Microsoft is expanding the role of the Trusted Platform Module required for Windows 11 by adding TPM-based attestation to Key Management Service, or KMS. The extra security step is meant to verify the identity of KMS host hardware before activation is allowed.

The change is aimed at KMS activation piracy. By linking approval more closely to trusted hardware, Microsoft appears to be making it harder for unauthorized activation setups to imitate legitimate systems.

It also shows how the company is pushing hardware-backed security deeper into core Windows features. Since TPM has already become a key requirement for Windows 11, Microsoft is now using that same component as another layer in its activation and licensing controls.

The report suggests the piracy scene has already reacted, with a new method called TSforge appearing as a response. That points to the same ongoing pattern seen in software protection: stronger defenses from Microsoft followed quickly by new attempts to bypass them.