Mastering Secure Boot and TPM for Enhanced VM Security

Mastering Secure Boot and TPM for Enhanced VM Security

David Lv13

Mastering Secure Boot and TPM for Enhanced VM Security

VirtualBox released version 7.0 in October 2022. It is the first hypervisor to support the emulation of TPM chips along with all the other system components. VirtualBox also offers a Secure Boot feature in EFI mode for virtual machines. The main reason behind these two features was Microsoft’s list of elaborate system requirements for Windows 11.

Without emulation of the TPM 2.0 chip, users couldn’t install Windows 11 on a virtual machine. But with VirtualBox 7.0 it is possible to enable Secure Boot and TPM for any Windows virtual machine. This post will elaborate on the methods to enable or disable TPM and Secure Boot for any VirtualBox virtual machine.

Disclaimer: This post includes affiliate links

If you click on a link and make a purchase, I may receive a commission at no extra cost to you.

Why Does Windows 11 Need TPM and Secure Boot?

Windows 11 needs both a TPM chip and Secure Boot to offer robust protection against threats and not allow any malware to run when the system boots up. Secure Boot only allows signed drivers to load and the TPM chip helps in BitLocker drive data protection. So, both these features are pretty important from a security standpoint. Check out our guide onwhat Secure Boot is and how it works for more information.

While Windows 11 can work without Secure Boot and a TPM 2.0 chip, it won’t be able to offer that extra layer of system protection it would do otherwise. Many features like Core-isolation, Data Encryption won’t work. If you want to enable or disable these features for Windows 10 or 11 virtual machines, you can do so in VirtualBox 7.0.

How to Enable or Disable Secure Boot and TPM Support in VirtualBox 7.0

Repeat the following steps to enable TPM 2.0 and Secure Boot in VirtualBox.

  1. Press theWin key and search VirtualBox. Click on the first relevant search result to launch the app.
  2. Click on a Windows virtual machine and then click on theSettings icon.
  3. Navigate to theSystem settings option.
  4. Find theTPM option. If it is set to none, click on thearrow icon to open the drop-down menu.
  5. Select the TPMv2.0 option from the list. Windows 11 won’t work with anything lower but if you are using Windows 10 then you can pickv1.2 from the list.
  6. Scroll down and locate theExtended Features section. Click on theEnable EFI (special OSes only) option check box.
  7. Then click on theEnable Secure Boot option check box.
    Enable Secure Boot and TPM Support in VirtualBox 7.0
  8. Now, click on theOK button. The settings window will close automatically.
  9. Go to the top area and click on theStart button to power on the Windows virtual machine.
  10. Now, press the Win key and search Security. Open theWindows security app.
  11. Navigate to the left-hand side menu and click on theDevice Security option. Here, all Windows security features will be active.
  12. To disable TPM and Secure Boot, reopen the virtual machine settings and set the TPM version toNone . Uncheck theEnable EFI (special OSes only) option check box. Click onOK to save the changes.

An Alternative Method to Check if TPM Is Active in the Windows Virtual Machine

Here’s how to check TPM on Windows 11 virtual machine:

  1. Press theWin + R key to launch the Run command box (seehow to open Windows Run for more ways). TypeTPM.msc and press theEnter key.
    check TPM on Windows 11 virtual machine 1
  2. TPM utility will launch. Navigate to the Manufacturer Information section.

check TPM on Windows 11 virtual machine 2
3. If the Specification version entry showcases 2.0, it means that TPM chip emulation is successful.

Manage TPM and Secure Boot Features in VirtualBox With Ease

You can choose to keep both features active or not. After installing Windows 11 as a virtual machine, you can turn TPM and Secure Boot off and not face any issues with the operating system. However, remember that these are important from a security perspective.

Also read:

  • Title: Mastering Secure Boot and TPM for Enhanced VM Security
  • Author: David
  • Created at : 2024-11-30 20:41:48
  • Updated at : 2024-12-07 05:14:26
  • Link: https://win11.techidaily.com/mastering-secure-boot-and-tpm-for-enhanced-vm-security/
  • License: This work is licensed under CC BY-NC-SA 4.0.