Using smlgr with MAK keys on Windows 11 Enterprise

Van Fifty 40 Reputation points
2026-06-04T00:21:50.83+00:00

I was reading the following which applies to Windows 10 and would like to know if it also applies to Windows 11 Enterprise:

https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/dn502526(v=ws.11)

It mentions "slmgr.vbs /ipk <MultipleActivationKey>" it then states "If users install a MAK by using the UI, the MAK client attempts to activate itself over the Internet one time. If the users install a MAK key by using the Slmgr.vbs script, the MAK client does not try to activate automatically."

I would like to confirm, if a system is disconnected from the Internet and slmgr.vbs /ipk is used then the license will be associated with the OS but Windows 11 will not activate? Even after connecting to the Internet Windows will still not activate and the MAK count will remain unchanged.

To activate, one would need to connect to the Internet and then also invoke : slmgr.vbs /ato

This will then use up one MAK count and Windows 11 will be activated, correct?

If slmgr.vbs /ato is invoked multiple times after activation on the same activated system then the MAK count will remain unchanged?

Windows for home | Windows 11 | Licensing and activation
0 comments No comments

Answer accepted by question author
Marcin Policht 109.6K Reputation points MVP Volunteer Moderator
2026-06-05T18:59:10.16+00:00

If a MAK key is specified in unattend.xml during Windows setup or Sysprep deployment, Windows 11 Enterprise will generally behave differently than when the key is manually installed later with slmgr.vbs /ipk. In the unattended setup case, Windows Setup integrates the key as part of the deployment and the Software Protection Platform is allowed to perform automatic activation when network connectivity becomes available, unless automatic activation has been explicitly disabled. In other words, a machine deployed with a MAK embedded in unattend.xml will normally attempt activation automatically once it can reach Microsoft’s activation servers, and you typically do not need to invoke slmgr.vbs /ato manually.

What you observed on Windows 11 Enterprise is consistent with the current activation behavior. Windows builds still include scheduled and event-triggered activation attempts through the Software Protection Platform service. The Event Viewer entries you found showing Action=AutoActivate and Trigger=NetworkAvailable confirm that Windows 11 is performing automatic activation retries when connectivity appears. So in practice, on Windows 11 Enterprise, installing a MAK with /ipk alone does not guarantee that activation will remain deferred indefinitely after Internet access is restored.

Because of that, if your goal is to preload the MAK onto systems but prevent activation until a later controlled step, setting the Manual registry value to 1 under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SoftwareProtectionPlatform\Activation is the correct approach. That disables automatic activation behavior and prevents the Software Protection Platform from automatically attempting activation when the network becomes available. In that configuration, the machine would remain in the Notification or grace state until slmgr.vbs /ato or another explicit activation method is invoked.

Regarding MAK activation counts, reimaging the same physical machine can consume another MAK activation even if the hardware itself has not changed. MAK activation is not strictly tied only to hardware identity; it is tied to an activation request generated by the installation instance. A clean reinstall or reimage produces a new Windows installation with a new installation ID, and Microsoft’s activation infrastructure may treat it as a separate activation event. Sometimes the activation servers correlate it closely enough to avoid incrementing the count again, but this is not guaranteed. In enterprise environments, repeated reimaging of the same devices using MAK keys can absolutely lead to additional MAK activations being consumed over time.

That behavior is one of the reasons Microsoft generally recommends KMS or Active Directory-Based Activation instead of MAK for frequently reimaged enterprise systems. MAK is best suited for systems that are relatively static or rarely redeployed.


If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

hth

Marcin

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Oldest
  1. Marcin Policht 109.6K Reputation points MVP Volunteer Moderator
    2026-06-04T00:39:56.54+00:00

    Yep - the behavior described in that Windows 10 / Windows Server documentation still applies to Windows 11 Enterprise when using a MAK (Multiple Activation Key). When you run:

    slmgr.vbs /ipk <MAK-key>
    

    you are only installing the product key into the licensing store. That alone does not activate Windows if the key was installed through slmgr.vbs. So in your scenario, on a system that is disconnected from the Internet will install the MAK into Windows 11 Enterprise, but Windows will remain in the unactivated state.

    If the machine is later connected to the Internet, Windows still will not automatically activate merely because the MAK is present. The activation attempt is not automatically triggered simply due to connectivity being restored after a scripted /ipk installation.

    Activation occurs when you explicitly invoke:

    slmgr.vbs /ato
    

    or otherwise initiate activation through the UI/API. At that point, Windows contacts Microsoft's activation servers, consumes one MAK activation from the pool, and activates the installation. After the system is already activated, running:

    slmgr.vbs /ato
    

    again on the same unchanged installation normally does not consume additional MAK activations. Microsoft activation servers recognize the existing activation state/hardware identity. Repeated /ato calls on the same installation are generally harmless and do not continually decrement the MAK count. Note though that substantial hardware changes or reinstallation/reimaging can cause the system to be treated as a new activation event, which can consume another MAK activation.


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.