فا
MSLicenseHub

KMSKey Management Service

Category: activation

Last reviewed by the MSLicenseHub Licensing Desk.

Key Management Service (KMS) is a local activation model used by organizations to activate Microsoft software—specifically Windows and Office—on their own internal network without requiring individual devices to connect to Microsoft’s hosted activation servers. It functions by designating a local server as the KMS host, which validates and manages the licenses for all "KMS client" devices within the corporate environment.

Technical Architecture and Operational Mechanics

KMS operates on a client-server model utilizing a specific Volume License Key (VLK) called a Customer Specific Volume License Token (CSVLK), also known as the KMS Host Key. Once the host is activated with Microsoft, it provides activation services to other devices on the network via Domain Name System (DNS) auto-discovery or manual configuration.

A critical characteristic of KMS is the activation threshold. The service does not begin issuing active status until a minimum number of unique physical or virtual machines check in. These thresholds are:

  • Windows Client (Pro/Enterprise): 25 machines.
  • Windows Server: 5 machines.
  • Microsoft Office: 5 machines.

Until these thresholds are met, devices remain in a 30-day grace period. Once activated, the client device must "check in" with the KMS host at least once every 180 days to renew its activation. If a device fails to communicate with the host for longer than 180 days, it eventually enters a 30-day grace period before losing its activated status.

Context within Licensing Agreements

The term KMS typically appears in the Microsoft 365 Admin Center under the "Download & Keys" section or within a Volume Licensing Service Center (VLSC) report. On a formal quote or agreement (such as an Enterprise Agreement or MPSA), you will not see "KMS" as a line item; rather, it is presented as a fulfillment method included with Volume License media. It is frequently contrasted with the Multiple Activation Key (MAK), which is a one-time activation method more suitable for disconnected devices.

Common Misunderstandings

  • Legal Entitlement vs. Technical Activation: Activating a machine via KMS does not inherently mean the organization is compliant. KMS is a technical mechanism; legal compliance is determined by having the appropriate number of licenses (base licenses plus upgrade rights) purchased through a valid program.
  • Internet Access: A common misconception is that KMS clients need internet access. Only the KMS Host requires a one-time connection to Microsoft to activate itself; the clients only need to see the Host on the local network.
  • OEM vs. Volume Licensing: KMS cannot be used to activate OEM licenses (licenses pre-installed by hardware manufacturers). OEM licenses are tied to the specific hardware they arrived with and use a different activation path (OA 3.0). KMS is exclusively for Volume Licensing editions.

Practical Implications for Procurement

When purchasing Microsoft software, choosing KMS means you are committing to maintaining internal infrastructure. It is the gold standard for high-security environments or large corporate fleets where devices are consistently connected to the LAN or a VPN. However, for organizations with a highly mobile workforce that rarely connects to the corporate network, KMS can lead to "activation expiry" issues. In such cases, modern alternatives like Active Directory-Based Activation (ADBA) or Subscription-Based Activation (linked to a user's Entra ID login) are often preferred to reduce the administrative overhead of maintaining a KMS host.

Need this in a quote?

Our team translates glossary concepts into concrete licenses, part numbers and price lists.

Request a quote