-only verification to hardware-based verification.

Previously, Windows mainly trusted the activation server’s software, making it easier for fake servers to imitate legitimate ones. Going forward, Microsoft will also require proof from the server’s hardware before allowing Windows activation.

“As Windows security continues to evolve, trusted activation infrastructure will play an increasingly important role,” Microsoft said.

For businesses, this means upgrading activation servers if necessary before the new requirements take effect. For users relying on fake KMS activation servers, Microsoft’s upcoming changes could make those methods significantly harder to use.

Get the latest tech news, telecom insights, and product launches wherever you prefer.

Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.

Shares