Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security & DevOps Insights

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form
Home » Windows » Enable vTPM and BitLocker HyperV VM: Fix the device that cannot use a TPM module
  • Windows Productivity Tips
    Windows Productivity Tips To Get The Most Out Of Your PC Windows
  • banner 1
    How to Create Shared Folder in Windows Sandbox Virtualization
  • Proxmox 9
    How to update Proxmox VE 9.0 now Supported by Veeam Virtualization
  • HAProxy
    Deploying a load balancer from scratch and adding backend servers Linux
  • vcx
    Fix Error code 0x4 Session disconnected: Your session ended because of an error, if this keeps happening, contact your system administrator Windows
  • sonarcloud
    How to Integrate SonarCloud with Azure DevOps Pipeline AWS/Azure/OpenShift
  • diag7
    How to run Windows Memory Diagnostics Tool on Windows Windows
  • Simple Notification Service AWS SNS
    Create Simple Notification Service (SNS) Notification on AWS AWS/Azure/OpenShift

Enable vTPM and BitLocker HyperV VM: Fix the device that cannot use a TPM module

Posted on 17/11/202218/09/2024 Temitope Odemo By Temitope Odemo No Comments on Enable vTPM and BitLocker HyperV VM: Fix the device that cannot use a TPM module
vtpm-1

Microsoft added more security features to Windows Server 2016 and one of them is the vTPM. You can now use a vTPM right inside the VM without using a physical TPM processor. A virtual Trusted Platform Module (vTPM) is a software-based representation of a physical Trusted Platform Module that can generate keys. In this article, we shall discuss “how to enable vTPM in Windows Server 2016 Hyper-v: Fix the device that cannot use a TPM module”. Here is how to Setup iSCSI Target and Storage LUN on Synology DS923+ for VBR.

When a vTPM is added to a virtual machine, the guest operating system on the VM creates and stores keys that are private to it. When the vTPM is enabled and the guest operating system is compromised the vTPM will greatly reduce the risk.

Here is a YouTube video discussing the topic “Steps to enable vTPM in Windows Server 2016 HYPER V”.

The keys generated will be used by the operating system for encryption or signing purposes. Both the vTPM and Bitlocker can add a layer of protection to Windows Server 2016. In this article, I will be showing you how to Enable vTPM and BitLocker on Windows Server on HyperV.

The same steps are applicable to all versions of Windows Server. Once this is done you can store your VM in any location without being afraid your VM files will be stolen or compromised.

Please see Enable HyperV on Windows: How to install Windows 11 on HyperV, and how to fix “There was an error opening the Trusted Platform Module snap-in: You do not have permission to open the Trusted Platform Module Console“.

Reason for the error “The Device can use a Trusted Platform Module”.

If your VM does not have vTPM enabled you will not be able to use BitLocker except you do some strenuous work which you can avoid by just enabling it on your VM.

Below is the image showing what will be prompted when it is not enabled.
tpm11

Please see Hyper-V Server Core Mode: How to install free Hyper-V Server on a VMware Workstation, and how to Disable BitLocker on Windows 10.

Enable vTPM and BitLocker in Windows server

Follow these steps on how to enable vTPM in Windows Server 2016 HYPER-V

  1. Open the Hyper-V
  2. Select and right-click the VM you want to encrypt and click Settings
tpm

3. On the Settings page click on Security TPM enabled and on the Right-hand section check the Enable Trusted Platform Module box. Click Ok. This will ensure the vTPM is enabled on the device.

tpm2

4. Start the Virtual Machine and log in.

tpm3

Read this if you want to know How to enable or disable BitLocker Drive Encryption on Windows 10 and Virtual Machines, and How to correctly disable Microsoft BitLocker Administration and Monitoring encrypted devices.

Launch Device Manager

5. Go into the Device Manager and Expand Security Devices you will see the Trusted Platform Module 2.0 listed.

tpm4

Enable BitLocker: Install BitLocker Role on Hyper VM

6. It’s now time to encrypt the Virtual Machine. Add the BitLocker Drive Encryption feature and restart the VM.

tpm5

Also, see how to install and Configure Hyper-V on Windows Server on Windows Server 2019, and 2022 via the Server Manager, PowerShell or DISM.

Enable BitLocker on Windows Server

7. Now search for BitLocker and open it. Click Turn On BitLocker.

tpm6

8. Save the key to a file or print and change the location of the file from your system. Keep in a safe place.

TPM7

9. Select how you want to encrypt your disk. Click Next

tpm8

10. You can start the encryption and be sure that nobody can copy your VM files to another HYPER-V to use it. This is How and where to find your BitLocker recovery key in Windows.

tpm10

I hope you found this blog post on how to enable vTPM in Windows Server 2016 Hyper-v: Fix the device that cannot use a TPM module interesting and helpful. In case you have any questions do not hesitate to ask in the comment section.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Telegram (Opens in new window) Telegram
  • Click to share on WhatsApp (Opens in new window) WhatsApp
  • Click to share on Pocket (Opens in new window) Pocket
  • Click to share on Mastodon (Opens in new window) Mastodon
  • Click to share on Bluesky (Opens in new window) Bluesky
  • Click to share on Threads (Opens in new window) Threads
  • Click to share on Nextdoor (Opens in new window) Nextdoor
Virtualization, Windows, Windows Server Tags:Bitlocker, BitLocker Drive Encryption Administration Utilities, BitLocker Recovery Keys, BitLocker Status, Hyper-V, hyperV, Hypervisor, PowerShell Cmdlet, Secure Boot, TPM, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: How to install Groovy on Linux and Windows
Next Post: How to Fix Boot Failed UEFI SCSI Device on HyperV

Related Posts

  • Run Linux on Windows Server
    How to install Windows Subsystem for Linux on Windows Server Linux
  • Screenshot 2021 02 09 at 16.10.30
    Download and install Fujitsu DeskUpdate & DeskUpdate Manager Windows Server
  • vmwareconverter
    vCenter Converter removed from available downloads on VMware – Use Veeam instead Virtualization
  • Add or remove features   fix dotnet framework issues
    Fix the request to add or remove features on the specified server failed Windows
  • How to Fix Application Error (0xc0000135) in Windows
    Fix the application was unable to start correctly (0xc0000135) error Windows
  • tpmbiosactivation
    Enable TPM: Determine if TPM is present Windows

More Related Articles

Run Linux on Windows Server How to install Windows Subsystem for Linux on Windows Server Linux
Screenshot 2021 02 09 at 16.10.30 Download and install Fujitsu DeskUpdate & DeskUpdate Manager Windows Server
vmwareconverter vCenter Converter removed from available downloads on VMware – Use Veeam instead Virtualization
Add or remove features   fix dotnet framework issues Fix the request to add or remove features on the specified server failed Windows
How to Fix Application Error (0xc0000135) in Windows Fix the application was unable to start correctly (0xc0000135) error Windows
tpmbiosactivation Enable TPM: Determine if TPM is present Windows

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

sysadmin top30a

  • Windows Productivity Tips
    Windows Productivity Tips To Get The Most Out Of Your PC Windows
  • banner 1
    How to Create Shared Folder in Windows Sandbox Virtualization
  • Proxmox 9
    How to update Proxmox VE 9.0 now Supported by Veeam Virtualization
  • HAProxy
    Deploying a load balancer from scratch and adding backend servers Linux
  • vcx
    Fix Error code 0x4 Session disconnected: Your session ended because of an error, if this keeps happening, contact your system administrator Windows
  • sonarcloud
    How to Integrate SonarCloud with Azure DevOps Pipeline AWS/Azure/OpenShift
  • diag7
    How to run Windows Memory Diagnostics Tool on Windows Windows
  • Simple Notification Service AWS SNS
    Create Simple Notification Service (SNS) Notification on AWS AWS/Azure/OpenShift

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,839 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

AWS Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

 

Loading Comments...
 

You must be logged in to post a comment.