Windows 11 Pro 25H2 Build 26200: VBS and Hypervisor remain running after all related features are disabled, preventing VMware nested virtualization

Shyam Narayan Gupta 0 Reputation points
2026-09-18T20:07:58.58+00:00

 issue

Hello Microsoft Support,

I am experiencing an issue with Windows 11 Pro where Virtualization-Based Security (VBS) and the Microsoft hypervisor remain active even after I have disabled Hyper-V, VBS, HVCI/Memory Integrity, Credential Guard, Virtual Machine Platform, Windows Hypervisor Platform, and related settings.

This is preventing VMware Workstation from providing nested Intel VT-x/EPT virtualization to my virtual machine.

System information

  • OS: Windows 11 Pro
  • Version: 25H2
  • Build: 26200
  • Device: Lenovo 83A0
  • Processor: Intel64 Family 6 Model 186
  • BIOS: Lenovo MCCN39WW
  • Hardware virtualization/Intel VT-x: Enabled in BIOS
  • VMware Workstation is installed

Problem

VMware reports that virtualized Intel VT-x/EPT is not supported/available when trying to start a VM that requires nested virtualization.

Windows continues to report:

1 Virtualization-based security: Status: Running

2 Hyper-V Requirements: A hypervisor has been detected.

  PowerShell also reports:

HyperVisorPresent


True

1 VirtualizationBasedSecurityStatus : 2

2 SecurityServicesConfigured : {0}

3 SecurityServicesRunning : {0}

Troubleshooting already performed

  1. Disabled Hyper-V.
  2. Disabled Windows Hypervisor Platform.
  3. Disabled Virtual Machine Platform.
  4. Disabled Windows Subsystem for Linux.
  5. Disabled Memory Integrity/HVCI.
  6. Disabled Credential Guard configuration.
  7. Disabled VBS through Device Guard configuration.
  8. Disabled Smart App Control.
  9. Set the following boot configuration:

1 hypervisorlaunchtype Off

2 vsmlaunchtype Off

  1. Verified the Device Guard registry configuration:

1 EnableVirtualizationBasedSecurity = 0

2 RequirePlatformSecurityFeatures = 0

  1. Verified HVCI configuration:

1 Enabled = 0

2 Locked = 0

  1. Verified Credential Guard configuration:

1 LsaCfgFlags = 0

  1. Ran the Microsoft Device Guard and Credential Guard Readiness Tool v3.6 with the Disable option.
  2. Performed full shutdowns/restarts after configuration changes.

Despite all of the above, Windows still reports:

1 HyperVisorPresent = True

2 VirtualizationBasedSecurityStatus = 2

and systeminfo continues to report:

1 Virtualization-based security: Status: Running

2 App Control for Business policy: Enforced

3 App Control for Business user mode policy: Off

4 Hyper-V Requirements: A hypervisor has been detected.

  Earlier CiTool.exe --list-policies output also showed Microsoft platform policies including:

Plain Text

1 Microsoft Windows Virtualization Based Security Policy

2 Microsoft Windows Endpoint Security Policy

3 Microsoft Windows Driver Policy

as currently enforced.

 

 

Request to Microsoft

Could you please investigate why VBS and the Windows hypervisor remain active despite the relevant Windows features, BCD settings, registry settings, HVCI, Credential Guard, and VBS configuration being disabled?

Specifically, I would like Microsoft to confirm:

  1. What component or platform policy is starting the hypervisor on this Windows 11 25H2 build?
  2. Whether the Microsoft Windows Virtualization Based Security Policy or another inbox/platform Code Integrity policy is responsible.
  3. Whether this behavior is expected on Windows 11 25H2 Build 26200.
  4. What Microsoft-supported method can completely disable VBS/the Windows hypervisor so VMware Workstation can expose Intel VT-x/EPT for nested virtualization.

Please advise on the supported remediation or collect any required diagnostic logs.

Thank you.

 

Windows for business | Windows Client for IT Pros | Storage high availability | Virtualization and Hyper-V
0 comments No comments

1 answer

Sort by: Most helpful
  1. Allan Solomon Mejia 9,820 Reputation points
    2026-09-18T21:10:53.2933333+00:00

    Hello @Shyam Narayan Gupta

    On Windows 11 25H2, disabling the Hyper-V optional feature alone does not necessarily mean the Windows hypervisor is no longer running.

    Features such as Virtualization-Based Security (VBS), Memory Integrity/HVCI, Credential Guard, and certain App Control policies can use the Windows hypervisor independently. Microsoft specifically documents that VBS uses the hypervisor to create its isolated security environment.

    First, confirm the actual state rather than relying only on the Windows Features dialog. Run:

    Get-CimInstance -ClassName Win32_DeviceGuard `
      -Namespace root\Microsoft\Windows\DeviceGuard |
    Select-Object VirtualizationBasedSecurityStatus,
                  SecurityServicesConfigured,
                  SecurityServicesRunning,
                  CodeIntegrityPolicyEnforcementStatus
    

    Microsoft documents VirtualizationBasedSecurityStatus as:

    0 = VBS isn't enabled

    1 = VBS enabled but not running

    2 = VBS enabled and running

    You can also run msinfo32. If System Information says:

    A hypervisor has been detected.

    Features required for Hyper-V will not be displayed.

    then the Windows hypervisor is still active. I recommend this check when troubleshooting third-party virtualization applications.

    If the goal is to run software such as VMware or VirtualBox without the Windows hypervisor, check all of the components that can keep it active:

    • Windows Security → Device security → Core isolation → Memory integrity
    • Windows Features → Hyper-V, Virtual Machine Platform, and Windows Hypervisor Platform
    • Group Policy → Computer Configuration → Administrative Templates → System → Device Guard → Turn On Virtualization Based Security
    • Credential Guard configuration
    • Any App Control for Business/WDAC policies

    The last one is particularly worth checking. Microsoft documents that an App Control policy can enable Memory Integrity/HVCI, even when the policy is operating in audit mode.

    You can also check the boot configuration:

    bcdedit /enum {current}
    

    Look for hypervisorlaunchtype

    If you're intentionally trying to prevent the hypervisor from starting, Microsoft's troubleshooting guidance also covers disabling Hyper-V and its dependent security features.

    Don't delete Code Integrity policies or manually change EFI/UEFI files. If VBS still reports 2 after the normal Hyper-V, Memory Integrity, and Credential Guard settings have been disabled, the next useful information would be:

    Get-CimInstance -ClassName Win32_DeviceGuard `
      -Namespace root\Microsoft\Windows\DeviceGuard
    

    together with:

    bcdedit /enum {current}
    

    and the Virtualization-based security section from msinfo32. That should tell us whether HVCI/VBS, an App Control policy, or another virtualization-dependent security feature is still driving it.

    Microsoft also describes the conflict with some third-party virtualization software as by design, rather than automatically indicating a Windows 11 25H2 defect.

    References:

    Enable Memory Integrity / VBS

    Hyper-V and third-party virtualization applications

    How Credential Guard works


    Help make this community better for everyone: If this answer helped or resolved your issue, please accept it or upvote it. If not, share more details in a comment so we can continue the discussion and find the right solution. Thank you.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.