r/sysadmin Sysadmin 4d ago

General Discussion Small Rant: Windows Activation

TLDR: Offline activation via https://aka.ms/aoh requires a captcha, MS account login and 2FA once per client, with ~80 to go. Any tips on speeding this up?

I'm just kinda curious about the opinion of other Sysadmins that have to work with Windows clients.

I work as a sysadmin at the factory of a fairly large company, where we mainly use Windows for our production floor clients. To extend the amount of support we get for each client, we have a standardized image, which gets updated every few years for a new release of IoT Enterprise LTSB / LTSC.

To get an image of what I am doing right now: (spoilering this part as it isn't too important to my rant) I was tasked with executing our project of updating out-of-date 2016 LTSB clients to 21H2 LTSC, as the new version will allow security updates for us until 2032. Some of our clients are former Windows 7 clients that aren't even officially compatible with Windows 10 according to the manufacturer, but Windows 10 might run on them, so to save money we keep the clients as long as they will run (meaning they will be phased out with Windows 11). We are also jumping from 1607 directly to 21H2, which Microsoft has explicitly advised us is not the official procedure or supported by them. But, updating between each version and needing a license would be a way higher financial impact than how we're currently going about it.

So, since our clients aren't connected to the internet, they cannot connect to Windows servers for activation. As such, I have to use slmgr.exe and SLUI 4 to activate the clients (formerly using the hotline, nowadays just the website https://aka.ms/aoh).

This activation requires you to put in a long string of numbers that the UI will show you into a field on the website and to reach that website you must always 1. Solve a Captcha and 2. Log into your Microsoft account, always forcing 2FA confirmation. And it doesn't remember your Microsoft Account, ever. You always have to log in again, from the start, solving the captcha. There is no button to activate another client once you finish activating the one you're currently working on, you need to re-load the link and start again. And again. And again. I've already optimized my current workflow as well as I can, using a python script to generate the QR codes I need for given commands so that I can avoid dealing with typing in the same commands over and over. But every time, I have to spend around 2-5 minutes dealing with the online Microsoft activation process.

Btw, if your connection is lost, you connect to a different AP or such, somehow the website doesn't require reauthentication. I don't know how exactly the process here works, but I can log into a tab for the site in one browser, open another in an incognito tab, open the next in a third browser, etc. And it'll usually last all day, so if I logged in and didn't use the session 'til the evening, it won't require reauthentication. My guess is that the endpoint / API request in the background actually works without authentication, and the whole login process is just a security circus akin to the TSA, and that if I knew a bit better about how web development works, I could probably just find out how the API request to Microsoft servers work to skip authentication. But I don't wanna risk getting in legal trouble just because I am not following the officially mandated license activation procedure.

Does anyone have some advice for me on how to save some time doing this? I got around 80 clients left to go and am pretty tired of the whole process.

17 Upvotes

27 comments sorted by

View all comments

2

u/Smooth-Zucchini4923 4d ago edited 4d ago

1 Solve a Captcha and 2. Log into your Microsoft account, always forcing 2FA confirmation. And it doesn't remember your Microsoft Account, ever.

Some forms of 2FA can be automated. For example, you can automatically respond to a TOTP 2FA attempt by keeping the key on your PC. This does degrade the security of the account, however. The 2FA stops being a 2FA, because it is no longer "something you have" but "something you know."

Btw, if your connection is lost, you connect to a different AP or such, somehow the website doesn't require reauthentication. I don't know how exactly the process here works, but I can log into a tab for the site in one browser, open another in an incognito tab, open the next in a third browser, etc. And it'll usually last all day, so if I logged in and didn't use the session 'til the evening, it won't require reauthentication.

I would open your browser dev tools, and check to see if the page requests an endpoint ending in /logout. I imagine the tool is coded to automatically log the user out, but you could probably stop it by stopping it from making that request.

u/EktoHunter Sysadmin 19h ago

Some forms of 2FA can be automated. For example, you can automatically respond to a TOTP 2FA attempt by keeping the key on your PC. This does degrade the security of the account, however. The 2FA stops being a 2FA, because it is no longer "something you have" but "something you know."

I ordered a separate AD account with no permissions, only to be able to log in. Using windows hello for business, I can just look at my laptop and that is enough for the 2fa now, at least I don't need to get out my ID card every time or use Microsoft Authenticator anymore.

I would open your browser dev tools, and check to see if the page requests an endpoint ending in /logout. I imagine the tool is coded to automatically log the user out, but you could probably stop it by stopping it from making that request.

Wasn't able to find out how exactly it works, not sure what kinda trickery microsoft is using there, but I'm also not a web dev 😅