ADBA Air Gapped Network

%3CLINGO-SUB%20id%3D%22lingo-sub-2842290%22%20slang%3D%22en-US%22%3EADBA%20Air%20Gapped%20Network%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2842290%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%20I%20am%20trying%20to%20find%20out%20how%20the%20ADBA%20operates%20within%20an%20air%20gapped%20network.%20I%20have%20an%20isolated%20network%20with%20200%20windows%2010%20clients.%20I%20know%20that%20once%20I%20load%20the%20KMS%20license%20to%20the%20ADBA%20and%20create%20the%20object%20that%20the%20clients%20will%20activate%20and%20check%20in%20every%20180%20days.%20What%20I%20don't%20know%20is%20does%20the%20ADBA%20need%20check%20in%20with%20Microsoft%20on%20an%20interval%20as%20that%20is%20impossible%20within%20my%20environment.%20If%20it%20cannot%20check%20in%20does%20it%20expire%20the%20license%20and%20stop%20activating%3F%20Any%20clarity%20on%20this%20matter%20would%20be%20greatly%20appreciated%20as%20I%20have%20not%20found%20any%20articles%20that%20speak%20to%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2842290%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2904599%22%20slang%3D%22en-US%22%3ERe%3A%20ADBA%20Air%20Gapped%20Network%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2904599%22%20slang%3D%22en-US%22%3EHi%2C%20Scruggst.%3CBR%20%2F%3E%3CBR%20%2F%3EWhile%20I%20don't%20use%20ADBA%2C%20from%20what%20I've%20read%20on%20the%20requirements%2C%20it%20comes%20across%20like%20KMS%20(my%20area%20of%20experience)%2C%20where%20the%20initial%20activation%20is%20once-off.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20know%20you're%20looking%20for%20an%20explicit%20statement%20but%20from%20reading%20the%20following%2C%20the%20implied%20discussions%20(around%20proxy%20and%20phone%20activation%20for%20isolated%20networks)%20are%20about%20as%20good%20as%20you're%20going%20to%20get%20from%20docs.microsoft.com.%3CBR%20%2F%3E%3CBR%20%2F%3EIt%20seems%20your%20best%20best%20may%20be%20the%20VAMT%20proxy%20activation%20route.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20the%20third%20article%2C%20as%20you%20read%20the%20%22isolated%20networks%22%20section%2C%20you%20can%20readily%20exchange%20the%20term%20%22KMS%22%20for%20%22ADBA%22%20in%20your%20scenario.%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fvolume-activation%2Factive-directory-based-activation-overview%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fvolume-activation%2Factive-directory-based-activation-overview%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fvolume-activation%2Factivate-forest-by-proxy-vamt%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fvolume-activation%2Factivate-forest-by-proxy-vamt%3C%2FA%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fvolume-activation%2Fplan-for-volume-activation-client%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fdeployment%2Fvolume-activation%2Fplan-for-volume-activation-client%3C%2FA%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

Hello, I am trying to find out how the ADBA operates within an air gapped network. I have an isolated network with 200 windows 10 clients. I know that once I load the KMS license to the ADBA and create the object that the clients will activate and check in every 180 days. What I don't know is does the ADBA need check in with Microsoft on an interval as that is impossible within my environment. If it cannot check in does it expire the license and stop activating? Any clarity on this matter would be greatly appreciated as I have not found any articles that speak to this.

2 Replies
Hi, Scruggst.

While I don't use ADBA, from what I've read on the requirements, it comes across like KMS (my area of experience), where the initial activation is once-off.

I know you're looking for an explicit statement but from reading the following, the implied discussions (around proxy and phone activation for isolated networks) are about as good as you're going to get from docs.microsoft.com.

It seems your best best may be the VAMT proxy activation route.

In the third article, as you read the "isolated networks" section, you can readily exchange the term "KMS" for "ADBA" in your scenario.

https://docs.microsoft.com/en-us/windows/deployment/volume-activation/active-directory-based-activat...
https://docs.microsoft.com/en-us/windows/deployment/volume-activation/activate-forest-by-proxy-vamt
https://docs.microsoft.com/en-us/windows/deployment/volume-activation/plan-for-volume-activation-cli...
I would also plea for keeping ADBA and for these airgapped ones use VAMT 3 with a special account and proxy activation using the same method. KMS imho is only used because it is well known and MSFT still refers to it in many docs instead of ADBA and VAMT.

You can also use VAMT from Windows 11 ADK and use MAK instead on airgapped systems. It is a neat tool. Check the docs. Have updated them throughout the year.