Illustration of a Windows 11 2026 clean installation showing Microsoft Store app privacy data retained after formatting, with secure local storage, Microsoft cloud synchronization, and account data persistence represented by security, cloud, and storage icons.

Microsoft Store App Privacy: Why History Survives a Clean Install

Microsoft Store app privacy is more complicated than most users realise. Do a full clean install of Windows 10 โ€” boot from USB, format the entire drive โ€” sign back into your Microsoft account, and open the Store. Years of app installations are already listed, waiting for you (or anyone else using that machine). No local data survived the wipe, yet the history is all there. This article explains exactly why it happens, what data Microsoft stores in the cloud, and the concrete steps you can take to prevent it.

Why Your Store App History Survives a Full Format

Cloud storage keeping Microsoft Store app history separate from local device data

Your Microsoft Store app history is not stored on your local drive โ€” it is stored against your Microsoft account in the cloud. When you sign in with a Microsoft account, the Store automatically pulls your full acquisition history from Microsoft’s servers, regardless of what happened to the device underneath it. The operating system version, whether you formatted once or five times, or whether you switched to a brand-new machine entirely โ€” none of that matters. The history lives in your account, not on your SSD.

This is by design. Microsoft treats app purchases and free acquisitions like a library: once an app is tied to your account, you can re-download it on any compatible device at any time. A handy feature for software continuity โ€” a significant privacy concern when you want a genuinely clean start.

What Exactly Is Recorded Under Your Account

The data that persists includes every app you have ever installed or purchased from the Microsoft Store, going back to whenever you first created your account. According to Microsoft’s own support documentation on order history, all purchases and free acquisitions are logged against your account billing record. This covers:

  • Free apps you downloaded (games, utilities, productivity tools)
  • Paid apps and any in-app purchases
  • Apps installed on previous devices you no longer own
  • Apps from accounts tied to old email addresses you’ve since linked
  • Apps installed by other users who signed in on the same machine

Because the Microsoft Store has been integrated into Windows since Windows 8 (launched in 2012), some accounts carry over a decade of installation history โ€” easily hundreds of entries.

The Real-World Privacy Risk of Persistent Store App History

Microsoft Store app privacy dashboard showing stored app history and clear option

Windows app privacy matters most in scenarios people don’t always anticipate. Selling or donating a laptop is an obvious one: even after a clean reinstall, the next user can simply sign in to see what apps were associated with the machine’s previous owner if credentials are ever shared or guessed. More subtly, anyone who shares a Microsoft account โ€” family members, a small business where staff use the same sign-in โ€” can see a full log of what everyone has downloaded.

There is also the profiling angle. Your app installation history forms part of the behavioural data Microsoft holds on your account. The Microsoft Privacy Statement confirms that personal data associated with your account includes device and usage data as well as activity-related information โ€” data that can inform advertising targeting and product recommendations across Microsoft’s ecosystem.

How to Check What Microsoft Store History Is Stored

Before clearing anything, it is worth seeing the full picture. Here is how to review your Microsoft Store history right now:

  1. Open the Microsoft Store and click your profile icon in the top-right corner.
  2. Select Library โ€” this shows all apps ever associated with your account, not just the ones currently installed.
  3. For a broader view, visit account.microsoft.com/billing and navigate to Order history. This lists every Store transaction, including free acquisitions.
  4. For the full data picture, go to account.microsoft.com/privacy (Microsoft’s Privacy Dashboard) and review your app and service activity data.

Most users are surprised by the volume. Hundreds of app entries accumulated over years are common for anyone who has used Windows 10 or Windows 11 since launch.

Step-by-Step: How to Reduce Your Windows App Privacy Footprint

Windows app privacy settings screen disabling activity history sync in Windows 11

A clean install alone will not solve a Microsoft Store history problem. These are the steps that actually work.

1. Clear Data via the Microsoft Privacy Dashboard

Head to account.microsoft.com/privacy and sign in. Microsoft’s Privacy Dashboard lets you view and delete various categories of stored activity data. Look for app and service activity, and use the clear function to remove entries. Note that purchase records for paid apps cannot be deleted (they are required for licence verification), but activity data for free acquisitions can be reduced.

2. Sign in with a Local Account Instead of a Microsoft Account

This is the single most effective change you can make for Windows app privacy. When you use a local account, the Microsoft Store cannot link your app activity to a persistent cloud profile. To switch:

  • Go to Settings โ†’ Accounts โ†’ Your info and select Sign in with a local account instead.
  • Complete the wizard and restart.
  • You can still use the Store by signing in just for that session, without permanently tying history to a cloud account.

The trade-off is losing features like cross-device sync and OneDrive integration, so consider whether those are features you use.

3. Create a Fresh Microsoft Account for Clean Installs

If you want cloud features but not decades of history, creating a new Microsoft account on a new device or after a reinstall gives you a genuinely clean slate in the Store. Free โ€” just a new email address. Useful when selling or donating a machine.

4. Disable Activity History in Windows Settings

In Windows 10 and Windows 11, navigate to Settings โ†’ Privacy โ†’ Activity history and toggle off Store my activity history on this device and Send my activity history to Microsoft. This does not delete past history but stops new activity from being recorded going forward.

5. Review App Permissions Before and After a Reinstall

Each time you do a fresh install, visit Settings โ†’ Privacy and audit which apps have access to your location, microphone, camera, and contacts. A reinstall resets some permission states, but linked cloud data means the apps themselves still know your history once you sign in.

Does This Affect Windows 11 as Well?

Yes โ€” and arguably more so. Windows 11 pushes users more aggressively towards Microsoft accounts during setup, making it harder to opt for a local account during the out-of-box experience. The Microsoft Store is also more deeply integrated into Windows 11, meaning Microsoft Store history is more likely to be pulled automatically at sign-in. The same privacy steps above apply, but local account setup on Windows 11 requires an extra step: on the network screen during install, press Shift + F10 to open a command prompt and type OOBE\BYPASSNRO to enable the “I don’t have internet” option, which allows local account creation.

If you are considering upgrading or doing a fresh install of Windows 11, Buy Now Key stocks genuine Windows 11 Pro Retail licences โ€” a clean, properly activated copy is the right foundation for managing your privacy settings from the start.

Should Microsoft Change How Store App History Works?

The Reddit thread that brought this issue to wider attention in 2025 sparked a clear consensus: users expect a full drive format to mean a fresh start. The fact that cloud-synced Store app history contradicts that expectation is a transparency problem, not just a technical quirk. Many commenters noted they had no idea the history was being stored at all, let alone that it would reappear automatically after a reinstall.

Microsoft does provide tools to manage this data โ€” the Privacy Dashboard exists precisely for this purpose โ€” but they are not surfaced during setup or during the clean-install process. A prompt at first sign-in saying “Your previous app history is available โ€” would you like to restore it or start fresh?” would be a straightforward improvement. Until that happens, users have to take matters into their own hands using the steps above.

Windows 10 Users: Your Licence and Your Privacy

If you are running Windows 10 and have been putting off getting a legitimate licence before the end-of-support deadline, now is a sensible time to sort both your activation and your privacy settings. Buy Now Key offers Windows 10 Pro OEM licences from โ‚ฌ8.90 โ€” a straightforward way to get a properly activated system on which you can immediately apply the privacy controls described in this guide.

Frequently Asked Questions

Does formatting my hard drive delete my Microsoft Store app history?

No. Formatting your drive and reinstalling Windows removes all local data, but your Microsoft Store app history is stored against your Microsoft account in the cloud. The moment you sign back in with that account, the history reappears automatically. To remove it, you need to use Microsoft’s Privacy Dashboard at account.microsoft.com/privacy.

Can I use the Microsoft Store without a Microsoft account?

You can browse the Store without an account, but downloading most apps requires signing in. Using a local Windows account and signing into the Store only when needed โ€” rather than keeping a permanent sign-in โ€” is the best middle ground for reducing persistent history tracking.

How do I delete my Microsoft Store purchase history?

Free app acquisitions and activity data can be cleared via the Microsoft Privacy Dashboard (account.microsoft.com/privacy). Paid purchase records cannot be deleted, as Microsoft retains them for licence and billing purposes. You can review what is stored under the “App and service activity” section of the dashboard.

Does Windows 11 have the same Microsoft Store history problem?

Yes. Windows 11 is even more tightly integrated with Microsoft accounts than Windows 10, meaning Store app history syncs automatically at sign-in. The same steps apply: use a local account where possible, or regularly clear activity data via the Privacy Dashboard. Windows 11 also makes local account setup harder during installation, requiring an extra workaround during the out-of-box experience.

Will switching to a local account delete my existing Microsoft Store history?

No โ€” switching to a local account on your device does not delete data already stored in the cloud against your Microsoft account. It simply prevents new activity from being automatically linked and displayed going forward. To delete the stored history itself, you need to log into account.microsoft.com/privacy and clear it there.

Fake Windows 11 apps download site displaying malware warning signs on laptop

Fake Windows 11 Apps: How to Spot Malware Download Sites

Fake Windows 11 apps are one of the fastest-growing threats on the internet right now โ€” and if you’ve ever Googled a utility like PowerToys or CrystalDiskMark, you may have already landed on one. Security researchers have identified more than 70 lookalike websites actively impersonating legitimate Windows app distributors, serving up trojanised installers packed with password-stealing malware, remote-access trojans, and spyware. This guide walks you through every red flag you need to recognise, and exactly what to do when something doesn’t look right.

Why Fake App Sites Are Booming in 2026

Comparison of legitimate versus fake Windows app download websites side by side

Cybercriminals have always followed traffic, and right now, Windows utility apps attract enormous search volumes. Tools such as PowerToys, Wintoys, WinUtil, and CrystalDiskMark are searched millions of times a month by users wanting to customise or maintain their PCs. Attackers clone the real sites pixel-for-pixel โ€” same logos, same screenshots, same changelogs โ€” then buy search ads or exploit SEO loopholes to push their clones above the genuine results. One click on the wrong “Download” button is all it takes.

According to a July 2026 investigation by Windows Latest, over 70 confirmed malware download sites were live and ranking in Google at the time of publication. The payload varied site to site: some dropped remote-access trojans (RATs) that hand full control of your machine to an attacker; others installed info-stealers that silently harvest saved passwords, credit-card numbers, and browser cookies within minutes of execution.

Red Flags That Identify Fake Windows Apps and Download Sites

Spotting malware download sites before you click is a learnable skill. The following warning signs appear on the vast majority of fraudulent pages โ€” train yourself to check them every time you download software.

1. The Domain Name Is Slightly Off

Legitimate developers own one canonical domain. Fake app sites register look-alikes: an extra hyphen (power-toys-official.com), a swapped letter (crysta1diskmark.net), an unusual country-code TLD (powertoys.top), or an extra word like -download or -free appended to a real brand name. Always compare the URL character by character against the developer’s official page before you download anything.

2. The Download Button Doesn’t Match the Real File Size

Real installers for Windows utilities are usually between 5 MB and 200 MB depending on the application. If the file that starts downloading is only a few hundred kilobytes, it is almost certainly a dropper โ€” a tiny loader whose sole job is to fetch and run the actual malware payload after it lands on your machine. Always cross-reference expected file sizes on the real developer’s GitHub or official page.

3. No HTTPS or an Untrusted Certificate

Every reputable software distributor uses HTTPS with a valid, trusted SSL certificate. Click the padlock icon in your browser’s address bar and inspect who issued the certificate. Fake app sites often use free, auto-issued certificates (perfectly valid technically, but trivially easy for anyone to obtain) under a domain name that does not match the software brand. A mismatch between the certificate’s registered domain and the brand name you’re expecting is a hard stop โ€” leave the page immediately.

4. Aggressive Pop-Ups and Fake “Your PC Is at Risk” Alerts

Malware download sites frequently inject JavaScript pop-ups that mimic Windows Security notifications, claiming your PC is already infected and urging you to download a fix. Windows never displays security alerts inside a web browser. If a website pops up a dialogue that looks like a system notification, close the browser tab โ€” do not interact with the dialogue, download anything, or call any phone number displayed.

5. Multiple Competing Download Buttons

A classic dark pattern on fake app sites is placing several large, bright “Download Now” buttons on a single page โ€” only one of which (if any) leads to the real file. The others trigger malware downloads, adware installers, or redirects to phishing pages. Legitimate developer pages usually have one clear, unambiguous download link.

6. Missing or Unverifiable Publisher Information

Genuine Windows installers are code-signed. When you run a downloaded .exe or .msi file, Windows displays a User Account Control (UAC) prompt showing the publisher’s name. If the publisher is listed as “Unknown” or shows a name that doesn’t match the software brand, cancel the installation and delete the file immediately. Verified publishers appear in blue on the UAC prompt; unverified publishers appear with a yellow warning shield.

7. Poor Grammar, Mismatched Logos, or Copied Content

Site cloners work fast and often miss small details: broken image links, slightly faded logos, timestamps that haven’t updated since 2024, or boilerplate legal text copy-pasted from an unrelated product. Read the page critically. If the “About” section describes a completely different app, or if there are obvious grammar errors in what is supposed to be an English-language site operated by a well-funded developer team, treat that as a strong signal the page is fraudulent.

How Fake App Sites Game Google Search Results

Fake Windows apps flagged by Windows UAC unknown publisher warning prompt

Understanding why these pages appear at the top of search results helps you develop better habits. Attackers use three primary techniques:

  • Paid search ads: They buy Google Ads keywords on the exact brand names of popular utilities. These ads often appear above the organic results, and the display URL can be made to look legitimate while the destination is a clone site.
  • SEO poisoning: Fake sites build artificial backlink networks to rank organically for high-volume queries like “download PowerToys Windows 11” or “CrystalDiskMark free download”.
  • Typosquatting: They register dozens of slight misspellings of popular app names and let organic traffic trickle in from users who mistype the URL directly in the address bar.

The practical takeaway: do not trust search-result position alone. The first result โ€” even a sponsored one โ€” can be a malware download site. Always navigate to the developer’s official domain directly, or bookmark it after your first verified visit.

How to Verify a Windows App Download Is Genuine

Before running any downloaded installer, run through this quick verification checklist:

  1. Check the official source. GitHub repositories (look for the verified tick next to the developer’s organisation name), Microsoft’s own app pages, or the Microsoft Store are the safest places to download Windows utilities.
  2. Scan the file on VirusTotal. Go to virustotal.com and upload the installer before running it. VirusTotal scans the file against 70+ antivirus engines simultaneously and returns a verdict in seconds. Any detection should be treated as a serious warning.
  3. Check the SHA-256 hash. Many developers publish the cryptographic hash of their official installer on their download page or GitHub release. Download a tool like CertUtil (built into Windows) to compute the hash of your downloaded file and compare it character by character. A mismatch means the file has been altered.
  4. Review the UAC prompt. Before clicking “Yes” on the installation prompt, read the publisher name carefully. A verified publisher displayed in blue is a strong positive signal.
  5. Use Windows Defender or Microsoft Security Intelligence. Keep Windows Security updated and run a quick scan immediately after installing any new software.

Apps Most Commonly Impersonated by Malware Sites

The July 2026 campaign targeted a specific cluster of popular Windows utilities. If you have recently downloaded any of the following from a non-official source, run a full scan immediately:

  • Microsoft PowerToys
  • Wintoys
  • CrystalDiskMark
  • WinUtil (Chris Titus Tech’s Windows utility)
  • Rufus
  • Ventoy
  • CPU-Z and GPU-Z
  • HWiNFO
  • NirSoft utilities

These are all legitimate, well-respected tools โ€” the risk comes entirely from downloading them through unofficial lookalike pages rather than from the developers themselves.

What to Do If You’ve Already Downloaded from a Fake App Site

Security checklist to protect against malware download sites on Windows 11

If you suspect you’ve already run a trojanised installer, act fast. Malware of this kind can exfiltrate saved credentials within minutes of execution.

  1. Disconnect from the internet immediately to cut off any active data-exfiltration or remote-access channel.
  2. Run a full offline scan using Windows Defender Offline (accessible through Windows Security โ†’ Virus & threat protection โ†’ Scan options).
  3. Change passwords for all important accounts from a different, clean device โ€” email, banking, Microsoft account, social media โ€” before reconnecting the infected machine.
  4. Enable multi-factor authentication (MFA) on every account that supports it, so stolen passwords alone cannot grant access.
  5. Consider a clean Windows reinstall. For sophisticated RATs and rootkits, a full OS reinstall from verified media is the only way to guarantee the machine is clean.

Why Your Windows License Source Matters Just as Much

The same vigilance that applies to third-party app downloads also applies to where you buy your Windows 11 licence. Fake app sites and rogue key sellers operate from the same playbook: clone a legitimate-looking storefront, take your money (and your payment details), and deliver either nothing at all or a blacklisted key that stops working within weeks.

Buying from a genuine Windows 11 Pro licence source that offers transparent activation guarantees and verifiable customer support removes that risk entirely. At Buy Now Key, every key is sourced from authorised distributors, backed by a money-back guarantee if activation fails, and delivered instantly to your inbox โ€” no shady download portals required. You can also explore the full range of Windows 11 Pro editions to find the right licence for your setup.

According to the Windows Latest investigation into fake Windows app sites, popular utilities including PowerToys and CrystalDiskMark had more than 70 active clone sites as of late July 2026 โ€” a number that is almost certainly growing. The campaigns are well-resourced and difficult for Google to purge in real time, which means user vigilance remains the most reliable defence.

Building Long-Term Habits Against Malware Download Sites

Individual awareness is the most durable protection against fake app sites. Search engines and browser vendors are continuously improving their detection, but attackers adapt faster than the filters. The habits below cost nothing and take seconds to build into your routine:

  • Bookmark verified sources the first time you visit a developer’s real page โ€” never rely on search results again for that app.
  • Use the Microsoft Store where possible. It isn’t perfect, but apps distributed through it go through a vetting process that direct-download sites bypass entirely.
  • Keep Windows Update current. Many RAT payloads exploit known OS vulnerabilities that patches have already fixed. A fully updated Windows 11 machine is significantly harder to compromise.
  • Install a browser extension like uBlock Origin to block malicious ad networks โ€” the same networks that serve search ads for fake app sites.
  • Treat urgency as a red flag. Any page that says you must download something “right now” to fix a critical problem is almost certainly lying. Legitimate software updates do not work this way.

FAQ

How can I tell if a Windows app download site is fake?

Check the domain name carefully for extra hyphens, swapped letters, or unusual TLDs. Verify the SSL certificate matches the brand, look for a single clear download button rather than multiple competing ones, and check that the downloaded file’s size matches what the official developer publishes. When in doubt, scan the file on VirusTotal before running it.

Which Windows apps are most commonly cloned by malware sites?

The July 2026 campaign targeted over 70 utilities, with PowerToys, Wintoys, CrystalDiskMark, WinUtil, Rufus, and CPU-Z among the most heavily impersonated. These are all legitimate, widely used tools โ€” the risk is entirely in downloading them from unofficial sources rather than from the developers’ own pages or GitHub repositories.

What should I do if I accidentally ran a fake app installer?

Disconnect from the internet immediately to interrupt any active data exfiltration. Run a Windows Defender Offline scan, then change all important passwords from a separate clean device before reconnecting. Enable multi-factor authentication on every account that supports it. If you suspect a rootkit or RAT, a clean Windows reinstall from verified media is the safest resolution.

Does Windows Defender protect against fake app malware?

Windows Defender (Windows Security) catches a significant proportion of known malware, but attackers frequently repackage payloads to evade signature-based detection for a window of several days after deployment. Combining Defender with a pre-execution VirusTotal scan and verifying file hashes against the developer’s published values gives much stronger protection than any single tool alone.

Is it safer to buy Windows 11 from a key reseller than to download a cracked version?

Absolutely. Cracked Windows images are one of the oldest and most effective malware distribution vectors โ€” the malicious code is embedded in the image itself, so no amount of post-install scanning will fully remove it. Purchasing a genuine licence from a reputable reseller gives you a clean, Microsoft-activated installation with none of that risk. Look for resellers that offer a money-back activation guarantee and have verifiable customer support.

TPM 2.0 chip powering Windows activation enforcement on a secure server

TPM Activation Enforcement in 2026: What Really Changes for Windows Users

TPM activation enforcement is the buzzword dominating tech headlines in mid-2026 โ€” and understandably so. Microsoft announced it will require TPM 2.0-backed hardware attestation for Key Management Service (KMS) hosts starting in August 2026. But here is the critical detail most coverage glosses over: this change targets enterprise KMS servers, not individual home users running a retail or OEM Windows licence. If you bought a genuine Windows key, your day-to-day experience changes very little. Read on for the full picture.

What Is TPM Activation Enforcement, Exactly?

Detailed diagram of a TPM 2.0 chip on a modern motherboard with labels showing hardware attestation flow to a KMS server, clean tech-infographic style, no dates visible

TPM activation enforcement refers to Microsoft’s new rule requiring that servers responsible for activating Windows across large networks โ€” called KMS (Key Management Service) hosts โ€” must possess a verified, uncompromised Trusted Platform Module 2.0 chip before they can issue activation tokens. According to Microsoft’s own Windows IT Pro Blog post on strengthening KMS with hardware-based trust, TPM attestation will become mandatory for KMS Hardware-Secured activation with the next Windows Server LTSC release, with readiness messages appearing from August 2026.

In plain terms: the KMS server must prove to Microsoft’s cloud infrastructure that its hardware hasn’t been tampered with. A fake or software-emulated TPM will no longer pass the check. This is a server-side enforcement mechanism, not a new gate installed on your personal PC.

How KMS Activation Works โ€” and Where Piracy Entered the Picture

KMS activation is the method large organisations use to activate hundreds or thousands of Windows installations without entering individual product keys on every machine. An IT department sets up a KMS host server; client PCs on the network contact that server every 180 days to renew their activation status.

The piracy angle emerged because bad actors set up rogue KMS servers โ€” software tools that mimic legitimate KMS hosts โ€” allowing unregistered Windows copies to “phone home” to a fake server rather than Microsoft’s own infrastructure. These tools have circulated for years, and some estimates from security researchers put the number of enterprise environments unknowingly running pirated volume licences in the hundreds of thousands globally.

  • Legitimate KMS host: a Windows Server 2025 machine with a valid Volume Licence Agreement and a genuine TPM 2.0 chip, registered with Microsoft.

  • Rogue KMS emulator: software running on any machine, spoofing the KMS protocol to hand out fake activation tokens.

  • New enforcement: from August 2026, the KMS host must pass a TPM attestation check; a software emulator cannot provide a real TPM signature, so it fails.

The result is that KMS-based piracy in enterprise environments becomes significantly harder to sustain. Whether it eliminates the problem entirely remains to be seen โ€” determined attackers often find workarounds โ€” but the barrier to entry rises considerably.

Does TPM Activation Enforcement Affect Home Users?

Side-by-side comparison graphic showing enterprise KMS server environment versus a home user desktop setup, highlighting which is affected by TPM activation enforcement in 2026, flat vector illustration style

No โ€” and this is where conflicting reports have created unnecessary panic. Windows activation for home users relies on a completely different path called online activation or phone activation, tied to a retail or OEM product key. Your PC contacts Microsoft’s activation servers directly over the internet; no KMS host is involved at any point. The August 2026 KMS TPM requirement simply does not touch this flow.

As TechSpot’s coverage of Microsoft’s TPM crackdown on Windows piracy makes clear, the enforcement specifically targets KMS hosts used in volume-licence environments. Home users, small business owners buying retail keys, and OEM device owners are unaffected.

What does apply to every consumer PC running Windows 11 is the pre-existing TPM 2.0 requirement introduced at launch in 2021. Windows 11 has always required a TPM 2.0 chip to install and activate โ€” that’s not new, and it hasn’t changed. If your machine already runs Windows 11, it already has a functioning TPM 2.0.

Windows Activation Methods: Which One Do You Use?

Understanding your own Windows activation method removes any lingering uncertainty. There are three main types:

  1. Retail / Digital Licence: You purchased a product key directly, or Windows was pre-activated on a new device and tied to your Microsoft account. Activation is handled peer-to-peer with Microsoft’s servers. Unaffected by KMS enforcement.

  2. OEM: A key embedded in your PC’s firmware by the manufacturer at the factory. Permanent, device-locked, and completely independent of KMS infrastructure. Unaffected.

  3. Volume / KMS: Used by businesses and educational institutions with Microsoft Volume Licensing agreements. This is the method under scrutiny. From August 2026, the KMS host server must pass TPM 2.0 attestation.

If you’re a home user or a small business owner who purchased individual Windows keys, you fall into category one or two. The new KMS TPM 2.0 requirement is irrelevant to your setup. To double-check your current activation status on any Windows 11 machine, go to Settings โ†’ System โ†’ Activation. A status of “Windows is activated with a digital licence” or “Windows is activated” confirms you’re on a retail or OEM path.

What Changes for IT Admins and Enterprise Teams

Screenshot-style illustration of a Windows 11 Pro genuine activation confirmation screen on a modern laptop, showing a valid licence status indicator, no calendar dates visible

For IT professionals managing Windows environments at scale, the August 2026 timeline demands attention. Windows Server 2025 KMS hosts will begin displaying TPM readiness messages from that date, and when the next Windows Server LTSC release ships, TPM attestation transitions from optional to mandatory.

Practical steps for enterprise teams include:

  • Audit all KMS hosts for TPM 2.0 presence and firmware TPM health โ€” use the tpm.msc console or PowerShell’s Get-Tpm command.

  • Ensure KMS hosts are running Windows Server 2025 with the latest cumulative updates applied.

  • Verify that Volume Licensing agreements are current and that KMS host keys are properly registered with Microsoft.

  • Replace or upgrade any server hardware that lacks a hardware-rooted TPM 2.0 chip.

  • Test KMS attestation readiness in a staging environment before the mandatory deadline.

Organisations that have inadvertently inherited rogue KMS infrastructure โ€” sometimes brought in by a previous IT contractor โ€” should treat this as an urgent remediation task. Failing the attestation check means client machines in the network will lose their KMS-granted activation on next renewal, which occurs every 180 days.

How to Get a Genuine Windows Licence the Right Way

Whether you’re a home user who wants peace of mind or a small business looking to bring devices into compliance, sourcing a legitimate Windows licence is the cleanest long-term solution. Genuine retail keys activate directly with Microsoft, are unaffected by any KMS enforcement changes, and remain valid for the lifetime of the device.

At Buy Now Key, you’ll find competitive pricing on genuine retail and OEM Windows licences. For example, a Microsoft Windows 11 Pro โ€“ Retail licence is available for just โ‚ฌ17.90 โ€” a fraction of the full Microsoft Store price โ€” and activates directly with Microsoft’s servers in minutes. If you’re running Windows 10 and not yet ready to upgrade, a Microsoft Windows 10 Pro OEM key (โ‚ฌ8.90) keeps you fully activated and secure until the October 2025 end-of-support date.

Choosing a legitimate licence means your activation is always tied to Microsoft’s own infrastructure โ€” no KMS host, no attestation gamble, no surprise deactivation when enforcement tightens.

Will Microsoft Ever Extend TPM Enforcement to Consumer Activation?

It’s a fair question, and the honest answer is: not announced, but not impossible. The KMS TPM attestation rollout gives Microsoft a proven technical framework for hardware-rooted verification. Whether that framework eventually extends to retail activation channels is speculative at this stage. Microsoft has made no such announcement for consumer products.

What we do know is that TPM 2.0 is already required on every Windows 11 device, so the hardware foundation is in place across the modern PC ecosystem. If Microsoft ever chose to layer additional attestation onto the consumer activation flow, most Windows 11 machines would already comply. For Windows 10 users still on older hardware without TPM 2.0, that theoretical future scenario would be an additional incentive to upgrade.

For now, the practical implication is simple: own a genuine licence, keep your Windows updated, and you have nothing to worry about regardless of how Microsoft’s activation architecture evolves.

FAQ

Will TPM activation enforcement deactivate my current Windows installation?

Only if your Windows was activated through a rogue or unauthorised KMS server in an enterprise environment. If you’re a home user with a retail or OEM licence activated directly with Microsoft, nothing changes. Your activation is independent of the KMS infrastructure being targeted by the new TPM rules.

What is the difference between KMS activation and retail activation?

KMS activation is a volume-licencing method used by businesses and institutions. Client machines contact an internal KMS host server every 180 days to maintain activation. Retail and OEM activation ties a product key directly to your device and your Microsoft account via Microsoft’s global servers. The TPM 2.0 requirement applies only to KMS hosts โ€” not to retail or OEM keys.

How do I check whether I have a genuine Windows licence right now?

Open Settings โ†’ System โ†’ Activation. If it reads “Windows is activated with a digital licence” or “Windows is activated” without a KMS-related note, you’re using a standard retail or OEM licence. You can also run slmgr /xpr in Command Prompt: a permanent-licence message confirms you’re not on a time-limited KMS renewal cycle.

Does TPM 2.0 requirement apply to Windows 10?

Windows 10 does not require TPM 2.0 to install or activate โ€” that requirement was introduced with Windows 11 in October 2021. However, the new KMS TPM attestation rules apply to KMS hosts running Windows Server 2025, regardless of which Windows client version those hosts are activating. Windows 10 clients in a KMS environment are indirectly affected if their host server fails attestation.

When exactly does the mandatory KMS TPM enforcement begin?

Windows Server 2025 KMS hosts will start showing TPM readiness warning messages from August 2026. Full mandatory enforcement arrives with the next Windows Server LTSC release. Microsoft has signalled organisations should treat the August 2026 readiness phase as preparation time before enforcement becomes absolute.

Laptop keyboard with Copilot key disable toggle in Windows 11 Settings

How to Disable the Copilot Key on Windows 11

You can now officially disable the Copilot key on Windows 11 โ€” no third-party hacks required. After months of user backlash, Microsoft has acknowledged the frustration and introduced a firmware-level toggle that lets you remap or completely silence the dedicated AI key that ships on most new Windows PCs. This guide explains exactly what changed, which devices support the new option, and every method available to reclaim that key right now.

Why Microsoft Finally Acted on the Copilot Key Backlash

Illustration comparing Copilot key interrupting workflow versus key disabled in Windows 11

When Microsoft introduced the Copilot key in early 2024, it became one of the most controversial hardware decisions the company had made in years. The key โ€” positioned where many users expected a right Ctrl key โ€” launched Copilot regardless of what you were doing, interrupting games, creative apps, terminal sessions, and anything else that relied on the bottom-right corner of the keyboard. Forum threads, Reddit posts, and developer communities filled up with complaints almost immediately.

For over a year, Microsoft’s official guidance amounted to: use PowerToys to remap it. That workaround worked inconsistently โ€” PowerToys’ Keyboard Manager failed to intercept the Copilot key in certain full-screen apps and games โ€” leaving a significant chunk of users effectively stuck with a key they never wanted. By mid-2026, the backlash had become impossible to ignore, and Microsoft quietly pushed a settings update that adds a native “do nothing” option for the Copilot key on supported hardware. It’s a modest concession, but it’s a real one.

What the New Firmware Toggle Actually Does

The new option appears inside Windows Settings and lets you assign the Copilot key to one of several actions โ€” including doing absolutely nothing. Unlike the PowerToys workaround, which operates at the software layer and can be bypassed by certain applications, the new toggle communicates with the keyboard firmware directly on supported devices. That means the key is intercepted before it ever reaches Windows, making it far more reliable across all apps and games.

Microsoft’s updated documentation on the Windows Copilot client management page now covers configuration options for both consumer and commercial environments, including policy-level controls that IT administrators can push across a fleet of managed devices. For home users, the path is simpler: a toggle in Settings does the job.

Which PCs Support the Native Copilot Key Disable

Windows 11 Settings showing Copilot key disable dropdown option in Typing menu

The firmware-level toggle is available on PCs that shipped with a dedicated Copilot key and have received the relevant firmware and driver updates from their manufacturer. In practice, that covers most laptops and desktops released from early 2024 onwards by major OEMs including Lenovo, Dell, HP, ASUS, Samsung, and Surface devices. If your PC shipped before the Copilot key era (before 2024), this toggle is irrelevant โ€” your keyboard simply doesn’t have the key.

Key compatibility notes to keep in mind:

  • New Copilot+ PCs (2024 onwards) โ€” fully supported with the firmware toggle.
  • Pre-2024 laptops with a repurposed key โ€” some manufacturers used an existing key to trigger Copilot via firmware; those may also support the toggle after an OEM update.
  • Desktop PCs with third-party keyboards โ€” the toggle won’t appear if the keyboard doesn’t identify a Copilot key to Windows. Use PowerToys or SharpKeys instead.
  • Windows 11 version requirement โ€” you’ll need a reasonably current build. The May 2026 KB5089549 update and later releases include the necessary hooks.

How to Disable the Copilot Key via Windows Settings

On supported hardware, disabling or remapping the Copilot key takes under a minute. Here’s exactly how:

  1. Open Settings (Win + I).
  2. Go to Bluetooth & devices, then select Typing โ€” or simply search for AI in the Settings search bar.
  3. Look for the Copilot key section.
  4. Click the dropdown and choose Do nothing to fully disable it, or select any other action you prefer (Search, Custom shortcut, etc.).
  5. The change takes effect immediately โ€” no restart needed.

If you don’t see the Copilot key section, your PC either lacks a dedicated Copilot key or the firmware update from your OEM hasn’t arrived yet. Check your manufacturer’s support page for the latest driver and firmware packages.

How to Remap the Copilot Key with PowerToys (Still Useful)

PowerToys Keyboard Manager showing how to remap the Copilot key on Windows 11

Microsoft PowerToys remains one of the most flexible ways to remap the Copilot key, particularly on desktops with third-party keyboards or on laptops whose OEM hasn’t issued a firmware update yet. The Keyboard Manager module inside PowerToys lets you point the Copilot key to virtually any other key or shortcut.

Steps to remap the Copilot key in PowerToys:

  1. Download and install Microsoft PowerToys from the Microsoft Store or GitHub.
  2. Open PowerToys and navigate to Keyboard Manager.
  3. Click Remap a key.
  4. Press the Copilot key in the “From” column, then assign your preferred key or action in the “To” column.
  5. Click OK to save.

Bear in mind that PowerToys operates at the application layer, so the remap may not apply in a handful of full-screen games or apps that capture raw input. For those edge cases, the native firmware toggle described above is the better solution.

Registry and Group Policy: Copilot Key Disable for Advanced Users

If you want to go deeper โ€” or you’re managing a small fleet of machines โ€” Windows 11 also exposes Copilot controls through Group Policy and the Registry Editor.

Via Group Policy (Windows 11 Pro and above):

  1. Open gpedit.msc.
  2. Navigate to User Configuration > Administrative Templates > Windows Components > Windows Copilot.
  3. Double-click Turn off Windows Copilot and set it to Enabled.
  4. Apply and close. The Copilot key and taskbar icon will both be suppressed.

Note that this disables Copilot as a feature entirely, not just the key. If you only want to silence the key while keeping Copilot accessible from the taskbar, stick to the Settings toggle or PowerToys.

For more keyboard productivity tips, the Windows 11 keyboard shortcuts guide on Buy Now Key covers dozens of lesser-known combinations worth learning.

Remap the Copilot Key to Something Actually Useful

If you don’t want to simply disable the Copilot key, remapping it to a function you use every day is a smart alternative. Popular remaps include:

  • Right Ctrl โ€” restores the layout many touch typists expect.
  • Mute / Volume โ€” handy for media-heavy setups.
  • Calculator โ€” a classic productivity shortcut that Windows still supports natively.
  • Custom shortcut โ€” launch a specific app, folder, or macro via the Settings custom action option.
  • Search โ€” replaces Copilot with Windows Search, which many users find more immediately useful.

The Windows 11 Settings method now supports custom shortcuts directly, so you can bind the key to a Win+letter combination without touching any third-party tools. That’s a significant usability improvement over the original Copilot-or-nothing design.

Does Disabling the Copilot Key Affect Copilot on the Taskbar?

No โ€” disabling or remapping the Copilot key has no effect on the Copilot icon in the taskbar or on Copilot’s availability through other entry points like the Start menu or Windows Search. You can disable the key and still use Copilot whenever you choose to open it manually. Conversely, if you want to remove Copilot entirely from the interface, you’ll need to go through Group Policy, the Registry, or the Taskbar settings under Settings > Personalisation > Taskbar.

For a deeper look at everything Microsoft has been adjusting in the Copilot key saga, the dedicated post on Windows 11 Copilot key remapping covers the full history of workarounds and what the official fix changes.

Still Running an Older Windows Version? Time to Consider Upgrading

If you’re on Windows 10 or an earlier build of Windows 11, you won’t have access to the latest Copilot key controls โ€” and you’ll miss out on a growing list of security patches and features. Windows 10 support ends in October 2025, meaning unpatched systems will stop receiving security updates. Moving to a fully licensed Windows 11 Pro is the cleanest solution, and Windows 11 Pro retail keys are available from Buy Now Key from just โ‚ฌ17.90, with lifetime activation and instant digital delivery.

Frequently Asked Questions

Can I disable the Copilot key without installing any extra software?

Yes, on supported hardware. If your PC shipped with a dedicated Copilot key and has the latest firmware updates installed, you can disable it directly in Windows Settings under Bluetooth & devices > Typing. No third-party software is required. Older hardware or keyboards without official firmware support will still need PowerToys or a registry edit.

Will disabling the Copilot key remove Copilot from Windows 11?

No. Disabling or remapping the Copilot key only changes what happens when you press that physical key. Copilot remains fully accessible from the taskbar icon, Windows Search, and the Start menu. To remove Copilot from the UI entirely, you need to use Group Policy or the Registry Editor โ€” or toggle the Copilot icon off in Taskbar settings.

Does the firmware toggle work in games and full-screen applications?

Yes โ€” that’s the main advantage over the PowerToys workaround. Because the firmware toggle intercepts the Copilot key before it reaches the OS, it works consistently across games, full-screen video players, and applications that capture raw keyboard input. The PowerToys method, by contrast, can fail in those scenarios.

My PC doesn’t show the Copilot key option in Settings. What should I do?

First, check whether your laptop or keyboard actually has a physical Copilot key โ€” it’s a dedicated key introduced on most new Windows PCs from 2024 onwards. If it does, visit your OEM’s support site (e.g. Lenovo Vantage, Dell SupportAssist, HP Support) and install the latest BIOS and keyboard firmware updates. The Settings toggle should appear after the firmware is updated and Windows is restarted.

Is the Copilot key disable option available on Windows 11 Home?

The Settings-based toggle is available on both Windows 11 Home and Windows 11 Pro. The Group Policy method (gpedit.msc) is only available on Pro, Enterprise, and Education editions. If you’re on Windows 11 Home and want Group Policy-style control, a registry edit achieves the same result, or you can upgrade to Windows 11 Pro for the full management toolkit.

Windows 10 hardware compatibility check showing compatible and blocked PC systems

Windows 10 Hardware Compatibility: Why 30% of PCs Still Can’t Upgrade

Windows 10 hardware compatibility is the reason roughly 30% of the world’s PCs are still locked out of Windows 11 โ€” and HP’s frank admission has finally put a number on a problem millions of users already know firsthand. CPU generation walls, mandatory TPM 2.0 chips, and minimum RAM thresholds combine to create one of the strictest OS upgrade barriers Microsoft has ever erected. If your machine is on the wrong side of that wall, this guide explains exactly why, and what your realistic options are before the extended Windows 10 support window closes in October 2027.

What HP’s Data Actually Tells Us About Hardware Compatibility

Three hardware compatibility barriers blocking Windows 11 upgrade on older PCs

HP โ€” one of the world’s largest PC manufacturers โ€” publicly acknowledged that around 30% of its active Windows install base is still running Windows 10, not by choice but because those machines fail Microsoft’s minimum hardware requirements for Windows 11. That is an enormous proportion when you consider HP alone ships tens of millions of units annually. Scale that across the entire global market and you are looking at hundreds of millions of PCs that are, by Microsoft’s own definition, incompatible with its current flagship OS.

This is not a software problem or a reluctance to upgrade. It is a fundamental PC upgrade compatibility ceiling imposed by hardware that was perfectly capable and even premium-grade just a few years ago. An Intel Core i7 from the 7th generation, for example, ran demanding workloads without complaint in 2018 โ€” yet it fails Microsoft’s approved CPU list for Windows 11 entirely.

The Three Hardware Walls Blocking Your Windows Upgrade

Understanding exactly which requirements create the bottleneck helps you diagnose your own machine quickly. There are three primary blockers, and most incompatible PCs fail on at least two of them simultaneously.

1. CPU Generation: The Biggest Barrier to Windows Upgrade Requirements

Microsoft’s official Windows 11 specifications restrict compatibility to Intel 8th-generation Core processors (Coffee Lake, 2017) and newer, or AMD Ryzen 2000 series and newer. Any CPU older than those cut-off generations is simply not on the approved list โ€” regardless of its clock speed, core count, or actual performance capability. This single rule disqualifies an enormous wave of 2015โ€“2017 hardware that is otherwise fully functional.

The stated reasoning involves silicon-level security features and instruction sets that older CPUs lack โ€” including hardware-enforced stack protection and certain virtualisation capabilities that Windows 11’s security model depends on.

2. TPM 2.0: The Chip Most Users Didn’t Know They Needed

Trusted Platform Module (TPM) 2.0 is a dedicated security chip โ€” either a discrete component soldered to the motherboard or a firmware-based implementation baked into the CPU. Microsoft made TPM 2.0 a non-negotiable requirement for Windows 11, citing its role in BitLocker encryption, Windows Hello, and Secure Boot authentication.

Many business-class machines manufactured before 2018 either have no TPM chip at all, have TPM 1.2 (which does not satisfy the requirement), or have TPM 2.0 disabled in the BIOS by default. The third scenario is actually fixable โ€” enabling TPM 2.0 in UEFI firmware settings costs nothing and takes under five minutes โ€” but the first two scenarios represent genuine hardware compatibility dead-ends without a motherboard replacement.

3. RAM: The 4 GB Floor

Windows 11 requires a minimum of 4 GB of RAM. This sounds modest by modern standards, but millions of older budget laptops and corporate thin-client machines shipped with just 2 GB or 3 GB. While RAM is often upgradeable, many of these machines also use soldered memory modules that cannot be expanded โ€” so even willing users have no path forward without buying new hardware.

Why Microsoft Extended Windows 10 Support to October 2027

Windows 10 hardware compatibility check result showing PC upgrade requirements failed

Originally, Microsoft set October 14, 2025 as the end-of-life date for Windows 10. When it became clear that hundreds of millions of devices simply could not meet Windows 11’s hardware requirements, the company quietly extended its free Extended Security Update (ESU) programme by a full year, then extended it again to October 12, 2027 โ€” giving users an additional two years of critical security patches beyond the original deadline.

This extension is a direct acknowledgement of the scale of the Windows 10 hardware compatibility crisis. Microsoft could not realistically force a third of the world’s PC fleet onto unsupported hardware overnight. The ESU programme means Windows 10 Home and Pro users continue to receive security patches through October 2027 at no extra cost โ€” though it is important to understand that this is a security-update lifeline, not a feature-development extension. No new features are coming to Windows 10.

How to Check Your PC’s Upgrade Compatibility Right Now

Microsoft’s own PC Health Check app is the fastest way to determine whether your machine meets Windows upgrade requirements. Download it directly from Microsoft’s website, run it, and it will return a pass/fail result along with the specific reason for failure โ€” whether that is CPU, TPM, RAM, storage, or Secure Boot. The process takes under two minutes.

Alternatively, you can check manually:

  • CPU: Open Task Manager โ†’ Performance โ†’ CPU. Note the model name, then cross-reference it with Microsoft’s approved processor list.
  • TPM status: Press Win + R, type tpm.msc, and press Enter. If TPM 2.0 is present and active, you will see the version number.
  • RAM: Task Manager โ†’ Performance โ†’ Memory. 4 GB minimum is required.
  • Storage: You need at least 64 GB of free drive space.
  • Firmware: Confirm UEFI mode (not legacy BIOS) and that Secure Boot is enabled in your firmware settings.

Your Options If Your PC Fails Windows 11 Hardware Compatibility

PC upgrade compatibility decision paths from Windows 10 to Windows 11 for users

Failing the compatibility check does not mean you have to rush out and buy a new machine tomorrow. There are several practical paths, each with different cost and risk profiles.

Option 1: Stay on Windows 10 and Buy an Affordable Licence

If your hardware is otherwise performing well, staying on Windows 10 through October 2027 is a perfectly rational decision. The ESU extension means you will keep receiving security patches for over two more years. The key is ensuring you are running a fully activated, genuine copy so you receive all updates reliably. A legitimate Windows 10 licence from Buy Now Key starts from as little as โ‚ฌ8.90 โ€” far cheaper than rushing into new hardware before you need to.

Option 2: Fix What Is Fixable (TPM and Secure Boot)

If TPM 2.0 and Secure Boot are the only obstacles โ€” and your CPU is on the approved list โ€” you may simply need to enable them in your UEFI/BIOS settings. Restart your PC, enter BIOS (usually Del, F2, or F10 at boot), locate the Security or TPM section, and enable both features. Then re-run the PC Health Check. Many users discover this is their only blocker.

Option 3: Upgrade to Windows 11 on a Compatible Device

If your machine genuinely cannot be made compatible and you need Windows 11’s features, the cleanest path is a new or refurbished device with a fresh licence. At Buy Now Key, Microsoft Windows 11 Pro Retail is available from โ‚ฌ17.90 โ€” meaning the software cost of stepping up is genuinely low. The bigger investment is hardware, but in many cases a modest refurbished business PC will easily meet Windows 11’s requirements and cost far less than a brand-new machine.

Option 4: The Unofficial Bypass Route (With Caveats)

Various registry edits and third-party tools exist to install Windows 11 on unsupported CPUs. Microsoft has explicitly warned that devices running Windows 11 outside the official PC upgrade compatibility list may not receive future updates and could encounter stability issues. In December 2024, Microsoft confirmed it would not relax hardware requirements. Proceed with this route only if you fully understand and accept the risks โ€” it is not a path Buy Now Key recommends for production or business machines.

What This Means for Businesses Managing Large PC Fleets

For IT administrators, the HP data point is a sobering reality check. If 30% of consumer PCs fail Windows upgrade requirements, enterprise fleets โ€” which tend to run hardware on longer refresh cycles โ€” could see even higher incompatibility rates. Microsoft’s own guidance recommends using tools like Microsoft Intune or Endpoint Configuration Manager to audit TPM 2.0 compatibility across your estate before planning a bulk migration.

The October 2027 deadline, while welcome, is not a permanent stay of execution. Businesses that have not begun phased hardware refresh planning risk facing a last-minute crunch with supply constraints, budget pressures, and a hard deadline for security patch coverage all converging at once. Starting that conversation now โ€” even if rollout is 18โ€“24 months away โ€” is strongly advisable.

Will Microsoft Ever Relax Its Hardware Compatibility Rules?

The short answer is almost certainly not. Microsoft confirmed in December 2024 that it has no plans to lower or remove the CPU, TPM 2.0, or RAM requirements. The official reasoning centres on the security architecture underpinning Windows 11 โ€” features like hardware-enforced stack protection, Pluton security processors, and future Secured-Core PC capabilities all depend on these hardware minimums being present. Relaxing them would, in Microsoft’s view, undermine the entire security proposition of Windows 11.

The more pragmatic reading is that Microsoft also has commercial incentives for a hardware refresh cycle. Regardless of motive, the requirements are not changing โ€” which makes understanding your own machine’s hardware compatibility position more important than ever.

FAQ

Which CPUs are incompatible with Windows 11?

Any Intel CPU older than 8th-generation Core (2017 Coffee Lake) and any AMD CPU older than Ryzen 2000 series (2018) is officially unsupported. This includes the very popular Intel 6th and 7th generation Core processors that powered millions of business laptops and desktops sold between 2015 and 2017. Microsoft publishes a full approved CPU list on its Windows 11 specifications page.

Is TPM 2.0 always a hardware problem, or can it be enabled in software?

Often it is a BIOS setting, not a missing chip. Many machines manufactured after 2016 include TPM 2.0 in firmware (called fTPM on AMD systems or PTT on Intel), but it is disabled by default. Entering your UEFI settings and enabling it costs nothing. If the chip is truly absent or only TPM 1.2 is present, however, you would need a discrete TPM module or a motherboard that supports firmware TPM โ€” which means a hardware upgrade or replacement.

How long will Windows 10 receive security updates?

Microsoft extended free consumer Extended Security Updates (ESUs) to October 12, 2027. This covers critical security patches for Windows 10 Home and Pro. After that date, no further security updates will be issued for Windows 10, and continuing to use it represents a genuine security risk. Feature updates stopped with Windows 10 version 22H2 in 2022.

Can I upgrade my RAM or add a TPM chip to make my PC compatible?

It depends on your hardware. If your RAM is in standard DIMM or SO-DIMM slots (not soldered), upgrading to 4 GB or more is straightforward and inexpensive. Discrete TPM 2.0 modules exist and can be fitted to motherboards with a TPM header, but compatibility varies by board. The bigger problem is usually the CPU generation requirement โ€” there is no upgrade path for that short of replacing the CPU and often the motherboard too, at which point a new system may be more cost-effective.

Is the free Windows 11 upgrade still available?

Yes โ€” if your PC meets the hardware requirements, the upgrade from Windows 10 to Windows 11 remains free through Windows Update. Simply ensure your Windows 10 copy is activated and up to date, then check Settings โ†’ Windows Update โ†’ Check for Updates. Eligible machines will be offered the upgrade at no charge. If your machine is not on the compatible list, the free upgrade will not appear regardless of your Windows 10 activation status.

What is the cheapest way to get a genuine Windows licence?

Buy Now Key offers both Windows 10 licences from โ‚ฌ8.90 and Windows 11 Pro from โ‚ฌ17.90. These are genuine, permanently activated licences with instant digital delivery โ€” far cheaper than buying through a retail box or directly from Microsoft’s storefront. If you are staying on Windows 10 through 2027, securing a proper licence now ensures uninterrupted update delivery.

Windows license check screen showing active genuine activation status on desktop

Windows License Check: How to Verify Your Copy Is Genuine

A quick Windows license check takes less than 60 seconds and can save you from losing access to features, security updates, or even your entire installation. Whether you just bought a new PC, upgraded your OS, or purchased a key from a third-party seller, confirming that your copy of Windows is properly licensed is one of the most important things you can do as a PC owner.

Why a Windows Activation Check Matters in 2026

Infographic showing benefits of a valid Windows license check and activation

Running unlicensed software is not just a legal risk โ€” it has real, day-to-day consequences. Microsoft restricts several features on unactivated Windows installations, including the ability to personalise your desktop, access certain security settings, and, critically, receive the full suite of Windows Update patches. In 2026, with over 1,000 vulnerabilities patched in Windows alone across the year, missing even one cumulative update can leave your device exposed to serious threats.

Beyond security, an unverified licence may fail silently. Your PC might appear to work normally while Windows gradually disables features or shows persistent activation nag screens. Catching this early with a proper Windows activation check protects both your productivity and your data.

The Fastest Windows License Check: Settings App Method

The quickest way to perform a Windows license check is directly inside the Settings app โ€” no command line needed.

  1. Press Windows key + I to open Settings.

  2. Go to System โ†’ Activation.

  3. Look at the Activation state field. If it reads Active, your licence is confirmed genuine by Microsoft’s servers.

  4. If it reads Activation required or shows an error code, your installation is not currently validated.

This panel also tells you the edition you are licensed for (Home, Pro, Enterprise, etc.) and whether your licence is linked to a Microsoft account โ€” which is important for reinstalling Windows in the future without needing your product key again.

Command-Line Windows Product Key Verification

Command Prompt showing genuine Windows verification result using slmgr tool

For a more detailed Windows product key report, use the built-in Software Licensing Management Tool (slmgr). This is what IT professionals use and it gives you granular licence data.

  • Open Command Prompt or PowerShell as Administrator.

  • Type slmgr /dli and press Enter to see basic licence information, including the licence channel (OEM, Retail, Volume).

  • Type slmgr /dlv for extended details โ€” licence expiry, activation ID, and partial product key.

  • Type slmgr /xpr to confirm whether your current licence is permanent or time-limited.

If the Description field in the slmgr /dli output shows a valid licence channel and the Licence Status reads Licensed, your installation has passed Microsoft’s genuine Windows verification. OEM licences (pre-installed by manufacturers) and Retail licences purchased from authorised sellers will both show as Licensed here.

Genuine Windows Verification via Microsoft’s Website

Microsoft provides its own About Genuine Windows guidance to help users understand what genuine software looks like. For physical copies, genuine Windows packaging includes a Certificate of Authenticity (COA), a proof-of-licence label, and an edge-to-edge hologram that is nearly impossible to replicate convincingly. If your physical packaging lacks these features, treat it as a red flag.

For digital purchases โ€” which represent the vast majority of Windows licences sold today โ€” the key indicator of a legitimate Windows license check is a successful activation that connects to Microsoft’s servers and returns a Licensed status. No third-party tool is needed, and no third-party tool can make a fake key genuine.

How to Spot Counterfeit Key Scams

The market for fake Windows keys is unfortunately active. Scammers exploit price sensitivity by selling keys that either never work, stop working after a few months, or are recycled from volume licence agreements that Microsoft has since revoked. Here is what to watch for:

  • Impossibly low prices: A legitimate retail Windows 11 Pro licence has a known market value. Keys priced at ยฃ1โ€“ยฃ3 from unknown sellers are almost always stolen volume keys or outright fakes. Prices from reputable specialist resellers sit at a more realistic level โ€” for example, Microsoft Windows 11 Pro Retail from Buy Now Key is priced at โ‚ฌ17.90, reflecting a genuine, globally valid licence.

  • No activation guarantee: Trustworthy sellers stand behind their keys. If a seller provides no support and no recourse if the key fails, that is a serious warning sign.

  • Vague seller identity: Reputable key resellers have verifiable contact details, clear terms, and a history of customer reviews. Anonymous listings on auction platforms or social media are high-risk.

  • No licence type disclosure: A legitimate seller will tell you whether you are buying a Retail, OEM, or Volume licence. If the listing is vague about what type of licence the key represents, walk away.

  • Keys that activate initially then fail: Volume Licence Agreement (VLA) keys harvested from corporate leaks may activate Windows briefly before Microsoft’s detection systems revoke them. A genuine Windows activation check run weeks after purchase is always a good idea.

OEM vs Retail vs Volume: Which Licence Type Do You Have?

Understanding your licence type is part of a thorough Windows product key verification. The slmgr /dli command will tell you, but here is a quick reference:

  • OEM (Original Equipment Manufacturer): Tied permanently to the device it was first activated on. Cannot be transferred to a new PC. Typically the most affordable option for a single device โ€” Buy Now Key offers Microsoft Windows 11 Pro OEM from โ‚ฌ12.90.

  • Retail: Transferable between PCs and linked to your Microsoft account. Better for power users who upgrade hardware regularly.

  • Volume: Issued to organisations. Not meant for individual resale. Keys of this type sold to consumers are almost always illegitimately sourced.

If your slmgr /dli output shows a Volume licence channel but you purchased a key from an individual seller, that is a major red flag for a potentially revocable licence.

What Genuine Activation Really Requires

A common misconception is that Windows activation is complicated or requires special software. It does not. Genuine Windows activation requires exactly three things:

  1. A valid product key (25 characters, alphanumeric, formatted as XXXXX-XXXXX-XXXXX-XXXXX-XXXXX).

  2. An internet connection so Windows can communicate with Microsoft’s activation servers.

  3. The key not having exceeded its allowed activation count (Retail keys allow one active installation at a time; OEM keys are locked to their first device).

That is it. You do not need to install any extra software, call a number to “verify” your purchase, or provide personal financial information at the point of activation. If any of these extra steps are demanded, you are being scammed.

What to Do If Your Windows License Check Fails

If your Windows license check returns an error or an Activation required status, do not panic โ€” there are legitimate paths forward.

  • Run the Activation Troubleshooter: In Settings โ†’ System โ†’ Activation, click Troubleshoot. This resolves many common issues automatically, including hardware changes on a linked Microsoft account.

  • Contact Microsoft Support: If you have a valid key that is not activating, Microsoft’s support team can verify it manually via phone activation. This is a built-in, free service.

  • Replace a bad key: If a third-party key has been revoked or was never valid, you will need a genuine replacement. Buying from a trustworthy, specialist reseller โ€” one that offers post-sale support and clear licence-type disclosure โ€” protects you from this scenario.

For a deeper look at all the legal routes to get Windows properly licensed, our guide to Windows licence activation and legal methods in 2026 covers every available option in detail.

Frequently Asked Questions

How do I check my Windows activation status quickly?

Press Windows key + I, navigate to System โ†’ Activation, and look at the Activation state field. If it says Active, your Windows licence is genuine and verified by Microsoft. The entire process takes under 30 seconds.

Can I do a Windows product key check from the command line?

Yes. Open Command Prompt as Administrator and run slmgr /dli for a standard licence summary, or slmgr /dlv for extended detail. These are official Microsoft tools built into every Windows installation โ€” no third-party software required.

What does it mean if my genuine Windows verification shows “Notification mode”?

Notification mode means Windows has detected that the licence is not valid and will begin limiting features. Common causes include a revoked key, a key used on more devices than the licence allows, or a hardware change on an OEM licence. Run the Activation Troubleshooter first; if that fails, you will need a valid replacement key.

Is it safe to buy a Windows key from a third-party reseller?

It can be โ€” provided the reseller is transparent about licence type (OEM, Retail, or Volume), offers post-sale activation support, and charges a realistic price. Suspiciously cheap keys (under ยฃ5) are almost always illegitimately sourced and risk being revoked by Microsoft. Stick with established specialist resellers who clearly disclose what you are buying.

Will Windows tell me if my key was stolen or is counterfeit?

Not always immediately. A revoked or counterfeit key may activate successfully at first, then fail when Microsoft’s servers detect it during a later check. This is why running a Windows activation check a few weeks after any new key purchase is good practice โ€” catching a problem early gives you time to seek a legitimate replacement before features are restricted.

Do I need to re-verify my Windows licence after a hardware upgrade?

It depends on your licence type. Retail licences linked to a Microsoft account generally survive hardware changes and can be reactivated through the Activation Troubleshooter. OEM licences are permanently bound to the original device’s hardware and cannot be transferred, so significant upgrades (such as a new motherboard) may require a new licence.

OneDrive Support Ends for Windows 10 warning notification on a PC desktop

OneDrive Support Ends for Windows 10: What to Do Before August 2026

OneDrive support ends on 15 August 2026 for every Windows 10 build earlier than 22H2 โ€” Microsoft has confirmed the OneDrive desktop sync app will stop receiving updates on those devices. If your PC is on version 21H2 or older, your files will not stop syncing overnight, but you will be left without security patches, bug fixes, or new features โ€” a risk no one should ignore. Here is everything you need to know to check your build, understand what changes, and plan your next move.

Which Windows 10 Builds Lose OneDrive Sync Support?

Windows 10 builds losing OneDrive sync support highlighted in a comparison chart

Microsoft’s decision targets all Windows 10 versions prior to 22H2. Specifically, Windows 10 OneDrive sync updates will cease for:

  • Windows 10 21H2 (Build 19044) and all earlier releases

  • Windows 10 21H1 (Build 19043)

  • Windows 10 20H2 (Build 19042)

  • Windows 10 2004 (Build 19041) and older

Windows 10 version 22H2 โ€” the final and most recent release of Windows 10 โ€” is the only build that retains OneDrive sync app support, and Microsoft has committed to continuing updates for it until October 2028, aligned with its extended support lifecycle. If you are on 22H2, you have breathing room. If you are not, the clock is ticking.

How to Check Whether OneDrive Support Ends on Your PC

Verifying your build takes under a minute. Press Windows key + R, type winver, and press Enter. A window appears showing your Windows edition and exact version number. You can also go to Settings > System > About and look for the “OS build” entry under Windows specifications. If the version shown is anything below 22H2 (19045), your device falls inside the affected range for OneDrive support ending.

What Happens When OneDrive Support Ends on 15 August 2026?

Three migration options for Windows 10 users before OneDrive support ends

Microsoft’s cut-off is about updates, not immediate disconnection. Once OneDrive support ending takes effect for your build, the sync app will likely continue to function in a basic capacity for a period โ€” but you will receive no further security patches, compatibility fixes, or performance improvements. Over time, this creates real risks:

  • Unpatched security vulnerabilities in the sync client itself

  • Potential incompatibility with future OneDrive cloud-side changes

  • No access to new features such as improved conflict resolution or Personal Vault updates

  • Eventual sync failures as Microsoft’s servers evolve beyond what the outdated client supports

In short, staying on a legacy build after the deadline is a ticking time bomb for data reliability and security. Treating this as a soft warning rather than a firm deadline is a mistake.

Your Migration Options Before the Deadline

You have three realistic paths forward, and the right one depends on your hardware and workflow.

Option 1: Update to Windows 10 22H2

If your device is already running Windows 10 and you do not want to change operating systems yet, simply updating to version 22H2 keeps OneDrive sync support intact until October 2028. Go to Settings > Update & Security > Windows Update and check for updates. On most supported Windows 10 devices, 22H2 is available as a free update. This is the fastest fix if your hardware does not meet Windows 11 requirements.

Option 2: Upgrade to Windows 11

Upgrading to Windows 11 is the longer-term solution Microsoft clearly prefers, and it fully resolves the OneDrive sync support question. Windows 11 ships with a deeply integrated, regularly updated OneDrive experience and continues to receive full support well into the next decade. If your hardware supports it โ€” you will need a compatible 64-bit processor, 4 GB RAM, 64 GB storage, and TPM 2.0 โ€” this is the cleanest path. At Buy Now Key, a genuine Microsoft Windows 11 Pro licence starts from just โ‚ฌ17.90, making the upgrade accessible without breaking the bank. For home users, Microsoft Windows 11 Home is available from โ‚ฌ15.60 โ€” a permanent, one-time licence key with lifetime activation.

Option 3: Supplement with Alternative Cloud Storage

If neither update is immediately possible, consider temporarily supplementing your setup with an alternative sync tool โ€” Google Drive, Dropbox, or similar โ€” while you plan the migration properly. This is not a long-term solution, but it reduces the risk of losing access to cloud-synced data if OneDrive becomes unreliable on your legacy build. Back up your OneDrive folder locally before the deadline regardless of which path you choose.

Why Microsoft Is Ending OneDrive Sync Support

OneDrive support timeline for Windows 10 22H2 ending in October 2028

This move fits neatly into Microsoft’s broader platform consolidation strategy. Windows 10 itself reached end of support on 14 October 2025, meaning the operating system as a whole no longer receives security updates unless organisations pay for Extended Security Updates (ESU). Continuing to develop and test the OneDrive sync app across a fragmented landscape of pre-22H2 builds adds engineering overhead for diminishing returns โ€” the vast majority of active Windows 10 users have already updated to 22H2, which became freely available years ago. Cutting support for older builds lets Microsoft focus engineering resources on Windows 11 and the cloud platform that drives its future revenue.

As reported by The Register, OneDrive sync app updates will continue on Windows 10 22H2 until October 2028, providing a clear and structured wind-down rather than an abrupt cut-off for all Windows 10 users at once.

Are Your Files Safe After OneDrive Support Ends?

Your files stored in the cloud on OneDrive.com are entirely unaffected by this change. The cut-off applies only to the desktop sync app โ€” the software that keeps a local folder on your PC in sync with your cloud storage. Even if the sync app stops working correctly on your device, you can always access your files through a web browser at OneDrive.com. That said, relying on browser-only access long term is inconvenient and risky if you depend on offline access. Do not assume your files are “fine” just because the cloud copy is intact โ€” plan the migration now while you have time.

How to Prepare a Clean Migration Plan

Follow these steps before 15 August 2026 to ensure a smooth transition:

  1. Check your build (winver or Settings > About) and confirm whether you are on 22H2 or earlier.

  2. Back up your OneDrive folder to an external drive or secondary storage location.

  3. Attempt a Windows 10 22H2 update via Windows Update if you want to stay on Windows 10.

  4. Check Windows 11 compatibility using Microsoft’s PC Health Check tool if an OS upgrade is viable.

  5. Purchase a Windows 11 licence if your PC is compatible and you are ready to upgrade โ€” our Windows licence category covers both Windows 10 and Windows 11 options at competitive prices.

  6. Reinstall and relink OneDrive after the upgrade to ensure a fresh, fully supported sync setup.

Frequently Asked Questions About OneDrive Support Ending

Does OneDrive support end for all Windows 10 users?

No. Only users on Windows 10 versions earlier than 22H2 are affected. Windows 10 22H2 retains full OneDrive sync support until October 2028. If you are already on 22H2 (build 19045), you do not need to take any action specifically related to this announcement.

Will my existing OneDrive files be deleted after the deadline?

No. Files stored in your OneDrive cloud account are not affected. The change only applies to the desktop sync application on older builds. You can still access all your files through a web browser even if the sync app stops receiving updates โ€” though for reliable day-to-day use, upgrading your OS remains the recommended course of action.

Can I keep using the OneDrive app on Windows 10 21H2 after 15 August 2026?

You may be able to use it for a period, but Microsoft will no longer patch it. Security vulnerabilities, compatibility issues, and eventual sync failures become increasingly likely the longer you stay on an unsupported build. Relying on an unpatched sync client for important data carries significant risk.

How much does it cost to upgrade to Windows 11?

At Buy Now Key, a genuine Windows 11 Pro licence is available from โ‚ฌ17.90 and Windows 11 Home from โ‚ฌ15.60 โ€” both are permanent, lifetime keys with instant digital delivery. This is a one-time cost with no ongoing subscription.

What if my PC cannot run Windows 11?

If your hardware does not meet Windows 11’s minimum requirements, updating to Windows 10 22H2 is the safest short-term option, preserving OneDrive sync support until October 2028. Beyond that date, you will need either new hardware capable of running Windows 11 or to migrate your workflow to a browser-based OneDrive setup.

Glowing Windows product key code displayed on a digital card

What Your Windows Product Key Really Does (and Doesn’t Do)

A Windows product key is a 25-character alphanumeric code that proves you own a genuine copy of Windows โ€” but it does far more than gatekeep the installer. In Windows 11, Microsoft has fundamentally changed how that key interacts with your hardware, your Microsoft account, and even future PC builds. Understanding those mechanics saves you money, headaches, and the panic of thinking your licence has “expired” when it hasn’t.

What a Windows Product Key Actually Is

Infographic comparing a Windows product key to a Windows digital licence

At its simplest, a Windows licence key is a cryptographic token. When you enter it during setup, Microsoft’s activation servers check that the key is genuine, hasn’t been used beyond its permitted device count, and matches the edition you’re installing (Home, Pro, and so on). Once verified, Windows stamps your device with an activation state stored in the firmware and in Microsoft’s cloud. The key itself is then largely retired โ€” what matters from that point on is the digital licence it created.

The 25-Character Code vs. a Digital Licence

Microsoft draws a clear distinction between the two. A product key is the one-time credential you enter; a digital licence (called a “digital entitlement” in some Windows 11 dialogs) is the persistent permission record that lives server-side and is linked to your hardware profile. According to Microsoft’s official activation support page, “Activation is a technical process that pairs the product key or digital entitlement with the hardware configuration of the device.” Once that pairing exists, you don’t need to type the key again.

How the Windows Activation Key Ties to Your Hardware

Windows doesn’t just remember that a copy is activated โ€” it remembers which machine. During activation, Windows samples a “hardware hash”: a fingerprint built from your CPU, motherboard, RAM configuration, network adapter, and storage devices. That hash is sent to Microsoft’s servers and associated with your licence.

  • Minor changes (adding RAM, swapping a hard drive) are usually tolerated without re-activation.
  • Significant changes (replacing the motherboard or moving to an entirely new PC) can break the hardware match, triggering an “activation required” state.
  • OEM licences are tied permanently to the original motherboard โ€” that’s why a Windows 11 Home OEM key bought for one machine cannot simply be transferred to another.
  • Retail licences are transferable: you can deactivate them on one machine and activate on another, which is one key reason retail keys cost more than OEM alternatives.

This hardware-binding approach has been refined significantly since Windows 7. In the XP era, activation was loose enough that the same key was routinely shared across dozens of machines. Windows 8 introduced UEFI-embedded keys, and Windows 10 and 11 take that further with cloud-anchored digital licences that are far harder to circumvent โ€” and far easier to recover legitimately.

Does a Windows Digital Licence Expire?

Diagram showing Windows licence key OEM versus Retail activation differences

This is one of the most common misconceptions. A genuine Windows digital licence does not expire. There is no annual renewal fee, no subscription clock ticking in the background. Once your device is activated, it stays activated indefinitely โ€” even through Windows Update cycles and major feature releases like Windows 11 24H2. The only scenario where an “expiry” message appears is with volume-licence KMS activations used by organisations, where each client PC must “phone home” to a KMS server every 180 days. Consumer retail and OEM licences are simply permanent.

What can lapse is your activation state after a major hardware change. That’s not expiry โ€” it’s the hardware hash no longer matching the stored record. Microsoft provides a clear path to fix this by linking your licence to a Microsoft account, which we’ll cover below.

Windows 11 vs Earlier Versions: What Changed?

Microsoft’s approach in Windows 11 differs from older versions in three meaningful ways.

1. Embedded UEFI Keys Are Now Universal

Most Windows 11 PCs sold by OEMs (Dell, HP, Lenovo, etc.) ship with the Windows activation key embedded directly in the UEFI firmware chip. You never see a sticker, never type a code โ€” Windows reads the key from firmware at first boot. This was introduced in Windows 8 but is now the absolute default in Windows 11.

2. Microsoft Account Linking Is a Game-Changer

In Windows 10 and 11, you can link your digital licence to your Microsoft account. Go to Settings โ†’ System โ†’ Activation โ†’ Add a Microsoft account. Once linked, if you ever replace your motherboard or build an entirely new PC, you can recover your licence through the Activation Troubleshooter โ€” no support call required. This single step is arguably the most important thing you can do with a retail key after activation.

3. Edition Upgrades Without Reinstalling

Windows 11 lets you upgrade from Home to Pro by simply entering a new Windows product key in the Activation settings panel โ€” no reinstall, no data loss. The upgrade path is instant once Microsoft’s servers verify the new key, a convenience that wasn’t seamless in older versions.

OEM vs Retail: Which Windows Licence Key Should You Buy?

Windows 11 activation settings panel showing Windows product key linked to Microsoft account

The difference comes down to portability and support. Here’s a quick comparison:

  • OEM key: cheaper, locked to first device activated, no transfer rights, Microsoft support goes through the OEM. Ideal if you’re activating one fixed machine that won’t change.
  • Retail key: costs more, fully transferable between PCs, direct Microsoft support, can be linked to your Microsoft account for hardware-change recovery.

At Buy Now Key, a Microsoft Windows 11 Pro OEM key is available from just โ‚ฌ12.90 โ€” ideal for a new build you won’t be repurposing. If you want full transfer flexibility, the Microsoft Windows 11 Pro Retail licence at โ‚ฌ17.90 gives you the freedom to move the key if you ever upgrade your PC hardware.

What the Windows Product Key Doesn’t Do

Knowing what the key doesn’t control is just as useful:

  • It doesn’t unlock features gated by hardware. TPM 2.0, Secure Boot, and Windows Hello still require compatible hardware regardless of which licence you hold.
  • It doesn’t determine update eligibility. Windows 11 feature updates are tied to the OS version and hardware compatibility, not the licence type.
  • It doesn’t include Office. A Windows key activates the operating system only. Microsoft 365 and standalone Office products each need their own separate licence.
  • It doesn’t prevent unactivated use โ€” entirely. Windows 11 runs without activation in a “limited” state: you’ll see a watermark, lose access to personalisation settings, and receive nags, but core functionality continues. Microsoft doesn’t brick your PC; it nudges you.

How to Find Your Existing Windows Activation Key

If you need to retrieve the Windows licence key already on your device (for a reinstall, for example), Windows itself only shows the last five characters of the embedded key. To retrieve the full key, open PowerShell as Administrator and run:

(Get-WmiObject -query 'select * from SoftwareLicensingService').OA3xOriginalProductKey

This works for UEFI-embedded OEM keys. For retail keys not embedded in firmware, you’ll need a third-party tool like ProduKey or the key management section of your Microsoft account dashboard.

Why Your Windows Digital Licence Belongs in Your Microsoft Account

The single best thing you can do after activating Windows 11 with a retail key is link it to your Microsoft account. When you do, the licence persists in Microsoft’s cloud independently of your device’s hardware hash. If you upgrade your motherboard, buy a new PC, or need to reinstall after a catastrophic failure, the Activation Troubleshooter can match your sign-in credentials to the stored digital licence and reactivate without you needing the original 25-character code at all. This is a fundamental shift from Windows 7 and earlier, where losing the key sticker often meant buying again. For a deeper look at all the legal paths to activate Windows, see our guide on Windows licence activation: free and legal methods in 2026.

FAQ

Can I use the same Windows product key on two computers?

In almost all cases, no. A retail Windows licence key covers one device at a time. You can transfer it to a new machine after deactivating it on the old one, but you cannot run two activated copies simultaneously with a single key. OEM keys are even stricter โ€” they’re permanently tied to the first device they activate and cannot be transferred at all.

What happens if I replace my motherboard?

Replacing the motherboard usually breaks the hardware hash, causing Windows to show an “activation required” message. If you have a retail licence linked to your Microsoft account, use the Activation Troubleshooter in Settings to recover it. OEM licences tied to the original motherboard cannot be reactivated on a new board โ€” you’ll need a new key. This is exactly why linking a retail key to your Microsoft account matters so much.

Does a Windows activation key work forever?

Yes โ€” a genuine retail or OEM Windows activation key doesn’t have an expiry date. Your licence remains valid for the lifetime of the device (OEM) or as long as you own it (retail). The only exception is volume KMS licensing used by businesses, which requires periodic renewal through a corporate KMS server. Standard consumer licences are permanent one-time purchases.

What’s the difference between a Windows product key and a digital licence?

A Windows product key is the 25-character code you enter during setup โ€” it’s the credential that proves ownership. A digital licence is the activation record Microsoft creates after verifying that key; it’s stored server-side and linked to your hardware. After initial activation, Windows uses the digital licence rather than re-checking the key, which is why you don’t need to re-enter it after reinstalling on the same PC.

Can I upgrade from Windows 10 to Windows 11 using my existing key?

If your Windows 10 licence is genuine and your hardware meets Windows 11’s system requirements (including TPM 2.0 and Secure Boot), the free upgrade from Windows 10 to Windows 11 replaces your old digital licence with a new Windows 11 one automatically โ€” no new key needed. If you’re starting fresh or your current PC isn’t eligible, you’ll need a new Windows 11 key.

Modern Windows 11 file properties dialog with WinUI 3 dark mode design

Windows 11 File Properties Gets a Modern WinUI Redesign

The Windows 11 file properties dialog is getting its most significant overhaul in roughly three decades. Microsoft is rebuilding the ageing Properties window โ€” one of the last surviving relics of the Windows 95 era โ€” using the modern WinUI 3 framework. If you right-click a file in File Explorer dozens of times a day, this update is going to matter to you.

Why the File Properties Dialog Needed an Overhaul

Comparison of Windows file properties dialogs from Windows 95 (1995) and a modern WinUI 3 (2026) design, highlighting the evolution from the classic gray interface to the dark Windows 11-style layout. Both windows display document details, file information and attributes over a Windows 11 desktop with the 2026 taskbar.

The current file properties dialog in Windows 11 has always looked out of place. While Microsoft has steadily redesigned Start, Settings, Taskbar, and File Explorer itself to match the Fluent Design language, the Properties window stubbornly remained a throwback โ€” white borders, fixed-size tabs, and no dark mode support. Users running Windows 11 in dark mode have long complained that every right-click โ†’ Properties pull-up breaks their carefully curated dark theme, flashing a bright white box onto the screen.

According to reporting by Windows Latest, the legacy dialog traces its roots back to Windows 95, meaning the code powering it is over 30 years old. That legacy codebase made it difficult to add new features, impossible to properly theme, and increasingly inconsistent with the rest of the OS shell.

What Is WinUI 3 and Why Does It Matter for File Metadata?

WinUI 3 is Microsoft’s modern UI toolkit, built on top of the Windows App SDK. It replaces the older Win32 and UWP component stacks with a unified framework that supports dynamic theming, improved accessibility, hardware-accelerated rendering, and consistent typography. When Microsoft rebuilds the WinUI file explorer Properties dialog with WinUI 3, all of those benefits flow directly to an interface millions of users touch every single day.

  • Dark mode support: The redesigned dialog will respect the system accent colour and dark/light theme toggle โ€” something the legacy version never did.

  • Consistent typography and spacing: Text will use the Segoe UI Variable font at correct weights, matching the rest of Windows 11’s shell.

  • Responsive sizing: The old dialog had a fixed, non-resizable window. The WinUI version can scale to different display densities and screen sizes.

  • Faster rendering: WinUI 3 uses a composition-based renderer, so the dialog can open and paint significantly faster than the legacy Win32 version.

  • Improved accessibility: WinUI components include built-in support for screen readers and keyboard navigation patterns that the old dialog lacked.

What Changes for Everyday Windows File Metadata Tasks

Windows 11 file properties Details tab showing editable Windows file metadata fields

If you regularly edit Windows file metadata โ€” tagging photos, editing document author fields, adjusting video titles, or checking file sizes before sharing โ€” the redesigned Properties window will feel substantially more pleasant to use. Here is what the updated experience looks like in practice:

The General Tab

The General tab, which shows file type, size, location, and creation/modification dates, gets a cleaner layout with better padding and legible icons. Timestamps are displayed in a format that adapts to your regional settings more reliably.

The Details Tab

The Details tab โ€” arguably the most powerful part of the file properties dialog โ€” is where you view and edit embedded metadata like title, subject, tags, authors, and copyright strings. In the WinUI redesign, this tab is expected to feature inline editing improvements and a scrollable, more readable list that no longer looks like it belongs in a 1990s enterprise app.

Dark Mode at Last

This is the change most users have been waiting for. The entire Windows 11 file properties window will finally honour the system-wide dark mode setting. No more jarring white flash when you inspect a file’s attributes at night.

The Security and Sharing Tabs

Advanced tabs like Security (NTFS permissions) and Sharing are also being brought under the WinUI umbrella, ensuring a coherent look throughout the entire dialog rather than a mix of old and new panels.

When Will the WinUI File Explorer Properties Update Arrive?

As of May 2026, the redesigned WinUI file explorer Properties dialog has been spotted in Windows 11 Insider Preview builds, hidden behind a feature flag. Microsoft typically enables such flags for Canary channel testers first, then Dev, Beta, and finally the Release Preview before a stable rollout. Based on the current cadence, a general availability release in the second half of 2026 is plausible, though Microsoft has not announced a specific date.

If you are on the Insider Programme’s Canary or Dev channel, you can try enabling experimental features using third-party tools such as ViVeTool โ€” though Microsoft does not officially support or recommend this for production machines.

How to View and Edit File Properties in Windows 11 Right Now

Windows 11 File Explorer right-click menu to open file properties dialog

While the redesign rolls out, the current Windows file metadata system is fully functional. Here is a quick refresher on getting the most from it:

  1. Right-click any file in File Explorer and choose Properties (or press Alt + Enter with a file selected).

  2. On the General tab, check the file type, size on disk, and the read-only/hidden attributes.

  3. Switch to the Details tab to view and click-to-edit embedded metadata fields such as title, tags, and author.

  4. To remove personal metadata before sharing a file, click Remove Properties and Personal Information at the bottom of the Details tab.

  5. On the Security tab, you can review and change NTFS permissions โ€” useful for managing access on shared or multi-user PCs.

Does the File Properties Redesign Require a New Windows 11 Licence?

No. Like most Windows 11 shell updates, the new file properties dialog will be delivered as a cumulative update to existing Windows 11 installations โ€” both Home and Pro editions. You do not need to repurchase your licence. However, you do need to be running a supported version of Windows 11 to receive ongoing updates. Windows 11 version 22H2 reached end of support on 8 October 2024, so if you are still on that build, you are no longer receiving feature updates of this kind.

If you have not yet upgraded to Windows 11 or need to activate a new device, Buy Now Key offers genuine Windows 11 licences at competitive prices โ€” including Microsoft Windows 11 Pro Retail from โ‚ฌ17.90 and Microsoft Windows 11 Home OEM from โ‚ฌ9.65. Both provide lifetime activation and instant digital delivery.

Windows 11 File Properties vs Windows 10: What’s Already Different

Windows 11 already made several incremental improvements to the Properties dialog compared to Windows 10, even before the WinUI overhaul:

  • The right-click context menu was redesigned in Windows 11, meaning you reach Properties via a cleaner, modern menu rather than the classic cascading list.

  • File Explorer in Windows 11 introduced a new toolbar with a more modern command bar, though Properties itself stayed legacy.

  • Windows 11 22H2 and later builds improved how the OS surfaces file compression and encryption status within the General tab.

The WinUI 3 redesign is the first time the dialog box itself โ€” not just the path to opening it โ€” is being fundamentally modernised.

What This Means for Power Users and Developers

Power users who rely on the Windows file metadata Details tab for organising large photo or video libraries, managing document workflows, or auditing file permissions will benefit most from the upgrade. The WinUI 3 framework also opens the door for Microsoft to add new metadata fields, contextual previews, and integration with cloud services like OneDrive without being constrained by Win32 limitations.

For developers building Windows shell extensions, the move to WinUI 3 signals a broader shift: Microsoft is actively retiring legacy Win32 UI surfaces. If your tools add custom tabs or overlays to the Properties dialog, you will eventually need to migrate your extensions to the Windows App SDK to remain compatible.

Frequently Asked Questions

Why does the Windows 11 file properties window not follow dark mode?

The current Properties dialog is built on legacy Win32 code that pre-dates Windows 11’s theming engine. It does not integrate with the modern Fluent Design system, which is why it always renders in a light theme regardless of your system setting. The WinUI 3 redesign is specifically aimed at fixing this long-standing issue.

Will the WinUI file properties update change how I edit file metadata?

The core workflow โ€” opening Properties, switching to the Details tab, clicking a field to edit it โ€” will remain familiar. The redesign focuses on visual consistency, performance, and accessibility rather than changing the fundamental metadata schema. You will still edit the same fields in the same place, just in a much cleaner interface.

How do I remove personal metadata from a file in Windows 11?

Right-click the file, choose Properties, go to the Details tab, and click Remove Properties and Personal Information at the bottom of the panel. You can choose to remove all possible properties at once or select specific fields to clear. This works in the current dialog and will continue to work in the redesigned version.

Do I need Windows 11 Pro to get the new file properties dialog?

No. The WinUI 3 Properties dialog redesign applies to all editions of Windows 11, including Home, Pro, Enterprise, and Education. Both Home and Pro users will receive the update through standard Windows Update channels once Microsoft enables it for stable builds.

Is the redesigned file properties dialog available now?

As of mid-2026, it is present in Windows 11 Insider Preview builds (Canary and Dev channels) but is not yet enabled by default on stable releases. Microsoft has not announced a specific general availability date, but the feature appears to be progressing towards a wider rollout later in 2026.

Windows 11 offline device ID fingerprint concept on a digital background

Windows 11 Offline Device ID: How It Works and What It Means for You

Your Windows 11 offline device ID is generated silently in the background โ€” no internet required โ€” and it plays a surprisingly powerful role in licence validation, device tracking, and system management. Most users never think about it, but understanding how Windows derives this identifier tells you a great deal about how your operating system really works, and what it means for your digital footprint.

What Is a Windows Offline Device ID?

Diagram of Windows offline device ID generation from TPM UEFI and registry

A Windows offline device ID is a 32-byte cryptographic identifier that Windows generates for a given machine without ever needing to phone home to Microsoft’s servers. It is scoped and salted, meaning its value changes depending on the context in which it is requested โ€” so two different callers asking for the same PC’s offline device ID may receive different results. Despite that scoping, the underlying hardware fingerprint remains the same, anchoring the identifier firmly to your specific device.

The function responsible for this process is GetOfflineDeviceUniqueID, exported from clipc.dll โ€” the Client Licensing Platform Client. This is an undocumented Windows API that security researchers and reverse engineers have traced through the ClipSVC service and deeper into the system’s hardware roots.

How GetOfflineDeviceUniqueID Derives Your Device Hardware ID

When Windows calls GetOfflineDeviceUniqueID, the function does not invent a random number. Instead, it sources the identifier from a hierarchy of trusted hardware components, working through the following fallback chain:

  • TPM (Trusted Platform Module): If a TPM 2.0 chip is present โ€” which is mandatory on Windows 11 hardware โ€” the identifier is seeded from an endorsement key baked into the chip at manufacture. This is the most stable and tamper-resistant source.
  • UEFI firmware variables: On systems with UEFI but no TPM, Windows falls back to a unique UEFI variable written during initial setup and stored in non-volatile UEFI storage.
  • Registry-based fallback: As a last resort, a registry key stores the identifier. This is the least durable option โ€” it can be erased or altered โ€” but it keeps systems functional even on older hardware without TPM or modern UEFI.

The result of this chain is passed through a salted cryptographic operation (using HMAC-SHA256 internally) so that the 32-byte output is both unique to the device and contextually scoped to the calling application. Researchers at iretq.com reverse-engineered this call chain in detail, tracing every step from clipc.dll through ClipSVC.dll to the hardware root.

Why the Windows Device Identifier Matters for Licensing

Windows device identifier privacy concept showing laptop with data stream padlock

The Windows device identifier is central to how Microsoft validates licences without requiring a constant internet connection. When you activate Windows, the system ties your product key to a hardware profile. If you later re-install Windows on the same machine, the offline device ID confirms you are on the same device โ€” so your licence remains valid. Move that same key to a different PC and the ID no longer matches, which is precisely how single-device licence enforcement works.

This mechanism also underpins Windows Autopilot, Microsoft’s zero-touch device deployment service used by enterprises and IT departments. According to Microsoft’s official Autopilot documentation, a device’s unique hardware identity โ€” closely related to its offline device ID โ€” is captured as a hardware hash and uploaded to the Autopilot service during registration. This lets administrators pre-configure devices before they even reach the end user’s desk.

From a licensing perspective, this is why Windows license binding is so reliable: the identifier persists across clean installs and OS reinstalls as long as the hardware โ€” specifically the TPM โ€” remains unchanged.

What a Windows Offline Device ID Means for Your Privacy

This is where many users start to feel uneasy. A stable, hardware-rooted offline device ID means Windows can uniquely identify your machine even before it connects to the internet. Here are the key privacy implications:

  • Persistent across reinstalls: Because the ID is seeded from the TPM or UEFI firmware, wiping your drive and reinstalling Windows does not change it. Your device is still uniquely identifiable.
  • Scoped but not anonymous: Although the salt-scoping prevents one application from trivially correlating its device ID with another’s, Microsoft โ€” as the controlling party โ€” can correlate IDs across contexts.
  • Offline tracking capability: The ID exists and can be logged even without a network connection. A PC that has never been online still carries a unique fingerprint.
  • Used in diagnostics: Microsoft’s own Windows Privacy Compliance Guide acknowledges that device identifiers are associated with diagnostic data that Windows sends back to Microsoft when telemetry is enabled.

None of this is inherently malicious โ€” licencing systems need a reliable device fingerprint to function. But it is worth understanding exactly what is happening under the hood of your operating system.

Does Changing Hardware Reset Your Device Hardware ID?

Comparison of Windows license binding for OEM and Retail offline device ID

This is one of the most practical questions for anyone who upgrades their PC or replaces a failed component. The answer depends on which hardware you change:

  • Replacing the motherboard typically resets the TPM and UEFI variables, generating a new device hardware ID. This is why Windows may require re-activation after a motherboard swap โ€” the device looks like a new machine.
  • Replacing RAM, storage, or GPU does not affect the TPM-rooted identifier and generally does not trigger re-activation.
  • Replacing only the SSD/HDD and reinstalling Windows will still produce the same offline device ID on Windows 11, because the TPM is untouched.

For users with a Retail licence โ€” as opposed to an OEM licence โ€” Microsoft does allow you to transfer the licence to a new device. A Retail key is not permanently bound to one offline device ID, while an OEM key typically is.

Windows 11 Licence Types and Device Binding

Understanding Windows license binding matters enormously when you are purchasing a new key. The offline device ID mechanism enforces different rules depending on the licence type you hold:

  • OEM licences are permanently bound to the first device they activate on โ€” that device’s hardware ID is registered, and the key cannot move to another machine.
  • Retail licences can be deactivated from one device and reactivated on another, making them the flexible option for users who upgrade hardware regularly.
  • Volume licences (used by businesses) use a different activation path โ€” Key Management Service (KMS) or Active Directory-based activation โ€” which is less rigidly tied to a single device identifier.

If you are buying a Microsoft Windows 11 Pro Retail key for a build you plan to upgrade in the future, the Retail licence is the smarter choice precisely because it is not permanently chained to one offline device ID. At Buy Now Key, a Windows 11 Pro licence starts from just โ‚ฌ17.90 โ€” a fraction of the full Microsoft Store price.

Can You View or Reset Your Offline Device ID?

Ordinarily, end users have no native Windows interface to view their raw offline device ID โ€” it is an internal API used by the operating system and enterprise management tools. Power users and developers can call clipc!GetOfflineDeviceUniqueID directly via a proof-of-concept published on GitHub by security researcher Wack0, which confirms the function’s behaviour on modern Windows builds.

Resetting it is another matter. On systems using the TPM as the hardware root, the only reliable way to get a new device ID is to clear the TPM from the UEFI firmware settings (or replace the motherboard). On the registry-based fallback, a determined user could theoretically delete the relevant key โ€” but Windows would simply regenerate it on next boot, re-anchoring to the same hardware source if a TPM is present.

How This Relates to Legal Windows Activation

If you have ever wondered why Microsoft emphasises activating Windows through legitimate channels, the offline device ID mechanism is part of the answer. A genuine licence tied to your device’s hardware fingerprint is the only kind that survives reinstalls cleanly, passes enterprise compliance checks, and qualifies for Microsoft support. Counterfeit or cracked activations bypass this system entirely โ€” and are detectable precisely because they produce inconsistent or absent device ID bindings.

For a clear breakdown of every legitimate activation route available today, the guide on Windows licence activation legal methods at Buy Now Key is a useful starting point โ€” covering everything from free upgrade paths to volume licensing.

FAQ

What is the Windows 11 offline device ID used for?

The offline device ID is primarily used for licence validation and device tracking. It lets Windows confirm your licence is bound to your specific hardware without needing an internet connection at the point of verification. It is also used by enterprise tools like Windows Autopilot to identify and pre-configure corporate devices.

Does reinstalling Windows change my offline device ID?

No โ€” on Windows 11 hardware with a TPM 2.0 chip, reinstalling Windows does not change the offline device ID because the identifier is rooted in the TPM, not the operating system files or the drive. Your licence will still recognise the device after a clean install as long as the TPM is intact.

Is my device hardware ID the same as my hardware hash?

They are closely related but not identical. The hardware hash used in Windows Autopilot is a broader fingerprint that includes multiple hardware attributes. The offline device ID (from GetOfflineDeviceUniqueID) is a 32-byte derived identifier that feeds into the same hardware root of trust but is scoped and salted per-caller. Both ultimately anchor to the same physical machine.

Can I transfer my Windows 11 licence to a new PC if my device ID changes?

It depends on your licence type. A Retail licence can be deactivated from one device and activated on a new one โ€” even if the new machine has a completely different offline device ID. An OEM licence is permanently bound to the device it first activated on and cannot be transferred. If you plan to change hardware, always opt for a Retail key.

Does my Windows device identifier get shared with Microsoft?

Microsoft’s Windows Privacy Compliance Guide confirms that device identifiers are associated with diagnostic and telemetry data sent to Microsoft when diagnostic settings are enabled. The identifier itself forms part of the data used to associate telemetry reports with a specific device, though Microsoft states this is used for product improvement and support purposes rather than advertising.