Earlier quoted context omitted.
I have heard/read that should be audited by Microsoft or any of the other large software houses that do that, they don't care for any certificate of authenticity or license keys, or anything. They want to see a valid purchase order for the SKU of the license. So, I think using a keygen might raise some red flags if the auditing software reports back the key even if it's the same SKU you paid for (and it had better be…
I've experienced multiple MSFT compliance audits at small business Customers in the 2004-2020 timeframe. MSFT only ever cared about reconciling what was in use with what was paid-for. I've been asked for photos of OEM key stickers attached to hardware but never asked to retrieve keys from installed software. I assume keys are another facet of keeping specific details around licenses vague enough that there's always r…
If I recall correctly, CALs don't really get 'installed', so my guess is that going off of 'provable licenses' keeps the audit process more uniform and streamlined.