Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.
A hot potato: After introducing Windows 11, Microsoft forced the entire PC ecosystem to turn the Trusted Platform Module (TPM) into a standard component for every new motherboard or CPU. Now, Redmond is exploiting the now-pervasive device to further strengthen the Windows activation process in the enterprise market.
Microsoft recently announced a brand-new addition to Key Management Service (KMS), a standard feature for mass activation of Windows devices in enterprises and other large-scale organizations. The KMS feature will soon rely on hardware-based security, using TPM's encryption "brain" to verify the legitimacy of the server hosting KMS data.
Redmond explained that attackers have traditionally abused KMS to spoof the activation process, which is both a security issue and a way for individual users to avoid paying for a new Windows license. The new "TPM-based attestation" option will use the TPM for verifying the cryptographic proof of the integrity of a KMS server.







