Microsoft said Windows enterprise volume activation will move to a hardware-backed trust model by requiring TPM-backed attestation for Key Management Service (KMS) servers. Under the change, a KMS host must prove its identity and integrity through TPM-generated attestation before Windows activation completes, replacing the current software-only approach. The requirement will take effect with the next Windows Server Long-Term Servicing Channel release, and Windows Server 2025 will begin showing readiness messaging in August 2026.
The update applies to organizations operating KMS infrastructure, not to consumer Windows devices, and reports portraying it as a broad anti-piracy measure were disputed. Microsoft is advising enterprises to inventory KMS servers, confirm TPM support and Windows Server certification on physical hosts, assess whether hardware upgrades are needed, and prepare migration plans ahead of enforcement.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft said Windows Server 2025 will start displaying readiness messaging or alerts related to the TPM-backed KMS change in August 2026. The messaging is meant to help organizations prepare by checking TPM support, certification, and migration needs ahead of enforcement.
On July 22, Microsoft announced KMS Hardware-Secured, a change that requires Windows Key Management Service servers to use TPM-backed attestation instead of the prior software-only trust model. The requirement is intended to strengthen enterprise Windows volume activation by having KMS servers prove identity and integrity before activation completes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcewindowslatest.com
Open sourcewindowslatest.com
Open sourcehelpnetsecurity.com
Open sourcetechcommunity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.