Microsoft is strengthening its enterprise activation security measures by introducing Trusted Platform Module (TPM)-backed attestation for Windows Key Management Service (KMS). As of September 2022, Windows 10 and 11 users will be required to use a hardware-based trust solution to activate their operating systems. This new approach replaces the traditional software-only trust model, which relied solely on the operating system's software-based trust module. The TPM-backed attestation will provide a more secure and reliable activation process, reducing the risk of unauthorized access and tampering.
In addition to the security enhancements, Microsoft is also providing a phased rollout plan to help organizations transition to the new attestation model. The plan will involve a series of updates to the Windows KMS service, starting with a minimum of 5% of the total number of Windows 10 and 11 devices, with a gradual increase in the percentage of devices covered over the next few years. This approach will enable organizations to adapt to the new requirements while minimizing disruptions to their business operations.
As part of the rollout, Microsoft will also provide support for a variety of TPM-based attestation methods, including Intel's vPro and AMD's Ryzen Secure, to ensure compatibility with different hardware platforms. This will allow organizations to choose the attestation method that best suits their specific needs and infrastructure.