If a MAK key is specified in unattend.xml during Windows setup or Sysprep deployment, Windows 11 Enterprise will generally behave differently than when the key is manually installed later with slmgr.vbs /ipk. In the unattended setup case, Windows Setup integrates the key as part of the deployment and the Software Protection Platform is allowed to perform automatic activation when network connectivity becomes available, unless automatic activation has been explicitly disabled. In other words, a machine deployed with a MAK embedded in unattend.xml will normally attempt activation automatically once it can reach Microsoft’s activation servers, and you typically do not need to invoke slmgr.vbs /ato manually.
What you observed on Windows 11 Enterprise is consistent with the current activation behavior. Windows builds still include scheduled and event-triggered activation attempts through the Software Protection Platform service. The Event Viewer entries you found showing Action=AutoActivate and Trigger=NetworkAvailable confirm that Windows 11 is performing automatic activation retries when connectivity appears. So in practice, on Windows 11 Enterprise, installing a MAK with /ipk alone does not guarantee that activation will remain deferred indefinitely after Internet access is restored.
Because of that, if your goal is to preload the MAK onto systems but prevent activation until a later controlled step, setting the Manual registry value to 1 under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Activation is the correct approach. That disables automatic activation behavior and prevents the Software Protection Platform from automatically attempting activation when the network becomes available. In that configuration, the machine would remain in the Notification or grace state until slmgr.vbs /ato or another explicit activation method is invoked.
Regarding MAK activation counts, reimaging the same physical machine can consume another MAK activation even if the hardware itself has not changed. MAK activation is not strictly tied only to hardware identity; it is tied to an activation request generated by the installation instance. A clean reinstall or reimage produces a new Windows installation with a new installation ID, and Microsoft’s activation infrastructure may treat it as a separate activation event. Sometimes the activation servers correlate it closely enough to avoid incrementing the count again, but this is not guaranteed. In enterprise environments, repeated reimaging of the same devices using MAK keys can absolutely lead to additional MAK activations being consumed over time.
That behavior is one of the reasons Microsoft generally recommends KMS or Active Directory-Based Activation instead of MAK for frequently reimaged enterprise systems. MAK is best suited for systems that are relatively static or rarely redeployed.
If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.
hth
Marcin