Fix it now
Both codes come from the client and both point at the server. Microsoft publishes 0xC004F041 as the Key Management Service not being activated, and 0xC004F039 as the Key Management Service not being enabled. Nothing on the client needs changing.
slmgr /dlv
sc query sppsvc
netstat -ano | findstr :1688
- Read two lines of the
slmgr /dlvoutput: the description should name a KMS host key, and Licence Status should read Licensed. Anything else is your answer. - If a host key is installed but the host is not licensed, activate it:
slmgr /ato. With no internet route, activate by phone instead – search for SLUI 04 from Start. - If no host key is installed, add the Volume Activation Services role and run the Volume Activation Tools wizard:
Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools, thenvmw.exe. - Open the port:
Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True. - Go back to a client and run
slmgr /ato.
Do not install a KMS host key on a client. Clients take a generic volume licence key; a host key on a client is one of the documented ways a host key gets used up.
If the client activates, you are done. If not, the next section separates the two codes, which have different causes and different fixes.
Why it happens
KMS is a chain with two links. A host holds a KMS host key, activates that key once against Microsoft, and from then on issues activations to clients on your network. A client holds a generic volume licence key, which is not an entitlement so much as an instruction to go and borrow one. Break the first link and the second cannot exist, which is why both of these codes appear on clients and are fixed on the server.
Microsoft publishes 0xC004F041 as “The Software Protection Service determined that the Key Management Server (KMS) isn’t activated. KMS needs to be activated”, and its resolution is a single line: activate the KMS host using online or telephone activation. That is unusually direct for an activation code. It means a host key is present and its own activation never completed.
0xC004F039 is published differently. Its text is that the computer could not be activated because the Key Management Service is not enabled, and Microsoft’s resolution is to troubleshoot the network connection between host and client and confirm no firewall is blocking TCP 1688. So the two codes are not two shades of the same thing: one is about the host’s licence state, the other about whether the client reached a working service at all.
Event ID 12290 is the fastest way to tell which you have. It is written on the host, in the Key Management Service log, once for each client that contacts it, and it carries the client’s CMID and the minimum count needed. Entries arriving from your failing clients mean they reached the host and were refused. No entries at all mean they never got there, and the fault is in front of the host rather than inside it. 0xC004E005 turns up in these conversations too, and Microsoft publishes no meaning for it.
A host key is installed but the host was never activated
You have this one if slmgr /dlv on the host names a KMS host key and Licence Status reads something other than Licensed. Clients report 0xC004F041.
- Confirm the host can reach Microsoft’s activation endpoints on TCP 443.
- Run
slmgr /atoon the host and wait for the result rather than assuming it. - With no internet route, activate by phone: search for SLUI 04 from Start, or use
slmgr /dtito read the Installation ID andslmgr /atp <Confirmation ID>to complete it. - Re-run
slmgr /dlvand confirm Licence Status now reads Licensed.
No host key was ever installed on this machine
You have this one if slmgr /dlv describes an ordinary volume client rather than a host, and nothing is listening on 1688.
- On Windows Server, add the role:
Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools. - Run the Volume Activation Tools wizard with
vmw.exe, choose the Key Management Service option, and supply your KMS host key. - Let the wizard activate the key online, or by phone if the host is isolated.
- Enable the firewall rule:
Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True.
You can get the organisation’s KMS host key from the Microsoft 365 admin centre. Installing it converts the machine into a KMS host, so do it deliberately rather than to see what happens.
The service is not answering on the port
You have this one if 0xC004F039 specifically, and netstat -ano | findstr :1688 on the host returns nothing.
- Check the Software Protection service with
sc query sppsvcand start it if it is stopped. - Re-check for a LISTENING line on 1688 once it is running.
- Confirm the firewall rule is enabled for the profile the host is actually on.
- Test from a client subnet with
Test-NetConnection <host> -Port 1688.
The host key has been spent on too many hosts
You have this one if The host refuses its own activation, and this key has stood up other hosts before – often test builds nobody decommissioned.
- Stop changing things on the server. The refusal is held against the key at Microsoft’s end.
- Count the machines this key has been installed on, including ones that no longer exist.
- Ask the Microsoft Licensing Activation Centers for a key reset or replacement, with your agreement details ready.
Microsoft publishes the figure against 0xC004C008: a KMS host key permits up to 10 activations on no more than 6 different computers. If you are seeing that code on a host, this is the cause.
Full reference
Which machine to look at, and what it should say
| What you see | Where | What it means |
|---|---|---|
| Description names a KMS host key, Licence Status Licensed | Host | The host is healthy. Look at the network path next |
| Description names a KMS host key, any other status | Host | The 0xC004F041 case. Activate the host |
| Description names a volume client | Host | No host key was installed. This machine is not a KMS host |
| No LISTENING line on 1688 | Host | The service is not answering. The 0xC004F039 case |
| Event ID 12290 entries from your failing clients | Host | Clients are reaching the host and being refused |
| No Event ID 12290 entries at all | Host | Clients never arrive. The fault is DNS, routing or the firewall |
Standing a host up the documented way
- On a supported Windows Server, add the Volume Activation Services role. In PowerShell:
Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools. - Enable the firewall rule:
Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True. - Run the Volume Activation Tools wizard:
vmw.exe. - Choose Key Management Service, enter your KMS host key, and activate it online or by telephone.
- Commit the configuration and close the wizard, then confirm with
slmgr /dlvthat the host reads Licensed.
The wizard route matters because it configures the role as well as installing the key. Installing the key with slmgr /ipk alone works, but it leaves you doing by hand the parts the wizard does for you, and it is the route most likely to end with a host that is licensed and still not answering.
Which log to read on which machine
| Event ID | Logged on | Log | What it records |
|---|---|---|---|
| 12288 | The client | Application | The client attempted activation, with the host name and port it used |
| 12289 | The client | Application | The response, carrying the activation flag – 1 for success, 0 for failure – and the host’s current count |
| 12290 | The host | Key Management Service | A client contacted the host, with its CMID and the minimum count needed |
| 12293 | The host | Key Management Service | The host failed to publish its DNS records |
A 12288 on the client with no 12289 after it means the request left and nothing came back. That is a network or host problem, not a licensing one, and no amount of work on the client will move it.
What a KMS host can and cannot activate
- A KMS host running Windows Server can activate both server and client operating systems. A KMS host running a Windows client edition can activate only client operating systems.
- A host may be physical or virtual. Microsoft states that you can run a KMS host on any physical or virtual system running a supported Windows Server or Windows client operating system.
- The host needs the host key that covers the products you are activating. A client reaching a host that cannot serve its product gets 0xC004F042, which is a different article.
- Clients need a count on the host before it will answer: 25 or higher for client editions, 5 or greater for servers and volume Office. Below that, the host is healthy and still refuses.
Before you conclude the host key is the problem
Two checks separate a genuine key problem from an infrastructure one, and both take seconds. First, does the host activate itself? A host that reads Licensed has a working key, whatever the clients are reporting. Second, do 12290 entries appear on the host when a client tries? If they do, the client is reaching a working service and being refused for a reason the host will name; if they do not, nothing about the key is in question yet.
It is worth being clear about what this code does not mean. It is not a shortfall of client licences, it is not a count problem, and it is not something a client-side registry edit reaches. The client is reporting, accurately, what the server told it.
When a licence is the actual fix
A KMS host is only as good as its host key, and a host key is issued against a volume licence agreement rather than bought off a shelf. If your organisation has grown past its original agreement, inherited an estate with no paperwork, or lost access to the portal the key lives in, you need a properly issued Windows Server KMS host key before any of the steps above will complete. Arco supplies them, and will check which host key covers the client editions you are actually running before you order, because a host key issued for an older product generation will activate the host and still refuse your newer clients – a separate code and a separate afternoon.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC004F041 |
The Key Management Service is not activated and needs to be activated. Microsoft’s resolution is to activate the host online or by telephone | Microsoft Learn |
0xC004F039 |
The computer could not be activated because the Key Management Service is not enabled. Documented checks are the network path and TCP 1688 | Microsoft Learn |
Event ID 12290 |
Written on the KMS host, in the Key Management Service log, once for each client activation request, with the client CMID and the minimum count needed | Microsoft Learn |
0xC004E005 |
Seen alongside these failures. Read it as the licensing service refusing to complete, and diagnose from the host’s licence state rather than the digits | not published by the vendor |
Confirm the fix worked
- On the host,
slmgr /dlvnames a KMS host key and Licence Status reads Licensed. netstat -ano | findstr :1688on the host returns a LISTENING line.Test-NetConnection <host> -Port 1688from a client subnet returns True.- On a client,
slmgr /atocompletes andslmgr /dlvreads Licensed. - A new Event ID 12290 appears in the host’s Key Management Service log for that client.
Questions people ask about this
Can I use a client key on the KMS host?
No. A host needs a KMS host key; clients take a generic volume licence key. Installing a client key on the host turns it into an ordinary client and it stops serving activations.
Does the KMS host need permanent internet access?
Only for its own activation and any later re-activation. Day to day it serves clients entirely on the local network, and telephone activation covers hosts that are permanently isolated.
How many KMS hosts should I run?
Enough for resilience and no more. Every host has to meet the count threshold on its own – 25 for client editions, 5 for servers – so spreading a small estate across several hosts can leave none of them able to activate anything.
Will fixing the host activate my clients automatically?
Yes, in time. Unactivated clients retry on a schedule, with a documented default of two hours. Run slmgr /ato on one client if you want to confirm the fix now rather than waiting.
Can the host be a virtual machine?
Yes. Microsoft states that a KMS host can run on any physical or virtual system running a supported Windows Server or Windows client operating system. There is no need to find physical hardware for it.
