Mikhail Gellerman: Russian Customers Do Not Want to Depend on Changes in Windows Policy
Tighter security requirements for Windows-based infrastructure will provide yet another incentive for Russian organizations to migrate to domestic operating systems under the current sanctions environment, according to Astra Group. Mikhail Gellerman, Director of Operating Systems, said the introduction of hardware-backed verification into Windows' corporate activation mechanism, announced this week, is not a one-off anti-piracy measure but part of Microsoft's long-term platform strategy.

Recent Microsoft decisions point to a broader direction for the Windows platform. The first major step was making TPM 2.0 (Trusted Platform Module) support a mandatory requirement for installing Windows 11. TPM 2.0 provides secure storage for cryptographic keys, verifies system boot integrity, and supports modern security mechanisms. In practice, that requirement effectively ended support for a significant share of older hardware and shifted Windows toward a model in which the ability to run the operating system depends on whether the underlying hardware meets the vendor's requirements.
Microsoft's next – and perhaps most indicative – move was ending trust for legacy kernel drivers signed through the cross-signed root certificate program. Since April 2026, the Windows kernel has trusted only drivers that have passed official validation under the Windows Hardware Compatibility Program (WHCP), along with previously approved legacy drivers included on an allowlist. To minimize compatibility issues, Microsoft is introducing the new policy in audit mode before moving to mandatory enforcement. For enterprise customers, the company has also added Application Control for Business, allowing IT administrators to manually authorize specific proprietary or in-house drivers. These changes apply to both client and server editions of Windows.
Finally, in July 2026, Microsoft announced that it would introduce TPM-based hardware verification into the Key Management Service (KMS). KMS is commonly used in enterprise environments for license management, but it has also been widely exploited for unauthorized activation, particularly of Windows Server licenses, through counterfeit or emulated KMS servers. The new mechanism is intended to make such schemes considerably more difficult. Beginning in August, administrators will start receiving system warnings, while the next LTSC release of Windows Server will make TPM-based verification mandatory. The initiative reflects a broader industry trend: vendors are gradually shifting trust mechanisms from the software layer to the hardware layer.
Astra Linux is evolving in line with market demand and its strategy of becoming the new national standard for import substitution. Astra Group is steadily expanding its ecosystem of infrastructure, system, and application software, broadening the portfolio of compatible solutions, increasing automation, improving the user experience, providing comprehensive vendor support, and delivering tools that simplify migration to Astra Linux.


![Astra AI [Code] vs. Open Source: Why Deploying an Open Model in a Secure Environment Is Costly and Risky](https://storage.yandexcloud.net/itrussia/uploads/c3b5b6da-1bf7-49cb-817e-0bab1cea8cff.webp)






































