This guide builds a standalone Hyper-V host on Windows Server 2025, from bare metal to a running Generation 2 VM. It covers the role install, host defaults, a Switch Embedded Teaming (SET) virtual switch, and a VM with Secure Boot and a virtual TPM. Every step is PowerShell-first, so you can script it for the next host. The GUI path sits alongside for when you want to see what the clicks do.
It also flags the defaults that bite six months later. Those are dynamic VHDX files on thin storage, checkpoints left in place for weeks, Dynamic Memory on workloads that dislike it, and the “Save” stop action that quietly reserves disk space. Fix those on day one and the host stays boring. That’s what you want from a hypervisor.
What Is Hyper-V on Windows Server 2025?
Hyper-V is Microsoft’s Type 1 hypervisor. It ships as a server role in Windows Server 2025. Once you install it, the hypervisor loads under Windows at boot. Your “host” OS then runs in a privileged partition alongside your VMs. Azure runs on the same hypervisor, so the concepts carry over to the cloud.
There’s no extra software cost. You pay for the Windows Server license, and the edition decides how many Windows VMs you’re allowed to run:
| Edition | Suggested MSRP (16-core license) | Windows Server VMs (OSEs) allowed |
|---|---|---|
| Standard | $1,176 | 2 per fully licensed host. Buy another full core license set to add 2 more |
| Datacenter | $6,771 | Unlimited on the licensed host |
Some practical notes on licensing:
- Every physical core must be licensed. The minimum is 8 cores per CPU and 16 cores per server.
- VM rights don’t replace CALs. Both editions still require Windows Server Client Access Licenses (CALs) for the users or devices that access the servers.
- Standard can get expensive past about 10 VMs. At list price, six Standard license sets cost more than one Datacenter license, and six sets give you 12 VMs. Treat that as a rough guide only. Your real break-even depends on your core count, licensing program, and discounts, so price both editions for your own host.
- Linux guests don’t use Windows Server VM rights. Every physical core on the host still needs a Windows Server license, though. Your Linux distribution’s own subscription terms are a separate matter.
Always confirm current terms on the Windows Server pricing page before you buy. Resellers and agreements vary.
In practical terms, 2025 brings much higher Generation 2 VM scale limits. It also adds GPU partitioning (GPU-P) with live migration support. Microsoft publishes figures on the order of 2,048 vCPUs and 240 TB of RAM per Gen 2 VM. Check the current numbers on Microsoft Learn’s Hyper-V overview before you size anything large. For a standalone SMB host, those ceilings won’t matter. Getting the basics right will.
Prerequisites
- Windows Server 2025 Standard or Datacenter installed on physical hardware. Desktop Experience or Server Core both work.
- 64-bit CPU with Second Level Address Translation (SLAT). That means Intel EPT or AMD RVI. Any Intel Xeon or AMD EPYC from the last decade qualifies.
- Hardware virtualization turned on in the BIOS/UEFI: Intel VT-x or AMD-V (called “SVM Mode” on many AMD boards).
- Hardware-enforced Data Execution Prevention (DEP) turned on: Intel XD bit or AMD NX bit.
- Optional: Intel VT-d or AMD IOMMU. Enable it now if you plan to use device passthrough later.
- RAM for the host plus every VM. Keep 4–8 GB for the host itself. ECC RAM is strongly recommended for production.
- A dedicated data volume for VMs, such as
D:. Don’t use the OS drive. An NVMe SSD or a RAID 10 array of enterprise SSDs gives you the most headroom. - At least one NIC. Two identical NICs let you build SET. A dual-port 10GbE card like the Intel X710 is a common choice.
- Out-of-band console access (iDRAC, iLO, IPMI, or a physical keyboard). You’ll need it when you create the external switch.
- Local Administrator rights and an elevated PowerShell 5.1 session.
- A UPS. Hyper-V recovers from a power cut far better when VMs get a clean shutdown signal.
Reference environment
The commands below target this setup:
- Windows Server 2025 Datacenter, build 26100, Desktop Experience
- Single-socket server with 16 cores and 128 GB ECC RAM
- OS on a 480 GB SSD mirror
- VMs on a 3.84 TB NVMe volume mounted as
D: - Two identical 10GbE ports,
NIC1andNIC2, cabled to a switch trunk port carrying VLANs 10 (management) and 20 (servers) - A Windows Server 2025 ISO at
D:\ISO\WS2025.iso
Adjust the names, paths, and VLAN IDs to match your own setup.
Step-by-Step Guide: Hyper-V on Windows Server 2025
Step 1: Verify Hardware and BIOS Prerequisites
Check the CPU and firmware before you install anything. Open PowerShell as Administrator and run:
# Shows only the Hyper-V related properties
Get-ComputerInfo -Property "HyperV*"
On a machine that’s ready for Hyper-V, you should see:
HyperVisorPresent : False
HyperVRequirementDataExecutionPreventionAvailable : True
HyperVRequirementSecondLevelAddressTranslation : True
HyperVRequirementVirtualizationFirmwareEnabled : True
HyperVRequirementVMMonitorModeExtensions : True
How to read the results:
- The four
HyperVRequirement...fields are the actual prerequisites. If all four showTrue, you’re good to go. Exact spacing and formatting can differ slightly between builds. HyperVRequirementVirtualizationFirmwareEnabledshowsFalse. VT-x or AMD-V is turned off in the BIOS. Reboot into setup and enable it. The setting usually lives under Processor Settings or Advanced > CPU Configuration.HyperVisorPresentisn’t a requirement. It only tells you whether a hypervisor is loaded right now. If it’sTrueand the requirement fields are blank, something is already running a hypervisor. That could be Hyper-V, a virtualization-based security feature such as Credential Guard, or the fact that you’re inside a VM. Windows hides the requirement checks in that state, so investigate before you continue.
You can also use systeminfo. On a ready machine, the bottom of its output lists four “Hyper-V Requirements” lines, each ending in Yes. If a hypervisor is already loaded, it prints “A hypervisor has been detected. Features required for Hyper-V will not be displayed.” instead. See Microsoft’s Hyper-V host hardware requirements.
Installing inside a VM for a lab? The outer host must expose virtualization extensions to it. Shut the lab VM down, then run
Set-VMProcessor -VMName "YOUR-LAB-VM" -ExposeVirtualizationExtensions $trueon the outer Hyper-V host.
Step 2: Install the Hyper-V Role
Pick one of the two methods below. They produce the same result.
Option A: PowerShell (recommended)
This single command is the one you’ll reuse on every future host:
# -IncludeManagementTools adds Hyper-V Manager and the Hyper-V PowerShell module
# -Restart reboots automatically when the install finishes (a reboot is required)
Install-WindowsFeature -Name Hyper-V -IncludeManagementTools -Restart
Warning: This command reboots the server without asking. Run it in a maintenance window. If you want to reboot on your own schedule, leave off
-Restart.
If you run it without -Restart, you’ll see this output before the reboot:
Success Restart Needed Exit Code Feature Result
——- ————– ——— ————–
True Yes SuccessRest… {Hyper-V, Hyper-V Module for Windows PowerShell, Hyper-V Manager…}
WARNING: You must restart this server to finish the installation process.
You can also install on a remote Server Core box from your admin workstation. Add -ComputerName "HV01" to the same command.
Option B: Server Manager
- Open Server Manager and click Manage > Add Roles and Features.
- On Installation Type, choose Role-based or feature-based installation.
- On Server Selection, pick the local server.
- On Server Roles, check Hyper-V. When prompted, click Add Features to include the management tools.
- Click through Features.
- On Virtual Switches, leave every adapter unchecked. You’ll build the switch properly in Step 5.
- On Virtual Machine Migration, leave the box unchecked. Migration is out of scope for a standalone host.
- On Default Stores, enter your data volume paths, such as
D:\Hyper-VandD:\Hyper-V\Virtual Hard Disks. - On Confirmation, check Restart the destination server automatically if required, then click Install.
The server restarts to finish the installation. Depending on its current state, you may see more than one restart. Wait for the final one before you move on to verification.
Step 3: Verify the Installation
After the reboot, open an elevated PowerShell window. Confirm the role and tools are in place:
Get-WindowsFeature -Name Hyper-V, Hyper-V-Tools, Hyper-V-PowerShell
Expected output:
Display Name Name Install State
———— —- ————-
[X] Hyper-V Hyper-V Installed
[X] Hyper-V Management Tools Hyper-V-Tools Installed
[X] Hyper-V Module for Windows PowerShell Hyper-V-PowerShell Installed
Next, confirm the hypervisor is actually running. A role can show as installed while the hypervisor itself failed to launch.
# Should return True once the hypervisor is loaded
(Get-ComputerInfo -Property HyperVisorPresent).HyperVisorPresent
# VMMS = Virtual Machine Management Service; should be Running
Get-Service vmms
Now open Hyper-V Manager. You’ll find it under Server Manager > Tools, or you can run virtmgmt.msc. Your host should appear in the left pane.
Step 4: Set Host Defaults Before Your First VM
Hyper-V’s out-of-the-box defaults put VM files on the OS drive:
- VM configuration files go to
C:\ProgramData\Microsoft\Windows\Hyper-V - Virtual disks go to
C:\ProgramData\Microsoft\Windows\Virtual Hard Disks
One growing VHDX can fill your system volume and take the whole host down. Change these defaults now, while there’s nothing to move.
# Create the folders on the dedicated data volume
New-Item -ItemType Directory -Path "D:\Hyper-V\Virtual Hard Disks" -Force
New-Item -ItemType Directory -Path "D:\ISO" -Force
# Point new VMs and VHDXs at D:
# Enhanced Session Mode is off by default on Windows Server; this turns it on
Set-VMHost -VirtualMachinePath "D:\Hyper-V" `
-VirtualHardDiskPath "D:\Hyper-V\Virtual Hard Disks" `
-EnableEnhancedSessionMode $true
Enhanced Session Mode runs the VMConnect console over RDP under the hood. That gives you clipboard sharing, drive redirection, and proper screen resizing in Windows guests. The trade-off is small. The guest must support it, and you’ll get a sign-in dialog when you connect. For admin work, it’s worth turning on.
Non-Uniform Memory Access (NUMA) spanning is a judgment call:
- Leave it enabled (the default) on single-socket hosts, or if you want VMs to start no matter what. A VM can then use memory from any NUMA node.
- Disable it on multi-socket hosts running latency-sensitive VMs such as SQL Server. Size those VMs to fit inside one node. VMs that don’t fit won’t start, and that’s the intent. You trade flexibility for predictable memory latency.
# Only on multi-socket hosts where you've sized VMs to fit a single NUMA node
Set-VMHost -NumaSpanningEnabled $false
Restart-Service vmms # the change takes effect after VMMS restarts
Warning: Restarting the Virtual Machine Management Service disconnects Hyper-V Manager and any other management tools, and it interrupts any management task in progress, such as an export or a checkpoint merge. Running VMs are designed to keep running, but do this in a maintenance window anyway.
Verify the settings:
Get-VMHost | Format-List VirtualMachinePath, VirtualHardDiskPath, NumaSpanningEnabled, EnableEnhancedSessionMode
VirtualMachinePath : D:\Hyper-V
VirtualHardDiskPath : D:\Hyper-V\Virtual Hard Disks
NumaSpanningEnabled : True
EnableEnhancedSessionMode : True
Step 5: Design and Create the Virtual Switch
Example topology: The SET commands below match the reference environment: two identical NICs on switch trunk ports, management tagged on VLAN 10, servers on VLAN 20, and a 10.0.10.0/24 management subnet. Swap in your own NIC names, VLAN IDs, and addresses. If you have one NIC and no VLANs, skip ahead to the single-NIC note at the end of the SET section.
Hyper-V offers three switch types:
| Type | Connects | Typical use |
|---|---|---|
| External | VMs, the host, and the physical network through a physical NIC or SET team | Production VMs that need LAN or internet access |
| Internal | VMs and the host only | Host-to-VM labs, NAT setups |
| Private | VMs to each other only | Isolated test networks, such as a lab AD domain |
SET vs legacy LBFO teaming
This part is short. Use SET. On Windows Server 2025, binding a Hyper-V switch to an LBFO team (the old “NIC Teaming” in Server Manager) is blocked. The old -AllowNetLbfoTeams workaround is obsolete and ignored on 2025, so SET is the only supported way to team NICs under a Hyper-V switch.
SET has its own trade-offs:
- It’s switch-independent only. There’s no LACP. Configure your physical switch ports as plain trunks with no port-channel.
- The team members should be identical. Same make, model, driver, and firmware.
- You can’t create it in Hyper-V Manager. It’s PowerShell only.
Warning: Creating an External switch rebinds the physical NICs. Your RDP session will likely drop, and a wrong IP setting can leave you locked out. Run this step from iDRAC, iLO, IPMI, or the local console.
Before you touch anything, do a short preflight:
- Record the current network settings. Run
Get-NetIPConfiguration -Detailed | Out-File C:\net-before.txtand keep a copy off the host too. It captures the IP address, gateway, and DNS servers. Note whether the address is DHCP or static. You’ll need these to rebuild or roll back. - Confirm the switch ports with your network team. The example below assumes trunk ports where management traffic is tagged on VLAN 10. If management arrives untagged (on the native VLAN), skip the
Set-VMNetworkAdapterVlanline for the management vNIC. A tag the switch doesn’t expect will cut the host off. - Plan the address move. The physical NIC’s IP address doesn’t follow it onto the switch. The host gets a new
vEthernetadapter, and you’ll assign the address there. If the old static address is still configured anywhere, remove it first so it doesn’t conflict. - Know your rollback. From the console,
Remove-VMSwitch -Name "SETswitch"returns the NICs to normal. You can then re-apply the settings you recorded.
Then find your adapter names:
Get-NetAdapter | Sort-Object Name | Format-Table Name, InterfaceDescription, LinkSpeed, Status
Then build the SET switch and a dedicated management virtual NIC (vNIC):
# Two physical NICs = SET. -EnableEmbeddedTeaming is implied, but stating it makes the intent obvious.
# -AllowManagementOS $false = we create a named management vNIC ourselves below
New-VMSwitch -Name "SETswitch" -NetAdapterName "NIC1","NIC2" `
-EnableEmbeddedTeaming $true -AllowManagementOS $false
# HyperVPort is Microsoft's recommended load-balancing mode for SET
Set-VMSwitchTeam -Name "SETswitch" -LoadBalancingAlgorithm HyperVPort
# Management vNIC for the host itself, tagged on VLAN 10
Add-VMNetworkAdapter -ManagementOS -Name "Management" -SwitchName "SETswitch"
Set-VMNetworkAdapterVlan -ManagementOS -VMNetworkAdapterName "Management" -Access -VlanId 10
# Give the host its IP on the new vNIC (adjust to your subnet)
New-NetIPAddress -InterfaceAlias "vEthernet (Management)" -IPAddress 10.0.10.21 `
-PrefixLength 24 -DefaultGateway 10.0.10.1
Set-DnsClientServerAddress -InterfaceAlias "vEthernet (Management)" -ServerAddresses 10.0.10.5,10.0.10.6
Verify the team and the VLAN tag:
Get-VMSwitchTeam -Name "SETswitch" | Format-List Name, NetAdapterInterfaceDescription, LoadBalancingAlgorithm
Get-VMNetworkAdapterVlan -ManagementOS
VMName VMNetworkAdapterName Mode VlanList
—— ——————– —- ——–
Management Access 10
Test connectivity with Test-NetConnection 10.0.10.1. Once the host is reachable again, you can go back to RDP.
Only have one NIC? Use the same command with a single adapter and add -AllowManagementOS $true. Expect a short network outage, because host management moves onto the new switch and its vEthernet adapter may come up on DHCP or with no address. Do it from the console and re-apply your recorded IP settings. You lose redundancy, but everything else still applies.
Create any Internal or Private switches you need at the same time:
New-VMSwitch -Name "LabInternal" -SwitchType Internal # host + VMs, no physical NIC
New-VMSwitch -Name "LabPrivate" -SwitchType Private # VM-to-VM only
GUI path: In Hyper-V Manager, click Virtual Switch Manager in the Actions pane. Choose External, Internal, or Private, then click Create Virtual Switch. For External switches, the Allow management operating system to share this network adapter checkbox controls whether the host keeps a vNIC on that switch. This dialog can’t build a SET team.
Step 6: Create a Generation 2 VM with the Wizard
Use Generation 2 unless a guest OS explicitly requires Gen 1. Gen 2 boots with UEFI, supports Secure Boot and vTPM, and boots from SCSI disks. You can’t change a VM’s generation after you create it.
- In Hyper-V Manager, click New > Virtual Machine in the Actions pane.
- On Specify Name and Location, enter
SRV-APP01. Check Store the virtual machine in a different location so the VM gets its own folder underD:\Hyper-V. - On Specify Generation, select Generation 2.
- On Assign Memory, enter
4096MB. Uncheck Use Dynamic Memory for this virtual machine for now. The trade-offs are covered below. - On Configure Networking, pick
SETswitch. - On Connect Virtual Hard Disk, the wizard only creates dynamic disks. For a production VM, choose Attach a virtual hard disk later and add a fixed disk in Step 9.
- On Installation Options, choose Install an operating system from a bootable image file and browse to
D:\ISO\WS2025.iso. - Click Finish.
Next, right-click the VM and choose Settings > Security:
- Enable Secure Boot is on by default with the Microsoft Windows template. For Linux guests, switch the template to Microsoft UEFI Certificate Authority.
- Check Enable Trusted Platform Module. Windows 11 guests require it. Any guest that will use BitLocker should have it.
The wizard also leaves the VM with 1 vCPU. Change that under Settings > Processor.
Step 7: Create the Same VM with PowerShell
This is the repeatable version of Step 6, with a fixed disk and a vTPM. Run it while the VM is off.
$vmName = "SRV-APP01"
$vhd = "D:\Hyper-V\Virtual Hard Disks\$vmName-OS.vhdx"
# Fixed VHDX: all 80 GB is allocated now (takes a moment on large disks)
New-VHD -Path $vhd -SizeBytes 80GB -Fixed
# -Path creates D:\Hyper-V\SRV-APP01\ for the config files
New-VM -Name $vmName -Generation 2 -MemoryStartupBytes 4GB `
-VHDPath $vhd -SwitchName "SETswitch" -Path "D:\Hyper-V"
Set-VMProcessor -VMName $vmName -Count 2
Set-VMMemory -VMName $vmName -DynamicMemoryEnabled $false -StartupBytes 4GB
# Put the VM on VLAN 20 (the switch port must be a trunk carrying VLAN 20)
Set-VMNetworkAdapterVlan -VMName $vmName -Access -VlanId 20
# Secure Boot with the Windows template. Linux guests: use MicrosoftUEFICertificateAuthority instead
Set-VMFirmware -VMName $vmName -EnableSecureBoot On -SecureBootTemplate MicrosoftWindows
# vTPM needs a key protector first; a local key protector is fine on a standalone host.
# Back up its guardian certificates right away (see Step 12) before you store BitLocker keys in the guest.
Set-VMKeyProtector -VMName $vmName -NewLocalKeyProtector
Enable-VMTPM -VMName $vmName
# Attach the ISO and boot from it first
Add-VMDvdDrive -VMName $vmName -Path "D:\ISO\WS2025.iso"
Set-VMFirmware -VMName $vmName -FirstBootDevice (Get-VMDvdDrive -VMName $vmName)
# Explicitly production checkpoints only, no automatic checkpoints
Set-VM -Name $vmName -CheckpointType ProductionOnly -AutomaticCheckpointsEnabled $false
Verify the security settings:
Get-VMFirmware -VMName SRV-APP01 | Format-List SecureBoot, SecureBootTemplate
Get-VMSecurity -VMName SRV-APP01 | Format-List TpmEnabled
SecureBoot : On
SecureBootTemplate : MicrosoftWindowsTpmEnabled : True
For what Secure Boot templates and the vTPM key protector do, see Microsoft’s Generation 2 VM security settings. Step 12 covers backing up the guardian certificates.
Dynamic Memory: when to use it
Dynamic Memory lets a VM start small and grow toward a maximum. It works well for light or bursty workloads such as file servers, jump boxes, and small web servers. It works poorly for anything that manages its own memory cache. SQL Server, Exchange, Java apps with fixed heaps, and some Linux database workloads will see memory pulled out from under them. Then they perform badly or crash.
A sensible default: static memory for anything important, Dynamic Memory for filler VMs.
# Example: Dynamic Memory for a light utility VM (run while the VM is off)
Set-VMMemory -VMName "SRV-UTIL01" -DynamicMemoryEnabled $true `
-MinimumBytes 1GB -StartupBytes 2GB -MaximumBytes 6GB
Step 8: Start the VM and Install the Guest OS
Start-VM -Name SRV-APP01
vmconnect.exe localhost SRV-APP01 # opens the console window
The first boot shows “Press any key to boot from CD or DVD.” You only get a few seconds. Miss it and the VM falls through to a PXE boot attempt. Click Action > Reset in VMConnect and try again.
After the OS installs, remove the ISO and confirm the VM is healthy:
Get-VMDvdDrive -VMName SRV-APP01 | Set-VMDvdDrive -Path $null
Get-VM -Name SRV-APP01 | Format-Table Name, State, CPUUsage, MemoryAssigned, Uptime, Status
Name State CPUUsage MemoryAssigned Uptime Status
—- —– ——– ————– —— ——
SRV-APP01 Running 2 4294967296 00:14:32.0410000 Operating normally
Step 9: Choose and Manage Virtual Disk Types
Fixed vs dynamic VHDX
| Fixed | Dynamic | |
|---|---|---|
| Space allocated | All of it, at creation | Only as the guest writes data |
| Performance | Consistent | Very close on SSD/NVMe, with slight overhead as the file grows |
| Main risk | Wastes space you never use | Overcommits the host volume. If D: fills, every VM on it pauses |
| Use for | Production, databases, anything you’d page someone about | Labs, templates, VMs with predictable small growth |
The performance gap on modern flash storage is small. The better argument for fixed disks is capacity honesty. With dynamic disks, the sum of all your VHDX maximum sizes can quietly exceed the size of the volume. Put dynamic disks on thin-provisioned SAN storage and you’re overcommitting twice.
To add a data disk and grow it later, use the commands below. On Gen 2 VMs, disks attach to SCSI, so you can expand them while the VM is running.
New-VHD -Path "D:\Hyper-V\Virtual Hard Disks\SRV-APP01-Data.vhdx" -SizeBytes 200GB -Fixed
Add-VMHardDiskDrive -VMName SRV-APP01 -Path "D:\Hyper-V\Virtual Hard Disks\SRV-APP01-Data.vhdx"
# Later: grow to 300 GB while the VM is running
Resize-VHD -Path "D:\Hyper-V\Virtual Hard Disks\SRV-APP01-Data.vhdx" -SizeBytes 300GB
Resizing the VHDX doesn’t grow the partition inside the guest. Do that next, inside the guest (Windows shown here; use growpart and resize2fs on Linux):
# Run INSIDE the guest; replace E with the data volume's drive letter
$max = (Get-PartitionSupportedSize -DriveLetter E).SizeMax
Resize-Partition -DriveLetter E -Size $max
Differencing disks are child disks that record only the changes made on top of a read-only parent. They’re great for labs. One sysprepped 20 GB parent can back ten test VMs, each using only a few GB of its own. They’re a poor fit for production. Every child depends on the parent. If the parent is modified or lost, every child breaks.
# Make the parent read-only first so nobody boots it by accident
Set-ItemProperty -Path "D:\Hyper-V\Templates\WS2025-Base.vhdx" -Name IsReadOnly -Value $true
New-VHD -Path "D:\Hyper-V\Virtual Hard Disks\LAB-DC01.vhdx" `
-ParentPath "D:\Hyper-V\Templates\WS2025-Base.vhdx" -Differencing
Pass-through disks give a VM a raw physical disk. They’re mostly a legacy option. You lose checkpoints and easy portability for a performance gain that VHDX has largely closed. I’d skip them unless a vendor requires them.
Step 10: Configure Checkpoints (and Know Their Limits)
Hyper-V has two checkpoint types:
- Production checkpoints tell the guest to flush its data first, using VSS on Windows or a filesystem freeze on Linux. The result is application-consistent. When you apply one, the VM comes back powered off, as if it just recovered from a clean backup. This is the safe choice for domain controllers, SQL Server, and Exchange.
- Standard checkpoints capture memory and device state, like an old-style snapshot. When you apply one, the VM resumes exactly where it was, open apps included. That’s handy for labs. It’s risky for anything that replicates or keeps transaction logs, because the app never knew time jumped backward.
The Production setting quietly falls back to a standard checkpoint if the production checkpoint fails. That’s why Step 7 used ProductionOnly, which fails loudly instead.
A typical patch-test workflow looks like this:
Checkpoint-VM -Name SRV-APP01 -SnapshotName "pre-patch-2026-09"
Get-VMCheckpoint -VMName SRV-APP01 | Format-Table Name, CheckpointType, CreationTime
# Patch went badly? Roll back:
Restore-VMCheckpoint -VMName SRV-APP01 -Name "pre-patch-2026-09" -Confirm:$false
# Patch went fine? Remove the checkpoint so its .avhdx merges back into the parent disk
Remove-VMCheckpoint -VMName SRV-APP01 -Name "pre-patch-2026-09"
Warning:
Restore-VMCheckpointthrows away every change made since the checkpoint was taken. Removing a checkpoint triggers a disk merge. On a big, old checkpoint, that merge can run for a long time and push disk I/O hard.
Treat checkpoints as a short-term undo button, and keep real backups elsewhere. Checkpoints live on the same volume as the VM. They depend on the parent disk, so if the parent is corrupted, the checkpoint dies with it. Each one keeps a growing .avhdx file until you remove it. Keep them for hours or days, not weeks. For real protection, use a backup that writes to a separate device. Our Windows Server Backup setup and restore guide covers that.
In the GUI, checkpoint settings live under Settings > Management > Checkpoints. The Checkpoints pane appears above the VM preview once a checkpoint exists. Right-click a checkpoint to Apply or Delete Checkpoint.
Step 11: Set Up Day-2 Operations
Integration Services are built into modern Windows and Linux guests. They update through the guest’s own update channel. Guest Service Interface is off by default. Turn it on if you want to push files from the host with Copy-VMFile.
Get-VMIntegrationService -VMName SRV-APP01 | Format-Table Name, Enabled, PrimaryStatusDescription
Enable-VMIntegrationService -VMName SRV-APP01 -Name "Guest Service Interface"
Power control:
Start-VM -Name SRV-APP01
Stop-VM -Name SRV-APP01 # clean guest shutdown via integration services
Stop-VM -Name SRV-APP01 -TurnOff # power pull; only for hung guests
Save-VM -Name SRV-APP01 # hibernate-style: RAM contents written to disk
Suspend-VM -Name SRV-APP01 # pause in RAM; Resume-VM to continue
Automatic actions decide what happens to each VM when the host boots or shuts down. The default stop action is Save. With Save, Hyper-V reserves disk space equal to each VM’s RAM for the saved-state file. On a host with 100 GB of VM RAM, that’s 100 GB of D: you can’t use. Switching to ShutDown frees that space. Stagger start delays so boot storms don’t flatten your storage.
Set-VM -Name SRV-APP01 -AutomaticStartAction Start -AutomaticStartDelay 60 `
-AutomaticStopAction ShutDown
Pair this with UPS management software that shuts the host down cleanly on low battery. The ShutDown action then gives every VM a clean stop.
Monitoring one-liners:
# Anything not running cleanly
Get-VM | Where-Object Status -ne "Operating normally" | Format-Table Name, State, Status
# Actual file size vs maximum size of every attached disk (spot dynamic-disk growth)
Get-VM | Get-VMHardDiskDrive | Get-VHD |
Format-Table Path, VhdType, @{n="FileGB";e={[math]::Round($_.FileSize/1GB,1)}}, @{n="MaxGB";e={$_.Size/1GB}}
# Forgotten checkpoints older than 3 days
Get-VM | Get-VMCheckpoint | Where-Object CreationTime -lt (Get-Date).AddDays(-3)
Step 12: Move a VM with Export-VM and Import-VM
Export works on a running VM. It writes the VM’s configuration, disks, and any checkpoints to a folder you can copy to another host.
Export-VM -Name SRV-APP01 -Path "E:\Export"
VMs with a vTPM need one extra step. This applies to the standalone setup in this guide, where the vTPM uses a local key protector. It doesn’t cover Host Guardian Service (HGS) guarded fabrics, which have their own process. A local key protector ties the vTPM to “untrusted guardian” certificates on the source host. Without those certificates, the VM won’t start on the new host.
Warning: Back these certificates up, with their private keys, somewhere off the host as soon as you enable a vTPM. Don’t wait until a migration. If the host dies and nobody exported them, the vTPM contents can’t be recovered. Keep BitLocker recovery keys for every guest that uses one, and test a restore on a spare host before you rely on this process.
Export the certificates alongside the VM:
$pfxPass = Read-Host -Prompt "Password to protect the exported certificates" -AsSecureString
Get-ChildItem "Cert:\LocalMachine\Shielded VM Local Certificates" | ForEach-Object {
Export-PfxCertificate -Cert $_ -FilePath "E:\Export\guardian-$($_.Thumbprint).pfx" -Password $pfxPass
}
On the destination host, import the certificates first:
$pfxPass = Read-Host -Prompt "Certificate password" -AsSecureString
Get-ChildItem "E:\Export\guardian-*.pfx" | ForEach-Object {
Import-PfxCertificate -FilePath $_.FullName -Password $pfxPass `
-CertStoreLocation "Cert:\LocalMachine\Shielded VM Local Certificates"
}
Importing the certificates is the documented local-protector approach, but it may not cover every case. If the VM still won’t start, Microsoft’s guidance is to update the VM’s key protector to authorize the new host. See Generation 2 VM security settings.
Then check for compatibility problems and import the VM:
$vmcx = Get-ChildItem "E:\Export\SRV-APP01\Virtual Machines\*.vmcx" | Select-Object -First 1
# Report problems (missing switch, too much RAM, etc.) before committing
$report = Compare-VM -Path $vmcx.FullName -Copy -GenerateNewId
$report.Incompatibilities | Format-Table Message
# -Copy copies files to the new host's paths; -GenerateNewId avoids ID clashes if the original still exists
Import-VM -Path $vmcx.FullName -Copy -GenerateNewId `
-VirtualMachinePath "D:\Hyper-V" -VhdDestinationPath "D:\Hyper-V\Virtual Hard Disks"
The most common incompatibility is a missing switch, because the destination switch has a different name. Name your switches the same on every host and this problem goes away. You also can’t import a VM into an older Hyper-V version than the one it came from.
Configuration Reference
| Setting | Default | Recommended for production | Command |
|---|---|---|---|
| VM/VHD paths | C:\ProgramData\... | Dedicated data volume | Set-VMHost -VirtualMachinePath |
| Enhanced Session Mode | Off on Server | On | Set-VMHost -EnableEnhancedSessionMode $true |
| NUMA spanning | On | On. Off only for tuned multi-socket hosts | Set-VMHost -NumaSpanningEnabled |
| Wizard VHDX type | Dynamic | Fixed | New-VHD -Fixed |
| Checkpoint type | Production (falls back to standard) | ProductionOnly | Set-VM -CheckpointType ProductionOnly |
| Dynamic Memory | Off in PowerShell; wizard offers it | Off for databases and caching apps | Set-VMMemory -DynamicMemoryEnabled |
| Automatic stop action | Save | ShutDown | Set-VM -AutomaticStopAction ShutDown |
| Teaming | None | SET with HyperVPort | New-VMSwitch -EnableEmbeddedTeaming $true |
Tips and Troubleshooting
Start every investigation with the event logs. In Event Viewer, go to Applications and Services Logs > Microsoft > Windows:
- Hyper-V-VMMS > Admin: management service errors such as config problems, permissions, and imports.
- Hyper-V-Worker > Admin: per-VM runtime errors such as start failures, firmware, and memory.
- Hyper-V-Hypervisor > Admin: hypervisor launch problems.
Get-WinEvent -LogName "Microsoft-Windows-Hyper-V-VMMS-Admin" -MaxEvents 20 | Format-Table TimeCreated, Id, LevelDisplayName, Message -Wrap
Get-WinEvent -LogName "Microsoft-Windows-Hyper-V-Worker-Admin" -MaxEvents 20 | Format-Table TimeCreated, Id, LevelDisplayName, Message -Wrap
“The virtual machine could not be started because the hypervisor is not running”
Why it happens: The role is installed, but the hypervisor didn’t load at boot. A BIOS update that reset VT-x/AMD-V is the most common cause. A boot configuration change is the next most common.
Fix: Check the boot configuration first:
bcdedit /enum "{current}"
If hypervisorlaunchtype shows Off or is missing, set it back and reboot:
bcdedit /set hypervisorlaunchtype auto
Restart-Computer
If it already shows Auto, go back into the BIOS and re-enable virtualization and DEP. Then re-run Step 1.
RDP to the host dropped when creating the External switch
Why it happens: Building the switch rebinds the physical NIC. The host’s IP moves to a new vEthernet adapter, which starts with DHCP or no address at all.
Fix: Connect through iDRAC, iLO, IPMI, or the local console. Run Get-NetIPConfiguration to find the new vEthernet (...) adapter. Assign its IP and VLAN as shown in Step 5. Next time, build the switch from the out-of-band console in the first place.
Linux Gen 2 VM fails with “The image’s hash and certificate are not allowed (DB)”
Why it happens: The VM is using the Microsoft Windows Secure Boot template. Linux boot loaders are signed by the Microsoft UEFI CA instead.
Fix: With the VM off, run:
Set-VMFirmware -VMName "YOUR-LINUX-VM" -SecureBootTemplate MicrosoftUEFICertificateAuthority
If the distro doesn’t ship a signed shim, set -EnableSecureBoot Off instead.
VM won’t start after a host cumulative update, or is stuck in “Saved”
Why it happens: The saved state was created before the update and no longer matches the host. Less often, the update changed the hypervisor launch settings.
Fix: First confirm hypervisorlaunchtype is Auto, as described above. Then check the Worker log for the specific error and find stuck VMs:
Get-VM | Where-Object State -eq "Saved"
Remove-VMSavedState -VMName "YOUR-VM" # discards saved RAM contents; the guest cold-boots
Warning:
Remove-VMSavedStateis the same as pulling the power on the guest at the moment it was saved. Any unsaved work in the guest is lost.
Before you patch, check the Windows Server 2025 release health page for known Hyper-V issues.
Imported vTPM VM fails: “The key protector could not be unwrapped”
Why it happens: The guardian certificates from the source host weren’t imported on the destination host.
Fix: Import the exported .pfx files into Cert:\LocalMachine\Shielded VM Local Certificates as shown in Step 12, then start the VM again. If the source host is gone and nobody exported the certificates, the vTPM contents can’t be recovered. Guests using BitLocker will then need their recovery key.
“Account does not have permission to open attachment” after copying a VHDX
Why it happens: Each VM runs under its own virtual account. A VHDX you copied in by hand doesn’t grant that account access.
Fix: Grant the VM’s account access to the file:
$id = (Get-VM -Name "YOUR-VM").Id
icacls "D:\Hyper-V\Virtual Hard Disks\YOUR-DISK.vhdx" /grant "NT VIRTUAL MACHINE\$($id):(F)"
Host volume suddenly full, VMs paused
Why it happens: Dynamic disks grew, forgotten checkpoints kept growing their .avhdx files, or the Save stop action reserved RAM-sized files.
Fix:
- Free space immediately by removing old checkpoints with
Remove-VMCheckpoint. - Resume the paused VMs.
- Audit disk sizes with the monitoring one-liner from Step 11.
- Switch the automatic stop action to
ShutDown. - To reclaim space in a dynamic VHDX, shut the VM down and run
Optimize-VHD -Path "YOUR.vhdx" -Mode Full.
Next Steps: Clustering, Live Migration, and GPUs
This guide stops at a single host on purpose. If you outgrow one box, the next step is Windows Server Failover Clustering with shared storage and live migration. Read the Microsoft Learn notes on live migration and GPU-P in Windows Server 2025 before you design that setup. Adding a GPU for AI inference or VDI? Our GPU passthrough (GPU-P/DDA) on Windows Server 2025 guide picks up from here.
Wrapping Up
You now have a Hyper-V host with sane storage paths, a SET switch with a tagged management vNIC, and a Gen 2 VM with Secure Boot and a vTPM. The whole build is scripted, so the next host is a repeatable job. Just adapt the NIC names, IPs, VLANs, and paths to each host. Hyper-V’s biggest weakness is its defaults, which favor convenience over production. Fixing them up front takes about 20 minutes. That’s cheaper than a 2 a.m. page because a dynamic disk filled D:.
| Step | Action | Applies To |
|---|---|---|
| 1–3 | Verify firmware, install role, confirm hypervisor running | Host |
| 4 | Set VM/VHD paths, Enhanced Session Mode, NUMA | Host |
| 5 | SET switch, management vNIC, VLANs | Host networking |
| 6–8 | Gen 2 VM with Secure Boot and vTPM | Each VM |
| 9 | Fixed VHDX, resize, differencing for labs | VM storage |
| 10 | ProductionOnly checkpoints, remove promptly | Each VM |
| 11–12 | Stop actions, monitoring, Export/Import with guardian certificates | Day-2 ops |