Notebookcheck Logo

Windows 11: Microsoft's new TPM rule does not affect your PC

Close-up of a keyboard with the Windows key in focus
ⓘ Ruben Boekeloo / Pexels
KMS Hardware-Secured verifies the activation server via TPM, not the individual computer.
Microsoft is linking Windows volume activation to the TPM chip. This led to reports over the weekend that pirated versions of Windows 11 would soon stop working. The blog post from July 22 does not say that. KMS servers in companies are affected, not individual computers. What was actually announced and when it takes effect.

Since the weekend, reports have been circulating that Microsoft is finally putting a stop to pirated Windows 11 installations. This was triggered by a post on the Windows IT Pro blog dated July 22. It discusses TPM, the security chip on the motherboard, and Windows activation. However, the post actually says something different from what the headlines claim.

What KMS actually is

Companies do not activate Windows one computer at a time through Microsoft. Instead, they run their own in-house server, the Key Management Service, or KMS for short. Every PC on the network queries this server and receives its activation. This saves effort but has a weakness. Until now, a KMS host has identified itself solely through its software configuration, and that can be copied.

According to Microsoft, that’s exactly what’s happening. Attackers set up fake or cloned KMS servers that pose as genuine ones within the corporate network and license machines that nobody has paid for. This creates a licensing and compliance problem for the company.

What Microsoft is doing about it

The new feature is called KMS Hardware-Secured and requires the KMS host to provide TPM attestation. The Trusted Platform Module (TPM) is a chip on the motherboard that can cryptographically verify the hardware’s identity and confirm that it has not been tampered with. The server must prove two things before it is even allowed to issue a license: its hardware identity, which Microsoft verifies, and that the platform has remained unchanged since then. If it fails either of these checks, it will no longer be able to activate anything.

The timeline, and what applies now

None of this is in effect yet. Starting in August 2026, Windows Server 2025 will simply display notifications indicating whether a host is ready. These notifications can be viewed using the command `slmgr /dlv` and in Event Viewer under Applications and Services Logs, Key Management Service. One message states that the device is suitable as a KMS host with hardware-based security; the other states that it does not meet the requirements.

TPM attestation will not become mandatory until the next Windows Server version released via the Long-Term Servicing Channel (LTSC). Microsoft has not specified a date for this. Until then, existing KMS installations will continue to operate as usual. If you want to check whether your hardware is compatible, you can do so in PowerShell with administrator privileges using the command `Get-TpmSupportedFeature -FeatureList "Key Attestation"`. If the server responds with "Key Attestation," the feature is available.

Why your computer has nothing to do with this

And that brings us to the point where the reporting has gone off the rails. KMS Hardware-Secured checks the server, not the client. Nothing happens on the PC in front of you. Anyone running Windows for personal use won’t notice the change, regardless of their license type.

The misunderstanding stemmed from a second point. Microsoft had rendered an activation method called KMS38 unusable at the end of 2025, leading to the expectation that the next change would follow. However, KMS38 had nothing to do with KMS servers or TPM. The method exploited a Windows upgrade support file to simulate a distant expiration date. Microsoft has previously removed instructions for bypassing the TPM check from its own support documentation, so this issue is not new.

Even the workaround that actually has “KMS” in its name is not affected. It does not contact a real KMS host, but instead launches a fake server on the user’s own computer that simply approves the request. There is no component that could perform a TPM check. The methods in widespread use today operate on an entirely different principle anyway.

The fact that TPM isn’t always as mandatory in Windows 11 as it sounds was already evident when upgrading older computers.

Who really needs to take action now

Administrators are affected, and even among them only those with their own KMS host. For physical servers, Microsoft requires that the device be certified in the Windows Server Catalog and have a TPM installed and enabled. There are currently no requirements for virtual KMS hosts. Microsoft plans to provide these details in a later post, so it has not yet published the rules for this scenario itself.

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
Comment on this article
> Expert Reviews and News on Laptops, Smartphones and Tech Innovations > News > News Archive > Newsarchive 2026 07 > Windows 11: Microsoft's new TPM rule does not affect your PC
Steffen Zahn, 2026-07-28 (Update: 2026-07-28)