Fix it now
This code appears when you install or activate a KMS host key, not later, and it stops the machine becoming a host. Microsoft publishes no meaning for it, so start by ruling out the two things that are documented: the edition you are running, and whether a host key belongs on this machine at all.
slmgr /dlv
DISM /Online /Get-CurrentEdition
- Read the description line from
slmgr /dlv. It says whether a KMS host key or an ordinary client key is installed, which is the first thing to establish. - Check the edition. An evaluation installation will not take a production key, and converting one is a planned change rather than a quick fix.
- Confirm the key you hold is the KMS host key for the product family you mean to serve, not a client key and not a MAK. Your licensing portal labels them differently.
- On Windows Server, stand the role up the documented way rather than with
slmgr /ipkalone:Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools, then runvmw.exeand follow the Volume Activation Tools wizard. - If the estate is domain-joined, look at Active Directory-Based Activation in the same wizard before building a host at all.
Being a virtual machine is not the cause. Microsoft states you can run a KMS host on any physical or virtual system running a supported Windows Server or Windows client operating system.
If the wizard completes and the key activates, you have a host. If it still refuses, the next section covers what else the licensing service is checking.
Why it happens
A KMS host is not something you install from a feature list and then switch on. It is a state the Software Licensing service enters when it is given a host key and that key activates against Microsoft. Before it enters that state it checks the machine underneath it, and this code is the check failing. It fires at key installation or key activation time, which is why chasing clients gets nowhere: no client was ever involved.
Microsoft publishes no meaning for 0xC004F06B. A search of Microsoft’s documentation returns nothing at all for it, and the same is true of 0xC004F029, 0xC004F016 and 0xC004FD00, which travel with it. That does not make the code meaningless – Windows is refusing something specific – but it does mean any confident statement about what it points at is somebody’s inference. This article works from what the documentation does say about hosts, and from what you can observe on the machine.
The most widely repeated inference about this code is that KMS cannot be hosted inside a virtual machine. That was true of the first generation of KMS hosts, which required physical hardware, and it has not been true for a long time. Microsoft’s current KMS planning and KMS host articles both state that you can run a KMS host on any physical or virtual system running a supported Windows Server or Windows client operating system. If you have been told to find spare hardware because of this code, check the build you are hosting on first.
What is documented, and worth knowing before you spend time on this, is that a KMS host running Windows Server can activate both server and client operating systems, while a KMS host running a Windows client edition can activate only client operating systems. For a mixed estate that settles which machine should hold the role.
You are trying to make an evaluation installation a host
You have this one if The failure happens the moment you install the key, on hardware where virtualisation cannot be the explanation.
- Read the running edition with
DISM /Online /Get-CurrentEdition. - If it is an evaluation edition, convert it to a licensed edition first and then retry the key.
- Check
DISM /Online /Get-TargetEditionsto see what the installation can be moved to. - Treat the conversion as a change with a maintenance window; some installed roles block it.
Server edition conversion is one-way. Take a backup before you start, and do not schedule it as the last step of an afternoon.
The key is not a KMS host key
You have this one if slmgr /dlv describes a volume client rather than a host, and the key came out of a shared spreadsheet rather than the portal.
- Look the key up in your volume licensing portal or the Microsoft 365 admin centre, where key types are labelled.
- A generic volume licence key makes the machine a client. A MAK activates that one machine permanently. Neither creates a host.
- Obtain the KMS host key for the product generation you intend to serve, then run the Volume Activation Tools wizard.
The role was never added, only the key
You have this one if Someone ran slmgr /ipk on a Windows Server and expected a host to appear.
- Add the role:
Install-WindowsFeature -Name VolumeActivation -IncludeManagementTools. - Enable the firewall rule:
Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True. - Run
vmw.exe, choose Key Management Service, and let the wizard install and activate the host key. - Confirm with
slmgr /dlvthat the description names a host key and the status reads Licensed.
You have a domain and do not need a host at all
You have this one if Every device is domain-joined, and the host is being built because nobody mentioned the alternative.
- On a domain controller, add the Volume Activation Services role.
- Run the Volume Activation Tools wizard and choose Active Directory-Based Activation.
- Enter your KMS host key and activate it online or by telephone, then commit and close.
- Leave the clients alone. Domain-joined machines carrying a generic volume licence key pick this up without any local change.
This requires the forest schema to have been updated with adprep.exe on a supported server operating system, and it activates domain-joined devices only.
The devices will never be on your network often enough
You have this one if Field laptops, an isolated lab, or a site too small to justify infrastructure.
- Install a Multiple Activation Key on each device:
slmgr /ipk XXXXX-XXXXX-XXXXX-XXXXX-XXXXX, thenslmgr /ato. - Confirm the channel changed with
slmgr /dli. - For an isolated network with more than a handful of machines, use VAMT proxy activation rather than visiting each one.
Each MAK activation spends a seat from a finite pool, and rebuilding a machine spends another. Count before committing an estate to it.
Full reference
Three ways to activate a volume estate
| KMS host | Active Directory-Based Activation | MAK | |
|---|---|---|---|
| Minimum machines | 25 client editions, 5 servers | None | None |
| What it needs | A host, TCP 1688, a service record | A domain, an updated forest schema, the Volume Activation Services role | Internet or telephone activation |
| Runs in a virtual machine | Yes, on any supported build | Yes | Not applicable |
| How it renews | 180-day activation, renewal attempted every 7 days | Up to 180 days from last domain contact, retried every 7 days | One-off per machine |
| Devices that live off-network | No | No | Yes |
| Activations | Unlimited while clients keep renewing | Unlimited for domain-joined devices | A finite pool per key |
What the documentation actually says about hosts
- A KMS host can run on any physical or virtual system running a supported Windows Server or Windows client operating system.
- A host on Windows Server can activate both server and client operating systems. A host on a Windows client edition can activate only client operating systems.
- The count thresholds are 25 or higher for client editions and 5 or greater for servers and volume Office editions, and the count includes virtual machines.
- The host counts only unique connections from the past 30 days and stores the 50 most recent contacts.
- Active Directory-Based Activation requires the forest schema to be updated with adprep.exe on a supported server operating system, and serves domain-joined devices only.
Standing the role up properly
Install-WindowsFeature -Name VolumeActivation -IncludeManagementToolsin an elevated PowerShell session.Set-NetFirewallRule -Name SPPSVC-In-TCP -Profile Domain,Private -Enabled True.vmw.exeto launch the Volume Activation Tools wizard.- Choose Key Management Service, or Active Directory-Based Activation if you would rather not run a host.
- Enter the KMS host key from the Microsoft 365 admin centre and activate it online or by telephone.
- Commit, close, and confirm with
slmgr /dlvthat the machine now describes itself as a host and reads Licensed.
Doing it this way rather than with slmgr /ipk alone is worth the extra two minutes. The wizard configures the role as well as installing the key, and it is the route Microsoft documents, so when something does fail you are failing in a state the documentation describes.
Codes that keep this company
| Code | Where it appears | What can be said about it |
|---|---|---|
0xC004F06B |
Installing or activating a host key | No published meaning. The machine is being refused the host role |
0xC004F029 |
The same operation | No published meaning |
0xC004F016 |
Usually at key-installation time | No published meaning |
0xC004FD00 |
The same family | No published meaning |
Four unpublished codes in one article is unusual and worth saying out loud. It means the honest diagnostic path is the machine in front of you – edition, key type, role state – rather than a lookup table. Anything that tells you precisely what 0xC004F06B means is guessing.
Deciding before you build anything
Most of the time this code is met by someone building a KMS host who did not need one. The threshold is the thing to check first: KMS will not activate a client edition until 25 machines have contacted the host, and that number is not adjustable. Below it, a host is not a slow solution, it is not a solution.
For a domain-joined estate of any size, Active Directory-Based Activation removes the host, the DNS record, the port and the threshold in one move, and it uses the same host key you already hold. For machines that are not domain-joined and rarely reach your network, MAK is the answer and always was. The middle case – a domain-joined estate above 25 machines that wants a single point of control – is where a KMS host genuinely earns its keep.
When a licence is the actual fix
Exhaust the free routes first, because two of them are real. If you hold a volume agreement you already have a host key, and Active Directory-Based Activation costs nothing beyond a domain you already run – it needs no host, no port and no count threshold. A purchase only becomes the answer where neither fits: a small site, permanently remote laptops, or an isolated network with no supported host to put the role on. Multiple Activation Keys are the supported option there, and Arco supplies Windows 11 Enterprise MAK keys sized to the number of devices that genuinely belong in that category. Send the output of slmgr /dlv and we will say plainly if your agreement already covers you.
Every code this article covers
| Code | What it points at | Source |
|---|---|---|
0xC004F06B |
Returned when the licensing service refuses to give this installation the KMS host role. Microsoft publishes no meaning for it | not published by the vendor |
0xC004F029 |
Appears at the same point in the same operation. No published meaning; read it as the same refusal | not published by the vendor |
0xC004F016 |
Usually seen at key-installation time rather than at activation. No published meaning | not published by the vendor |
0xC004FD00 |
In the same family of refusals raised while configuring a host. No published meaning | not published by the vendor |
Confirm the fix worked
- On the host,
slmgr /dlvnames a KMS host key and Licence Status reads Licensed. netstat -ano | findstr :1688on the host returns a LISTENING line.- A client runs
slmgr /atosuccessfully andslmgr /dlvon it names the host you built. - If you took the Active Directory route instead, a domain-joined client activates without any KMS machine name appearing in its
slmgr /dlvoutput. - The host still reads Licensed a week later, which confirms its own activation held rather than sitting in a grace window.
Questions people ask about this
Can a KMS host run in a virtual machine?
Yes. Microsoft states that a KMS host can run on any physical or virtual system running a supported Windows Server or Windows client operating system. The restriction belonged to the first generation of KMS hosts and no longer applies, so this code is not evidence that you need physical hardware.
Do I have to buy anything to clear 0xC004F06B?
Usually not. If you hold a volume agreement you already have a host key, and Active Directory-Based Activation comes with the domain you already run. A purchase only becomes the answer when you have no supported host, no domain, and devices that need permanent activation.
Can a Windows client edition act as the host?
For other client editions, yes. A KMS host running a Windows client operating system can activate only client operating systems, so a mixed estate that includes servers needs a Windows Server host.
Why is there no documented meaning for this code?
Microsoft publishes meanings for the activation codes readers meet most often, and this one is not among them. That is not unusual for codes raised while configuring a host rather than while activating a client, and it is why this article works from the machine’s state rather than from the digits.
Will moving a machine from KMS to MAK break anything?
No. Installing a MAK replaces the volume client key and activates that machine on its own. It simply stops trying to renew against a host, which is the point.
