Windows 11 23H2 (now with december CU). 24H2 still not made available.
The VBS started up again after monthly CU.
As mentioned bafore, never had this issure on Intel laptops (done it on 10+ Lenovo laptops), but on this AMD Ryzen I am stumped by VBS.
Original Message:
Sent: Dec 12, 2024 09:01 AM
From: Mladen Zecevic
Subject: AMD + Nested virtualization
Hello,
Which version of Windows do you have?
I am on 23H2 and did not have to do any changes in BIOS nor did the VBS come
back after installing monthly CU's
Br,
Mladen
Original Message:
Sent: 12/11/2024 9:58:00 AM
From: leifkh
Subject: RE: AMD + Nested virtualization
Not too persistant.. Had to reapply after december windows patch...
Original Message:
Sent: Dec 10, 2024 07:56 AM
From: leifkh
Subject: AMD + Nested virtualization
As you might have guessed 'Virtual Based Security' was running.
Found a reference in this article https://learn.microsoft.com/en-us/answers/questions/2118859/unable-to-disable-virtual-based-security-in-window
After running the dgreadiness with -disable flag, rebooting and verifying disabling Virtual based security is 'Enabled, but not running'.
I am able to use nested virtualization., and it seems to be persistant between reboots.
Original Message:
Sent: Dec 07, 2024 05:46 PM
From: Mladen Zecevic
Subject: AMD + Nested virtualization
And what is the status of Virtualization-based security
(start>run>"msinfo32")?
It should be "Not enabled", otherwise nested virtualization will not work.
Original Message:
Sent: 12/5/2024 9:03:00 AM
From: leifkh
Subject: RE: AMD + Nested virtualization
Hi,
Can confirm core isolation is disabled
Virtual Machine Platform is disabled
Registry keys modified
C:\Windows\System32>REG QUERY HKLM\system\currentcontrolset\control\deviceguard\ -v EnableVirtualizationBasedSecurity
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\deviceguard
EnableVirtualizationBasedSecurity REG_DWORD 0x0
C:\Windows\System32>REG QUERY HKLM\system\currentcontrolset\control\deviceguard\ -v DisableVirtualizationBasedSecurity
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\deviceguard
DisableVirtualizationBasedSecurity REG_DWORD 0x0
bcdedit command has been executed
C:\Windows\System32>bcdedit /set hypervisorlaunchtype off
The operation completed successfully.
C:\Windows\System32>
Machine rebooted, but the issue persists.
Original Message:
Sent: Nov 19, 2024 04:01 AM
From: Mladen Zecevic
Subject: AMD + Nested virtualization
Hi,
have you done all these changes:
- turn off memory integrity (core isolation in windows settings)
- disable Virtual Machine Platform (in windows features)
- add registry entry (location: HKLM\system\currentcontrolset\control\deviceguard\, new DWORD-32 "DisableVirtualizationBasedSecurity" with a value of 0)
- In administator CMD window run "bcdedit /set hypervisorlaunchtype off"
check by running msinfo32 if VBS is off.
Hope that helps
Original Message:
Sent: Nov 18, 2024 05:58 AM
From: leifkh
Subject: AMD + Nested virtualization
Hi, still not found a solution.
Original Message:
Sent: Nov 14, 2024 07:17 PM
From: kasper
Subject: AMD + Nested virtualization
Having same issue. Were you able to disable VBS?
Original Message:
Sent: Oct 23, 2024 03:40 AM
From: leifkh
Subject: AMD + Nested virtualization
Hi, have issues enabling nested virtualization on a new AMD laptop recentrly bought.
The problematic laptop is LENOVO P16V G1 AMD Ryzen™ 9 PRO (7940HS)
Tested with Windows 11 pro all updates and latest updates using Lenovo Vantage
Installed Wmware Workstation Pro 17.6.1
Disabled Core isolation, after that ran the following commands in a CMD with admin rights
powershell.exe Disable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V-Hypervisorpowershell.exe Disable-WindowsOptionalFeature -Online -FeatureName "Microsoft-Hyper-V"bcdedit /set hypervisorlaunchtype offdism /online /disable-feature /featurename:Microsoft-hyper-v-allbcdedit /set vsmlaunchtype offpowercfg /powerthrottling disable /path "C:\Program Files (x86)\VMware\VMware Workstation\x64\vmware-vmx.exe"
Usually the procedure does the trick and nested virtualization is available, but not this time.
Tried installing Windows10 and here everything works as expected, but must be missing something on the Windows11 setup.
Any tips?