Resolving Siemens ALM License Transfer Errors and Inactive License Keys
Siemens Automation License Manager (ALM) is the central utility used to handle software license keys for TIA Portal, STEP 7, WinCC, STARTER, and other SIMATIC engineering tools. License transfer errors in ALM are among the most disruptive issues for automation engineers because they block commissioning, prevent engineering station rebuilds, and can strand a project if the source machine is no longer available. The most common and least understood error class is the "inactive license" state, which ALM displays as a grey checkmark in the Status column rather than the normal green checkmark.
This reference covers the exact symptoms, root causes, and field-proven recovery procedures for ALM license transfer failures, with a focus on the inactive-key condition that prevents standard drag-and-drop transfer, requires offline transfer for virtual machines, and forces a Technical Support engagement for reactivation.
1. Problem Overview and Symptom Catalog
ALM license transfer failures manifest in a small number of repeatable patterns. Identifying the exact symptom shortens the diagnostic path significantly.
| Symptom in ALM | Status Icon | Likely Root Cause |
|---|---|---|
| License displays normal, drag-and-drop to USB fails with error | Green check | USB encryption, ALM not elevated, TIA Portal still running |
| License shows grey checkmark; cannot drag, copy, or transfer | Grey check (inactive) | Defective certificate, partition restore, overwritten key |
| VM does not enumerate USB stick; ALM reports no target | Green or grey | USB passthrough misconfiguration, encryption mismatch |
| Error: "Automation licence key could not be transferred because it is inactive" | Grey check | TIA Portal still holds the license, key corrupted |
| Drag-drop appears to start, then vanishes on new machine | Green check (source) | License server on source already reissued, key desync |
The grey-checkmark state is the failure mode that drives most escalations to Siemens Technical Support, because the key is still visible in ALM but is treated by the license engine as if it does not exist. Drag-and-drop operations silently fail, the offline transfer wizard reports "no valid licenses to export," and the receiving machine never sees the key on its USB target.
2. Root Cause Analysis
Siemens license keys are cryptographically bound to the host fingerprint at the moment of activation. The fingerprint is computed from hardware attributes including disk volume serial numbers, MAC addresses, and CPU identifiers, with the exact recipe versioned per ALM release. When any of those attributes change after activation, the license engine flags the key as defective or inactive rather than destroying it. This design lets Siemens Technical Support repair the binding without reissuing a new key, but it also means that any of the following common engineering actions can put a license into the grey-checkmark state:
- Disk image restore from backup: Restoring a Windows partition image taken before activation changes the volume serial number the license engine sees on next boot.
- Motherboard replacement or VM clone: CPU ID, MAC address, or disk device path changes, breaking the hardware fingerprint.
- Windows reinstall or major feature update: Reattaches storage devices in a different enumeration order.
- Activation of the same key on a second PC without a prior transfer: The original binding is invalidated when the second activation succeeds.
- Restoring a license that was previously transferred and then re-imported to the source: The transferred copy is deactivated, but if the source key was never re-bound, it can be marked inactive.
- Loss of the original CoL (Certificate of License) or USB hardware dongle before the transfer completed, leaving no proof of ownership for reactivation.
For license transfer between two physical PCs, drag-and-drop is the correct procedure. For transfer between a physical PC and a virtual machine, or between two virtual machines, drag-and-drop is unreliable because ALM cannot always reach the USB target inside the VM, and the offline transfer wizard must be used. The two cases require different procedures and have different failure modes.
3. Standard Drag-and-Drop Transfer Procedure (Physical to Physical)
This is the fastest method when both source and destination are real PCs with locally attached USB ports. It works only on active, green-checkmark licenses.
3.1 Prerequisites
- ALM is installed on both source and destination PCs (the version should match or be newer on the destination).
- A USB stick formatted as FAT32 or NTFS, with at least 16 MB free per license.
- The USB stick has been unlocked if it uses hardware encryption (IronKey, Apricorn, etc.). Siemens ALM cannot write to encrypted volumes.
- Administrative rights on both PCs.
- All TIA Portal, STEP 7, WinCC, and STARTER instances are closed on both machines.
3.2 Procedure
- Plug the USB stick into the source PC and wait for it to enumerate in Windows Explorer.
- Start Automation License Manager on the source PC as Administrator (right-click → Run as administrator).
- In the left navigation pane, expand the source drive and locate the license you want to move. Confirm the Status column shows a green checkmark.
- Click and hold the license entry, drag it onto the USB drive listed in the left navigation pane, and release. ALM writes a transfer package (a
.zip-style bundle) to the USB root. - Right-click the USB drive in ALM and select Eject to flush all writes, then physically remove the stick.
- Plug the USB into the destination PC, start ALM as Administrator, and drag the license from the USB drive onto the destination drive in the left pane.
- Verify the license now shows a green checkmark on the destination, and that the source no longer lists it.
4. Offline Transfer Procedure (VM, Network-Isolated, or Encrypted USB)
The offline transfer procedure is required whenever ALM cannot reach the USB target directly. This includes all virtual machines, network-isolated engineering stations, and cases where the USB stick is encrypted and ALM cannot see the drive letter. The procedure exports a transfer request file on the source, which must be re-imported on a machine with internet access (or submitted to Siemens) to obtain a transfer response file, which is then re-imported on the destination to apply the license.
4.1 Generate Transfer Request on Source
- Open ALM on the source PC as Administrator.
- Click License Key in the menu bar and select Offline Transfer.
- Choose Generate transfer request file and select the licenses to include. ALM creates a file named
Customer_<timestamp>.WibuCmRacor similar in the chosen output directory. - Copy the request file to a USB stick or network share accessible from a machine with internet access.
4.2 Process Transfer Request on Online Machine
- On any PC with ALM installed and internet access, open ALM as Administrator.
- Click License Key → Offline Transfer → Process transfer request.
- Point ALM to the request file. ALM uploads the request to the Siemens license server, validates the request against the source hardware fingerprint, and downloads a transfer response file (
Response_<timestamp>.WibuCmRac). - Copy the response file back to the source machine or directly to the destination machine.
4.3 Import Transfer Response on Destination
- On the destination machine, open ALM as Administrator.
- Click License Key → Offline Transfer → Import transfer response.
- Select the response file. ALM binds the license to the destination hardware fingerprint and registers it on the chosen drive.
5. Inactive License (Grey Checkmark) Recovery Procedure
The grey-checkmark state requires Siemens Technical Support engagement for reactivation. The procedure is well-defined and reproducible; the timeline depends on the support region and whether the original Certificate of License (CoL) or USB dongle is available.
5.1 Information to Gather Before Contacting Support
| Required Information | Where to Find It |
|---|---|
| License key number (CoL number) | Original CoL PDF, USB dongle sleeve, or ALM license details |
| Siemens order number (if available) | Purchase order, delivery note, or reseller invoice |
| Software product and version (e.g., TIA Portal V17, STEP 7 V5.7) | ALM Help → About, or installation media label |
| HostID / Computer ID of the affected machine | ALM menu → License Key → Computer ID (a 20-digit hex string) |
| Cause of the failure (disk image restore, VM clone, hardware change, etc.) | Engineer's knowledge of recent workstation events |
| Original CoL PDF or USB license stick (if still in possession) | Document archive, original delivery package |
5.2 Channel for Support Engagement
Siemens has consolidated license support into the SiePortal. In the US, phone-only intake for new cases is restricted; the recommended entry points are:
- SiePortal support requests: sieportal.siemens.com
- Local Siemens Industrial Customer Support; contact details are listed under Support → Contact in SiePortal.
- The original reseller from whom the software was purchased. Resellers have direct escalation channels and can submit the reactivation request on the customer's behalf.
For engineers in Singapore, the regional Siemens support contact is reached through the same SiePortal entry point, with the country selector routing the case to the APAC team. Email intake has historically been available at [email protected], but the SiePortal web form is the current preferred channel and produces a tracked ticket.
5.3 What Siemens Support Will Request
Siemens Technical Support will request the Computer ID of the target machine and the CoL number. They will then issue a new license file (.zip bundle) bound to that Computer ID. The bundle is imported by dragging it onto the destination drive in ALM, at which point the grey checkmark becomes a green checkmark and the license is fully active.
6. USB Authorization and Encryption Issues
A common drag-and-drop failure is the "USB not authorized" error, which is reported by ALM when the destination USB stick is hardware-encrypted and Windows presents it as read-only or refuses to expose the underlying FAT/NTFS volume. Siemens license transfer requires a writable, unencrypted target volume.
| USB Type | ALM Behavior | Workaround |
|---|---|---|
| Plain FAT32 / NTFS | Drag-and-drop works | None required |
| Hardware-encrypted (IronKey, Apricorn, etc.) | ALM cannot write; transfer fails | Use a plain USB stick for the transfer |
| Software-encrypted (BitLocker To Go, VeraCrypt) | ALM cannot write; transfer fails | Decrypt before transfer, or use plain USB |
| USB with secure partition (some OEM sticks) | Only the public partition is visible | Reformat as plain FAT32, or use a different stick |
| USB 3.0 hub with insufficient power | Intermittent enumeration, ALM loses device | Plug directly into a rear port, or use USB 2.0 |
The lack of encryption on the USB stick is, ironically, the source of the authorization error. Siemens ALM uses the Wibu-Systems CodeMeter runtime, which refuses to write to encrypted volumes because the license transfer package itself contains cryptographic material that must remain accessible to the next host. The transfer package is a one-time-use artifact bound to the destination fingerprint, so the security exposure is limited, but it must be physically moved on a writable medium.
7. ALM Administrative Privileges and Windows Compatibility
ALM must be run with elevated privileges on every operation that touches the license store. On Windows 10 and Windows 11, the default user context for double-clicked applications does not include write access to the %ProgramData%\Siemens\Automation\License tree, and a failed write inside ALM can leave the license store in an inconsistent state where the source key is removed but the destination key has not been written.
7.1 Verified Failure Mode Without Elevation
On some non-Siemens license managers (notably Rockwell EVRSI), the documented failure mode is that the license is first deleted from the source and then the destination write fails, leaving the customer with no license at all. The same hazard exists for ALM under specific combinations of TIA version and Windows version, and the safe practice is to always run ALM as Administrator regardless of UAC settings.
7.2 Windows 11 Specific Considerations
Windows 11 introduces additional UAC prompts for COM and WMI access, and on first launch after installation ALM may fail to enumerate license targets until the elevation is accepted. If the elevated prompt is dismissed, ALM starts in a degraded mode that reads the license store but cannot write. The symptom is identical to the inactive-license state but is resolved by a right-click → Run as administrator relaunch.
8. TIA Portal Interaction Constraints
The single most common reason a license appears "inactive" during a transfer is that TIA Portal is holding a license handle. TIA Portal checks out licenses at startup and holds them for its entire session; while a license is checked out, ALM cannot move it, and the Status column will reflect the checked-out state with a different icon than the normal green checkmark. Closing TIA Portal, including all open project instances, releases the handle and restores the green checkmark.
The same constraint applies to the following processes, all of which must be closed before any ALM transfer:
- TIA Portal (all versions, V13 through V19)
- STEP 7 (V5.x and TIA-based)
- WinCC flexible, WinCC (TIA), WinCC Explorer, WinCC Runtime
- STARTER and Startdrive (SINAMICS commissioning)
- S7-PLCSIM and S7-PLCSIM Advanced
- SINEC NMS, SINEMA Server, and any other Siemens engineering tool that depends on a license
- Wibu-Systems CodeMeter Control Center if it is open and has a slot reserved
To verify nothing is holding the licenses, open Task Manager → Details, sort by publisher, and confirm that no Siemens AG or Wibu-Systems process is running. If CodeMeter.exe is the only remaining process, that is expected and is the ALM runtime service.
9. Virtual Machine (VMware, Hyper-V, VirtualBox) Considerations
Engineering stations are increasingly deployed on VMs, and ALM behavior inside a VM is the source of recurring tickets. The two issues are (1) USB passthrough for the transfer media and (2) VM cloning, which always invalidates licenses.
9.1 USB Passthrough
ALM in a VM cannot write to a USB stick on the host unless the stick is passed through to the guest. The supported configurations are:
- VMware Workstation / VMware Player: VM → Removable Devices → [USB stick] → Connect
- Hyper-V: USB passthrough requires the enhanced session mode on the host, and a USB redirector on the guest. The offline transfer procedure is generally the simpler option for Hyper-V environments.
- VirtualBox: Devices → USB → [USB stick]
If USB passthrough is unreliable, the offline transfer procedure (Section 4) is the recommended path for VM-based engineering stations. It avoids the USB enumeration problem entirely by exchanging request and response files through any writable share.
9.2 VM Clone or Snapshot Revert
Cloning a VM is functionally identical to restoring a disk image: the Wibu-Systems CodeMeter hardware fingerprint changes, and every license on the cloned VM enters the grey-checkmark state. The same is true for any revert to snapshot operation that restores a CPU ID, MAC address, or disk serial number that differs from the running VM. The only safe practice is to license the VM after it has been deployed to its final hardware configuration, and to never clone a licensed VM. If cloning is unavoidable, expect to contact Siemens Technical Support for a full license reactivation on each clone.
10. TIA Portal and ALM Version Compatibility Matrix
ALM version is independent of the TIA Portal version, but the license keys issued for one TIA generation are not always usable on an older TIA Portal. The following compatibility table reflects the rules Siemens uses when issuing new licenses and is the basis for choosing the correct ALM version on the destination PC.
| TIA Portal Version | Compatible ALM Version | License Server |
|---|---|---|
| V13 / V13 SP1 / V13 SP2 | ALM V5.3 and newer | CodeMeter V6.30+ |
| V14 / V14 SP1 | ALM V5.4 and newer | CodeMeter V6.40+ |
| V15 / V15.1 | ALM V6.0 and newer | CodeMeter V6.50+ |
| V16 | ALM V6.1 and newer | CodeMeter V6.60+ |
| V17 | ALM V6.2 and newer | CodeMeter V6.70+ |
| V18 | ALM V6.2 SP1 and newer | CodeMeter V7.10+ |
| V19 | ALM V6.2 SP2 and newer | CodeMeter V7.21+ |
ALM is forward-compatible: a newer ALM can read and manage older licenses. A license issued for TIA V17 cannot, however, be used by a TIA V15 installation, and ALM will display the key with a grey checkmark because the local CodeMeter runtime does not recognize the license certificate version.
11. Verification Checklist After Transfer
Run the following checks after every license transfer to confirm the operation succeeded and the licenses are usable:
- Open ALM as Administrator on the destination and confirm the transferred license shows a green checkmark in the Status column.
- Confirm the source machine no longer lists the license (i.e., the move was destructive, not a copy).
- Launch TIA Portal on the destination and open the project that requires the license. Verify the Licenses dialog in TIA Portal (menu Options → License management) lists the key as valid.
- Open a sample project, compile it, and start a download to the PLC to confirm the runtime path is functional.
- Record the new Computer ID for the destination, the CoL number, and the transfer date in a license register. This accelerates any future reactivation request.
- If the license shows a grey checkmark after the transfer, do not retry the drag-and-drop operation; the key is now in an unrecoverable state on both machines and requires Siemens Technical Support for reactivation.
12. Troubleshooting Matrix
| Error Condition | Likely Cause | First Action | Escalation |
|---|---|---|---|
| Drag-and-drop to USB silently fails | TIA Portal open, or ALM not elevated | Close all Siemens tools, run ALM as Administrator | None required |
| USB not visible in ALM | USB is encrypted or VM passthrough not configured | Use plain USB, or configure VM passthrough | Use offline transfer procedure |
| "License key could not be transferred because it is inactive" | Defective key (partition restore, VM clone, hardware change) | Gather CoL number and Computer ID | Siemens Technical Support via SiePortal |
| License shows green on source but not on destination | Drag-and-drop did not complete on destination | Re-run ALM as Administrator on destination, retry drag | Use offline transfer if repeat fails |
| Offline transfer upload fails | Source PC not connected to internet, or firewall blocks CodeMeter | Run the upload on a separate internet-connected PC | None required |
| Reactivation request rejected by support | Lost CoL, no reseller of record | Provide order number and reseller contact | Regional Siemens support manager |
13. Preventive Engineering Practices
The cheapest license to reactivate is the one that was never broken. The following practices prevent the most common ALM failure modes:
- Image engineering workstations after license activation, never before. If a restore is required, document the original Computer ID and CoL number so the reactivation can be filed immediately.
- Maintain a license register listing every CoL, the host Computer ID, the TIA Portal version, and the engineer responsible. This is the single biggest time-saver when a reactivation request is filed.
- Never clone a licensed VM. License after clone, never before. Treat every VM template as unlicensed.
- Run ALM as Administrator by default, on every PC, for every operation.
- Close TIA Portal before any ALM operation, including license checks. The error "license is inactive" is often a TIA-is-holding-the-handle error.
- Use a dedicated, plain USB stick for license transfers. Label it, store it in a known location, and never encrypt it.
- Subscribe to ALM updates in SiePortal. CodeMeter and ALM updates include hardware-fingerprint algorithm refreshes that can prevent false inactive flags on newer hardware.
What does a grey checkmark in ALM mean?
A grey checkmark in the ALM Status column means the license is inactive and cannot be used or transferred. The key is still present in the license store but the hardware fingerprint does not match the binding issued by Siemens, typically because of a disk-image restore, VM clone, hardware change, or Windows reinstall. Contact Siemens Technical Support via SiePortal with the CoL number and the target Computer ID to request reactivation.
Why does drag-and-drop of a license to USB fail even though the license is shown as valid?
Drag-and-drop fails when TIA Portal, STEP 7, WinCC, STARTER, or S7-PLCSIM is running and holds a license handle, or when ALM is not launched as Administrator. Close every Siemens engineering application, run ALM as Administrator (right-click → Run as administrator), and retry. If the USB stick is hardware- or software-encrypted, ALM cannot write to it; use a plain FAT32 or NTFS stick.
How do I transfer a license to a virtual machine that does not see the USB stick?
Use the offline transfer procedure. On the source, open ALM → License Key → Offline Transfer → Generate transfer request file, save the file to a network share, then on any PC with internet access run License Key → Offline Transfer → Process transfer request to obtain a transfer response. Import the response on the destination VM with License Key → Offline Transfer → Import transfer response. The full procedure is documented in Siemens KB 109990997.
Can I recover a license after cloning a VM?
No. Cloning a VM changes the hardware fingerprint, and all Siemens licenses on the clone enter the inactive (grey checkmark) state. You must contact Siemens Technical Support with the CoL number and the new Computer ID of the clone to obtain a reactivation file. The original license on the source VM is unaffected, but the clone requires a fresh reactivation for every license it carried.
What information do I need to provide to Siemens for a license reactivation?
Provide the Certificate of License (CoL) number, the original order number if available, the Software product and TIA Portal version, and the Computer ID of the target machine (found in ALM under License Key → Computer ID, a 20-digit hex string). Have the original CoL PDF or USB license stick available for ownership verification. Open the case in SiePortal or contact your regional Siemens support channel for the fastest response.