Plan volume activation of Office 2016

Summary: Explains each method that you can use to activate volume license editions of Office 2016.

You plan the deployment of Office for volume activation of Office 2016 in several steps. Before you read this article, we recommend that you read Windows Volume Activation Planning Guide.

Are you a user?
If you are a user activating a personal copy of Office 2016, follow the Activate Office 365, Office 2016, or Office 2013 directions instead.
Are you an admin?
If you are an admin planning to activate and license Office 365 ProPlus, review the Overview of licensing and activation in Office 365 ProPlus instead.

If you are an admin planning to activate and license volume license edition of Office 2016, you're at the right place, keep reading.

Microsoft policy requires the activation of all editions of Office 2016 client software, including volume license editions. For Office 2016, volume activation occurs through Office Activation Technologies, which are based on the Software Protection Platform (SPP) that is used in Windows 7, Windows Server 2008 R2, Windows 8, Windows 8.1, Windows Server 2012 and Windows Server 2012 R2. Office Activation Technologies provides three activation methods for Office 2016:

The model that you choose depends on the size, network infrastructure, connectivity, and security requirements in your environment.

Plan a volume license deployment

Planning an Office 2016 deploying requires the same considerations as planning a Windows deployment of Windows 7, Windows Server 2008 R2, Windows 8, or Windows Server 2012. To help determine which activation method to use for Windows, see the Windows Volume Activation Planning Guide. Most likely, Office 2016 will use the same method.

A volume activation deployment includes the following steps:

  1. Learn about product activation.

  2. Review available activation models.

  3. Evaluate client connectivity.

  4. Map the physical computer or virtual computer to an activation method.

  5. Determine product key needs.

  6. Determine monitoring and reporting needs.

Most of the information about these steps is covered in the Windows Volume Activation Planning Guide. This article describes an overview of the technology.

When you plan for Office Activation Technologies, think about the following:

  • The Key Management Service (KMS) activation threshold for Office 2016 is five computers. This means that Office 2016 client computers will be activated only after five or more client computers have requested activation.

  • You do not have to enter a product key for Office 2016 KMS client computers. You only have to enter an activation key on the KMS host computer.

    The same is true for client computers in an Active Directory Domain Services (AD DS)-based deployment.

  • If you decide to use Multiple Activation Key (MAK), you enter the product key either through the Office Customization Tool (OCT) or the Config.xml file. ((Although these articles are for an earlier version of Office, the information also applies to Office 2016.) After Office 2016 installation, you can change the product key by using the Volume Activation Management Tool (VAMT) or the Office Software Protection Platform script ( ospp.vbs ). For more information about ospp.vbs, see The ospp.vbs script.

    For information about VAMT 3.0, see Volume Activation Management Tool (VAMT).

Review and compare activation methods

Office Activation Technologies provides three activation methods for Office 2016: KMS, MAK, and AD DS-based activation.

  • Key Management Service (KMS) A client-server model in which you must install and activate a KMS host activation key on a KMS host computer. This establishes a local activation service in your environment. Office 2016 client computers connect to the local Office 2016 KMS host for activation.

  • Multiple Activation Key (MAK) If you use MAK, Office 2016 client computers are activated online by using the Microsoft-hosted activation servers or by telephone.

  • AD DS-based activation Available only for Office 2016 on Windows 8 and Windows Server 2012. AD DS-based activation can activate all Office 2016 volume license clients throughout a domain. You set up AD DS-based activation from either a Windows 8 volume license edition computer or a Windows Server 2012 computer.

The kind of key that you install determines the activation method. All Office 2016 volume license editions have the KMS client key pre-installed. You do not have to enter a product key if you are deploying KMS clients. If you want to use MAK activation, you have to enter the correct MAK.

You can also use a combination of KMS and MAK within your deployment. For example, Office 2016 running on desktops that are connected to the corporate network has the KMS client key installed, whereas Office 2016 running on portable computers has the MAK installed.

The model that you choose depends on the size, network infrastructure, connectivity, and security requirements in your environment. You can choose to use only one or a combination of these activation methods. Typically on a client computer, you would use the same activation method for a particular instance of Windows that you use for Office. For more information about how to decide which activation method to use, see the Windows Volume Activation Planning Guide.

To find out more about how to buy volume license editions of Office 2016, see Microsoft Office Volume Licensing Buyer's Guide.

Key Management Service (KMS)

KMS is a client-server model in which each client requests activation from a computer serving as the KMS host computer. By default, clients connect to the KMS host computer on port 1688. The KMS host computer uses DNS to publish the KMS service. You can either use the default settings, which require little or no administrative action, or manually configure the KMS host computer and clients based on the network configuration and security requirements in your environment. To be licensed, each client must be activated.

You must prepare a KMS host computer by first installing the licensing files (see Prepare and set up the Office 2016 KMS host computer), and then activating the KMS host key before it can accept activation requests from client computers.

Publication of Key Management Service

KMS uses service (SRV) resource records (RRs) in DNS to store and communicate the locations of KMS host computers. KMS host computers use dynamic updates, if available, to publish the SRV RRs. For more information, see Dynamic update. If dynamic updates are not available, or if the KMS host computer does not have permissions to publish the RRs, you must publish the DNS records manually or configure client computers to connect to specific KMS host computers. This might require changing permissions on DNS to let more than one KMS host computer publish SRV records.

Note

DNS changes might take time to propagate to all DNS hosts, depending on the complexity and topology of your network. For more information, see Set up DNS for Office 2016 KMS-based volume activation.

Multiple Activation Key (MAK)

MAK is used for one-time activation with the Microsoft hosted activation services. Each MAK has a predetermined number of allowed activations. This number is based on volume licensing agreements and may not match the organization's exact license count. Each activation that uses MAK with the Microsoft hosted activation service counts toward the activation limit. After Office 2016 is activated, no re-activation is required unless the hardware changes significantly.

There are two ways to activate computers by using MAK:

  • MAK independent activation MAK independent activation requires that each computer independently connect and be activated with Microsoft, either over the Internet or by telephone. MAK independent activation is best for computers that do not maintain a connection to the corporate network.

  • MAK proxy activation by using VAMT This enables a centralized activation request on behalf of multiple computers that have one connection to Microsoft. MAK proxy activation is configured by using the Volume Activation Management Tool (VAMT). MAK proxy activation is appropriate for environments in which security concerns might restrict direct access to the Internet or the corporate network. It is also suited for development and test labs that do not have this connectivity.

MAK architecture

MAK activation requires that a MAK is installed on a client computer and instructs that computer to activate itself against Microsoft hosted activation servers over the Internet. In MAK proxy activation, a MAK must be installed on the client computer by any of the methods previously described. VAMT obtains the installation ID (IID) from the target computer, sends the IID to Microsoft on behalf of the client, and obtains a confirmation ID (CID). The tool then activates the client by installing the CID. The CID is saved and can be used later, for example, to activate test computers that were re-imaged after 90 days.

For more information, see Activate Office 2016 MAK clients.

Active Directory Domain Services-based activation

As with KMS, AD DS-based activation can activate all Office 2016 volume license clients within the domain. To use AD DS-based activation, you configure AD DS from one computer to support the activation of all Office 2016 volume license clients within the domain.

AD DS-based activation uses the same GVLK/KMS host key pair that KMS activation uses. When you use AD DS-based activation, the Software Protection Platform Services periodically attempts to activate the GVLK against either an activation object in AD DS or a discoverable KMS if the AD DS-based activation attempt fails. A successful AD DS-based activation grants a license to the Office 2016 client for 180 days.

For more information about AD DS-based activation, see Active Directory Domain Services-based activation of Office 2016.