# Activating Legacy Systems for Extended Security Updates (ESU) with MAS

> Activate legacy Windows systems for Extended Security Updates ESU using Microsoft Activation Scripts MAS. Extend security patch availability on older systems with TSforge activation.

- Repository: [MASSGRAVE/Microsoft-Activation-Scripts](https://github.com/massgravel/Microsoft-Activation-Scripts)
- Tags: how-to-guide
- Published: 2026-02-24

---

**Microsoft Activation Scripts (MAS) enables Extended Security Updates (ESU) on legacy Windows systems through the TSforge activation engine, which applies year-specific KMS client IDs to extend security patch availability beyond mainstream support deadlines.**

The `massgravel/Microsoft-Activation-Scripts` repository provides an open-source toolkit that bundles multiple activation methods into a unified PowerShell and Batch interface. For organizations maintaining Windows 7, Windows 8.1, Windows Server 2008 R2, or Windows Server 2012 R2 beyond their end-of-life dates, MAS offers a documented pathway to activate ESU entitlements using the **TSforge** method. This approach bypasses standard licensing restrictions by injecting ESU-specific KMS client identifiers directly into the Software Licensing Manager (`slmgr`).

## How ESU Activation Works in MAS

### The TSforge Activation Engine

The core ESU logic resides in `MAS/Separate-Files-Version/Activators/TSforge_Activation.cmd`. When the All-in-One script (`MAS_AIO.cmd`) receives the **`/Z-ESU`** parameter, it sets the internal flag `_actesu=1` and routes execution to the ESU-specific activation block (lines 43-64). The TSforge engine then enumerates hard-coded KMS client IDs that correspond to specific ESU years and editions, such as `4220f546-f522-46df-8202-4d07afd26454_Client-ESU-Year3` for Windows 10 Enterprise ESU Year 3 (lines 1120-1137).

### Why KMS-4k Is Excluded

Unlike standard volume activation, ESU activation **explicitly skips** the KMS-4k method. The script contains a hardcoded bypass that outputs `Skipping Windows ESU [KMS4k method is not supported with Windows ESU]` (line 1076) and proceeds with standard KMS client activation using the ESU-specific product keys. This architectural decision prevents compatibility conflicts with Microsoft's ESU entitlement validation system.

### Command-Line Interface and Flags

The unified entry point `MAS/All-In-One-Version-KL/MAS_AIO.cmd` parses several flags to control ESU behavior:

- **`/Z-ESU`** — Activates Extended Security Updates only.
- **`/Z-WindowsESUOffice`** — Activates both Windows ESU and Office products simultaneously.
- **`/Z-Reset`** — Clears the rearm counter and tamper flags before attempting activation (lines 31-33).

In interactive mode, selecting option **[2] Activate – ESU** from the `ts_menu` interface triggers the same `_actesu=1` flag without requiring command-line input (lines 50-51).

## Supported Legacy Platforms

MAS supports ESU activation for the following end-of-life Microsoft operating systems:

- **Windows 7** — Enterprise and Professional editions (3-year and 6-year ESU programs).
- **Windows 8.1** — Enterprise edition only.
- **Windows Server 2008 R2** — Datacenter and Standard editions.
- **Windows Server 2012 R2** — All eligible server variants.
- **Windows 10 LTSC Enterprise** — While LTSC already includes 10-year support, MAS allows ESU activation for testing purposes.

## Step-by-Step ESU Activation

### Interactive PowerShell Method

For single-system activation with user guidance, execute the official download command:

```powershell
irm https://get.activated.win | iex

```

This command fetches the latest `MAS_AIO.cmd` from the content delivery network and launches the interactive menu. Press **2** to select **Activate – ESU**, then follow the on-screen prompts to complete the KMS handshake with the default host `kms8.msguides.com`.

### Silent Headless Deployment

For enterprise deployment or scripting scenarios, download the All-in-One script and invoke it with silent flags:

```cmd
:: Download the AIO script
curl -L -o MAS_AIO.cmd "https://dev.azure.com/massgrave/Microsoft-Activation-Scripts/_apis/git/repositories/Microsoft-Activation-Scripts/items?path=/MAS/All-In-One-Version-KL/MAS_AIO.cmd&download=true"

:: Execute ESU activation without user interaction
MAS_AIO.cmd /Z-ESU /Z-Reset

```

The `/Z-Reset` parameter ensures clean activation state by removing previous rearm counts and tamper flags before the TSforge engine applies the ESU KMS ID.

### Direct TSforge Execution

Advanced users may invoke the TSforge activator directly without the menu wrapper:

```cmd
:: Navigate to the extracted MAS folder
cd MAS\Separate-Files-Version\Activators

:: Execute ESU activation
TSforge_Activation.cmd /Z-ESU

```

This method displays verbose output including the selected ESU KMS ID and real-time communication status with the KMS host.

## Verifying ESU Activation Status

Confirm successful activation using the built-in Software Licensing Manager:

```cmd
slmgr /dlv

```

Look for **"License Status: Licensed"** and an **"Extended Security Updates"** descriptor in the detailed output. The partial product key shown should match the ESU-specific key injected by the TSforge script, confirming that security updates will install through Windows Update until the selected ESU period expires.

## Summary

- **MAS uses TSforge**, not KMS-4k, to activate ESU entitlements on legacy Windows systems via year-specific KMS client IDs.
- The **`/Z-ESU`** flag triggers activation through `MAS_AIO.cmd`, while the **`/Z-Reset`** flag ensures clean licensing state.
- Core logic lives in `TSforge_Activation.cmd` (lines 1076-1137), which maps detected Windows editions to hardcoded ESU product keys.
- Supported platforms include Windows 7, Windows 8.1, Windows Server 2008 R2, and Windows Server 2012 R2.
- Verification requires checking `slmgr /dlv` for "Extended Security Updates" licensing status.

## Frequently Asked Questions

### What is the difference between ESU activation and standard Windows activation in MAS?

Standard Windows activation typically uses the HWID (Hardware ID) or Online KMS methods to validate a full operating system license. ESU activation specifically targets the **Extended Security Updates** add-on package using the TSforge engine with dedicated KMS client IDs that represent paid security update entitlements. While HWID permanently activates the base OS, ESU activation requires periodic KMS renewal and uses product keys prefixed with "Client-ESU-Year" identifiers.

### Does ESU activation require an internet connection?

Yes, the TSforge activation method requires network connectivity to contact a KMS host. By default, MAS uses `kms8.msguides.com`, though administrators can override this by setting the `kms` environment variable before execution. The script performs a standard KMS client handshake (TCP port 1688) to activate the ESU SKU, unlike offline methods such as HWID.

### Which Windows versions qualify for ESU activation through MAS?

MAS supports ESU activation for **Windows 7 Enterprise/Professional**, **Windows 8.1 Enterprise**, **Windows Server 2008 R2** (Datacenter/Standard), and **Windows Server 2012 R2**. These systems must have the ESU patching prerequisite updates installed. Windows 10 LTSC editions do not require ESU for security updates but can be activated for testing purposes using the same TSforge pathway.

### Why does MAS skip the KMS-4k method for ESU activation?

The KMS-4k method, which exploits a specific count-limit bypass in volume licensing, is **explicitly unsupported** for ESU products (as noted in line 1076 of `TSforge_Activation.cmd`). Microsoft's ESU validation infrastructure requires standard KMS client activation with authentic product key entries. The script architecture deliberately routes ESU requests through the traditional KMS flow to ensure compatibility with Windows Update's entitlement checking mechanisms.