From August 2026, KMS servers will begin checking through the TPM chip. The requirement will become fully mandatory in the next LTSC release of Windows Server. The impact falls primarily on corporate schemes and old emulators.
KMS has emerged as a convenient way to mass activate Windows within organizations, notes xrust. The company installs one server, clients access it every few days, and the license is renewed. The scheme worked for years and almost did not require constant access to the Internet.
It was her simplicity that made her vulnerable. Back in the early 2010s, emulators appeared that pretended to be a real KMS server. I installed the program and Windows believed that it was on a large corporate network. This method survived several generations of operating systems and remained one of the most enduring.
At the end of 2025, Microsoft seriously cut one of the popular options — KMS38. After the October and November updates, the method stopped working on fresh builds, and the Massgrave team removed it from their main MAS script. Users were advised to migrate to HWID or the new TSforge.
Now the company is going further and transferring the check to the hardware level. The technology is called KMS Hardware-Secured. The KMS host must prove its hardware authenticity and integrity through TPM. Only after successful certification the server receives the right to distribute activations. Simply copying the software configuration and running it on another machine will no longer work — the secrets are tied to a specific chip.
Beginning in August 2026, Windows Server 2025 will introduce readiness notifications. Administrators will be able to understand in advance whether their server passes the test. This will become a mandatory requirement in the next release of Windows Server from the LTSC channel. For physical machines, an enabled TPM and certification in the Windows Server Catalog are sufficient. For virtual hosts, Microsoft is still promising separate recommendations.
In Russian companies, KMS remained a working tool for a long time, especially in medium-sized businesses and in enterprises where licenses were purchased in packages. After 2022, the situation became more complicated: some organizations faced problems renewing legal subscriptions, and gray activation schemes became more common. On specialized forums of system administrators, the topic “how to activate now” periodically comes up, although there are still few high-profile public discussions of this particular news.
For ordinary home users, the change is almost invisible. Most modern activators have already moved away from the classic KMS. The main blow will fall on those who continued to use server emulation, and on corporate infrastructures where KMS hosts run on old hardware or virtual machines without a normal TPM.
Developers of pirated tools are not sitting idle. TSforge is positioned as a deeper way to work with the licensing system and is already included in current versions of MAS. How much it can withstand hardware certification will become clear only after the requirement comes into force.
While there is time. It is worth checking the presence and status of TPM on existing KMS servers, checking the official Microsoft catalog and including a possible upgrade in the work plan. Notifications in August will provide a margin, but waiting until the last moment is risky.
In one of the recent documentation updates, Microsoft specifically emphasized that the trusted activation infrastructure will play an increasingly important role.
Sources:
- https://techcommunity.microsoft.com/blog/windows-itpro-blog/strengthening-key-management-service—kms-with-hardware-based-trust/4539465
- https://www.techspot.com/news/113232-microsoft-using-tpm-chips-crack-down-pirated-windows.html
- https://3dnews.ru/1145758/microsoft-podklyuchit-chipi-tpm-k-borbe-s-piratskimi-aktivatorami-windows
Microsoft's Xrust will tie Windows enterprise activation to the TPM. What will happen to pirated KMS
- Если Вам понравилась статья, рекомендуем почитать
- Microsoft patched a record 966 holes in Windows and its services
- AppCleaner для Mac: как удалить программы и остаточные файлы






