Forum Discussion
Encrypted vhdx moved to new host, boots without pin or recovery key
I just wanted to post an update on this. I created a new VM but made sure to enable VTPM prior to installing the OS. Once the VM was up and running, I shut it down and copied the .vhdx to another off-network Hyper-V Host, created a new VM based on the .vhdx I copied over and attempted to boot. It prompted for a recovery key (as it should). So, my question is does VTPM only work if you enable it during a fresh VM install or is there a "bug" in Hyper-V where if you enable VTPM on an existing VM, it doesn't work as designed?
- thetinkeringtoadSep 21, 2026Copper Contributor
I have to admit after accidentially running across this thread. It is a bit unsetteling to discover that there is an actual way to bypass the intended purpose of encrypting a drive with bitlocker. If it fails as in this regardless if it was a wrong procedure that was followed or performing a step out of sequence. This exposes an aspect that defeats the whole intended purpose of encryption. Encrypt it and it cant be open without providing the proper credentials for access. If all it takes is a bad sequence of drive reproduction to move some other place. Means everything is accessible with a little bit of work.