KMS servers hand out licenses for Windows Vista and Server 2008 on corporate networks.
One aspect that was not addressed very well, in my opinion, was the situation when an "outsider" plugs into your network. If their copy of Vista needs to be re-authorized, they could potentially pull down your enterprise's license key. Does it happen very often? I doubt it. Is it possible? Very much so.
A clever solution I overheard this week from someone at Microsoft was the following:
Problem: Anyone that plugs into a KMS-enabled network can grab an enterprise license for their Vista/Windows 2008 computer by default with KMS services.
Solution: IPSec-ize the KMS server ports – only domain joined computers can “see” the KMS server due to IPsec rules. "Outsiders" can't see the KMS server.
This could also be a handy thing for NAP to take care of, now that I think about it.