You bought Windows 11 Enterprise E3. You imaged a laptop. You opened Settings and it says Windows 11 Pro. Somebody on the team asks which KMS server the device is pointing at. That question has no answer, because modern Windows Enterprise activation does not involve a KMS server, a Multiple Activation Key, or a product key of any kind. The licence arrives from Microsoft Entra ID when a licensed user signs in. This post explains that mechanism end to end, then shows you how to find out why a specific device is refusing to move.
Windows subscription activation steps a device up from Pro to Enterprise when a user holding a Windows Enterprise E3 or E5 licence signs in with their Entra account. There is no product key and no KMS host anywhere in that flow, which is why a freshly imaged device correctly shows Pro until that first sign-in. The device must be Microsoft Entra joined or Microsoft Entra hybrid joined, with the underlying Pro licence already activated. When a device stays on Pro, the block is the device, the join, or the licence, and you can tell which in about ninety seconds by reading two separate licence layers.
The problem: the device says Pro and the KMS hunt begins
The scenario is always the same shape. The organisation has an Enterprise Agreement with Windows Enterprise E3, or it has Microsoft 365 E3 or E5, which carries the same Windows entitlement. Devices are built from a Windows 11 Pro image, or arrive from the OEM with Pro preinstalled. Somebody checks the Activation page and finds Pro.
What follows is usually a hunt for infrastructure that is not part of the design. Someone looks for a Key Management Service host. Someone else finds a Generic Volume License Key on an old wiki page and pastes it into a command. A third person opens a ticket asking for the Enterprise ISO. All three actions are wrong, and one of them actively makes the situation worse.
Here is the first thing to internalise. A device that installs as Pro and shows Pro before anybody has signed in with a licensed Entra account is behaving exactly as documented. Microsoft describes the feature as a "step-up" from Pro to Enterprise, triggered by user sign-in. Nothing steps up before a user signs in, because the licence is attached to the user, not the device.
The genuinely broken cases look different, and they are the ones worth your time:
- A licensed user has signed in, the device is Entra joined, and hours later it is still Pro.
- The Activation page shows no Subscription section at all. Microsoft documents that behaviour: if the Windows Enterprise subscription has never been applied, the Subscription pane is not displayed.
- The device was Enterprise, went offline for a few weeks, and came back as Pro.
- The Activation page reads
Windows Enterprise subscription isn't valid.
Why it happens: two licence layers, one of them in the cloud
Windows has two independent licensing stacks, and almost every subscription activation misdiagnosis comes from confusing them.
Layer one is the Software Protection Platform. The service is sppsvc, display name Software Protection, and its binary is a real executable rather than a shared service host. It owns the base edition licence: the retail, OEM, or volume key that makes your Windows installation genuine. Everything the licensing script traditionally reported comes from here.
Layer two is the Client License Service. The service short name is ClipSVC, display name Client License Service (ClipSVC). It owns store-delivered licences, including the Enterprise subscription. This is the layer that steps the edition up.
The chain, in order, from trigger to result:
- A user signs in to a Microsoft Entra joined or Entra hybrid joined device with their work account.
- Windows obtains a token for that user and asks the store licensing service whether the user holds a Windows Enterprise entitlement. Microsoft names the cloud app involved in its Conditional Access guidance: Universal Store Service APIs and Web Application.
- If the answer is yes, ClipSVC installs an application licence and a lease for it locally.
- The edition steps up from Pro to Enterprise. Enterprise features unlock. No reboot.
- The device renews the licence periodically. When the subscription lapses or is reassigned, the device reverts to Pro once the current validity expires.
Notice that steps 2 and 3 need a working user token and internet access. That is why an authentication problem shows up as an activation problem, and why a Conditional Access policy applied too broadly can leave a fully licensed user stuck on Pro.
Prerequisites, in the order they must be true
Microsoft lists these across two articles. Combined and ordered, they are:
- A supported version of Windows Pro (or Pro Education for the Education path) installed. Out-of-support versions do not support the feature.
- The base Pro licence activated. Subscription activation does not remove the need to activate the underlying operating system. Automatic, non-KMS activation of that base licence also requires a firmware-embedded activation key.
- Microsoft Entra ID available for identity management.
- The device Microsoft Entra joined or Microsoft Entra hybrid joined. Microsoft is explicit: workgroup-joined and Microsoft Entra registered devices are not supported. Federated customers are eligible. For hybrid, the on-premises user must be synchronised to Entra ID with Microsoft Entra Connect Sync.
- Per-user Enterprise licensing. The documentation states plainly that subscription activation requires Enterprise per user licensing and does not work with per device licensing.
- A Windows Enterprise licence assigned to the signing-in user from the Microsoft 365 admin center. Group-based licensing is the preferred assignment method.
dsregcmd /status, Entra joined means AzureAdJoined : YES. Entra hybrid joined means AzureAdJoined : YES and DomainJoined : YES together. Registered-only devices show WorkplaceJoined : YES with AzureAdJoined : NO.
How this differs from KMS, MAK and Active Directory-Based Activation
Spelling out the acronyms, because they get thrown around loosely. KMS is Key Management Service. MAK is Multiple Activation Key. ADBA is Active Directory-Based Activation. GVLK is Generic Volume License Key.
| Method | What it needs | What it produces |
|---|---|---|
| Subscription activation | Entra join or hybrid join, per-user Enterprise E3 or E5, internet, base Pro licensed | An edition step-up from Pro to Enterprise, no key, no reboot |
| KMS | A KMS host on your network, a GVLK on the client, TCP reachability on port 1688 by default | A time-limited volume activation of an edition already installed |
| MAK | A five-by-five product key from the Volume Licensing Service Center, installed per device | A perpetual activation of an edition already installed |
| ADBA | A KMS host key activated against the Active Directory forest, domain-joined clients | Volume activation from Active Directory, with no KMS host service |
The important column is the third one. KMS, MAK and ADBA all activate an edition you already installed. Subscription activation changes the edition. If you deploy an Enterprise image and then wonder why you need a key, you have chosen the old path by accident.
There is a useful subtlety here. Microsoft documents that on currently supported versions of Windows, subscription activation pulls the firmware-embedded key, activates the underlying Pro licence, then steps up to Enterprise. That means existing KMS-activated or MAK-activated Enterprise devices migrate to subscription-activated Enterprise automatically when a licensed user signs in. You do not have to rebuild them.
The timings that make this look broken when it is not
| Behaviour | Documented timing | What it means for you |
|---|---|---|
| Licence renewal | Upgraded devices attempt renewal about every 30 days | An offline device eventually reverts to Pro, then recovers when reconnected |
| Upgrade eligibility cache | Up to four days after a qualifying purchase | A brand-new subscription can look broken on day one. Wait before escalating |
| Devices per user licence | Up to five | On a sixth device, the machine the user has not signed in to for longest reverts to Pro |
| Reactivation after a long spell offline | Prompted at sign-in on Windows 11 23H2 with KB5034848 or later | A toast appears reading "Your account requires authentication" |
How to verify: read the licence, the subscription, then the join
Verification has a natural order that mirrors the layers. Base licence first, subscription second, join third, plumbing fourth. Do not skip ahead, because a device with an unlicensed Pro base can never step up, and every other check will look fine.
Step 1: the graphical answer
The fastest read is the Activation page. Press Windows and R, type ms-settings:activation, and press Enter. On Windows 11 the same page sits under Settings, System, Activation.
Expand both Activation state and Subscription. A healthy device shows two separate statements: Windows is activated with a digital license for the base licence, and Windows 11 Enterprise subscription is active for the step-up. If the Subscription block is absent entirely, the subscription has never been applied on this device.
Step 2: slmgr, and how to read it properly
The licensing script lives at C:\Windows\System32\slmgr.vbs. Two options matter here and neither requires elevation. /dli prints basic licence information. /dlv prints detailed licence information, including the activation ID, the key channel and the trusted time.
Read that output as two answers, not one. The first block is the Software Protection Platform reporting the base licence, and on a subscription-activated device it correctly reports Professional with a Retail channel. The second block is the subscription. An admin who reads only the first four lines concludes the step-up failed, when the four lines below prove it succeeded.
/ipk option installs a product key. The /upk option uninstalls the current product key and leaves the system Unlicensed after a restart. The /ato option forces an activation attempt, and on a device carrying a GVLK it forces a KMS attempt against infrastructure you do not have. The /rearm option resets activation timers. None of these fix a subscription activation problem, and pasting a GVLK to "make it Enterprise" replaces a working firmware-derived Pro licence with one that cannot activate. Diagnose with /dli and /dlv only.
Step 3: the same answers from PowerShell, where automation lives
Two WMI classes carry this state, and knowing which is which is the whole trick.
The SoftwareLicensingProduct class is the Software Protection Platform view. It exposes LicenseStatus, whose values are documented:
| LicenseStatus | Name | Practical reading |
|---|---|---|
| 0 | Unlicensed | No usable licence for this SKU |
| 1 | Licensed | Healthy. This is what the base Pro SKU should show |
| 2 | OOBGrace | Out-of-box grace period, not yet activated |
| 3 | OOTGrace | Out-of-tolerance grace, typically after a hardware change |
| 4 | NonGenuineGrace | Failed genuine validation |
| 5 | Notification | Grace exhausted. This is the state behind the desktop watermark |
| 6 | ExtendedGrace | Extended grace period |
The subscription is not in that class. It is exposed on SoftwareLicensingService, through four properties that the in-box licensing script reads to print its Subscription block: SubscriptionEdition, SubscriptionType, SubscriptionStatus and SubscriptionExpiry.
SoftwareLicensingService class documentation. The mapping above is read out of Microsoft's own in-box slmgr.vbs on Windows 11 25H2, which is why it matches what the script prints. Treat it as observed rather than contractual, and prefer alerting on the human-readable /dli text if you need something stable across updates.
Step 4: the join, which is the other half of the answer
Microsoft's own troubleshooting guidance sends you to dsregcmd.exe /status and tells you to confirm that AzureAdJoined reads YES under Device State.
Step 5: the plumbing surfaces
Services. Three services matter. Two of them are trigger-start, so a Stopped status is not automatically a fault.
| Short name | Display name | Expected state |
|---|---|---|
| sppsvc | Software Protection | Start type Automatic. Runs from its own binary, not a shared service host |
| ClipSVC | Client License Service (ClipSVC) | Start type Manual, trigger-started, hosted in the wsappx service host group |
| LicenseManager | Windows License Manager Service | Start type Manual, trigger-started, hosted in a LocalService group |
Scheduled tasks. Two tasks under a single parent path do the recurring work of acquiring and keeping the subscription. Parent path, stated once:
| Task | Observed state on a working device | What to check |
|---|---|---|
| LicenseAcquisition | Ready, last result 0x0 | A non-zero last result on a device stuck on Pro is your strongest single clue |
| EnableLicenseAcquisition | Ready, last result 0x0 | Runs alongside the task above. Same reading |
| \Microsoft\Windows\Clip\License Validation | Disabled on the device tested | Disabled is normal here, not a fault to chase |
| \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask | Ready | Restarts the Software Protection service on schedule. Unrelated to the step-up itself |
\Microsoft\Windows\Subscription\ in the subscription activation articles. They exist on the Windows 11 25H2 device used for this post and their last-result codes are genuinely useful when triaging. Read them, but do not build a compliance rule that fails when Microsoft renames them.
System files and binaries. Every one of these was verified present on the test device.
| Path | Role in the flow | Layer |
|---|---|---|
C:\Windows\System32\sppsvc.exe | The Software Protection service itself. Owns the base edition licence | SPP |
C:\Windows\System32\sppc.dll and sppcext.dll | Software licensing client libraries the service and tooling call | SPP |
C:\Windows\System32\ClipSVC.dll | The Client License Service implementation, loaded into the wsappx host | ClipSVC |
C:\Windows\System32\ClipUp.exe | Client licensing setup and update helper | ClipSVC |
C:\Windows\System32\ClipRenew.exe | Renews store-delivered licences, including the subscription lease | ClipSVC |
C:\Windows\System32\slmgr.vbs | The licensing script. Reads both layers for its output | Both |
C:\Windows\System32\licensingdiag.exe | Licensing Diagnostic Tool. Collects a licensing report bundle | Both |
C:\Windows\System32\changepk.exe | Applies a product key. Used by the MDM edition-upgrade path, not by subscription activation | SPP |
C:\Windows\System32\spp\store\2.0\data.dat | The SPP token store holding base licence state | SPP |
C:\ProgramData\Microsoft\Windows\ClipSVC\tokens.dat | The ClipSVC token store holding store licences and leases | ClipSVC |
Log files, honestly. There is no documented plain-text log for the step-up. Windows does not write a text log you can tail while a device steps up. What exists instead is licensingdiag.exe, present in System32, which collects licensing diagnostics into a report and a cabinet file. Its command-line switches are not documented on Microsoft Learn, so if you use it, treat the syntax as observed and read the report it produces rather than scripting against it. The real diagnostic trail lives in the event log, which is the next surface.
Step 6: Event Viewer
Microsoft publishes no event ID catalogue for subscription activation. What it does publish, in its Conditional Access guidance, is the identity side of the story, and the channels below are the ones that carry the evidence. Channel names verified on the test device by enumerating the log list.
| Channel | Provider | What it tells you |
|---|---|---|
| Microsoft-Client-Licensing-Platform/Admin | Microsoft-Client-Licensing-Platform | ClipSVC lifecycle, application licence installs and lease installs. The step-up itself |
| Microsoft-Client-License-Flexible-Platform/Admin | Microsoft-Client-License-Flexible-Platform | The related flexible-licensing channel. Frequently empty |
| Application | Microsoft-Windows-Security-SPP | Base licence status checks and service restarts. The Pro layer |
| Microsoft-Windows-AAD/Operational | Microsoft-Windows-AAD | Token acquisition. Where a blocked licensing call actually shows up |
Within the ClipSVC admin channel, these are the IDs observed on a working device. Channel, stated once:
| Event ID | Message text observed | Reading |
|---|---|---|
| 100 | ClipSVC service is starting. Caller: TriggerStarted | Normal trigger start |
| 101 | ClipSVC service is running. Version follows | Normal |
| 102 | ClipSVC service has shutdown | Normal idle shutdown |
| 116 | Application license successfully installed | The step-up licence landed. This is the success line |
| 117 | Lease successfully installed | The renewal lease landed alongside it |
Two things to take from that panel. A device that has ever stepped up shows 116 and 117. A device that has not, but whose ClipSVC starts and stops cleanly, is telling you the service is fine and the answer from the cloud was no. In that case the AAD channel is where you look next, because a token failure and a licence failure look identical from the Activation page.
Step 7: registry
There is no registry switch that turns subscription activation on. What the registry holds is Software Protection Platform configuration and policy. Shared parent key, stated once:
| Value | Type | What it does |
|---|---|---|
| SkipRearm | REG_DWORD | Documented. When set to 1, the rearm operation does nothing |
| UserOperations | REG_DWORD | Documented. Setting 1 lets standard users install keys and activate without elevation |
| VLActivationInterval | REG_DWORD | Documented. KMS activation attempt interval in minutes, default 120 |
| VLRenewalInterval | REG_DWORD | Documented. KMS renewal interval in minutes, default 10080 |
| KeyManagementServiceName | REG_SZ | Documented. Pins a KMS host. Its presence on a subscription fleet is a smell, not a cause |
| Activation\Manual | REG_DWORD | Documented subkey value. Setting 1 disables automatic online activation |
| TokenStore, CacheStore, ClipSvcStart, LicStatusArray | Various | Present on the test device and undocumented. Read-only curiosity. Do not build on them |
One policy value genuinely matters, and it lives elsewhere:
| Value | Type | Effect on the step-up |
|---|---|---|
| DoNotConnectToWindowsUpdateInternetLocations | REG_DWORD | Documented. When set to 1, the device can lose activation status or be blocked from upgrading to Enterprise. Must be 0, or absent |
The fix: prerequisites in order, and the settings that really exist
Work the list top down. Stop at the first thing that is false, fix it, and re-test with a fresh sign-in.
- Is the base Pro licence activated? If the basic licence read shows anything other than
License Status: Licensed, fix that first. If the device has a firmware key but was never activated with a Pro key, Microsoft publishes a one-liner that reads the OEM key and applies it withchangepk.exe. That is a write operation, so treat it as a change, not a diagnostic. Note also that firmware-embedded activation happens automatically only during the out-of-box experience. - Is the device Entra joined or Entra hybrid joined? Confirm with
dsregcmd /status. A registered-only device needs a proper join, which for most fleets means a rebuild through Autopilot, or an Entra join from the Access work or school pane. - Is the user licensed with Windows Enterprise E3 or E5? Check the assignment, not the bundle name. See the table below.
- Was the licence assigned in the last four days? If yes, wait. The eligibility cache is documented to take up to four days to expire.
- Is Windows Update blocked? Clear the policy covered below.
- Is Conditional Access blocking the licensing call? Exclude the store app, or move to Windows 11 23H2 with KB5034848 or later, where the user is prompted with a toast instead.
- Sign out and sign back in with the licensed account while connected to the internet. The step-up is a sign-in-triggered event.
Which licence bundles actually carry the entitlement
This is where a lot of tickets die. The requirement is a Windows Enterprise licence assigned from the Microsoft 365 admin center. Bundle marketing names do not tell you whether the right service plan is inside. Microsoft publishes the authoritative mapping in its product names and service plan identifiers reference:
| Bundle | Windows service plan inside | Steps a Pro device up? |
|---|---|---|
| Windows 10/11 Enterprise E3 or E5, standalone | WIN10_PRO_ENT_SUB | Yes. This is the documented licence for the feature |
| Microsoft 365 E3 and E5 | WIN10_PRO_ENT_SUB, listed as Windows 10/11 Enterprise | Yes. The same service plan as the standalone SKU |
| Microsoft 365 F3 | WIN10_ENT_LOC_F1, listed as Windows 10 Enterprise E3 (Local Only) | A different plan. Do not assume a step-up. Verify in your own tenant |
| Microsoft 365 Business Premium | WINBIZ, listed as Windows 10/11 Business | No Windows Enterprise plan is present at all |
Group Policy: the only setting that matters, and the one that does not exist
Be clear about this, because it is the point of the whole post. There is no Group Policy setting that enables subscription activation. No administrative template turns it on, turns it off, or points it anywhere. The feature is driven by identity and licence assignment, not by device policy.
The one policy Microsoft's troubleshooting guidance sends you to is a Windows Update setting that can break re-activation. On Windows 11 the full path is:
- Press Windows and R, type
gpedit.msc, and press Enter. In a domain, edit the GPO in the Group Policy Management Console instead. - Expand Computer Configuration, then Administrative Templates.
- Expand Windows Components, then Windows Update.
- On Windows 11, open Manage updates offered from Windows Server Update Service. On Windows 10 the setting sits directly under Windows Update.
- Double-click Do not connect to any Windows Update Internet locations.
- Set it to Disabled or Not Configured, then select OK.
- Confirm on the device that the policy value under the WindowsUpdate key is 0 or absent. If the policy is still Enabled somewhere, the value returns to 1 no matter how many times you edit the registry by hand.
Intune: what exists, what does not, and the trap in between
There is no Settings Catalog setting that enables subscription activation either. That is not an oversight. There is nothing to configure, because the trigger is a licensed user signing in.
What Intune and MDM genuinely expose is the WindowsLicensing configuration service provider. Its read-only nodes are the useful part for reporting:
| OMA-URI | Access | What you get |
|---|---|---|
./Vendor/MSFT/WindowsLicensing/Edition | Get | The running edition as an integer |
./Vendor/MSFT/WindowsLicensing/Subscriptions/{SubscriptionId}/Status | Get | The status of a subscription on the device |
./Vendor/MSFT/WindowsLicensing/DeviceLicensingService/LicenseType | Get, Replace | 0 is a user-based subscription, 1 is device-based |
./Vendor/MSFT/WindowsLicensing/DeviceLicensingService/DeviceLicensingLastError | Get | The last error from a refresh or remove device-licence operation |
Note the shape of that CSP. It reports on, and manipulates, device-based subscription, and several of the subscription nodes are marked as Windows Insider Preview at the time of writing. None of it is a switch that makes user-based subscription activation happen.
The trap is the profile that does exist. Intune has an Edition upgrade and mode switch template, and it will happily upgrade Pro to Enterprise. Read its prerequisites: it needs a valid product key, either a MAK or a KMS key. That is the old path wearing a modern portal. If you hold E3 or E5, using it is a mistake, and Microsoft notes that removing the policy later does not revert the device.
- Sign in to the Microsoft Intune admin center.
- Select Devices, then Manage devices, then Configuration.
- Select Create, then New policy.
- For Platform, select Windows 10 and later.
- For Profile type, select Templates, then Edition upgrade and mode switch.
- Select Create, give the profile a name in Basics, then select Next.
- In Configuration settings, choose the target edition and supply the MAK or KMS product key.
- Complete Scope tags, then Assignments, then Review + create.
Conditional Access, which is the identity-side fix
Microsoft documents that organisations using subscription activation with Conditional Access should exclude the Universal Store Service APIs and Web Application cloud app from their policies, using Select Excluded Cloud Apps. The symptom this prevents is specific: a device that has been offline for an extended period might not reactivate automatically.
- Sign in to the Microsoft Entra admin center and open the Conditional Access policy that targets all cloud apps.
- Under Target resources, open the Exclude tab.
- Choose Select excluded cloud apps.
- Find and select Universal Store Service APIs and Web Application. Depending on the tenant, the same application ID may appear under the retired Windows Store for Business name.
- Save the policy, then re-test the step-up with a licensed sign-in.
On Windows 11 23H2 with KB5034848 or later, Microsoft changed the behaviour so the user is prompted with a toast instead, reading "Your account requires authentication". That removes the need for the exclusion, though the exclusion is still valid if you would rather users never saw the prompt.
The other environmental limits worth knowing
- Tenant type. As of 1 October 2022, subscription activation is available for commercial and GCC tenants. It is not available on GCC High or DoD tenants.
- Education. The Education path needs Windows Pro Education installed, plus a Windows Enterprise licence in the tenant. Critically, if Windows Pro was converted to Pro Education, subscription activation does not work. The device must be reimaged to Pro Education, or directly to Education.
- Virtual machines. Inherited activation lets a Windows virtual machine inherit activation state from a Windows client host, with Hyper-V as the hypervisor and both host and guest on supported versions. For virtual desktops there is a separate configuration path for Virtual Desktop Access.
Proof it worked: a real hybrid-joined device that stepped up
The companion script for this post is Get-SubscriptionActivationState.ps1. It reads every surface above in one pass and tells you whether the block is the device, the join, or the licence. It is strictly read-only: it never issues an activation command, never writes a registry value or service state, and it reports the presence of product keys rather than their characters. If any read fails it prints READ FAILED and exits 1, so a broken read can never be mistaken for a healthy device.
The output below is a genuine run on a Windows 11 Enterprise 25H2 device that is Entra hybrid joined and subscription activated. Device name, domain and key material have been replaced, and the section separators are shortened to fit.
The verdict block is the part built for triage. When the subscription is not active and no device-side blocker is found, the script says so explicitly and points off-device: no Windows Enterprise licence on the signed-in user, a licence assigned inside the four-day cache window, or a blocked token. That is the sentence that stops the KMS hunt.
Script validation, stated plainly: zero parse errors under Windows PowerShell 5.1 and PowerShell 7, zero non-ASCII bytes, no null-conditional operator, no module dependency, and no write of any kind. It exits 0 on a healthy device and 1 when a read fails or a prerequisite is unmet.
References
Microsoft official documentation:
- Windows subscription activation - the step-up mechanism, requirements, licence renewal timings, Conditional Access guidance and inherited activation.
- Deploy Windows Enterprise licenses - the deployment walkthrough, the verification steps, the four-day eligibility cache and the Windows Update policy that blocks the step-up.
- Slmgr.vbs options for obtaining volume activation information - the authoritative description of every option, including which ones require elevation.
- SoftwareLicensingProduct WMI class - the documented LicenseStatus values 0 to 6.
- WindowsLicensing CSP - the MDM nodes for edition, subscriptions and device licensing.
- Upgrade Windows editions or switch S mode using Intune policy - the key-based edition upgrade profile and its MAK or KMS prerequisite.
- Registry settings for volume activation - the documented SoftwareProtectionPlatform values.
- Product names and service plan identifiers for licensing - which bundle contains which Windows service plan.
Community deep-dives, both fetched and confirmed on topic before citing:
| Author | Post | Why it is worth reading |
|---|---|---|
| Rudy Ooms | Night at the Windows Store API Service: Secret of the Subscription Activation | Reproduces the failure by deliberately blocking the store API with Conditional Access, then compares event logs from working and broken devices |
| Rudy Ooms | KB5036980 breaks the Windows 11 Enterprise Subscription Activation | A worked example of a servicing regression breaking the step-up during Autopilot, and how it was traced |
Companion script: Get-SubscriptionActivationState.ps1 in the Windows-11-Scripts repository, under the subscription-activation-entra-licensing folder.
Download it from Imran76Awan/Windows-11-Scripts — no sign-in required. It is read-only: it reports and never changes a device or anything in Intune. Validate it in your own environment before relying on the output.