Microsoft is putting the TPM chip it requires for Windows 11 to another use. The company has announced TPM-based attestation, a new security layer for Key Management Service (KMS), the activation system enterprises use to license Windows across large fleets of devices.
Starting with the next Windows Server release, the feature will become mandatory, and Microsoft is beginning to push readiness notifications to Windows Server 2025 users from August 2026 to give organizations time to prepare.
Popular Now: GTA 6 physical copies in Japan have a 170-day expiration dateKMS has been a persistent target for abuse. Pirates have long spun up fake KMS servers that mimic legitimate Microsoft activation infrastructure, effectively tricking Windows into believing it has been properly licensed. The Online KMS method used by the Massgrave collective, for example, keeps activations alive by periodically contacting a spoofed server every six months. TPM-based attestation is designed to make that approach significantly more difficult.
The new system works in three steps. First, it verifies the hardware identity of the KMS host, confirming Microsoft has recognized the server as a legitimate physical device. Second, it checks that the host has not been tampered with. Only after passing both checks is the KMS server permitted to handle activation requests from client devices. The cryptographic verification runs through the TPM chip, making it considerably harder to fake than the software-level checks that existing piracy tools have been bypassing for years.
However, pirates have already responded by releasing a new method called TSforge Activation, which reportedly targets Microsoft's DRM architecture more broadly rather than relying on KMS emulation at all. The move is primarily aimed at enterprise environments and affects the KMS activation path specifically.

Frequently Asked Questions
TweakBot answers common questions about this news using TweakTown's own coverage from this page and related content from our archive. Tap a question to reveal the answer, or type your own below.
When does Microsoft plan to make TPM-based attestation mandatory for KMS in Windows Server?
Which versions or releases of Windows Server and client Windows are affected by this TPM attestation requirement?
What specific checks does TPM-based attestation perform on a KMS host before allowing activations?
How does TPM-based attestation make spoofed or emulated KMS servers harder to use for piracy?
Have a question not listed here? Ask below and TweakBot will answer it.
That said, many users have historically relied on KMS emulation tools for personal activations, and those methods will become increasingly unreliable as the new requirements take hold. It also means the same TPM requirement that became synonymous with Windows 11 compatibility is now playing a direct role in Microsoft's licensing enforcement strategy, a possibility critics raised when the requirement was first introduced.






