Activating Legacy Systems for Extended Security Updates (ESU) with MAS

Microsoft Activation Scripts (MAS) enables Extended Security Updates (ESU) on legacy Windows systems through the TSforge activation engine, which applies year-specific KMS client IDs to extend security patch availability beyond mainstream support deadlines.

The massgravel/Microsoft-Activation-Scripts repository provides an open-source toolkit that bundles multiple activation methods into a unified PowerShell and Batch interface. For organizations maintaining Windows 7, Windows 8.1, Windows Server 2008 R2, or Windows Server 2012 R2 beyond their end-of-life dates, MAS offers a documented pathway to activate ESU entitlements using the TSforge method. This approach bypasses standard licensing restrictions by injecting ESU-specific KMS client identifiers directly into the Software Licensing Manager (slmgr).

How ESU Activation Works in MAS

The TSforge Activation Engine

The core ESU logic resides in MAS/Separate-Files-Version/Activators/TSforge_Activation.cmd. When the All-in-One script (MAS_AIO.cmd) receives the /Z-ESU parameter, it sets the internal flag _actesu=1 and routes execution to the ESU-specific activation block (lines 43-64). The TSforge engine then enumerates hard-coded KMS client IDs that correspond to specific ESU years and editions, such as 4220f546-f522-46df-8202-4d07afd26454_Client-ESU-Year3 for Windows 10 Enterprise ESU Year 3 (lines 1120-1137).

Why KMS-4k Is Excluded

Unlike standard volume activation, ESU activation explicitly skips the KMS-4k method. The script contains a hardcoded bypass that outputs Skipping Windows ESU [KMS4k method is not supported with Windows ESU] (line 1076) and proceeds with standard KMS client activation using the ESU-specific product keys. This architectural decision prevents compatibility conflicts with Microsoft's ESU entitlement validation system.

Command-Line Interface and Flags

The unified entry point MAS/All-In-One-Version-KL/MAS_AIO.cmd parses several flags to control ESU behavior:

  • /Z-ESU — Activates Extended Security Updates only.
  • /Z-WindowsESUOffice — Activates both Windows ESU and Office products simultaneously.
  • /Z-Reset — Clears the rearm counter and tamper flags before attempting activation (lines 31-33).

In interactive mode, selecting option [2] Activate – ESU from the ts_menu interface triggers the same _actesu=1 flag without requiring command-line input (lines 50-51).

Supported Legacy Platforms

MAS supports ESU activation for the following end-of-life Microsoft operating systems:

  • Windows 7 — Enterprise and Professional editions (3-year and 6-year ESU programs).
  • Windows 8.1 — Enterprise edition only.
  • Windows Server 2008 R2 — Datacenter and Standard editions.
  • Windows Server 2012 R2 — All eligible server variants.
  • Windows 10 LTSC Enterprise — While LTSC already includes 10-year support, MAS allows ESU activation for testing purposes.

Step-by-Step ESU Activation

Interactive PowerShell Method

For single-system activation with user guidance, execute the official download command:

irm https://get.activated.win | iex

This command fetches the latest MAS_AIO.cmd from the content delivery network and launches the interactive menu. Press 2 to select Activate – ESU, then follow the on-screen prompts to complete the KMS handshake with the default host kms8.msguides.com.

Silent Headless Deployment

For enterprise deployment or scripting scenarios, download the All-in-One script and invoke it with silent flags:

:: Download the AIO script
curl -L -o MAS_AIO.cmd "https://dev.azure.com/massgrave/Microsoft-Activation-Scripts/_apis/git/repositories/Microsoft-Activation-Scripts/items?path=/MAS/All-In-One-Version-KL/MAS_AIO.cmd&download=true"

:: Execute ESU activation without user interaction
MAS_AIO.cmd /Z-ESU /Z-Reset

The /Z-Reset parameter ensures clean activation state by removing previous rearm counts and tamper flags before the TSforge engine applies the ESU KMS ID.

Direct TSforge Execution

Advanced users may invoke the TSforge activator directly without the menu wrapper:

:: Navigate to the extracted MAS folder
cd MAS\Separate-Files-Version\Activators

:: Execute ESU activation
TSforge_Activation.cmd /Z-ESU

This method displays verbose output including the selected ESU KMS ID and real-time communication status with the KMS host.

Verifying ESU Activation Status

Confirm successful activation using the built-in Software Licensing Manager:

slmgr /dlv

Look for "License Status: Licensed" and an "Extended Security Updates" descriptor in the detailed output. The partial product key shown should match the ESU-specific key injected by the TSforge script, confirming that security updates will install through Windows Update until the selected ESU period expires.

Summary

  • MAS uses TSforge, not KMS-4k, to activate ESU entitlements on legacy Windows systems via year-specific KMS client IDs.
  • The /Z-ESU flag triggers activation through MAS_AIO.cmd, while the /Z-Reset flag ensures clean licensing state.
  • Core logic lives in TSforge_Activation.cmd (lines 1076-1137), which maps detected Windows editions to hardcoded ESU product keys.
  • Supported platforms include Windows 7, Windows 8.1, Windows Server 2008 R2, and Windows Server 2012 R2.
  • Verification requires checking slmgr /dlv for "Extended Security Updates" licensing status.

Frequently Asked Questions

What is the difference between ESU activation and standard Windows activation in MAS?

Standard Windows activation typically uses the HWID (Hardware ID) or Online KMS methods to validate a full operating system license. ESU activation specifically targets the Extended Security Updates add-on package using the TSforge engine with dedicated KMS client IDs that represent paid security update entitlements. While HWID permanently activates the base OS, ESU activation requires periodic KMS renewal and uses product keys prefixed with "Client-ESU-Year" identifiers.

Does ESU activation require an internet connection?

Yes, the TSforge activation method requires network connectivity to contact a KMS host. By default, MAS uses kms8.msguides.com, though administrators can override this by setting the kms environment variable before execution. The script performs a standard KMS client handshake (TCP port 1688) to activate the ESU SKU, unlike offline methods such as HWID.

Which Windows versions qualify for ESU activation through MAS?

MAS supports ESU activation for Windows 7 Enterprise/Professional, Windows 8.1 Enterprise, Windows Server 2008 R2 (Datacenter/Standard), and Windows Server 2012 R2. These systems must have the ESU patching prerequisite updates installed. Windows 10 LTSC editions do not require ESU for security updates but can be activated for testing purposes using the same TSforge pathway.

Why does MAS skip the KMS-4k method for ESU activation?

The KMS-4k method, which exploits a specific count-limit bypass in volume licensing, is explicitly unsupported for ESU products (as noted in line 1076 of TSforge_Activation.cmd). Microsoft's ESU validation infrastructure requires standard KMS client activation with authentic product key entries. The script architecture deliberately routes ESU requests through the traditional KMS flow to ensure compatibility with Windows Update's entitlement checking mechanisms.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →