Microsoft is using TPM chips to crack down on pirated Windows activations

Alfonso Maruccia

Posts: 2,613   +980
Staff
A hot potato: After introducing Windows 11, Microsoft forced the entire PC ecosystem to turn the Trusted Platform Module (TPM) into a standard component for every new motherboard or CPU. Now, Redmond is exploiting the now-pervasive device to further strengthen the Windows activation process in the enterprise market.

Microsoft recently announced a brand-new addition to Key Management Service (KMS), a standard feature for mass activation of Windows devices in enterprises and other large-scale organizations. The KMS feature will soon rely on hardware-based security, using TPM's encryption "brain" to verify the legitimacy of the server hosting KMS data.

Redmond explained that attackers have traditionally abused KMS to spoof the activation process, which is both a security issue and a way for individual users to avoid paying for a new Windows license. The new "TPM-based attestation" option will use the TPM for verifying the cryptographic proof of the integrity of a KMS server.

TPM-based attestation will first check the hardware identity of the KMS host, proving that the server has been verified by Microsoft as a legitimate hardware device. Then, the feature will confirm that the KMS host has not been tampered with in any way. Finally, the TPM chiplet will let the now-verified KMS host manage the mass activation requests required by the organization.

TPM-based attestation will become a mandatory requirement for KMS activation starting with the next Windows Server release, Microsoft stated. The corporation will begin to pressure business customers by sharing its "readiness messaging" in Windows Server 2025, starting from August 2026. Sysadmins will need to adapt and prepare their organizations in time, checking whether their KMS infrastructure is ready for hardware-based activation security.

"As Windows security continues to evolve, trusted activation infrastructure will play an increasingly important role," Microsoft stated. "KMS Hardware Secured helps position your environment for the future while aligning with Microsoft's continued investment in hardware-rooted trust."

Popular tools designed to activate pirate copies of Windows have used KMS-based methods for quite some time. In 2025, Microsoft stopped the workaround employed in the so-called "KMS38" activation method, although "pure" KMS activation should still work as expected.

The elusive Massgrave collective provides open-source tools for "unofficial" Windows activation procedures, including an Online KMS method that needs to "phone home" to a fake KMS server every six months. TPM-based attestation might very much be the end of Online KMS-based piracy, although we will have to wait and see how the story actually ends. Massgrave recently introduced the new TSforge Activation method, which can allegedly bypass Microsoft's entire DRM architecture for software product activation.

Permalink to story:

 
Gee I wonder if anyone saw this coming........

Everyone knew this is why TPM was demanded. You WILL pay for your slop software and you WILL not own it.
 
I know too many people who only use windows because they can get it for free. They need to use the WinRar business model. Market share means they keep the enterprise market locked in. If market share starts dropping then spending millions a year on software licenses will stop making sense.
 
"Massgrave recently introduced the new TSforge Activation method, which can allegedly bypass Microsoft's entire DRM architecture for software product activation."

If I remember correctly, the Tsforge method works by tricking the licensing system on the client side, then passes the genuine ticket generated to Microsoft's servers for activation. There's also the default HWID method.
 
I know too many people who only use windows because they can get it for free. They need to use the WinRar business model. Market share means they keep the enterprise market locked in. If market share starts dropping then spending millions a year on software licenses will stop making sense.
Better idea: adopt the linux method and just open source the thing already. Its not like windows licenses are a significant profit center for them anymore.
 
Better idea: adopt the linux method and just open source the thing already. Its not like windows licenses are a significant profit center for them anymore.
No, but locking many of their services to windows does make windows revenue a nice little booster.

I'm already on the Linux bandwagon. I had enough years ago. I'm just saying that they're going to shoot themselves in the foot by making Linux the only alternative.
 
Better idea: adopt the linux method and just open source the thing already. Its not like windows licenses are a significant profit center for them anymore.
I would say that Microsoft is not averse to open sourcing, and have opened up a few pieces of Windows already. But the Windows codebase is gigantic, containing proprietary code even from others. A file-by-file audit would be necessary before open sourcing.

Here's an example of just one framework and how long it takes before full open sourcing is possible:
 
I could see doing that a while back, but for a while now you can get a copy of Windows 11 Pro for $12. It's advertised right here on TechSpot. I paid $44 for mine, a few years ago, yikes!
 
I don’t get why you’d pirate windows. For a start you can use it unactivated indefinitely unless it’s changed recently and you can buy keys for £10-20.
 
I don’t get why you’d pirate windows. For a start you can use it unactivated indefinitely unless it’s changed recently and you can buy keys for £10-20.
Sometimes, the MAS tools are a practical way to get Windows activated. I believe Microsoft support has used it on occasion. This February, formatting and reinstalling W7 on my grandfather's old laptop, it would not activate: neither by internet nor telephone. MAS worked in less than a minute.
 
Windows can be used for free without any activation and practically without restrictions.
A few features that are not available via the GUI in non-activated copies, like some customizations, are still fully available via registry editing/scripts.

Only a true id1ot would use a "pirated" copy when Windows is, for all practical purposes, free for personal use. And only less than well informed people may link TPM to "crack down on pirated Windows activations".
 
I don’t get why you’d pirate windows. For a start you can use it unactivated indefinitely unless it’s changed recently and you can buy keys for £10-20.
Windows can be used for free without any activation and practically without restrictions.
A few features that are not available via the GUI in non-activated copies, like some customizations, are still fully available via registry editing/scripts.

Only a true id1ot would use a "pirated" copy when Windows is, for all practical purposes, free for personal use. And only less than well informed people may link TPM to "crack down on pirated Windows activations".
Because you don't want to registry hack, you don't want to pay ANYTHING, and you don't want the annoying "Windows is not activated"...

Pirating is basically sanctioned by MS - the bypass is on Github (which MS owns) and is much easier to use than any registry hacking...
 
Because you don't want to registry hack, you don't want to pay ANYTHING, and you don't want the annoying "Windows is not activated"...

Pirating is basically sanctioned by MS - the bypass is on Github (which MS owns) and is much easier to use than any registry hacking...
Editing the registry is not "hacking", the registry editor is a legitimate, built-in OS tool, and using it is not "pirating". Windows is already free, why breaking an open door?
 
Because you don't want to registry hack, you don't want to pay ANYTHING, and you don't want the annoying "Windows is not activated"...

Pirating is basically sanctioned by MS - the bypass is on Github (which MS owns) and is much easier to use than any registry hacking...
Then don’t use it?
 
Back