- Microsoft has introduced KMS Hardware-Secured, an enhancement that utilizes Trusted Platform Module (TPM)-based attestation to validate Key Management Service (KMS) hosts before they can activate Windows devices.
- KMS Hardware-Secured will require hosts in upcoming Windows Server releases to demonstrate that they are running on verified and uncompromised hardware before issuing activation licenses to enterprise clients.
- Microsoft indicated that this change can help reduce activation misuse, limit licensing and compliance risks, and create a more robust foundation for future activation security requirements.
- Unlike legacy KMS deployments, KMS Hardware-Secured deployments will require TPM support and attestation capability.
- Microsoft has stated that TPM attestation will become mandatory for KMS Hardware-Secured activation with the next Windows Server Long-Term Servicing Channel (LTSC) release.
- Microsoft has stated that guidance for virtualized KMS host environments will be shared in future blog posts.
Microsoft's new KMS Hardware-Secured activation will require Trusted Platform Module (TPM) attestation for Key Management Service (KMS) hosts in upcoming Windows Server releases. This change aims to mitigate risks associated with spoofed and untrusted KMS infrastructures.12
The initiative, announced in a July 2022 blog post, mandates that KMS hosts demonstrate they are running on verified and uncompromised hardware before issuing activation licenses to enterprise clients. This is a significant shift from legacy KMS deployments, which lacked mandatory hardware prerequisites.
Microsoft emphasized that this enhancement can reduce activation misuse, limit licensing and compliance risks, and establish a stronger foundation for future activation security requirements. The company plans to provide guidance for virtualized KMS host environments in future communications.36
Starting in August 2022, readiness messages will assist administrators in determining whether a KMS host meets the new hardware-based security requirements. Ultimately, TPM attestation will become a mandatory requirement for KMS Hardware-Secured activation with the next Windows Server Long-Term Servicing Channel (LTSC) release.5
“KMS Hardware-Secured will mandate that hosts demonstrate they are running on verified hardware before issuing activation licenses to enterprise clients. Microsoft stated that guidance for virtualized KMS host environments will be shared in future blog posts, enhancing security and compliance.”

