# TSforge Activation: Technical Implementation in Microsoft-Activation-Scripts

> Explore the technical implementation of TSforge activation within Microsoft Activation Scripts. Learn how this modular engine automates licensing using StaticCID ZeroCID and KMS4k methods for Windows Office and ESU.

- Repository: [MASSGRAVE/Microsoft-Activation-Scripts](https://github.com/massgravel/Microsoft-Activation-Scripts)
- Tags: deep-dive
- Published: 2026-02-24

---

**TSforge activation is a modular batch-script engine that automates Windows, Office, and ESU licensing through three cryptographic methods—StaticCID, ZeroCID, and KMS4k—by orchestrating `slmgr.vbs` commands and manipulating the Software Licensing Manager store.** The implementation resides in the `massgravel/Microsoft-Activation-Scripts` repository as a comprehensive alternative to hardware-based or traditional KMS activation schemes.

The `TSforge_Activation.cmd` script serves as the primary activation driver, providing both interactive menus and fully unattended command-line operation. It handles environment hardening, edition detection, and method selection through a linear architecture designed for enterprise deployment reliability.

## Configuration and Command-Line Interface

The script exposes activation targets through feature-toggle variables that can be modified directly or overridden via command-line switches. At lines 14-44, the default configuration block defines behavior for Windows, ESU, and Office activation:

```batch
::  To activate Windows, run the script with "/Z-Windows" parameter or change 0 to 1 in below line
set _actwin=0
::  To activate Windows ESU, run the script with "/Z-ESU" parameter or change 0 to 1 in below line
set _actesu=0
::  To activate all Office apps (including Project/Visio), run the script with "/Z-Office" parameter or change 0 to 1 in below line
set _actoff=0

```

The argument parsing loop at lines 84-103 processes parameters such as `/Z-Windows`, `/Z-ESU`, `/Z-Office`, and `/Z-Reset`, stripping quotes and setting internal flags like `_actwin` and `_actoff`. Advanced switches include `/Z-SCID` to force StaticCID, `/Z-ZCID` for ZeroCID, and `/Z-KMS4k` for the 4000-year KMS method.

## Environment Preparation and Validation

Before executing licensing commands, the script performs rigorous sanitization to prevent interference from third-party tools. Lines 65-75 rebuild the `Path` environment variable to include only `%SystemRoot%\System32` and verified system directories, while forcing a known `PathExt` to avoid executable hijacking.

Architecture detection ensures proper execution across x86, x64, and ARM64 platforms. If launched from a 32-bit CMD on a 64-bit OS, the script automatically relaunches itself using `%SystemRoot%\Sysnative\cmd.exe` (lines 89-104). Administrative rights are verified through a `fltmc` test (lines 101-107); if elevation is missing, the script restarts with the `runas` verb.

Diagnostic pre-flight checks include validating the "Null" service state, detecting Unix line-endings (which would cause parsing errors), and optionally pinging remote servers to check for script updates.

## Activation Method Selection Logic

TSforge activation implements three distinct cryptographic approaches selected automatically or via override parameters. Lines 47-53 define the default `Auto` behavior:

```batch
::  Choose activation method:
::  In builds 26100 and later, the script will auto select StaticCID (requires internet). 
::  If no internet is detected, it will then auto select the KMS4k method. 
::  For builds lower than 26100, the script will auto select ZeroCID.
set _actmethod=Auto

```

**StaticCID** requires internet connectivity to generate a confirmation ID and is the default for Windows builds 26100 and later. **ZeroCID** operates entirely offline using zeroed confirmation identifiers for older builds. **KMS4k** implements a 4000-year Key Management Service key that requires no network access and serves as the fallback when StaticCID connectivity tests fail.

## Core Activation Routine Implementation

The `:ts_start` subroutine orchestrates the actual licensing operations after menu selection or direct parameter invocation. This routine follows a structured sequence of detection, validation, and injection.

### Windows Version and Edition Detection

The script queries registry values to determine the current edition ID and build number, storing these in variables like `tsedition` (lines 15-22, 263-276). This detection enables precise matching against the embedded activation ID database and determines eligibility for specific methods.

### Activation ID Extraction

Product-specific activation identifiers are extracted from the `:tsforge:` data block located at the end of the script file (lines 66-70, 262-276). This embedded database contains mappings between Windows editions, Office SKUs, and their corresponding GUIDs, which the script loads into the `tsids` variable for batch processing.

### Method-Specific Handling

Each activation path follows distinct implementation patterns within the core routine:

- **StaticCID**: Inserts the generic product key using `slmgr /ipk`, then attempts online confirmation ID retrieval through Microsoft licensing servers.
- **ZeroCID**: Applies the same ID database but uses zero-filled confirmation IDs, bypassing server communication entirely.
- **KMS4k**: Clears existing KMS caches via `:dk_clear`, installs the CSVLK host key, and activates against a local 4000-year KMS server implementation defined in `:dk_act`.

### Office and ESU Activation Paths

Office activation branches to `:ts_off` (lines 12-24, 30-44), which handles Word, Excel, Project, and Visio through similar ID injection techniques. The script checks for **Ohook** presence and falls back to classic KMS methods if necessary.

Windows ESU (Extended Security Updates) uses the dedicated `:ts_esu` branch (lines 71-112), validating eligible editions against internal SKU tables and injecting special ESU keys when available in the database.

## Helper Subroutines and Shared Libraries

Low-level operations are delegated to standardized `:dk` functions defined toward the end of the file (starting around line 2600). These utilities ensure consistent behavior across the Microsoft-Activation-Scripts ecosystem:

- `:dk_setvar` – Aggregates system variables including `winbuild` and `tsedition`.
- `:dk_inskey` – Executes `slmgr.vbs /ipk` for product key installation.
- `:dk_act` – Triggers activation via `slmgr /ato` or Office-specific binaries.
- `:dk_errorcheck` and `:dk_color` – Standardized error handling and console output formatting.

These routines are shared with sibling activators like `Online_KMS_Activation.cmd` and `HWID_Activation.cmd`, creating a unified utility layer that abstracts registry manipulation and WMI queries.

## Practical Usage Examples

Activate Windows using automatic method selection:

```batch
MAS\Separate-Files-Version\Activators\TSforge_Activation.cmd /Z-Windows

```

Force the ZeroCID offline method for air-gapped systems:

```batch
MAS\Separate-Files-Version\Activators\TSforge_Activation.cmd /Z-ZCID

```

Activate Office suite with manual ID specification:

```batch
MAS\Separate-Files-Version\Activators\TSforge_Activation.cmd /Z-Office /Z-ID-550e-...-XXXX

```

Reset all licensing timers, rearm counters, and tamper states:

```batch
MAS\Separate-Files-Version\Activators\TSforge_Activation.cmd /Z-Reset

```

## Summary

- **TSforge activation** is implemented in `TSforge_Activation.cmd` as a comprehensive batch-script solution for Windows and Office licensing.
- The script supports three activation methods: **StaticCID** (online), **ZeroCID** (offline), and **KMS4k** (4000-year KMS emulation).
- Command-line parameters like `/Z-Windows`, `/Z-Office`, and `/Z-ESU` enable unattended deployment across enterprise environments.
- Environment hardening includes path sanitization, architecture detection, and administrative elevation checks before executing `slmgr.vbs` commands.
- Activation IDs are extracted from an embedded `:tsforge:` data block and matched against detected Windows editions or Office SKUs using helper subroutines like `:dk_setvar` and `:dk_inskey`.

## Frequently Asked Questions

### What is TSforge activation and how does it differ from HWID activation?

TSforge activation is a software-based licensing technique that manipulates the Software Licensing Manager through CID injection or KMS emulation, whereas HWID activation binds the license to specific hardware identifiers. According to the Microsoft-Activation-Scripts source code, TSforge works on both modern Windows 11 builds and legacy systems through multiple fallback methods, while HWID is specific to Windows 10/11 digital entitlements stored on Microsoft servers.

### How does the script choose between StaticCID and KMS4k methods?

The script automatically selects **StaticCID** for Windows builds 26100 and later when internet connectivity is detected through ping tests to root DNS servers and Google domains. If the connectivity check at lines 75-88 fails, it falls back to **KMS4k**. Users can override this logic using `/Z-SCID` or `/Z-KMS4k` switches to force a specific implementation.

### Can TSforge activate Office without activating Windows?

Yes. The `/Z-Office` parameter triggers the `:ts_off` subroutine independently of Windows activation logic. The script queries the Office installation directory, validates SKUs against the embedded ID database, and applies licensing tokens through `ospp.vbs` or `slmgr` without modifying the Windows activation state or requiring the `/Z-Windows` switch.

### Is internet access required for TSforge activation?

Internet access is only required for the **StaticCID** method, which must communicate with Microsoft servers to retrieve valid confirmation IDs. The **ZeroCID** method works entirely offline using zero-filled confirmation identifiers for builds below 26100, and **KMS4k** requires no network connectivity as it implements a local 4000-year KMS server emulation that bypasses external validation.