Microsoft is using TPM chips to crack down on pirated Windows activations
Microsoft Tightens Measures Against Pirated Windows Activation
Tech Spot. Microsoft recently announced a brand-new addition to Key Management Service (KMS), a standard feature for mass activation of Windows devices in enterprises and other large-scale organizations. The KMS feature will soon rely on hardware-based security, using TPM’s encryption (Trusted Platform Module) “brain” to verify the legitimacy of the server hosting KMS data.
Microsoft explained that attackers have traditionally abused KMS to spoof the activation process, which is both a security issue and a way for individual users to avoid paying for a new Windows license. The new “TPM-based attestation” option will use the TPM for verifying the cryptographic proof of the integrity of a KMS server.
Read also
TPM-based attestation will first check the hardware identity of the KMS host, proving that the server has been verified by Microsoft as a legitimate hardware device. Then, the feature will confirm that the KMS host has not been tampered with in any way. Finally, the TPM chiplet will let the now-verified KMS host manage the mass activation requests required by the organization.
Read more at the source

















































