VAMT 3.1 on Windows Server 2016 issue activating Windows 10 through proxy - invalid pointer

Raul Cuevas 40 Reputation points
2025-09-27T12:03:03.11+00:00

Good morning,

I am having a problem with VAMT 3.1 (latest version as of 12/2024) on Windows Server 2016 latest patch, and SQL 2022 CU21. I imported a Windows 10 EnterpriseS OEM 2019 IoT LTSC key into VAMT and it accepts it fine, then I have my Windows 10 computer same version EnterpriseS IoT 2019 LTSC.

When I try to activate the key through VAMT the process works fine, up to the point when activating the key via proxy (the computer is in a closed network directly connected to the server. with no internet access. The server has two nics, one for the computer closed network and one for the internet). When I try to activate the key it returns "Invalid Pointer". When I look at the event log on the VAMT server it shows "Error while acquiring CID for product: Application Name: Windows".

But if I try to activate the key manually on the Windows 10 computer connecting it to the internet it works.

I also notice that on my VAMT 3.1 the key is imported fine but on Activations remaining count sometimes it shows the number of activations and some times it shows "Not Applicable".

Am not sure where else to look for an answer as I have done all the troubleshooting steps to fix this problem, checked all ports are open on server and client computer, no firewalls, remove/reinstalled VAMT 3.1, reinstalled SQL fresh, created a new database, etc...

thank you,

Raul

Windows for business | Windows Server | Devices and deployment | Licensing and activation

Answer accepted by question author
Gmelch Gerhard 75 Reputation points
2025-09-30T14:23:46.68+00:00

We had the same issues since 24.09, but since today morning everything is working fine again. Can anyone confirm this?

Was this answer helpful?


2 additional answers

Sort by: Oldest
  1. Henry Mai 8,230 Reputation points Independent Advisor
    2025-09-27T14:26:19.59+00:00

    Hello Raul, I am Henry and I want to share my thought about your issue.

    After reviewing your case, your successful manual activation test was a perfect troubleshooting step, as it proved your key and the client OS are both valid, allowing us to focus entirely on the VAMT process. VAMT installation involves three distinct scenarios, and it's unclear whether all steps for Scenario 2: Proxy Activation were followed correctly.

    Let's quickly address what the symptoms are telling us:

    • "Error while acquiring CID for product": This error is the key piece of evidence. It confirms that your VAMT server on the isolated network is being instructed to connect directly to the internet to get a Confirmation ID (CID). In a secure offline environment, this action should never be performed by the isolated server, and this command is guaranteed to fail, producing the error you see.
    • "Invalid Pointer": This is a secondary error that often appears in the VAMT console when the underlying activation process (like acquiring a CID) fails unexpectedly.
    • Activation Count "Not Applicable": The reason you sometimes see a number is due to the way the VAMT console and its underlying database handle data when a new key is added or the status is being updated. This is not a sign that your key has a count; it is a temporary display artifact of the software. Once VAMT communicates with Microsoft and understands the key type, it corrects the display to the proper state of "Not Applicable."

    Based on the symptoms you've described, it seems the error occurred at Step 9 of the process, specifically when handling the CID (Confirmation ID). I recommend repeating the activation process, following all steps outlined in Scenario 2: Proxy Activation, ensuring that Step 9 is performed correctly after the product key has been installed.User's image

    I hope this information and these keywords help point you in the right direction for your research. Let me know how it goes, and if this answer helps, feel free to hit “Accept Answer” so others can benefit too

    Was this answer helpful?


  2. Raul Cuevas 40 Reputation points
    2025-09-30T12:41:54.2833333+00:00

    Good morning,

    Am going to share with you a work-around I implemented on my network to activate Windows 10 IoT using proxy activation from VAMT.

    My scenario is as follows but an example:

    ·         1 VAMT 3.1 server with latest patch.

    ·         2 NICs on same server (1 nic connects directly to router-internet, 1 nic connects to air-gapped isolated network – for activation of Windows machines)

    ·         OEM keys installed on VAMT database

    ·         SQL 2022 express (free)

    ·         Both my Windows server VAMT and the computers waiting to be activated have the Windows Firewall disabled (you can enable the firewall and add inbound and outbound rules if you want to be more granular but for the sake of simplicity I opted to disabled them)

    ·         My VAMT 3.1 server DNS entries on the NIC connected to the internet are 8.8.8.8 8.8.4.4

    ·         MY VAMT 3.1 server hostname is VAMT_SERVER

    For this example I will say that on my VAMT server the NIC connected to the internet has a private IP address: 10.10.10.2/24 gateway 10.10.10.1. The other NIC connected to the isolated network has IP address: 20.20.20.2/24 (no gateway)

    First, I downloaded Squid for Windows

    https://squid.diladele.com/

    on the web site download the Squid for Windows MSI (do not download the Web Proxy for Windows)

    Install Squid for Windows on the VAMT server, follow the installation prompts (keep everything as default).

    This will install the Squid for windows on C:\Squid directory

    Once the Squid program has been installed go to C:\Squid\etc\squid and make a backup of the configuration file squid.conf (in case something messes up)

    Next, modify the squid.conf file as follows:

    #

    # Recommended minimum configuration:

    #

     

    visible_hostname VAMT_SERVER

     

    # Example rule allowing access from your local networks.

    # Adapt to list your (internal) IP networks from where browsing

    # should be allowed

     

    acl activation src 20.20.20.0/24

     

    # Assign outgoing IP addresses based on ACLs

                   

    tcp_outgoing_address 10.10.10.2 activation

                   

    # Default outgoing IP address

    tcp_outgoing_address 0.0.0.0

     

    acl SSL_ports port 443

    acl Safe_ports port 80                    # http

    acl Safe_ports port 21                    # ftp

    acl Safe_ports port 443                  # https

    acl Safe_ports port 70                    # gopher

    acl Safe_ports port 210                  # wais

    acl Safe_ports port 1025-65535  # unregistered ports

    acl Safe_ports port 280                  # http-mgmt

    acl Safe_ports port 488                  # gss-http

    acl Safe_ports port 591                  # filemaker

    acl Safe_ports port 777                  # multiling http

    acl CONNECT method CONNECT

     

    ## Allow Local network

    http_access allow activation

     

    # Define allowed domains

    acl allowed_sites dstdomain .microsoft.com

     

    # Allow access to the defined domains

    http_access allow allowed_sites

     

    # Deny access to all other sites

    http_access deny all

     

    # Recommended minimum Access Permission configuration:

    #

     

    # Only allow cachemgr access from localhost

    http_access allow localhost manager

    http_access deny manager

     

    # Deny requests to certain unsafe ports

    http_access deny !Safe_ports

     

    # Deny CONNECT to other than secure SSL ports

    http_access deny CONNECT !SSL_ports

     

    # We strongly recommend the following be uncommented to protect innocent

    # web applications running on the proxy server who think the only

    # one who can access services on "localhost" is a local user

    #http_access deny to_localhost

     

    #

    # INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS

    #

     

    # Example rule allowing access from your local networks.

    # Adapt localnet in the ACL section to list your (internal) IP networks

    # from where browsing should be allowed

    # http_access allow localnet

    http_access allow localhost

     

    # And finally deny all other access to this proxy

    http_access deny all

     

    # Squid normally listens to port 3128

    http_port 20.20.20.2:3128

     

    ## custom acl

     

    # Uncomment the line below to enable disk caching - path format is /cygdrive/<full path to cache folder>, i.e.

    #cache_dir aufs /cygdrive/d/squid/cache 3000 16 256

     

     

    # Leave coredumps in the first cache dir

    coredump_dir /var/cache/squid

     

    # Add any of your own refresh_pattern entries above these.

    refresh_pattern ^ftp:                    1440       20%        10080

    refresh_pattern ^gopher:            1440       0%          1440

    refresh_pattern -i (/cgi-bin/|?) 0            0%          0

    refresh_pattern .                             0              20%        4320

     

    dns_nameservers 8.8.8.8 8.8.4.4

     

    max_filedescriptors 3200

     

    Once you have modified the squid.conf file with the settings above (make the adjustments on the italic entries to match your setup) save and close the file.

    Then open a command prompt with admin rights and go to C:\Squid\bin

    Type squid.exe -z

    This will start the squid utility

    Next, on the bottom right corner of your screen you will see the squid tray icon, right click on it and left click Start Squid Service.

     

    Now, on the Windows 10 computer that is isolated in the 20.20.20.0/24 network (adjust this to your environment) you can either hardcode an IP address or use DHCP to obtain an IP address.

    On my example my Windows 10 has IP: 20.20.20.100/24 and gateway 20.20.20.2 and DNS entries 8.8.8.8 8.8.4.4

     

    Next, on the Windows 10 computer, go to Settings --> Proxy

    Disable all the settings there and only enable Use a proxy server (turn it on)

    Then add your VAMT IP for the NIC that is on the isolated network, on my example I added 20.20.20.2 and port 3128

     

    Last, go to VAMT, perform a Discover Products, select manually enter name or IP address

    Then, type the IPs of the computers that need activation.

    Once the computers are registered in VAMT select the computers and perform Update license status --> alternate credentials.

    Then, install product key --> alternate credentials.

    Final step, select activate --> online activate --> alternate credentials.

     

    That’s it!

    In the example above I was able to activate two machines following this procedure as shown in the picture I shared.

    I hope this helps whoever has issue with Invalid Pointer when activating via proxy.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.