Skip to content

Avoiding Microsoft Software Piracy

The five ways unlicensed Microsoft software gets into an organisation — hard disk loading, unauthorised downloads, standalone certificates, leaked volume keys and auction-site resale — updated for a world where almost none of it arrives on a disc.

Unlicensed Microsoft software rarely arrives because somebody set out to steal it. It arrives because a purchase looked legitimate, a supplier cut a corner, or an employee needed something on a Friday afternoon and found a key online.

Microsoft has published an overview of the ways it happens for years. The five categories below are that framework, restated — and updated, because when this post was first written most of the risk still travelled on physical media, and almost none of it does now.

1. Hard disk loading

This occurs when a system builder installs — and typically activates — one licence across multiple devices, then sells those devices without the accompanying licences. The builder avoids the licence cost while usually still charging the customer for the software. The customer often remains unaware until something breaks: an activation failure, a blocked update, or an audit.

How to avoid it. If you are a system builder, supply a genuine, fully licensed copy alongside anything you preinstall. Microsoft OEM software exists specifically for this, and is bought through Microsoft Authorised OEM Distributors. If you are a buyer, the tell is a machine that arrives with a full Windows and Office build and no corresponding licence documentation. Ask for it in writing before the invoice is paid, not after the fleet is deployed.

What has changed. Modern OEM licensing is usually a digital entitlement tied to the device firmware rather than a label on the case, which makes it harder to inspect visually and easier to misrepresent. The check is now the paperwork and the activation status, not the sticker.

2. Unauthorised downloads

Software distributed illegally through peer-to-peer networks or downloaded from unauthorised sites. Beyond the licensing problem, installers from these sources are a common delivery route for malware — which is why this category is a security concern as much as a compliance one.

How to avoid it. Download only from sources you know are legitimate: Microsoft directly, the Microsoft Store, or an authorised reseller or Cloud Solution Provider. Never from peer-to-peer networks, BitTorrent index sites or one-click file hosting services.

What has changed. The modern version of this is less about downloading a cracked installer and more about activation: “activator” scripts and generic volume key tooling applied to legitimate media. The media is genuine, the activation is not, and the machine looks compliant to anything that only checks what is installed.

3. Standalone Certificates of Authenticity

Standalone COAs are certificates sold on their own, separated from the software they authenticate. They are frequently branded as “excess inventory” or “unused labels”, and are frequently counterfeit. Buying them and passing them to customers is a form of piracy.

How to avoid it. A COA should never be sold, shipped or bought on its own. It belongs affixed to a PC, or accompanying related Microsoft software — either full packaged product, or OEM software acquired by a system builder.

What has changed. Retail packaged product is largely gone, and with it much of this category. Its successor is the standalone product key sold without any entitlement behind it, which is the same trick with the physical object removed.

4. Leaked volume licence keys

Volume Licensing Agreements provide keys for activation in particular scenarios. Distributing those keys outside the organisation the agreement is tied to is piracy — and unlike most of this list, it is usually committed by employees of legitimate customers rather than by outsiders.

How to avoid it. Only devices belonging to the organisation holding the agreement may use its keys. A volume key is never legitimate when sold or distributed outside that organisation. Never buy, download or reuse one.

What has changed. Very little, except the scale. MAK and KMS keys circulate easily, get pasted into build documentation, and survive in imaging scripts long after the agreement they came from has lapsed. The most common real-world version of this is not malice — it is a build image that outlived its entitlement.

5. Auction and marketplace listings

Pirated or unauthorised software is routinely sold through online auction sites and marketplaces. Sellers may offer second-hand product, previously activated product, stolen or used certificates, or illegally copied media. Buyers are generally left without recourse once they discover the problem.

How to avoid it. Ask the obvious questions. Does it come with original documentation? Are all the components there? Is the price too good to be true? Is the seller a reseller you know and trust? Price is the strongest single signal on this list — heavily discounted keys are discounted for a reason.

The category that did not exist in 2016

None of the five above covers the most common route to unlicensed and ungoverned software today, which is somebody signing up to a service with a corporate email address and a personal card. There is no key, no media and no installer. There is a subscription nobody approved, holding company data, often under terms nobody read.

It belongs in the same conversation because the failure mode is identical: software in use that procurement never saw, with an entitlement position nobody can evidence.

CerteroX SaaS Management handles this with three converging discovery signals — a browser extension detecting application domains and per-user usage, identity provider sync from Entra ID and Okta, and connector sync pulling authoritative user and licence lists from the vendors themselves. Applications are classified against a catalogue of over 35,000, which is also what drives Shadow AI detection: AI tools are identified from application feature tags rather than a hardcoded list, so the detection set grows on its own.

Finding it, rather than warning about it

Advice about buying carefully only protects the purchases you know about. The rest of the problem is detection, and that is a tooling question.

Recognition that resolves what is actually installed. The Software Recognition Database holds over 3.5 million titles with centrally maintained categorisation, behind publisher normalisation and version recognition. Software Identification (SWID) tags with UNSPSC classification handle the titles that publish them. The point is that a deliberately mislabelled or repackaged installation is resolved to the real publisher and product rather than recorded as whatever it called itself.

Reconciliation against what Microsoft says you bought. Microsoft Licence Statement import brings the publisher’s own record of your entitlement into the same place as your deployment data. Volume licence, retail, OEM and FPP transactions are captured separately, because the licence type determines what each installation is permitted to be. An installation with no transaction behind it is exactly the thing this post is about, and it is visible as a variance rather than as an anecdote.

A continuously computed position. Purchased, used, available, required, variance and exposure — calculated continuously, not reconciled once a year. Unlicensed installations show up as they appear, which is the only point at which removing them is cheap.

Prohibition with evidence. Application blacklisting and prohibition rules block titles you have decided are not acceptable, and the Blocked Files log records per-user and per-device block counts. That log is worth more than the blocking: it tells you which teams keep trying, which is where your unmet demand is.

Policy as code. Governance Policies work through a reusable filter builder, with definitions that export and import as JSON, so a standard is a check that runs rather than a document that circulates.

A legitimate route that is easier than the illegitimate one. The App-Centre self-service portal, with manager approval chains and software distribution for MSI, EXE and Click-to-Run packages, is the part of this most organisations skip. Almost every piece of unlicensed software inside a well-run company got there because somebody needed it and the sanctioned path took three weeks. Make the sanctioned path take an hour and most of the problem stops recurring.

The point

Piracy is a procurement failure and a supply-chain failure far more often than it is a moral one. The controls that work are unglamorous: buy from sources you can name, keep entitlement records with the transactions that produced them, recognise what is installed accurately enough to spot what does not belong, and give people a fast legitimate way to get what they need.

Book a demo, or read more about CerteroX SAM.

Related reading

Other posts covering the same ground.

  • 5 Ways Software Asset Management Improves Your Business

    SAM is usually sold as audit insurance. It is also a security control, a cost-reduction programme, due diligence for an acquisition, and the only reliable basis for rationalising your applications.

    • SAM
    • Governance
    • Security
    7 min
  • Software Vendor Audits – 8 Things you need to know

    What an audit actually is, how it differs from a SAM review, what triggers one, and what you can do about it once the letter has arrived — including whether a completed audit can still be challenged.

    • SAM
    • Governance
    • Security
    9 min
  • The Rise in Oracle Java Audits: How to gain clarity

    Oracle asks to see your Java deployments before it will sell you more subscriptions. Why Java is the hardest thing in your environment to count, what the employee-based subscription changed, and how to build a deployment record you can actually defend.

    • SAM
    • Governance
    • Security
    6 min
From reading to evidence

Put the hardest claim here
to a technical person.

Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.

No gated download at the end of it.