<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>rss.livelink.threads-in-node</title>
    <link>https://techcommunity.microsoft.com/t5/windows-server/ct-p/Windows-Server</link>
    <description>rss.livelink.threads-in-node</description>
    <pubDate>Mon, 27 Jul 2026 20:50:28 GMT</pubDate>
    <dc:creator>Windows-Server</dc:creator>
    <dc:date>2026-07-27T20:50:28Z</dc:date>
    <item>
      <title>Arm 64 mseries windows server</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-insiders/arm-64-mseries-windows-server/m-p/4540550#M4398</link>
      <description>&lt;P&gt;I have downloaded and done every step tht is possible at the end i have recieved this error I have tried all the prompts to correct the error but couldnt&amp;nbsp;&lt;BR /&gt;FYI: VMware fusion on m series mac&lt;BR /&gt;&lt;BR /&gt;Could anyone please lead.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 18:46:30 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-insiders/arm-64-mseries-windows-server/m-p/4540550#M4398</guid>
      <dc:creator>vasundharamareedu</dc:creator>
      <dc:date>2026-07-24T18:46:30Z</dc:date>
    </item>
    <item>
      <title>Cannot Connect to VMs in Windows Admin Center</title>
      <link>https://techcommunity.microsoft.com/t5/windows-admin-center/cannot-connect-to-vms-in-windows-admin-center/m-p/4540370#M2802</link>
      <description>&lt;P&gt;Hi all,&lt;BR /&gt;&lt;BR /&gt;I have 1 Server Cluster made up of 3 Server 2022 Hosts on which there is a large number of VMs running on Hyper-V.&lt;BR /&gt;&lt;BR /&gt;The typical process for accessing the VMs has been through Windows Admin Center, which is hosted on one of the VMs in the cluster.&lt;BR /&gt;&lt;BR /&gt;Around 1 week ago, it was no longer possible to connect to the VMs through Windows Admin Center as an infinite loading screen was presented. Sometimes, the following error shows up in VMConnect:&lt;/P&gt;&lt;img /&gt;&lt;P class="lia-clear-both"&gt;&lt;BR /&gt;The cluster and servers are still connected to WAC and all the VMs that are expected are present on WAC.&lt;BR /&gt;&lt;BR /&gt;Since then, the following things have been attempted:&lt;BR /&gt;&lt;BR /&gt;- Restart all servers&lt;BR /&gt;- Rebuild WAC on Current VM&lt;BR /&gt;- Build WAC on Fresh VM with the same and different network configuration, using current (2606) and previous (2511) versions of WAC&lt;BR /&gt;- Build WAC on one of the hosts&lt;BR /&gt;&lt;BR /&gt;All these attempts result in the same error as seen before.&lt;BR /&gt;&lt;BR /&gt;Has anyone experienced this issue before? Or does anyone have any advice?&lt;BR /&gt;&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Jul 2026 10:09:29 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-admin-center/cannot-connect-to-vms-in-windows-admin-center/m-p/4540370#M2802</guid>
      <dc:creator>jr2299</dc:creator>
      <dc:date>2026-07-24T10:09:29Z</dc:date>
    </item>
    <item>
      <title>Resize-StorageTier / Expand Volume on Windows Server 2025 Campus Cluster does not work</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-insiders/resize-storagetier-expand-volume-on-windows-server-2025-campus/m-p/4540097#M4396</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Insider Community!&lt;/P&gt;&lt;P&gt;Want to expand a CSV on an S2D Windows Server 2025 Campus Cluster. (4-nodes)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I get an error message.&lt;/P&gt;&lt;P&gt;Resize-StorageTier : Not enough available capacity&lt;/P&gt;&lt;P&gt;FullyQualifiedErrorId : StorageWMI 40000,Resize-StorageTier&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hint for me?&lt;/P&gt;&lt;P&gt;Does Microsoft know about the issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2026 11:27:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-insiders/resize-storagetier-expand-volume-on-windows-server-2025-campus/m-p/4540097#M4396</guid>
      <dc:creator>ThomasS-aus-S</dc:creator>
      <dc:date>2026-07-23T11:27:53Z</dc:date>
    </item>
    <item>
      <title>Windows Server Datacenter: Azure Edition preview build 29621 now available in Azure</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-insiders/windows-server-datacenter-azure-edition-preview-build-29621-now/m-p/4537406#M4387</link>
      <description>&lt;H1&gt;Hello Windows Server Insiders!&lt;/H1&gt;
&lt;P&gt;We welcome you to try&amp;nbsp;&lt;STRONG&gt;Windows Server vNext Datacenter: Azure Edition&lt;/STRONG&gt; preview build &lt;STRONG&gt;29621&lt;/STRONG&gt; in both Desktop experience and Core version on the &lt;A href="https://azuremarketplace.microsoft.com/en-us/marketplace/apps/microsoftwindowsserver.microsoftserveroperatingsystems-previews?tab=Overview" target="_blank"&gt;Microsoft Server Operating Systems Preview offer&lt;/A&gt;&amp;nbsp;in Azure. Azure Edition is optimized for operation in the Azure environment. For additional information, see&amp;nbsp;&lt;EM&gt;&lt;A href="https://docs.microsoft.com/en-us/azure/automanage/windows-server-azure-edition-vnext" target="_blank"&gt;Preview: Windows Server VNext Datacenter (Azure Edition) for Azure Automanage&lt;/A&gt;&lt;/EM&gt;&amp;nbsp;on Microsoft Docs. For more information about this build, see &lt;EM&gt;&lt;A href="https://techcommunity.microsoft.com/discussions/windowsserverinsiders/announcing-windows-server-vnext-preview-build-29621/4536572" target="_blank"&gt;Announcing Windows Server vNext Preview Build 29621 | Microsoft Community Hub&lt;/A&gt;&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 16:38:53 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-insiders/windows-server-datacenter-azure-edition-preview-build-29621-now/m-p/4537406#M4387</guid>
      <dc:creator>StaceyCL_RM</dc:creator>
      <dc:date>2026-07-15T16:38:53Z</dc:date>
    </item>
    <item>
      <title>How to check RDP access to the server</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/how-to-check-rdp-access-to-the-server/m-p/4537333#M13092</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a virtual machine running Windows Server 2019 Datacenter with Active Directory, and all users access it via RDP. No specific access configurations have been set up; I wanted to know if it is possible to check how many times a specific user has connected and from which IP address—is that possible? Also, I wanted to ask if it is possible to determine whether a specific user copied files to their local PC using copy/paste during a session.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 13:26:35 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/how-to-check-rdp-access-to-the-server/m-p/4537333#M13092</guid>
      <dc:creator>MC2026</dc:creator>
      <dc:date>2026-07-15T13:26:35Z</dc:date>
    </item>
    <item>
      <title>HLK test failing for a KMDF driver with error “A lower driver failed IRP_MN_QUERY_STOP_DEVICE”</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-insiders/hlk-test-failing-for-a-kmdf-driver-with-error-a-lower-driver/m-p/4537321#M4386</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Subject:&lt;/STRONG&gt;&amp;nbsp;HLK DF‑PNP Rebalance Fail Restart Device: E: target widens to all volumes; QueryStop fails even without my driver installed.&lt;/P&gt;&lt;P&gt;Hi all,&lt;BR /&gt;I’m trying to pass all HLK tests for my driver.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Driver:&lt;/STRONG&gt;&amp;nbsp;KMDF PnP volume upper‑filter (attached via UpperFilters to the Volume/Disk class)&lt;BR /&gt;&lt;STRONG&gt;OS:&lt;/STRONG&gt;&amp;nbsp;Windows Server 2016 Datacenter, build 14393&lt;BR /&gt;&lt;STRONG&gt;HLK:&lt;/STRONG&gt;&amp;nbsp;10.1.14393.8069&lt;BR /&gt;&lt;STRONG&gt;Test:&lt;/STRONG&gt;&amp;nbsp;DF - PNP Rebalance Fail Restart Device (Reliability)&lt;BR /&gt;&lt;STRONG&gt;Target volume:&lt;/STRONG&gt;&amp;nbsp;E: (NTFS)&lt;BR /&gt;&lt;STRONG&gt;Storage:&lt;/STRONG&gt;&amp;nbsp;PERC H330 Mini (DELL) (HBA)&lt;/P&gt;&lt;H3&gt;&lt;STRONG&gt;Observed behavior&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;The DQ initially targets&amp;nbsp;&lt;STRONG&gt;E:&lt;/STRONG&gt;, but the test later widens to all&amp;nbsp;STORAGE\Volume&amp;nbsp;devnodes:&lt;/P&gt;&lt;P&gt;WDTF_TARGETS : INFO : - Query("IsDevice AND (DriverBinaryNames!='i8042prt.sys') AND (Class!=hdc) AND (Class!=scsiadapter) AND (DsmDevice!=TRUE) AND (IsDevice AND (DriverBinaryNames!='i8042prt.sys') AND (Class!=hdc) AND (Class!=scsiadapter) AND (DsmDevice!=TRUE) AND (DeviceID='STORAGE\VOLUME{01FEB6F1-3717-11F1-9707-806E6F6E6963}#0000000001000000'))")&lt;BR /&gt;WDTF_TARGETS : INFO : Target: Volume (E:) STORAGE\VOLUME{01FEB6..&lt;BR /&gt;WDTF_SUPPORT : INFO : - ClearSetupAPILogs()&lt;BR /&gt;WDTF_TARGETS : INFO : - Query("IsDevice AND (SemiUniqueTargetHardwareIdentifier='STORAGE\Volume')")&lt;BR /&gt;WDTF_TARGETS : INFO : Target: Volume STORAGE\VOLUME{01FEB6..&lt;BR /&gt;WDTF_TARGETS : INFO : Target: Volume STORAGE\VOLUME{01FEB6..&lt;BR /&gt;WDTF_TARGETS : INFO : Target: Volume (C:) STORAGE\VOLUME{01FEB6..&lt;BR /&gt;WDTF_TARGETS : INFO : Target: Volume (E:) STORAGE\VOLUME{01FEB6..&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Failures report A lower driver failed IRP_MN_QUERY_STOP_DEVICE and PNP.RestartDevice() Win32=1 - Incorrect function.&lt;BR /&gt;For each of the 4 target volumes, it shows this error,&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;DTF_PNP : INFO : - EDTTryStopDeviceFailRestart()&lt;BR /&gt;WDTF_PNP : INFO : Target: Volume (C:) STORAGE\VOLUME{01FEB6EF-3717-11F1-9707-806E6F6E6963}#000000001F500000&lt;BR /&gt;WDTF_PNP : INFO : Result: A lower driver failed IRP_MN_QUERY_STOP_DEVICE. Rebalance tests cannot proceed...&lt;BR /&gt;WDTF_PNP : INFO : - EDTTryStopDeviceFailRestart()&lt;BR /&gt;WDTF_PNP : INFO : Target: Volume (E:) STORAGE\VOLUME{01FEB6F1-3717-11F1-9707-806E6F6E6963}#0000000001000000&lt;BR /&gt;WDTF_PNP : INFO : Result: A lower driver failed IRP_MN_QUERY_STOP_DEVICE. Rebalance tests cannot proceed...&lt;BR /&gt;WDTF_PNP : ERROR : PNP.RestartDevice() Win32=1 - Incorrect function.&lt;/P&gt;&lt;P&gt;WDTF_PNP : ERROR : PNP.RestartDevice() Win32=1 - Incorrect function.&lt;/P&gt;&lt;P&gt;Q1. I have tried multiple variations of the DQ query, and each successfully targets the E volume only. Why does this test later widen to&amp;nbsp;&lt;STRONG&gt;all volumes&lt;/STRONG&gt;&amp;nbsp;even when DQ targets only E:? How can I force it to stay on E: ?&lt;/P&gt;&lt;P&gt;Q2. I also ran this on a physical server client and a VM client, but faced the same issue both times. I understand the system/boot volume may veto QueryStop, but why does each volume report ‘a lower driver failed IRP_MN_QUERY_STOP_DEVICE’ in this test?&lt;/P&gt;&lt;P&gt;Q3. I uninstalled my driver completely and still see the same failures when the test is running with only inbox drivers (e.g., msdmfilt.sys, volsnap.sys, volume.sys) listed by Driver Verifier for target E in the logs. That makes me suspect setup/config rather than my driver. Why would only these drivers fail the test as well, what am I missing here?&lt;/P&gt;&lt;P&gt;WDTF_DRIVER_VERIFIER : INFO : - EnableOnAllDriversOfDevices()&lt;BR /&gt;WDTF_DRIVER_VERIFIER : INFO : Target: Volume (E:) STORAGE\VOLUME{01FEB6F1-3717-11F1-9707-806E6F6E6963}#0000000001000000&lt;BR /&gt;WDTF_DRIVER_VERIFIER : INFO : Driver: msdmfilt.sys&lt;BR /&gt;WDTF_DRIVER_VERIFIER : INFO : Driver: volsnap.sys&lt;BR /&gt;WDTF_DRIVER_VERIFIER : INFO : Driver: volume.sys&lt;/P&gt;&lt;P&gt;Thanks for any guidance!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2026 12:17:40 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-insiders/hlk-test-failing-for-a-kmdf-driver-with-error-a-lower-driver/m-p/4537321#M4386</guid>
      <dc:creator>RakeshAgrawal</dc:creator>
      <dc:date>2026-07-15T12:17:40Z</dc:date>
    </item>
    <item>
      <title>Announcing Trusted Launch for Virtual Machines for Windows Server Insiders</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-news-and-best/announcing-trusted-launch-for-virtual-machines-for-windows/ba-p/4537082</link>
      <description>&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Trusted Launch&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt; for &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;v&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;irtual &lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;m&lt;/SPAN&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;achines&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;We are excited to announce Trusted Launch for virtual machines (TVMs) in Windows Server Insider Preview. Trusted Launch is a security feature you can enable when creating Hyper-V Generation 2 VMs. It enables Secure Boot, installs a virtual Trusted Platform Module (vTPM), protects vTPM state at rest, and supports boot integrity verification (ability to verify if the VM started in a well-known good state). &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Further, when the VM runs in a Failover Cluster, the vTPM state is automatically made available when the VM live migrates or fails over to other nodes in the cluster – this ensures the VM remains available after migration or failover. This is unlike a Generation 2 VM with a vTPM, which will not start after migration or failover to another node in the cluster – the TPM state protection key needs to be moved to the destination node manually so the VM can start.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;SPAN data-teams="true"&gt;With boot integrity verification, the entire boot path is measured and boot integrity is verified by Microsoft Azure Attestation service.&lt;/SPAN&gt; This helps detect any alterations to the boot path or boot components. Such alterations, e.g. implanting malware in the boot path, can be detected by boot integrity verification. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Increasingly attackers prefer implanting malware in the boot path for a variety of reasons: the OS layer is usually well protected, while firmware – as highly privileged code – can be used to alter what gets loaded (boot loader and drivers). Such alterations are not easily detectable by anti-virus software running at the OS layer. Boot integrity verification helps detect such alterations so a relying party (such as an app or service) can take suitable remediation actions, e.g. shutting down the VM. Boot integrity verification is an important part of establishing trust by verifying that the virtual machine started in a well-known good state.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Insider preview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;TVMs are available for preview starting with Windows Server Insider preview build 29621. This initial preview only supports some of the Trusted Launch capabilities: Secure boot, vTPM, and vTPM state protection (at rest). You can create and manage TVMs using PowerShell.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Guest state protection: The guest state (including the vTPM state) for each TVM is protected using a unique key that is stored in a KSP (Key Storage Provider) local to the server. Without this key, the VM will not start. Moving the VM to another server is not supported in this release.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Not supported&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; in this release:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="1" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Moving TVMs to another server.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="2" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;TVMs in Failover Clusters or Hyper-V Replica. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="3" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Boot integrity verification.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="4" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Support for TVMs in Windows Admin Center (WAC).&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2 aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Instructions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;At a high-level, the steps involve:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="5" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Install Windows Server Insider preview build on your server&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="6" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Enable Hyper-V&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="7" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Enable Trusted Launch feature&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;UL&gt;
&lt;LI aria-setsize="-1" data-leveltext="" data-font="Symbol" data-listid="23" data-list-defn-props="{&amp;quot;335552541&amp;quot;:1,&amp;quot;335559685&amp;quot;:720,&amp;quot;335559991&amp;quot;:360,&amp;quot;469769226&amp;quot;:&amp;quot;Symbol&amp;quot;,&amp;quot;469769242&amp;quot;:[8226],&amp;quot;469777803&amp;quot;:&amp;quot;left&amp;quot;,&amp;quot;469777804&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;469777815&amp;quot;:&amp;quot;hybridMultilevel&amp;quot;}" data-aria-posinset="8" data-aria-level="1"&gt;&lt;SPAN data-contrast="auto"&gt;Verify guest state protection&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;1. Install&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Windows&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Server&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;Insider preview build&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Trusted Launch for virtual machines is available starting with the Windows Insider preview build number 29621. Install this build or a later build on your server. (Join &lt;/SPAN&gt;&lt;A href="https://insider.windows.com/en-us/for-business-getting-started-server" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Server Insiders&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt; if you haven’t already!)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;2. Enable Hyper-V&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; (if it is not already enabled)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Install-WindowsFeature -Name Hyper-V -IncludeManagementTools -Restart &lt;/LI-CODE&gt;
&lt;P class=""&gt;&lt;SPAN data-contrast="auto"&gt;After en&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;abling Hyper-V, the server needs to be restarted.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;3. Set registry key property value (required to enable the Trusted Launch feature)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;New-Item -Path "HKLM:\SOFTWARE\Microsoft\AszIgvmAgent" -Force 
New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\AszIgvmAgent" -Name "TvmWinServer" -Value 1 -PropertyType DWord -Force &lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Setting the above regkey informs &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;relevant&lt;/SPAN&gt; &lt;SPAN data-contrast="auto"&gt;system components &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;that the &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Trusted Launch feature is being used in a Windows Server environment.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;4. Enable Trusted Launch feature&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Enable-WindowsOptionalFeature -Online -FeatureName "IsolatedGuestVm"  -NoRestart &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;5. Verify if IgvmAgent is running&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;IgvmAgent (Isolated Guest Virtual Machine agent) is a system-level service that helps support Trusted Launch capabilities.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;Get-Service -Name "IGVmAgent"  &lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The output should show Status as Running.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If the Status is Running, you can skip to next step.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If the Status is not Running, please report the issue. Add the following event logs to the report:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Event Viewer: Applications and Services Logs =&amp;gt; Microsoft =&amp;gt; Windows =&amp;gt; IGVmAgent =&amp;gt; Operational&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;Event Viewer: Applications and Services Logs =&amp;gt; Microsoft =&amp;gt; Windows =&amp;gt; IGVmSystem =&amp;gt; Operational&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;You can open Event Viewer via the Run dialog:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Press &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Win + R&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; → type "eventvwr.msc" → press &lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;Enter&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;6. Create an external virtual switch&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; (if you don't already have one you can use)&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/get-started/create-a-virtual-switch-for-hyper-v-virtual-machines?tabs=powershell&amp;amp;pivots=windows" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Create and configure a virtual switch with Hyper-V | Microsoft Learn&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;  &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To see available external virtual switches:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;(Get-VMSwitch | Where-Object { $_.SwitchType -eq "External" }).Name &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;7. Create TVM&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;If you already have a virtual hard disk (VHD or VHDX) for a Gen 2 VM with an installed guest OS, run:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;New-VM -Name &amp;lt;VMName&amp;gt; -Generation 2 -GuestStateIsolationType TrustedLaunch -SwitchName &amp;lt;virtual switch name&amp;gt;  -VHDPath &amp;lt;path to vhdx&amp;gt;  -Path &amp;lt;path to where VM config files will be stored&amp;gt; &lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Else, run:&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:-360,&amp;quot;335559731&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;New-VM -Name &amp;lt;VMName&amp;gt; -SwitchName &amp;lt;virtual switch name&amp;gt; -NewVHDPath &amp;lt;path to where new VHD will be stored&amp;gt; -NewVHDSizeBytes 40GB -Generation 2 -GuestStateIsolationType TrustedLaunch -Path &amp;lt;path to where VM config files will be stored&amp;gt;  &lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Then, add to the VM a virtual DVD drive containing an ISO image for the guest OS (Windows or Linux OS-compatible with Hyper-V Gen 2 virtual machine).&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt; Add-VMDvdDrive -VMName &amp;lt;VMName&amp;gt; -Path &amp;lt;Guest OS ISO image path&amp;gt;  &lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Note: The guest OS will be installed when the VM starts up. When connecting to the VM you will be prompted to install the guest OS from the DVD drive. Make sure that the DVD drive is at the top of the boot order specified in the firmware so the VM will boot from the DVD drive.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;For more information, see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/powershell/module/hyper-v/new-vm?view=windowsserver2025-ps" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;New-VM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:360,&amp;quot;469777462&amp;quot;:[1080],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;8. Verify VM guest state isolation type&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;469777462&amp;quot;:[360],&amp;quot;469777927&amp;quot;:[0],&amp;quot;469777928&amp;quot;:[8]}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;LI-CODE lang="powershell"&gt;(Get-VM -name &amp;lt;VMName&amp;gt;).GuestStateIsolationType&lt;/LI-CODE&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;should return "TrustedLaunch".&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;335559685&amp;quot;:-360}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;9. Verify guest state protection&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;To verify guest state protection, stop IGVmAgent service and restart the VM. &lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Without IGVmAgent in Running state, a&amp;nbsp;TVM&amp;nbsp;with guest state protection will not start.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134233117&amp;quot;:false,&amp;quot;134233118&amp;quot;:false,&amp;quot;201341983&amp;quot;:0,&amp;quot;335551550&amp;quot;:1,&amp;quot;335551620&amp;quot;:1,&amp;quot;335559685&amp;quot;:0,&amp;quot;335559737&amp;quot;:0,&amp;quot;335559738&amp;quot;:0,&amp;quot;335559739&amp;quot;:160,&amp;quot;335559740&amp;quot;:278}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;img /&gt;&lt;img /&gt;
&lt;H2&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-parastyle="heading 2"&gt;Call to action&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{&amp;quot;134245418&amp;quot;:true,&amp;quot;134245529&amp;quot;:true,&amp;quot;335559738&amp;quot;:160,&amp;quot;335559739&amp;quot;:80}"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Trusted Launch brings foundational VM security — Secure Boot, a vTPM, and protected guest state — to Windows Server, helping safeguard your VMs against boot-level and firmware threats. Please try out TVMs and provide your feedback via the &lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/category/windows-server/discussions/windowsserverinsiders" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="none"&gt;&lt;SPAN data-ccp-charstyle="Hyperlink"&gt;Windows Server Insiders Forum&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;SPAN data-ccp-props="{}"&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;—&lt;BR /&gt;&lt;EM&gt;Christina Curlette and Ram Jeyaraman (and the Windows Server team)&lt;/EM&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 01:53:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-news-and-best/announcing-trusted-launch-for-virtual-machines-for-windows/ba-p/4537082</guid>
      <dc:creator>Christina_Curlette</dc:creator>
      <dc:date>2026-07-16T01:53:49Z</dc:date>
    </item>
    <item>
      <title>Announcing Windows Server vNext Preview Build 29621</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-insiders/announcing-windows-server-vnext-preview-build-29621/m-p/4536572#M4385</link>
      <description>&lt;H1&gt;&lt;SPAN class="lia-text-color-15"&gt;&lt;STRONG&gt;Hello Windows Server Insiders!&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/H1&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Today we are pleased to release a new build of the next Windows Server Long-Term Servicing Channel (LTSC) Preview that contains both the Desktop Experience and Server Core installation options for Datacenter and Standard editions and Azure Edition (for VM evaluation only). Branding remains Windows Server 2025 in this preview - when reporting issues please refer to&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows Server vNext preview&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Build 29531 established a new Server preview&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;baseline build&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;&lt;STRONG&gt;.&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Please perform a&amp;nbsp;&lt;STRONG&gt;clean install of Build 29531 (or later)&lt;/STRONG&gt;&amp;nbsp;using the installation media&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;linked below&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/EM&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Please note:&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;Upgrades from&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;Windows Server vNext preview&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;builds older than 29531 are not supported. We encourage all Windows Server vNext preview users to perform a clean install using 29531 or later to successfully upgrade to future Windows Server vNext preview builds.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;While upgrades from earlier Windows Server previews&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;(&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Build 26525 and older&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;&lt;EM&gt;&lt;STRONG&gt;)&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;are not technically blocked by&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="none"&gt;setup.exe&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="none"&gt;, a number of known issues have been identified related to upgrades necessitating the establishment of a new baseline build for our Server vNext Preview Program.&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI data-aria-posinset="2" data-aria-level="2"&gt;&lt;SPAN data-contrast="none"&gt;The new baseline build&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;(&lt;STRONG&gt;29531&lt;/STRONG&gt;)&lt;/SPAN&gt;&lt;SPAN data-contrast="none"&gt;&amp;nbsp;will not be Flighted due to upgrade issues. Flighting support resumed with preview build 29550 or later.&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;What's New&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-10"&gt;&lt;EM&gt;&lt;STRONG&gt;[NEW]&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt; We're excited to announce &lt;EM&gt;&lt;STRONG&gt;Trusted Launch for virtual machines (TVMs)&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;on Windows Server—a security feature you can enable when creating &lt;STRONG&gt;Generation&amp;nbsp;2 VMs.&lt;/STRONG&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class=""&gt;This initial preview supports&amp;nbsp;&lt;STRONG&gt;TVMs with&amp;nbsp;Secure Boot, vTPM, and vTPM state protection (at rest)&lt;/STRONG&gt;, managed via PowerShell.&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;SPAN class="lia-text-color-7"&gt;&lt;STRONG&gt;⚠&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt; Not supported in this release:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Moving TVMs to another server&lt;/LI&gt;
&lt;LI&gt;TVMs in failover clusters or Hyper-V Replica&lt;/LI&gt;
&lt;LI&gt;Boot integrity verification&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt;TVMs in Windows Admin Center (WAC)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;Instructions&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;1.&amp;nbsp; Install the latest ServerInsider preview build.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;2.&amp;nbsp; Enable Hyper-V &lt;/STRONG&gt;(restarts the server):&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="width: 847px; height: 47px; border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;Install-WindowsFeature -Name Hyper-V -IncludeManagementTools -Restart&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;3.&amp;nbsp; Set the registry keys:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;New-Item -Path "HKLM:\SOFTWARE\Microsoft\AszIgvmAgent" -Force &lt;BR /&gt;&lt;BR /&gt;New-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\AszIgvmAgent" -Name "TvmWinServer" -Value 1 -PropertyType DWord -Force&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;4.&amp;nbsp; Enable Trusted Launch:&lt;/STRONG&gt;&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;Enable-WindowsOptionalFeature -Online -FeatureName "IsolatedGuestVm" -NoRestart&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;5.&amp;nbsp; Verify IGVmAgent is running &lt;/STRONG&gt;(should show &lt;STRONG&gt;Running&lt;/STRONG&gt;):&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;Get-Service -Name "IGVmAgent"&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;If it isn't running, report the issue with the &lt;STRONG&gt;IGVmAgent&lt;/STRONG&gt;&amp;nbsp;and &lt;STRONG&gt;IGVmSystem&lt;/STRONG&gt; Operational logs (Event Viewer → Applications and Services Logs → Microsoft → Windows).&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;6.&amp;nbsp; Create an external virtual switch &lt;/STRONG&gt;(if needed):&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;(Get-VMSwitch | Where-Object { $_.SwitchType -eq "External" }).Name&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;7.&amp;nbsp; Create the TVM. &lt;/STRONG&gt;With an existing Gen&amp;nbsp;2 VHDX:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;New-VM -Name &amp;lt;VMName&amp;gt; -Generation 2 -GuestStateIsolationType TrustedLaunch -SwitchName &amp;lt;switch&amp;gt; -VHDPath &amp;lt;path to vhdx&amp;gt; -Path &amp;lt;config path&amp;gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-90px"&gt;Or with a new VHD, then attach a Gen&amp;nbsp;2–compatible guest OS ISO:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;New-VM -Name &amp;lt;VMName&amp;gt; -SwitchName &amp;lt;switch&amp;gt; -NewVHDPath &amp;lt;new VHD path&amp;gt; -NewVHDSizeBytes 40GB -Generation 2 -GuestStateIsolationType TrustedLaunch -Path &amp;lt;config path&amp;gt; &lt;BR /&gt;&lt;BR /&gt;Add-VMDvdDrive -VMName &amp;lt;VMName&amp;gt; -Path &amp;lt;Guest OS ISO path&amp;gt;&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;EM&gt;Ensure the DVD drive is first in the firmware boot order so the VM boots from it.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;8.&amp;nbsp; Verify isolation type &lt;/STRONG&gt;(should return&amp;nbsp;TrustedLaunch):&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN lia-indent-padding-left-60px"&gt;&lt;table class="lia-indent-margin-left-60px" border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr class="lia-indent-padding-left-60px"&gt;&lt;td class="lia-indent-padding-left-60px"&gt;
&lt;BLOCKQUOTE class="lia-indent-padding-left-60px"&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;(Get-VM -Name &amp;lt;VMName&amp;gt;).GuestStateIsolationType&lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 100.00%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;STRONG&gt;9.&amp;nbsp; Verify guest state protection: &lt;/STRONG&gt;Stop the IGVmAgent service and restart the VM—without IGVmAgent running, a Trusted launch VM with guest state protection won't start.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;EM&gt;For more information, please review our blog post: &lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/announcing-trusted-launch-for-virtual-machines-for-windows-server-insiders/4537082" target="_blank"&gt;Announcing Trusted Launch for Virtual Machines for Windows Server Insiders | Microsoft Community Hub&lt;/A&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Quick Machine Recovery&lt;/STRONG&gt;&lt;/EM&gt;&amp;nbsp;available in&amp;nbsp;&lt;EM&gt;Windows Server vNext Insider Previews&lt;/EM&gt;.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/?tabs=intune" target="_blank" rel="noopener"&gt;Quick machine recovery (QMR)&lt;/A&gt;&amp;nbsp;is now available for Server vNext Insiders to test. This feature enables the recovery of Windows Server devices when they encounter boot critical errors that prevent them from booting. QMR can automatically search for cloud‑based remediations to recover from widespread boot failures significantly reducing the burden on IT administrators when multiple devices are impacted. This supports the goals of the&amp;nbsp;&lt;EM&gt;&lt;A href="https://adoption.microsoft.com/files/windows11/Windows-Resiliency-Initiative-eBook.pdf" target="_blank" rel="noopener"&gt;Windows Resiliency Initiative&lt;/A&gt;&lt;/EM&gt;&amp;nbsp;by enabling applicable fixes to be delivered through trusted Windows Update to restore affected devices, helping reduce downtime and minimize manual recovery efforts across enterprise environments.&lt;/P&gt;
&lt;P&gt;This feature is currently enabled in the&amp;nbsp;&lt;STRONG&gt;latest&lt;/STRONG&gt;&amp;nbsp;&lt;STRONG&gt;Server vNext Insider builds&lt;/STRONG&gt;&amp;nbsp;for customers to experience test mode.&lt;EM&gt;&amp;nbsp;A Group Policy option to enable or disable the feature will be introduced in upcoming builds to provide additional administrative control.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;To simulate the quick machine recovery experience, use the following commands from an elevated command prompt:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;EM&gt; Enable test mode:&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;reagentc.exe /SetRecoveryTestmode&lt;/PRE&gt;
&lt;OL start="2"&gt;
&lt;LI&gt;&lt;EM&gt; Configure Windows to boot to Windows Recovery Environment on the next boot:&lt;/EM&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;PRE class="lia-indent-padding-left-60px"&gt;reagentc.exe /BootToRe&lt;/PRE&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;EM&gt; Reboot your device. &lt;/EM&gt;The system goes through autoremediation of a simulated crash safely and reboots back to Windows Server.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;For more information, please review&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/windows/configuration/quick-machine-recovery/?tabs=intune" target="_blank" rel="noopener"&gt;Quick machine recovery (QMR)&lt;/A&gt;&amp;nbsp;and&amp;nbsp;&lt;A href="https://adoption.microsoft.com/files/windows11/Windows-Resiliency-Initiative-eBook.pdf" target="_blank" rel="noopener"&gt;Windows Resiliency Initiative&lt;/A&gt;. When providing feedback using Feedback hub, please select QMR from the Recovery and Uninstall category in the app.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NVMe-over-Fabrics (NVMe-oF)&lt;/STRONG&gt;&amp;nbsp;extends the NVMe protocol—originally designed for local PCIe-attached SSDs—across a network fabric. Instead of using legacy SCSI-based protocols such as iSCSI or Fibre Channel, NVMe-oF allows a host to communicate directly with&amp;nbsp;&lt;STRONG&gt;remote NVMe controllers&lt;/STRONG&gt;&amp;nbsp;using the same NVMe command set used for local devices. In this Insider build, Windows Server supports:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;NVMe-oF over TCP (NVMe/TCP)&lt;/STRONG&gt;, allowing NVMe-oF to run over standard Ethernet networks without specialized hardware.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;NVMe-oF over RDMA (NVMe/RDMA)&lt;/STRONG&gt;, enabling low-latency, high-throughput NVMe access over RDMA-capable networks (for example, RoCE or iWARP) using supported RDMA NICs.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;For more information, please visit:&lt;/EM&gt;&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/blog/windowsservernewsandbestpractices/introducing-the-windows-nvme-of-initiator-preview-in-windows-server-insiders-bui/4501344" target="_blank" rel="noopener"&gt;Introducing the Windows NVMe-oF Initiator Preview in Windows Server Insiders Builds | Microsoft Community Hub&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;ReFS Boot is enabled for Windows Server vNext preview builds.&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Known Limitations&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;ReFS&amp;nbsp;Boot systems create a&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;minimum&amp;nbsp;2GB WinRE partition.&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;When&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;WinRE&amp;nbsp;cannot be updated due to space constraints&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, the system may&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;disable WinRE&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;. Disabling WinRE does not remove the partition.&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN data-contrast="auto"&gt;If the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;WinRE partition is deleted and the boot volume is extended over it&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;, this operation is&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;unrecoverable without a clean install&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;EM&gt;For more information, please visit:&lt;/EM&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Resilient File System (ReFS) overview | Microsoft Learn&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Feedback Hub&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;app is available for&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Server Desktop&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;users!  The app should automatically update with the latest version, but if it does not, simply&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN data-contrast="auto"&gt;Check for updates&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in the app’s settings tab.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Known Issues&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-teams="true"&gt;A race condition in the TLS hybrid key exchange implementation may cause the LSASS service to crash &lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-teams="true"&gt;when hybrid groups are negotiated by a TLS server. To avoid this issue until the fix is released, please disable hybrid groups (&lt;EM&gt;X25519_MLKEM768, SecP256r1_MLKEM768, SecP384r1_MLKEM1024&lt;/EM&gt;) using TLS cmdlets or Group Policy, as outlined &lt;A href="https://learn.microsoft.com/en-us/windows/win32/secauthn/tls-supported-groups-in-windows-11-24h2-and-later" target="_blank" rel="noopener" aria-label="Link here"&gt;here&lt;/A&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-teams="true"&gt;.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Server Core Upgrades and AppCompat FOD: Enabling AppCompat FOD after reinstall may fail due to legacy 3rd-party license compatibility issues on Server Core devices. &lt;/STRONG&gt;Server Core users may be unable to install the latest AppCompat FOD after upgrading to build 29574. This appears to be limited to Server Core installations with 3rd-party application licenses that fail compatibility checks after upgrade. This will be addressed in a future build.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Upgrading from older builds of Windows Server vNext previews (26525 or older) are not supported.&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;U&gt;&lt;EM&gt;Please perform a clean install of build 29531 or later&lt;/EM&gt;&lt;/U&gt;&lt;EM&gt;.&amp;nbsp;&lt;/EM&gt;&lt;SPAN data-contrast="auto"&gt;Users may experience failures when attempting to upgrade from earlier previews&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;(build 26525 and older)&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;.&amp;nbsp;VMs may fail to upgrade or start after upgrade from older preview builds impacting live migration and failover cluster scenarios.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Download Windows Server Insider Preview (microsoft.com)&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Flighting&lt;/STRONG&gt;:&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;The label for this flight may incorrectly reference Windows 11. However, when selected, the package installed is the Windows Server vNext update. Please ignore the label and proceed with installing your flight. This issue will be addressed in a future release.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;Available Downloads&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;Downloads to certain countries may not be available. See&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://blogs.microsoft.com/on-the-issues/2022/03/04/microsoft-suspends-russia-sales-ukraine-conflict/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft suspends new sales in Russia - Microsoft On the Issues.&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-aria-posinset="1" data-aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows Server Long-Term Servicing Channel Preview&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in ISO format in 18 languages, and in VHDX format in English only. &lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI data-aria-posinset="2" data-aria-level="2"&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows Server Datacenter Azure Edition Preview&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;in ISO and VHDX format, English only.&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;LI data-aria-posinset="3" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Microsoft Server Languages and Optional Features&lt;/STRONG&gt;&amp;nbsp;Preview&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt; &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Keys:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;Keys are valid for preview builds only &lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI data-aria-posinset="1" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Server Standard:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;MFY9F-XBN2F-TYFMP-CCV49-RMYVH&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-aria-posinset="2" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Datacenter:&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;2KNJJ-33Y9H-2GXGX-KMQWH-G6H67&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-aria-posinset="3" data-aria-level="2"&gt;&lt;SPAN data-contrast="auto"&gt;Azure Edition does not accept a key.&lt;/SPAN&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Symbols:&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt; Available on the public symbol server – see&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://msdn.microsoft.com/library/windows/desktop/ee416588(v=vs.85).aspx#using_the_microsoft_symbol_server" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Using the Microsoft Symbol Server&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;. &lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Expiration:&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;This Windows Server Preview will expire September 15, 2026.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;How to Download&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Registered Insiders may navigate directly to the&amp;nbsp;&lt;A href="https://www.microsoft.com/en-us/software-download/windowsinsiderpreviewserver" target="_blank" rel="noopener"&gt;Windows Server Insider Preview download page&lt;/A&gt;.&amp;nbsp;&amp;nbsp; If you have not yet registered as an Insider, see&amp;nbsp;&lt;A href="https://insider.windows.com/en-us/for-business-getting-started-server/" target="_blank" rel="noopener"&gt;GETTING STARTED WITH SERVER&lt;/A&gt;&amp;nbsp;on the&amp;nbsp;&lt;A href="https://insider.windows.com/en-us/for-business" target="_blank" rel="noopener"&gt;Windows Insiders for Business&lt;/A&gt;&amp;nbsp;portal.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;We value your feedback!&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The most important part of the release cycle is to hear what's working and what needs to be improved, so your feedback is extremely valued. Please use the new&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;Feedback Hub app for Windows Server&lt;/STRONG&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN data-contrast="auto"&gt;if you are running a Desktop version of Server. If you are using a Core edition, or if you are unable to use the Feedback Hub app, you can use your registered Windows 10 or Windows 11 Insider device and use the Feedback Hub application.  In the app, choose the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;Windows Server&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;category and then the appropriate subcategory for your feedback. In the title of the Feedback, please indicate the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;build number&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;you are providing feedback on as shown below to ensure that your issue is attributed to the right version:&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;     [Server&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="auto"&gt;#####&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN data-contrast="auto"&gt;] Title of my feedback&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;See&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-insider/feedback-hub/feedback-hub-app" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Give Feedback on Windows Server via Feedback Hub&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;for specifics.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN data-contrast="auto"&gt;The&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/Windows-Server-Insiders/bd-p/WindowsServerInsiders" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Windows Server Insiders&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;space on the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Microsoft Tech Communities&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;supports preview builds of the next version of Windows Server. Use the forum to collaborate, share and learn from experts.  For versions that have been released to general availability in market, try the&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/bd-p/WindowsServer?emcs_t=S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufEtaUjM4UUFHM0JYOVFQfDMxNzg4NjB8U1VCU0NSSVBUSU9OU3xoSw" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Windows Server for IT Pro&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;&amp;nbsp;forum or contact&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.serviceshub.microsoft.com/supportforbusiness" target="_blank" rel="noopener"&gt;&lt;SPAN data-contrast="auto"&gt;Support for Business&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN data-contrast="auto"&gt;.&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Diagnostic and Usage Information&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;Microsoft collects this information over the internet to help keep Windows secure and up to date, troubleshoot problems, and make product improvements. Microsoft server operating systems can be configured to turn diagnostic data off, send Required diagnostic data, or send Optional diagnostic data.&amp;nbsp;&lt;STRONG&gt;&amp;nbsp;During previews, Microsoft asks that you change the default setting to Optional to provide the best automatic feedback and help us improve the final product.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Administrators can change the level of&amp;nbsp;&lt;STRONG&gt;information&lt;/STRONG&gt;&amp;nbsp;collection through Settings. For details, see&amp;nbsp;&lt;A href="http://aka.ms/winserverdata" target="_blank" rel="noopener"&gt;http://aka.ms/winserverdata&lt;/A&gt;. Also see the&amp;nbsp;&lt;A href="http://aka.ms/privacy" target="_blank" rel="noopener"&gt;Microsoft Privacy Statement&lt;/A&gt;.&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;Terms of Use&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;This is&lt;STRONG&gt;&amp;nbsp;pre-release software&amp;nbsp;&lt;/STRONG&gt;- it is provided for use "as-is" and is not supported in production environments. Users are responsible for installing any updates that may be made available from Windows Update.&amp;nbsp;All pre-release software made available to you via the Windows Server Insider program is governed by the&amp;nbsp;&lt;A href="https://insider.windows.com/en-us/program-agreement/" target="_blank" rel="noopener"&gt;Insider Terms of Use&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2026 00:11:28 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-insiders/announcing-windows-server-vnext-preview-build-29621/m-p/4536572#M4385</guid>
      <dc:creator>StaceyCL_RM</dc:creator>
      <dc:date>2026-07-16T00:11:28Z</dc:date>
    </item>
    <item>
      <title>Patch the Kernel, Skip the Reboot: The Case for Arc-Enabled Hotpatching on Windows Server 2025</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-news-and-best/patch-the-kernel-skip-the-reboot-the-case-for-arc-enabled/ba-p/4536562</link>
      <description>&lt;P&gt;For decades, applying a security fix to core OS components meant swapping files on disk and restarting so the loader could map the new image into memory. Rebooting to patch is a workaround for a limitation we no longer must accept. Windows Server 2025 removes that constraint with &lt;STRONG&gt;Arc-enabled hotpatching&lt;/STRONG&gt;: in-memory patching of running code, delivered at &lt;STRONG&gt;no additional charge&lt;/STRONG&gt; through Azure Arc.&lt;/P&gt;
&lt;P&gt;Let me say this again: &lt;STRONG&gt;Hotpaching for Arc-enabled Windows Server 2025 AT NO COST.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;This post is for the engineers who run the fleet. Let's get into how it works, what it requires, and why you should Arc-enable a server this week.&lt;/P&gt;
&lt;H3&gt;The Real Cost of an Unpatched Window&lt;/H3&gt;
&lt;P&gt;The interval between a CVE's public disclosure and active exploitation in the wild is now frequently measured in hours. Automated scanners fingerprint exposed services and match them against known vulnerabilities faster than most change-management processes can approve a maintenance window. Every reboot you defer widens the exposure window on a known, documented, fixable attack path.&lt;/P&gt;
&lt;P&gt;Traditional patching forces a trade-off:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Patch aggressively&lt;/STRONG&gt; and absorb frequent reboots, service interruptions, failover events, and the operational risk of something not coming back cleanly.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Patch conservatively&lt;/STRONG&gt; and accept a standing backlog of unremediated vulnerabilities on production systems.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://aka.ms/hotpatchdocs" target="_blank" rel="noopener"&gt;Hotpatching&lt;/A&gt; removes that trade-off. You patch aggressively and keep the process running.&lt;/P&gt;
&lt;H3&gt;How Hotpatching Actually Works&lt;/H3&gt;
&lt;P&gt;Hotpatching operates on the in-memory image of running code rather than requiring the OS to reload a new binary from disk on restart. At a high level:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The hotpatch engine applies fixes by patching the loaded code of target processes and kernel components&amp;nbsp;&lt;STRONG&gt;in place&lt;/STRONG&gt;, so a fix takes effect immediately on the running system—no reboot, no process restart.&lt;/LI&gt;
&lt;LI&gt;Updates are organized around a&amp;nbsp;&lt;STRONG&gt;baseline plus hotpatch&lt;/STRONG&gt; model:&lt;/LI&gt;
&lt;LI&gt;A&amp;nbsp;&lt;STRONG&gt;baseline&lt;/STRONG&gt; is a standard cumulative update (new on-disk binaries) applied on a scheduled cadence—typically &lt;STRONG&gt;once per quarter&lt;/STRONG&gt;—which does require a reboot.&lt;/LI&gt;
&lt;LI&gt;Between baselines, hotpatches deliver the intervening security fixes with&amp;nbsp;&lt;STRONG&gt;no reboot required&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;The practical outcome on Windows Server 2025: reboots drop from a roughly monthly rhythm to about&amp;nbsp;&lt;STRONG&gt;four planned reboots per year&lt;/STRONG&gt; (the quarterly baselines), while security content lands continuously in between.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Because the hotpatch payload targets the same code paths the corresponding cumulative update would have, you get equivalent security coverage without the restart. When a fix genuinely can't be hotpatched, it's rolled into the next baseline—so nothing is silently skipped.&lt;/P&gt;
&lt;H3&gt;What It Requires&lt;/H3&gt;
&lt;P&gt;&lt;A href="https://techcommunity.microsoft.com/blog/AzureArcBlog/simplified-access-to-hotpatching-enabled-by-azure-arc-for-windows-server-2025/4521251" target="_blank" rel="noopener"&gt;Arc-enabled hotpatching for Windows Server 2025&lt;/A&gt; hinges on three things:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Windows Server 2025&lt;/STRONG&gt; (Standard or Datacenter).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Arc connectivity:&lt;/STRONG&gt; the machine is projected into Azure via the Azure Connected Machine agent (`azcmagent`), giving it a resource identity in an Azure subscription and resource group.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;The Hotpatch capability enabled&lt;/STRONG&gt; managed through &lt;STRONG&gt;Azure Update Manager&lt;/STRONG&gt;, which orchestrates baseline/hotpatch scheduling and reports per-machine hotpatch compliance.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Notably, for Windows Server 2025 connected through Arc, the hotpatching capability itself carries no additional charge. There's no separate SKU to buy and no premium tier to unlock—just the Arc onboarding step.&lt;/P&gt;
&lt;H3&gt;Arc Is the Control Plane, Not Just a Prerequisite&lt;/H3&gt;
&lt;P&gt;Connecting a server with the Connected Machine agent does more than switch on hotpatching—it registers that machine as a first-class Azure resource. Everything Azure's governance and security stack does for native VMs now extends to your on-prem, edge, and multi-cloud servers:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Microsoft Defender for Cloud&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Onboard Arc machines to &lt;STRONG&gt;Defender for Servers&lt;/STRONG&gt; to get agent-based EDR (via the Defender for Endpoint sensor), vulnerability assessment, file integrity monitoring, and continuous Secure Score-based posture management. Findings surface in the same portal and APIs as the rest of your Azure estate, so on-prem is no longer a monitoring blind spot.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Monitor&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Deploy the &lt;STRONG&gt;Azure Monitor Agent&lt;/STRONG&gt; (AMA) via Arc to stream performance counters, event logs, and custom logs into a Log Analytics workspace. From there you get KQL queries, VM Insights, workbooks, and metric/alert rules. Hotpatch and update status can be correlated with performance and security signals in one query surface.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Azure Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Use &lt;STRONG&gt;Azure Policy&lt;/STRONG&gt; and &lt;STRONG&gt;Machine Configuration&lt;/STRONG&gt; (guest configuration) to audit and enforce in-guest state—required agents installed, hotpatch enabled, baseline hardening applied—at fleet scale. Assign a policy initiative once and let Azure continuously evaluate drift and, where configured, remediate it automatically.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;And the rest of the toolchain&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Azure Update Manager&lt;/STRONG&gt; — centralized patch orchestration, scheduling, and compliance reporting across the whole fleet (and the control point for hotpatch).&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Change Tracking &amp;amp; Inventory&lt;/STRONG&gt; — track software, files, registry, and service changes over time.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Extended Security Updates via Arc&lt;/STRONG&gt; — for the down-level Windows Server versions still in your environment.&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3&gt;The Layered Result&lt;/H3&gt;
&lt;P&gt;Put together, this is defense in depth expressed as an integrated platform rather than a pile of point tools:&lt;/P&gt;
&lt;DIV class="styles_lia-table-wrapper__h6Xo9 styles_table-responsive__MW0lN"&gt;&lt;table border="1" style="border-width: 1px;"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Layer&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Capability&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;What it closes&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Patch&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Arc-enabled hotpatching&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;The disclosure-to-remediation gap, minus the downtime&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Detect&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Defender for Cloud / Servers&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Active threats and exploit attempts&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Observe&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Azure Monitor + Log Analytics&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Blind spots in health and behavior&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;
&lt;P&gt;&lt;STRONG&gt;Enforce&lt;/STRONG&gt;&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Azure Policy + Machine Config&lt;/P&gt;
&lt;/td&gt;&lt;td&gt;
&lt;P&gt;Configuration drift and compliance gaps&lt;/P&gt;
&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;colgroup&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;col style="width: 33.33%" /&gt;&lt;/colgroup&gt;&lt;/table&gt;&lt;/DIV&gt;
&lt;P&gt;Each layer reinforces the others, and all four are driven from the same Azure control plane against the same resource inventory.&lt;/P&gt;
&lt;H3&gt;Arc-Enable One Server. Try It.&lt;/H3&gt;
&lt;P&gt;At this point you may still be skeptical. You may be thinking, “Windows Server 2025 hotpatching for free? No downtime? No cost? There must be a catch.”&lt;/P&gt;
&lt;P&gt;Here’s what I tell everyone when I have this conversation, “Don’t believe a word I just said. Just try it. Setup one server, Arc-enable the server and enable Windows Server 2025 hotpatching through Azure Update Manager.” You don't need a project plan, a steering committee, or a budget line to evaluate this. Pick one non-critical Windows Server 2025 box and Arc-enable it:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In the Azure portal, go to &lt;STRONG&gt;Azure Arc → Servers → Add&lt;/STRONG&gt;, and generate an onboarding script (or grab a service-principal script for at-scale later).&lt;/LI&gt;
&lt;LI&gt;Run the script on the server to install and configure the &lt;STRONG&gt;Connected Machine agent&lt;/STRONG&gt; (`azcmagent connect`).&lt;/LI&gt;
&lt;LI&gt;In &lt;STRONG&gt;Azure Update Manager&lt;/STRONG&gt;, enable &lt;STRONG&gt;Hotpatch&lt;/STRONG&gt; for the machine.&lt;/LI&gt;
&lt;LI&gt;Watch the next hotpatch land—and enjoy the lack of reboot and peace of mind.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That's it. Arc-enabling a server cost nothing, and hotpatching on Windows Server 2025 through Arc costs nothing. You risk one afternoon on one server and get back reboot-free security patching, plus a live demo of Defender, Azure Monitor, and Azure Policy reaching a machine that used to be invisible to Azure.&lt;/P&gt;
&lt;P&gt;Free tooling, free hotpatching, less downtime, and a stronger security posture. &lt;STRONG&gt;Who doesn't want free hotpatching?&lt;/STRONG&gt; Arc-enable one server. Try it. Then decide how fast you want to roll it out to the rest.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;-Jeff Woolsey&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jul 2026 17:29:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-news-and-best/patch-the-kernel-skip-the-reboot-the-case-for-arc-enabled/ba-p/4536562</guid>
      <dc:creator>Jeff-Woolsey</dc:creator>
      <dc:date>2026-07-13T17:29:33Z</dc:date>
    </item>
    <item>
      <title>Unable to Build Switchless Storage using Network ATC</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/unable-to-build-switchless-storage-using-network-atc/m-p/4535795#M13080</link>
      <description>&lt;P&gt;3-Node HV/S2D Cluster using Switchless Storage and Network ATC getting Network HUD Error&lt;/P&gt;&lt;P&gt;I have a Dell 3-node server cluster being used to host Hyper-V with S2D.&amp;nbsp; Each node is identical and certified to pass S2D requirements.&amp;nbsp; The networking consists of 2 onboard 1 Gbps and 2 quad-port PCI(e) NICs at 10/25 Gbps.&amp;nbsp; The 2 onboard ports are being used for the management intent, 2 ports from each of those NICs are being connected to 2 top-of-rack switches for the compute intent at a total of 12 10 Gbps connections, and the other 2 ports from each of those NICs are being connected directly to the other nodes in a dual mesh method for the storage intent at a total of 6 25 Gbps connections.&amp;nbsp; Very similar to the Microsoft diagram for a three-node storage switchless, dual TOR, dual link deployment network reference pattern for Azure Local, but I am using Windows Server 2025 Datacenter, not Azure Local.&lt;/P&gt;&lt;P&gt;The problem I am encountering is when I attempt to create the switchless storage intent, I get an error (shown below) that reads "Failed to fetch physical NIC mapping from the Network HUD service. Please diagnose..."&amp;nbsp; If I leave off the switchless option, it builds without issue.&amp;nbsp; The error only occurs when I attempt to use the switchless option.&lt;/P&gt;&lt;P&gt;I tried without configuring the NIC IP addresses first, as well as trying configuring the NIC IP addresses beforehand.&amp;nbsp; I tried without having a cluster built first, as well as building a failover cluster without storage before running the network intent command.&amp;nbsp; The error I posted below shows my last attempt after having the NICs configured with IP addresses and having a failover cluster established before running the command.&amp;nbsp; The error has remained the same throughout the process.&lt;/P&gt;&lt;P&gt;Has anyone else run into an issue like this with switchless storage?&amp;nbsp; It seems like everything that I am trying to do is within scope and should be a supported solution.&amp;nbsp; My fallback plan is to use my existing switches, but that drops my connection speeds down from 25 Gbps to 10 Gbps due to hardware limitations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 15:12:37 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/unable-to-build-switchless-storage-using-network-atc/m-p/4535795#M13080</guid>
      <dc:creator>Slivers</dc:creator>
      <dc:date>2026-07-10T15:12:37Z</dc:date>
    </item>
    <item>
      <title>PowerShell DSC Pullserver stops working with SQL database</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/powershell-dsc-pullserver-stops-working-with-sql-database/m-p/4535199#M13076</link>
      <description>&lt;P&gt;After updating Windows Server 2025, our DSC Pull Server stopped communicating with its SQL backend database. The issue was not present before the update, and reverting to the previous version of Microsoft.PowerShell.DesiredStateConfiguration.Service.dll immediately restored normal functionality.&lt;/P&gt;&lt;P&gt;With the newer DLL version, the service starts successfully and the endpoint remains available, but no connection is established to the SQL Server database. As a result, database initialization does not occur, required tables are not created or updated, and node registration fails. No database sessions are observed on the SQL Server during registration attempts, indicating that the service does not reach the SQL connection phase.&lt;/P&gt;&lt;P&gt;We compared the previous working DLL version with the updated version and confirmed that the regression is introduced by the newer DLL. Replacing the updated DLL with the earlier version consistently restores SQL database connectivity and normal Pull Server Operation.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jul 2026 07:10:23 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/powershell-dsc-pullserver-stops-working-with-sql-database/m-p/4535199#M13076</guid>
      <dc:creator>PatHel</dc:creator>
      <dc:date>2026-07-09T07:10:23Z</dc:date>
    </item>
    <item>
      <title>Installing NDES on Windows 2025, Virtual Directories "CertSrv\mscep" and "mscep_admin" are missing.</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/installing-ndes-on-windows-2025-virtual-directories-quot-certsrv/m-p/4534730#M13065</link>
      <description>&lt;P&gt;Installing NDES on Windows 2025 the installation ends with no errors, but Virtual Directories "CertSrv\mscep" and "mscep_admin" is missing.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Regards Ib Tornøe&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 06:54:33 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/installing-ndes-on-windows-2025-virtual-directories-quot-certsrv/m-p/4534730#M13065</guid>
      <dc:creator>IbTornoee</dc:creator>
      <dc:date>2026-07-08T06:54:33Z</dc:date>
    </item>
    <item>
      <title>Storage migration service operational log is empty</title>
      <link>https://techcommunity.microsoft.com/t5/windows-admin-center/storage-migration-service-operational-log-is-empty/m-p/4534041#M2796</link>
      <description>&lt;P&gt;Hi I can not find logs for operational but only for debug and admin for Storagemigrationservice and storagemigrationservice-proxy.&lt;/P&gt;&lt;P&gt;I justy disable and re-enable operational log from the gui and also from powershell but nothing change.&lt;/P&gt;&lt;P&gt;There is some trick in the registry? I find the registration in&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\ProgramData\Microsoft\StorageMigrationService but there is a edb and their relative logs that are not txt format.&lt;/P&gt;&lt;P&gt;I need to trace the duration of the past process because I need to sync the migration in scheduled manner&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2026 09:38:11 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-admin-center/storage-migration-service-operational-log-is-empty/m-p/4534041#M2796</guid>
      <dc:creator>agobum365</dc:creator>
      <dc:date>2026-07-06T09:38:11Z</dc:date>
    </item>
    <item>
      <title>Windows Server 2022 File Server Cluster | Network Teaming</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/windows-server-2022-file-server-cluster-network-teaming/m-p/4533881#M13059</link>
      <description>&lt;P&gt;Hello Microsoft Community,&lt;/P&gt;&lt;P&gt;I have a Windows Server 2022 File Server Cluster (all physical nodes) running with SMB shares. At present, it is not configured with NIC teaming.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are planning to setup NIC teaming.&amp;nbsp; I am going to add an additional network adapter to achieve this.&lt;/P&gt;&lt;P&gt;Since this is a production file server server. It tried to perform NIC teaming in a test environment. Upon setting up network teaming, File server clustered roles do not come online and fail. It registers an Event ID 1049 about duplicate IPs despite the fact that I have deleted old network adapter via device manager (show hidden devices). New network adapter comes online without any previous knowledge of IPs. When setting up old IP scheme on a new individual network adapter, File server clustered roles come online successfully. However, setting up the old IP scheme on teamed network adapter, it registers Event ID 1049 about duplicate IPs and roles shows a status of Failed instead of Stopped. Duplicate IPs are only registered for clustered file server roles. They are not registered for node IPs and cluster management IPs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be a best way to achieve network teaming on an existing file server cluster without setting up the cluster from scratch?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2026 02:59:01 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/windows-server-2022-file-server-cluster-network-teaming/m-p/4533881#M13059</guid>
      <dc:creator>aleemsyed12</dc:creator>
      <dc:date>2026-07-08T02:59:01Z</dc:date>
    </item>
    <item>
      <title>Issue with winlogon on Remote Desktop Services:</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/issue-with-winlogon-on-remote-desktop-services/m-p/4532091#M13050</link>
      <description>&lt;P&gt;We are investigating intermittent session establishment failures on Windows Server 2019 servers used as CyberArk PSM / RDS hosts.&lt;/P&gt;&lt;P&gt;At unspecified intervals, new privileged sessions fail to establish or are disconnected during the initial session/logon phase. The issue is intermittent and affects new sessions. Existing sessions may continue to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The strongest and most consistent correlation identified so far is:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Microsoft-Windows-TerminalServices-LocalSessionManager/Operational – Event ID 36&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Application / Microsoft-Windows-Winlogon – Event ID 4005&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We observed that TerminalServices-LocalSessionManager Event ID 36 can occur without a subsequent Winlogon Event ID 4005. However, every observed Winlogon Event ID 4005 is correlated with TerminalServices-LocalSessionManager Event ID 36 in the same incident window.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This suggests that Event ID 36 is a consistent precursor or required condition for the Winlogon 4005 cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Operating system: Windows Server 2019&lt;/P&gt;&lt;P&gt;Role: CyberArk PSM / RDS session host&lt;/P&gt;&lt;P&gt;Issue type: intermittent failure during new RDP/PSM session initialization&lt;/P&gt;&lt;P&gt;Impact: affected users cannot establish privileged sessions or are disconnected during session startup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Similar issue exists on previous windows server 2012 R2 and was fixed : August 16, 2016 – KB3179574 (During virtual channel management, a deadlock condition occurs that prevents the RDS service from accepting new connections.)&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="lia-external-url" href="https://support.microsoft.com/en-us/topic/august-2016-update-rollup-for-windows-8-1-and-windows-server-2012-r2-d472b5d5-4b3a-8e6e-c22a-f62fed604caf" target="_blank"&gt;https://support.microsoft.com/en-us/topic/august-2016-update-rollup-for-windows-8-1-and-windows-server-2012-r2-d472b5d5-4b3a-8e6e-c22a-f62fed604caf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I'm looking forward for any ideas how to resolve this issue. Many thanks!!&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 09:14:49 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/issue-with-winlogon-on-remote-desktop-services/m-p/4532091#M13050</guid>
      <dc:creator>kris1975</dc:creator>
      <dc:date>2026-06-30T09:14:49Z</dc:date>
    </item>
    <item>
      <title>Server 2025 to server 2022 downgrade keys</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/server-2025-to-server-2022-downgrade-keys/m-p/4531971#M13049</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We bought licenses with these part #'s MFR# P73-08495 and MFR# EP2-25187 which, according to searches on the internet, have downgrade rights.&lt;/P&gt;&lt;P&gt;We need to get downgrade keys for server 2022 standard.&lt;/P&gt;&lt;P&gt;Our reseller referred us to Microsoft for this.&lt;/P&gt;&lt;P&gt;Could someone help? The activation portal does not give us an option to do this and a microsoft support agent told us to make a post here which seems weird to us. We don't know why they couldn't help us via the phone.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 22:56:09 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/server-2025-to-server-2022-downgrade-keys/m-p/4531971#M13049</guid>
      <dc:creator>Tonyams</dc:creator>
      <dc:date>2026-06-29T22:56:09Z</dc:date>
    </item>
    <item>
      <title>Windows Server 2025 Failover Cluster Live Migration Issue</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/windows-server-2025-failover-cluster-live-migration-issue/m-p/4531427#M13048</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I am facing an issue in a Hyper-V Failover Cluster environment where Live Migration intermittently fails due to a service logon-related problem. The environment was previously working normally, but now whenever we attempt to Live Migrate a VM between cluster nodes, the migration fails unless we manually run “gpupdate /force” on the Hyper-V host first.&lt;/P&gt;&lt;P&gt;After running gpupdate /force, the migration works temporarily, but the issue returns again during the next migration attempt. This makes it appear that some policy or permission is not being applied consistently on the cluster nodes.&lt;/P&gt;&lt;P&gt;During troubleshooting, I attempted to add “NT VIRTUAL MACHINE\Virtual Machines” to the “Log on as a service” policy under Local Security Policy &amp;gt; Local Policies &amp;gt; User Rights Assignment. However, the account does not appear or resolve in the Object Picker when trying to add it manually.&lt;/P&gt;&lt;P&gt;At this stage, I am trying to understand whether this is related to a domain GPO overwriting local policy settings, a Failover Cluster permission issue, or something specific to Hyper-V virtual machine accounts.&lt;/P&gt;&lt;P&gt;Has anyone encountered a similar issue where Live Migration only works after running gpupdate /force? Also, is there a correct method to add “NT VIRTUAL MACHINE\Virtual Machines” to the “Log on as a service” policy, or should this permission already exist by default on Hyper-V hosts?&lt;/P&gt;&lt;P&gt;Any guidance or recommendations would be greatly appreciated.&lt;/P&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;img /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jun 2026 03:06:15 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/windows-server-2025-failover-cluster-live-migration-issue/m-p/4531427#M13048</guid>
      <dc:creator>madushan_gunarathne</dc:creator>
      <dc:date>2026-06-27T03:06:15Z</dc:date>
    </item>
    <item>
      <title>Windows Admin Center version 2606 is now generally available!</title>
      <link>https://techcommunity.microsoft.com/t5/windows-admin-center-blog/windows-admin-center-version-2606-is-now-generally-available/ba-p/4530811</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;SPAN data-contrast="none"&gt;July 9th, 2026: The Windows Admin Center installer has been updated to build number 2.7.4. This build includes multiple security improvements such as correcting elevation of privilege and remote code execution. There are no other functionality changes in this build.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;We're pleased to announce the availability of the latest release for Windows Admin Center, version 2606!&lt;/P&gt;
&lt;P&gt;This update focuses on improving the overall reliability, accessibility, security, and user experience of the platform based on customer feedback and development partner-reported issues. It delivers important quality improvements that make everyday administration smoother and more dependable.&lt;/P&gt;
&lt;P&gt;Version 2606 is exclusively an Administration Mode release. Not sure what this means? Check out our &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-admin-center-blog/windows-admin-center-architectural-changes/4488583" target="_blank" rel="noopener" data-lia-auto-title="blog post" data-lia-auto-title-active="0"&gt;blog post&lt;/A&gt; explaining the differences between “Windows Admin Center: Administration Mode” and “Windows Admin Center: Virtualization Mode.”&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;We know we updated version 2511 multiple times. We're exploring a more frequent release cadence in the future so that new features, enhancements, and fixes reach you sooner.&lt;/P&gt;
&lt;P&gt;If you'd like to see more frequent releases, give this post a 👍🏼. We'd also love your feedback. Share your thoughts in the comments and let us know what release cadence works best for you!&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;H1&gt;The Windows Admin Center: Virtualization Mode public preview build has been updated&lt;/H1&gt;
&lt;P&gt;Earlier this year, we announced an &lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-admin-center-blog/announcing-windows-admin-center-virtualization-mode-public-preview-2/4508937" target="_blank" rel="noopener" data-lia-auto-title="update to the public preview build" data-lia-auto-title-active="0"&gt;update to the public preview build&lt;/A&gt; of Windows Admin Center: Virtualization Mode. We’ve reviewed the ample feedback and have refreshed the build again to address critical bugs and asks. Check out the&amp;nbsp;&lt;A class="lia-internal-link lia-internal-url lia-internal-url-content-type-blog" href="https://techcommunity.microsoft.com/blog/windows-admin-center-blog/the-windows-admin-center-virtualization-mode-public-preview-build-has-been-updat/4527304" target="_blank" rel="noopener" data-lia-auto-title=" latest blog post " data-lia-auto-title-active="0"&gt; latest blog post&lt;/A&gt; to learn more!&lt;/P&gt;
&lt;H1&gt;What’s new in Windows Admin Center 2606&lt;/H1&gt;
&lt;H2&gt;Platform updates&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;Fixed an issue where users trying to install on a standalone machine with a non-English OS were receiving an error message about high availability installations not being supported&lt;/LI&gt;
&lt;LI&gt;Fixed an issue where users were unable to add Allowed Groups containing spaces in the Access tab of gateway settings&lt;/LI&gt;
&lt;LI&gt;Hardened security posture&lt;/LI&gt;
&lt;LI&gt;Addressed major accessibility issues
&lt;UL&gt;
&lt;LI&gt;Improvements to keyboard navigation, dialog accessibility, screen reader support, and ARIA compliance across key management experiences&lt;/LI&gt;
&lt;LI&gt;Common workflows are now easier to navigate using assistive technologies and help improve compliance with accessibility standards&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H2&gt;Extension updates&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;The GPU tool is now available for Windows Server 2025 standard edition&lt;/LI&gt;
&lt;LI&gt;Fixed &lt;A class="lia-external-url" href="https://learn.microsoft.com/windows-server/manage/windows-admin-center/support/known-issues#incorrect-deletions-in-volumes-tool" target="_blank" rel="noopener"&gt;an issue with volume deletion operations&lt;/A&gt; present in versions of the Cluster Manager extension lower than 5.2.6&lt;/LI&gt;
&lt;LI&gt;Fixed an issue where scheduled task status was not changing after starting task&lt;/LI&gt;
&lt;LI&gt;Import VM
&lt;UL&gt;
&lt;LI&gt;A network summary has been added to the review tab of the Import VM workflow&lt;/LI&gt;
&lt;LI&gt;Fixed an issue where the VHD destination was not displaying correctly in the Storage Summary section of the review tab of the Import VM workflow&lt;/LI&gt;
&lt;LI&gt;Fixed an issue where VM name was not displaying correctly in the Review tab of the Import VM workflow&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Fixed an issue where copying a physical hard disk in virtual machine settings was not working&lt;/LI&gt;
&lt;LI&gt;Increased maximum network adapter limits for Gen2 virtual machines from 8 to 64 (8 is still the Gen1 virtual machine maximum)&lt;/LI&gt;
&lt;LI&gt;Updated Secure Boot logic and status in the Security tool with clearer messaging and next steps&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;
&lt;img /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Improved error handling in the platform and tools such as Files &amp;amp; file shares, Processes, Virtual machines, and Services&lt;/LI&gt;
&lt;LI&gt;Software-defined networking (SDN)
&lt;UL&gt;
&lt;LI&gt;Virtual networks
&lt;UL&gt;
&lt;LI&gt;We now block deletion of virtual networks and deletion and editing of virtual subnets that are in use by virtual gateways. Previously, customers were accidentally modifying these resources which would result in a failed provisioning state.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Implemented critical bug fixes such as allowing the removal of network security groups from the virtual subnet resource&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Virtual gateway
&lt;UL&gt;
&lt;LI&gt;Included a host IP form field to support a critical fix in the l3 fast path feature. &amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Added an option for users to set the unit of measurement for their bandwidth allocation&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Logical networks
&lt;UL&gt;
&lt;LI&gt;Implemented a bugfix that allows users to update their logical networks with default network policies (no address prefix)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Partner Ecosystem&lt;/H1&gt;
&lt;P&gt;The Windows Admin Center management experience would not be complete without our development partners, who make managing your hardware and firmware through Windows Admin Center a streamlined experience. Since the last generally available release of Windows Admin Center, two partners have made updates to their extensions.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The &lt;STRONG&gt;Dell OpenManage&lt;/STRONG&gt; &lt;STRONG&gt;Integration&lt;/STRONG&gt; extension has been upgraded to version &lt;STRONG&gt;3.6.0&lt;/STRONG&gt;—this version contains the following improvements:
&lt;UL&gt;
&lt;LI&gt;Hardware Alert Polling - Provides configurable hardware alert polling, and severity thresholds to ensure timely and consistent notifications across all servers and clusters.&lt;/LI&gt;
&lt;LI&gt;WDAC support for Windows Server 2025 - OMIMSWAC is supported on Windows Server 2025 with Windows Defender Application Control (WDAC) enabled by using Dell provided supplemental policies.&lt;/LI&gt;
&lt;LI&gt;Custom Hardware Alert Configuration - Allows user to configure or remove iDRAC hardware alerts at the cluster or individual node level by offering granular control over alert categories, subcategories, and severity.&lt;/LI&gt;
&lt;LI&gt;Warranty Status Improvements - Improves the accuracy of warranty reporting by identifying cases where node data is unavailable and marking them as Unknown. Adds node-level warranty information in tooltips for quicker insight and easier diagnostics&lt;/LI&gt;
&lt;LI&gt;Azure Policies Onboarding Quota Handling - Provides clear information when Azure policy onboarding fails due to quota restrictions and provide guidance to help resolve the issue efficiently.&lt;/LI&gt;
&lt;LI&gt;Enhanced Hardware Configuration Policies - Extended configuration compatibility for HCP/SCP (on‑premises) and Azure onboarding policies by recognizing either On or Last as compliant for AC Power Recovery settings&lt;/LI&gt;
&lt;LI&gt;BitLocker Improvements - Ensures more reliable BitLocker management during updates and cluster expansion by reliably suspending and resuming protection. Restores the original state regardless of job status as failure, cancellation, or successful completion.&lt;/LI&gt;
&lt;LI&gt;Added support for Multi Cloud (APEX MC) platform for Azure Local.&lt;/LI&gt;
&lt;LI&gt;Added support for PowerEdge 17G models: R7725xd and R770AP&lt;/LI&gt;
&lt;LI&gt;Added support for IPv6 while connecting with iDRAC through Remote NDIS adapter.&lt;/LI&gt;
&lt;LI&gt;HCI Configuration Profile is enhanced to support a minimum of two storage drives for Azure Stack HCI operating system per server for all-flash configurations.&lt;/LI&gt;
&lt;LI&gt;AX 16G clusters now support mixed processor generations, allowing Sapphire Rapids and Emerald Rapids based nodes to run together for greater deployment flexibility&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;The Fujitsu ServerView Health extension has been rebranded to&amp;nbsp;&lt;STRONG&gt;FSAS Technologies ServerView Health&lt;/STRONG&gt; with the extension ID fsastech.sme.serverview.health-extension—this extension has also been upgraded to Angular 15&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;The Fujitsu ServerView RAID extension has been rebranded to &lt;STRONG style="color: rgb(30, 30, 30);"&gt;FSAS Technologies ServerView RAID&lt;/STRONG&gt;&lt;SPAN style="color: rgb(30, 30, 30);"&gt; with the extension ID fsastech.sme.serverview.raid-extension—this extension has also been upgraded to Angular 15&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;H1&gt;Download today!&lt;/H1&gt;
&lt;P&gt;Thanks for reading along and continuing to support Windows Admin Center!&amp;nbsp;We hope you enjoy this new version and the various new functionality now available.  &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A class="lia-external-url" href="https://aka.ms/DownloadWAC" target="_blank" rel="noopener"&gt;Download now!&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As always, thanks for your ongoing support, adoption, and feedback. Your contributions through &lt;A class="lia-external-url" href="https://aka.ms/wacfeedback" target="_blank" rel="noopener"&gt;user feedback&lt;/A&gt; continue to be vital and valuable to us, helping us prioritize and sequence our investments. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows&amp;nbsp;Admin Center is continuously evolving and growing as a tool and a platform, and we are beyond thrilled to&amp;nbsp;have you part of our journey. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;  &lt;/P&gt;
&lt;P&gt;Thank you, &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Windows Admin Center Team (@servermgmt) &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2026 17:31:05 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-admin-center-blog/windows-admin-center-version-2606-is-now-generally-available/ba-p/4530811</guid>
      <dc:creator>Davanna-White</dc:creator>
      <dc:date>2026-07-10T17:31:05Z</dc:date>
    </item>
    <item>
      <title>Secure Boot update still pending on deadline day</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/secure-boot-update-still-pending-on-deadline-day/m-p/4530646#M13044</link>
      <description>&lt;P&gt;After checking the registry keys on 2x VMs which run services for a number of important customers I found they both have:&lt;/P&gt;&lt;P&gt;UEFICA2023Error 2147942750&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apparently this means they're pending a reboot.&lt;/P&gt;&lt;P&gt;https://blog.mindcore.dk/2026/04/secure-boot-certificate-update-intune/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't reboot the VM inside working hours, can they be rebooted after the deadline or do I need to disable Secure Boot on the VMs?&lt;/P&gt;&lt;P&gt;I'm concerned I'll have to disable Secure Boot before they're next rebooted for Windows updates.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2026 13:54:32 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/secure-boot-update-still-pending-on-deadline-day/m-p/4530646#M13044</guid>
      <dc:creator>LouisT</dc:creator>
      <dc:date>2026-06-24T13:54:32Z</dc:date>
    </item>
    <item>
      <title>Save the date: Secure Boot Q&amp;A in July</title>
      <link>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/save-the-date-secure-boot-q-a-in-july/m-p/4530397#M13042</link>
      <description>&lt;P&gt;To help, Microsoft is continuing its Q&amp;amp;A series with several opportunities to connect directly with Microsoft experts. Whether you're managing physical servers, virtualized workloads, or working with your hardware partners on firmware readiness, you can get answers to the questions that matter most to your environment.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Learn more and add the events to your calendar:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;8:00 AM PDT July 1 - &lt;A href="https://techcommunity.microsoft.com/event/windowsevents/windows-server-secure-boot-ama/4529322" target="_blank" rel="noopener" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;Windows Server Secure Boot AMA&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;8:00 AM PDT July 8 -&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/event/windowsevents/secure-boot-office-hours-for-virtualized-environments/4530355" target="_blank" rel="noopener" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;Secure Boot Office Hours for virtualized environments&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;7:00 AM - 7:00 PM PDT July 15 -&amp;nbsp;&lt;A href="https://techcommunity.microsoft.com/event/windowsevents/oem-secure-boot-office-hours/4530352" target="_blank" rel="noopener" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;OEM Secure Boot Office Hours&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If there's a question that's been holding up your rollout—or one you simply want to validate before moving forward—this is a great opportunity to ask. Feel free to post questions ahead of time or join the conversation live. We look forward to seeing you there.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jun 2026 23:44:27 GMT</pubDate>
      <guid>https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/save-the-date-secure-boot-q-a-in-july/m-p/4530397#M13042</guid>
      <dc:creator>Heather_Poulsen</dc:creator>
      <dc:date>2026-06-23T23:44:27Z</dc:date>
    </item>
  </channel>
</rss>

