Microsoft reportedly using TPM chips to weed out Windows piracy

Microsoft’s Trusted Platform Module, specifically TPM 2.0, has been part of Windows 11’s system requirements since the operating system’s introduction in 2021. Now that the TPM is ubiquitous, being included with most CPUs for many years, Microsoft is looking to leverage it “to activate Windows devices at scale.”

Currently, the enterprise sector activates Windows via Microsoft’s Key Management Service (KMS), but according to the Windows IT Pro Blog, “modern organizations increasingly require stronger assurances around device identity and activation integrity.” Basically, hackers can already clone or fake KMS server software, so the TPM is intended to provide a hardware-level security check to curb this.

The blog post then very briefly breaks down how TPM attestation works. Essentially, the KMS host flashes its TPM credentials to prove its hardware identity. These TPM credentials also reveal whether the KMS host has been tampered with or not, and Microsoft checks these before it allows the host to activate any devices. When everything appears to be in order, the KMS host will be allowed to “securely serve activation requests for Windows devices in the organization.”

Microsoft goes on to say, “Starting with upcoming Windows Server releases, KMS hosts must prove they are running on verified, uncompromised hardware before activating clients.”

Basically, TPM-attestation will become mandatory for KMS hosts at some point in the future. That doesn’t mean loads for most of us PC gamers with presumably totally legitimate copies of our operating system of choice. But hey, maybe you dabble in the dark art of system administration professionally and this is actually good to know. That said, I must admit the wording ‘starting with’ gives me the creeps.

At any rate, from August 2026 “Windows Server 2025 will provide readiness messaging to help administrators assess whether a KMS host is ready for hardware-based security, giving teams time to plan upgrades before enforcement begins.”

With even the vaguest notion of the hardware environments some sysadmins are compelled to shepherd, I’m wishing them only the best on their upcoming migration. Here’s hoping it’s at worst only a medium-sized headache, and one that doesn’t spread to our poor civilian PCs.