Unlicensed Microsoft software rarely arrives because somebody set out to steal
it. It arrives because a purchase looked legitimate, a supplier cut a corner, or
an employee needed something on a Friday afternoon and found a key online.
Microsoft has published an overview of the ways it happens for years. The five
categories below are that framework, restated — and updated, because when this
post was first written most of the risk still travelled on physical media, and
almost none of it does now.
1. Hard disk loading
This occurs when a system builder installs — and typically activates — one
licence across multiple devices, then sells those devices without the
accompanying licences. The builder avoids the licence cost while usually still
charging the customer for the software. The customer often remains unaware until
something breaks: an activation failure, a blocked update, or an audit.
How to avoid it. If you are a system builder, supply a genuine, fully
licensed copy alongside anything you preinstall. Microsoft OEM software exists
specifically for this, and is bought through Microsoft Authorised OEM
Distributors. If you are a buyer, the tell is a machine that arrives with a
full Windows and Office build and no corresponding licence documentation. Ask
for it in writing before the invoice is paid, not after the fleet is deployed.
What has changed. Modern OEM licensing is usually a digital entitlement tied
to the device firmware rather than a label on the case, which makes it harder to
inspect visually and easier to misrepresent. The check is now the paperwork and
the activation status, not the sticker.
2. Unauthorised downloads
Software distributed illegally through peer-to-peer networks or downloaded from
unauthorised sites. Beyond the licensing problem, installers from these sources
are a common delivery route for malware — which is why this category is a
security concern as much as a compliance one.
How to avoid it. Download only from sources you know are legitimate:
Microsoft directly, the Microsoft Store, or an authorised reseller or Cloud
Solution Provider. Never from peer-to-peer networks, BitTorrent index sites or
one-click file hosting services.
What has changed. The modern version of this is less about downloading a
cracked installer and more about activation: “activator” scripts and generic
volume key tooling applied to legitimate media. The media is genuine, the
activation is not, and the machine looks compliant to anything that only checks
what is installed.
3. Standalone Certificates of Authenticity
Standalone COAs are certificates sold on their own, separated from the software
they authenticate. They are frequently branded as “excess inventory” or “unused
labels”, and are frequently counterfeit. Buying them and passing them to
customers is a form of piracy.
How to avoid it. A COA should never be sold, shipped or bought on its own.
It belongs affixed to a PC, or accompanying related Microsoft software — either
full packaged product, or OEM software acquired by a system builder.
What has changed. Retail packaged product is largely gone, and with it much
of this category. Its successor is the standalone product key sold without any
entitlement behind it, which is the same trick with the physical object removed.
4. Leaked volume licence keys
Volume Licensing Agreements provide keys for activation in particular scenarios.
Distributing those keys outside the organisation the agreement is tied to is
piracy — and unlike most of this list, it is usually committed by employees of
legitimate customers rather than by outsiders.
How to avoid it. Only devices belonging to the organisation holding the
agreement may use its keys. A volume key is never legitimate when sold or
distributed outside that organisation. Never buy, download or reuse one.
What has changed. Very little, except the scale. MAK and KMS keys circulate
easily, get pasted into build documentation, and survive in imaging scripts long
after the agreement they came from has lapsed. The most common real-world
version of this is not malice — it is a build image that outlived its
entitlement.
5. Auction and marketplace listings
Pirated or unauthorised software is routinely sold through online auction sites
and marketplaces. Sellers may offer second-hand product, previously activated
product, stolen or used certificates, or illegally copied media. Buyers are
generally left without recourse once they discover the problem.
How to avoid it. Ask the obvious questions. Does it come with original
documentation? Are all the components there? Is the price too good to be true?
Is the seller a reseller you know and trust? Price is the strongest single
signal on this list — heavily discounted keys are discounted for a reason.
The category that did not exist in 2016
None of the five above covers the most common route to unlicensed and
ungoverned software today, which is somebody signing up to a service with a
corporate email address and a personal card. There is no key, no media and no
installer. There is a subscription nobody approved, holding company data, often
under terms nobody read.
It belongs in the same conversation because the failure mode is identical:
software in use that procurement never saw, with an entitlement position nobody
can evidence.
CerteroX SaaS Management handles this with three converging discovery signals —
a browser extension detecting application domains and per-user usage, identity
provider sync from Entra ID and Okta, and connector sync pulling authoritative
user and licence lists from the vendors themselves. Applications are classified
against a catalogue of over 35,000, which is also what drives Shadow AI
detection: AI tools are identified from application feature tags rather than a
hardcoded list, so the detection set grows on its own.
Finding it, rather than warning about it
Advice about buying carefully only protects the purchases you know about. The
rest of the problem is detection, and that is a tooling question.
Recognition that resolves what is actually installed. The Software
Recognition Database holds over 3.5 million titles with centrally maintained
categorisation, behind publisher normalisation and version recognition. Software
Identification (SWID) tags with UNSPSC classification handle the titles that
publish them. The point is that a deliberately mislabelled or repackaged
installation is resolved to the real publisher and product rather than recorded
as whatever it called itself.
Reconciliation against what Microsoft says you bought. Microsoft Licence
Statement import brings the publisher’s own record of your entitlement into the
same place as your deployment data. Volume licence, retail, OEM and FPP
transactions are captured separately, because the licence type determines what
each installation is permitted to be. An installation with no transaction behind
it is exactly the thing this post is about, and it is visible as a variance
rather than as an anecdote.
A continuously computed position. Purchased, used, available, required,
variance and exposure — calculated continuously, not reconciled once a year.
Unlicensed installations show up as they appear, which is the only point at
which removing them is cheap.
Prohibition with evidence. Application blacklisting and prohibition rules
block titles you have decided are not acceptable, and the Blocked Files log
records per-user and per-device block counts. That log is worth more than the
blocking: it tells you which teams keep trying, which is where your unmet demand
is.
Policy as code. Governance Policies work through a reusable filter builder,
with definitions that export and import as JSON, so a standard is a check that
runs rather than a document that circulates.
A legitimate route that is easier than the illegitimate one. The App-Centre
self-service portal, with manager approval chains and software distribution for
MSI, EXE and Click-to-Run packages, is the part of this most organisations skip.
Almost every piece of unlicensed software inside a well-run company got there
because somebody needed it and the sanctioned path took three weeks. Make the
sanctioned path take an hour and most of the problem stops recurring.
The point
Piracy is a procurement failure and a supply-chain failure far more often than
it is a moral one. The controls that work are unglamorous: buy from sources you
can name, keep entitlement records with the transactions that produced them,
recognise what is installed accurately enough to spot what does not belong, and
give people a fast legitimate way to get what they need.
Book a demo, or read more about CerteroX SAM.