Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

License Error 0xC004F041

0xC004F041 and 0xC004F039: Your KMS Host Is Not Activated or Enabled

11 min read Updated October 5, 2026 Windows Activation & Licensing

Fix it now

Both codes come from the client and both point at the server. Microsoft publishes 0xC004F041 as the Key Management Service not being activated, and 0xC004F039 as the Key Management Service not being enabled. Nothing on the client needs changing.

Run these on the KMS host, in an elevated Command Prompt, in order

slmgr /dlv
sc query sppsvc
netstat -ano | findstr :1688
  1. Read two lines of the slmgr /dlv output: the description should name a KMS host key, and Licence Status should read Licensed. Anything else is your answer.
  2. If a host key is installed but the host is not licensed, activate it: slmgr /ato. With no internet route, activate by phone instead – search for SLUI 04 from Start.
  3. If no host key is installed, add the Volume Activation Services role and run the Volume Activation Tools wizard: Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools, then vmw.exe.
  4. Open the port: Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True.
  5. Go back to a client and run slmgr /ato.

Do not install a KMS host key on a client. Clients take a generic volume licence key; a host key on a client is one of the documented ways a host key gets used up.

If the client activates, you are done. If not, the next section separates the two codes, which have different causes and different fixes.

Why it happens

KMS is a chain with two links. A host holds a KMS host key, activates that key once against Microsoft, and from then on issues activations to clients on your network. A client holds a generic volume licence key, which is not an entitlement so much as an instruction to go and borrow one. Break the first link and the second cannot exist, which is why both of these codes appear on clients and are fixed on the server.

Microsoft publishes 0xC004F041 as “The Software Protection Service determined that the Key Management Server (KMS) isn’t activated. KMS needs to be activated”, and its resolution is a single line: activate the KMS host using online or telephone activation. That is unusually direct for an activation code. It means a host key is present and its own activation never completed.

0xC004F039 is published differently. Its text is that the computer could not be activated because the Key Management Service is not enabled, and Microsoft’s resolution is to troubleshoot the network connection between host and client and confirm no firewall is blocking TCP 1688. So the two codes are not two shades of the same thing: one is about the host’s licence state, the other about whether the client reached a working service at all.

Event ID 12290 is the fastest way to tell which you have. It is written on the host, in the Key Management Service log, once for each client that contacts it, and it carries the client’s CMID and the minimum count needed. Entries arriving from your failing clients mean they reached the host and were refused. No entries at all mean they never got there, and the fault is in front of the host rather than inside it. 0xC004E005 turns up in these conversations too, and Microsoft publishes no meaning for it.

A host key is installed but the host was never activated

You have this one if slmgr /dlv on the host names a KMS host key and Licence Status reads something other than Licensed. Clients report 0xC004F041.

  1. Confirm the host can reach Microsoft’s activation endpoints on TCP 443.
  2. Run slmgr /ato on the host and wait for the result rather than assuming it.
  3. With no internet route, activate by phone: search for SLUI 04 from Start, or use slmgr /dti to read the Installation ID and slmgr /atp <Confirmation ID> to complete it.
  4. Re-run slmgr /dlv and confirm Licence Status now reads Licensed.

No host key was ever installed on this machine

You have this one if slmgr /dlv describes an ordinary volume client rather than a host, and nothing is listening on 1688.

  1. On Windows Server, add the role: Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools.
  2. Run the Volume Activation Tools wizard with vmw.exe, choose the Key Management Service option, and supply your KMS host key.
  3. Let the wizard activate the key online, or by phone if the host is isolated.
  4. Enable the firewall rule: Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True.

You can get the organisation’s KMS host key from the Microsoft 365 admin centre. Installing it converts the machine into a KMS host, so do it deliberately rather than to see what happens.

The service is not answering on the port

You have this one if 0xC004F039 specifically, and netstat -ano | findstr :1688 on the host returns nothing.

  1. Check the Software Protection service with sc query sppsvc and start it if it is stopped.
  2. Re-check for a LISTENING line on 1688 once it is running.
  3. Confirm the firewall rule is enabled for the profile the host is actually on.
  4. Test from a client subnet with Test-NetConnection <host> -Port 1688.

The host key has been spent on too many hosts

You have this one if The host refuses its own activation, and this key has stood up other hosts before – often test builds nobody decommissioned.

  1. Stop changing things on the server. The refusal is held against the key at Microsoft’s end.
  2. Count the machines this key has been installed on, including ones that no longer exist.
  3. Ask the Microsoft Licensing Activation Centers for a key reset or replacement, with your agreement details ready.

Microsoft publishes the figure against 0xC004C008: a KMS host key permits up to 10 activations on no more than 6 different computers. If you are seeing that code on a host, this is the cause.

Full reference

Which machine to look at, and what it should say

What you see Where What it means
Description names a KMS host key, Licence Status Licensed Host The host is healthy. Look at the network path next
Description names a KMS host key, any other status Host The 0xC004F041 case. Activate the host
Description names a volume client Host No host key was installed. This machine is not a KMS host
No LISTENING line on 1688 Host The service is not answering. The 0xC004F039 case
Event ID 12290 entries from your failing clients Host Clients are reaching the host and being refused
No Event ID 12290 entries at all Host Clients never arrive. The fault is DNS, routing or the firewall

Standing a host up the documented way

  1. On a supported Windows Server, add the Volume Activation Services role. In PowerShell: Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools.
  2. Enable the firewall rule: Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True.
  3. Run the Volume Activation Tools wizard: vmw.exe.
  4. Choose Key Management Service, enter your KMS host key, and activate it online or by telephone.
  5. Commit the configuration and close the wizard, then confirm with slmgr /dlv that the host reads Licensed.

The wizard route matters because it configures the role as well as installing the key. Installing the key with slmgr /ipk alone works, but it leaves you doing by hand the parts the wizard does for you, and it is the route most likely to end with a host that is licensed and still not answering.

Which log to read on which machine

Event ID Logged on Log What it records
12288 The client Application The client attempted activation, with the host name and port it used
12289 The client Application The response, carrying the activation flag – 1 for success, 0 for failure – and the host’s current count
12290 The host Key Management Service A client contacted the host, with its CMID and the minimum count needed
12293 The host Key Management Service The host failed to publish its DNS records

A 12288 on the client with no 12289 after it means the request left and nothing came back. That is a network or host problem, not a licensing one, and no amount of work on the client will move it.

What a KMS host can and cannot activate

  • A KMS host running Windows Server can activate both server and client operating systems. A KMS host running a Windows client edition can activate only client operating systems.
  • A host may be physical or virtual. Microsoft states that you can run a KMS host on any physical or virtual system running a supported Windows Server or Windows client operating system.
  • The host needs the host key that covers the products you are activating. A client reaching a host that cannot serve its product gets 0xC004F042, which is a different article.
  • Clients need a count on the host before it will answer: 25 or higher for client editions, 5 or greater for servers and volume Office. Below that, the host is healthy and still refuses.

Before you conclude the host key is the problem

Two checks separate a genuine key problem from an infrastructure one, and both take seconds. First, does the host activate itself? A host that reads Licensed has a working key, whatever the clients are reporting. Second, do 12290 entries appear on the host when a client tries? If they do, the client is reaching a working service and being refused for a reason the host will name; if they do not, nothing about the key is in question yet.

It is worth being clear about what this code does not mean. It is not a shortfall of client licences, it is not a count problem, and it is not something a client-side registry edit reaches. The client is reporting, accurately, what the server told it.

When a licence is the actual fix

A KMS host is only as good as its host key, and a host key is issued against a volume licence agreement rather than bought off a shelf. If your organisation has grown past its original agreement, inherited an estate with no paperwork, or lost access to the portal the key lives in, you need a properly issued Windows Server KMS host key before any of the steps above will complete. Arco supplies them, and will check which host key covers the client editions you are actually running before you order, because a host key issued for an older product generation will activate the host and still refuse your newer clients – a separate code and a separate afternoon.

Every code this article covers

Code What it points at Source
0xC004F041 The Key Management Service is not activated and needs to be activated. Microsoft’s resolution is to activate the host online or by telephone Microsoft Learn
0xC004F039 The computer could not be activated because the Key Management Service is not enabled. Documented checks are the network path and TCP 1688 Microsoft Learn
Event ID 12290 Written on the KMS host, in the Key Management Service log, once for each client activation request, with the client CMID and the minimum count needed Microsoft Learn
0xC004E005 Seen alongside these failures. Read it as the licensing service refusing to complete, and diagnose from the host’s licence state rather than the digits not published by the vendor

Confirm the fix worked

  1. On the host, slmgr /dlv names a KMS host key and Licence Status reads Licensed.
  2. netstat -ano | findstr :1688 on the host returns a LISTENING line.
  3. Test-NetConnection <host> -Port 1688 from a client subnet returns True.
  4. On a client, slmgr /ato completes and slmgr /dlv reads Licensed.
  5. A new Event ID 12290 appears in the host’s Key Management Service log for that client.

Questions people ask about this

Can I use a client key on the KMS host?

No. A host needs a KMS host key; clients take a generic volume licence key. Installing a client key on the host turns it into an ordinary client and it stops serving activations.

Does the KMS host need permanent internet access?

Only for its own activation and any later re-activation. Day to day it serves clients entirely on the local network, and telephone activation covers hosts that are permanently isolated.

How many KMS hosts should I run?

Enough for resilience and no more. Every host has to meet the count threshold on its own – 25 for client editions, 5 for servers – so spreading a small estate across several hosts can leave none of them able to activate anything.

Will fixing the host activate my clients automatically?

Yes, in time. Unactivated clients retry on a schedule, with a documented default of two hours. Run slmgr /ato on one client if you want to confirm the fix now rather than waiting.

Can the host be a virtual machine?

Yes. Microsoft states that a KMS host can run on any physical or virtual system running a supported Windows Server or Windows client operating system. There is no need to find physical hardware for it.

Related error codes

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Free Fix 0x803FABBC and 0x803FABBE: Activation Throttled After Too Many Tries Free Fix 0xC004F301 and Event ID 12321: Token-Based Activation Will Not Complete License Error 0xC004F014: No Product Key on This PC After a Clean Install Free Fix 0xC004D401: Security Processor Reports a System File Mismatch
โ† Back to Knowledge Base