Friday, August 4, 2017

Install KMS 2012 Step By Step


Here I'm Going to demonstrate the installation and the use of KMS role which is in the Windows Server.

First of all you need to setup the Windows 2012 Server and then can go in to

Manage > Add Roles and Features > Role-based or feature-based installation > "Select the Server" where you want to install the role > Add Roles and Features Wizard > Select "Volume Activation Services" > Then install the additional features

Then you will get the Volume Activation Services wizard. There you can find a description about the VAS.

Note: The Volume Activation Services (VAS) role is not required to configure a KMS Server. To do the management, it is highly recommended to install this role.

Volume Activation Tools 
Introduction to Volume Activation Services 
ntroduction 
Activstion Type 
Product Key Management 
Configuration 
Volume Activation Services enables you to automate and simplify the issuance and management of 
Microsoft software volume licenses for a variety of scenarios and environments. With Volume 
Activation Services, you can install and activate a Key Management Service (KMS) host key, and 
configure the (MS. After this service is installed, you can also use it to issue, monitor and manage 
volume licenses for Microsoft products which support Volume Activation in your organization 
based on computer account information in Active Directory Domain Services (AD DS) 
Things to Note 
To install and enable Volume License Services, the account you use must have: 
- Local administrator permissions on the computer running Server Manager and on the computer (if 
separate) where you intend to install keys and manage KMS. 
- Permissions to write data to the Activation Object container. These permissions, which by default 
require membership in the Enterprise Administrators group, can be delegated. 
- You also must have a unique Key Management Service (KMS) host key for ├čur organization. For 
more information about volume licensing options, go to Microsoft Volume Licensing homepage. 
Additional Information 
Microsoft Volume Licensing Home Page 
Managing Volume Licensing clients using the Volume Activation Management Tool PVAMT)

Note. If all Windows OSs activated on this KMS server belong to one and the same Active Directory domain, you can use a special KMS extension — Active Directory Based Activation.

Select the computer name which you want to activate. (The computer need to be in the domain.)

Volume Activation Tools 
Select Volume Activation Method 
Introduction 
Activation Type 
Key Msnsgement 
Configuration 
You can modify an existing volume activation configuration or create a new one. Select the method 
you want to manage and, for the Key Management Service, the ser.'er on which the service is 
installed. 
If you need to use credentials other than your current account, enter the usemame and password 
before proceeding. 
O 
Active Directory Based Activation 
@ Key Management Service (KMS) 
Alternate credentials (optional) 
domain\username 
user name: 
password

Now you can copy paste the KMS key which you can get from the Microsoft Volume Licensing portal

Volume Activation Tools 
Manage (MS Host 
Introduction 
Activstion Type 
Product Key Management 
Configuration 
KMS —11 
Create a new KMS host by installing yn•ur KMS host key. If have already installed a KMS host 
key, you can activate installed products, or select Skip to Configuration to review and modi%' KMS 
configurations. 
@ Install pur KMS host key 
CD Skip to Activation 
C) Skip to Configuration

Once that done you will get the below window. Here  you can select the Review configuration and click next to proceed.

Volume Activation Tools 
Product Key Installation Succeeded 
KMS — 1 
'w ale 
Introduction 
Activstion Type 
Product Key Management 
The product key has been installed. The product may need to be activated. Select Activate Product 
and click Next to complete activation. Otherwise select Review Configuration and click Next. 
CD Activate Product 
Review Configuration

If you have not added the firewall exceptions, you will get the below window. You can add the firewall exceptions as mentioned below. And then run the setup again.

But for the initial run, disable the Windows firewall and run the activation. This way you will have a way to understand that KMS is not giving any errors. Later give the exceptions in the firewall and enable the destination PC firewall.

If the firewall enabled, you will get the below error.

Volume Activation Tools 
Product Key Installation Succeeded 
Introduction 
Activstion Type 
Product Key Manageme 
Configuration 
The product key has been installed. The product may need to be activated. Select 
and click Next to complete activation. Otherwise select Review Configuration and cli 
Activate Product 
Error 
The following error has occurred. Please resolve the error and try' again. 
Description: 
The firewall rules could not be accessed. Please check your network and 
remote firewall settings.

Go in to Windows firewall and click on New Inbound rule Wizard.

New Inbound Rule Wizard 
Rule Type 
Select the type of firewall rule to create 
Rule Type 
Protocol and Ports 
Action 
Profile 
Name 
What type of rule would you like to create? 
o 
Rule that controls connections for a program 
Rule that controls connections for a TCP or UDP port 
o 
AIJoyn Router 
Rule that controls connections for a Windows experience 
Custom rule

Then add a TCP port 1688.

Protocnl and Ports 
Specfy the protocols and ports to which this rule applies 
Rule Type 
Protocol and Ports 
Action 
Profile 
Name 
Does this rule apply to TCP or UDP? 
@ TCP 
O UDP 
Does this rule apply to all local ports or specific local ports? 
o 
Al locA ports 
@ locA ports: 
Example 80. 443. 5000-5010

Click allow connection.

New Inbound Rule Wizard 
Action 
Specify the action to be taken when a connection matches the conditions specified in the rule 
Rule Type 
Protocol and Ports 
Profile 
Name 
What action should be taken when a connection matches the specified conditions? 
@ Alow ttE corvEdion 
This includes connections that are protected with IPsec as well as those are not 
o 
Alow ttE corvEdion if it is 
This includes only connections that have been authenticated by using IPsec Connections 
will be secured using tha settings in IPsec properties and rules in tha Connection Security 
Rule noda 
Customize n 
o 
Bock ttE corvEdion

Here you can select the Domain as the selected network. But I prefer to go with the Domain and the Private networks.

New Inbound Rule Wizard 
Profile 
Specfy the profiles for which this rule applies 
Rule Type 
Protocol and Ports 
Action 
Name 
When does this rule apply? 
Applies when a computer is connected to ts corporate domain 
Priv*e 
Applies when a computer is connected to a private network location such as a home 
or work place 
Public 
Applies when a computer is connected to a public network location

Give a name for the newly created rule and apply the changes.

New Inbound Rule Wizard 
Name 
Specify the name and description of this rule 
Rule Type 
Protocol and Ports 
Action 
Profile 
The KMS TCP listening portl 
Name 
Descnpt'on (optional)

Now you will be able to use your KMS server to activate Domain joined computers.