A complete Windows Server 2025 lab running inside Hyper-V on one Windows 11 PC — the exact topology you will build in this guide.
Most Hyper-V tutorials end the moment one empty virtual machine boots — and that is exactly why so many Windows Server 2025 labs collapse the first time someone adds a second domain controller. To build a Hyper-V lab for Windows Server 2025 that survives a real Active Directory build-out, you need the three things most guides skip: a stable internal virtual switch with NAT, a memory plan sized for four VMs instead of one, and checkpoints that let you undo any mistake in seconds.
This is Lesson 004 of the Windows Server 2025: Zero to Admin series, and it walks you through the complete build: enabling Hyper-V on Windows 11, planning an AZ-800-ready topology, understanding virtual switch types the way they actually behave, provisioning your first VMs through both the GUI and PowerShell, and protecting every step with checkpoints. By the end, your host will be ready for Lesson 007, where we install Windows Server 2025 into these machines.
I'm Mostafa Amaan, and on Valley4Techs I write practical, hands-on engineering guides for systems administrators and IT professionals. I've spent more than 16 years managing Windows environments — from multi-branch medical networks (PACS/RIS) to domain controllers serving hundreds of clients — and the habits in this lesson are the same ones I rely on to keep risky experiments inside a disposable lab, never on production servers.
This is Lesson 004 of our complete 66-lesson engineering roadmap. In Lesson 003: Hyper-V vs VMware vs Proxmox we chose the hypervisor — today we build the Hyper-V lab itself. If your hardware suits VMware Workstation or Proxmox better, dedicated build guides arrive in Lessons 005 and 006, and Lesson 001 covers what makes Windows Server 2025 worth installing in the first place.
How Do You Build a Hyper-V Lab for Windows Server 2025?
The whole build breaks down into six steps. Each one follows this series' dual-track method: the graphical way and the PowerShell way, so you learn the tools the AZ-800 exam actually tests.
- Enable Hyper-V on your Windows 11 host (GUI or PowerShell).
- Plan the lab topology — which VMs, how much RAM, which subnet.
- Create the virtual switches and NAT network your domain will live on.
- Create the Windows Server 2025 virtual machines (shells only — installation comes in Lesson 007).
- Protect everything with checkpoints before touching configuration.
- Optional: build a template disk with differencing VHDXs so new VMs take seconds, not gigabytes.
Before You Start: Lab Requirements and Prerequisites
Hyper-V is built into Windows as an optional feature — there is no separate download — but your host still has to meet a few hard requirements. From my experience, most "Hyper-V is missing" support questions trace back to one of these four items, so check them now and save yourself an hour of troubleshooting later.
- Windows edition: Windows 11 (or Windows 10) Pro, Enterprise, or Education, 64-bit. The Hyper-V role cannot be installed on Windows Home editions.
- Processor: a 64-bit CPU with Second Level Address Translation (SLAT) — any Intel VT-x or AMD-V processor from roughly the last decade qualifies — with virtualization enabled in UEFI/BIOS.
- Memory: 16 GB is the practical minimum for a starter lab; 32 GB for the full AZ-800 topology below. Lesson 002 covers full hardware sizing in depth.
- Storage: at least 120 GB of free SSD/NVMe space (about 15–30 GB per Server VM plus the ISO).
- Installation media: the free 180-day evaluation ISO from the Microsoft Evaluation Center — choose Windows Server 2025 | 64-bit ISO.
One more note before we start: if you also use VMware Workstation or VirtualBox on this machine, they will coexist with Hyper-V through the Windows Hypervisor Platform, but you should pick one primary hypervisor per lab machine to avoid CPU scheduling overhead. That decision is exactly what Lesson 003 was for — from here on, this host is Hyper-V territory.
Step 1: Enable Hyper-V on Windows 11 (GUI & PowerShell)
Enabling Hyper-V installs the hypervisor layer plus the two tools you will live in: Hyper-V Manager (GUI) and the Hyper-V PowerShell module. Your PC will restart to complete the installation, so save your work first.
Method A: Turn Windows Features On or Off (GUI)
This is the route you'll see in every screenshot-laden tutorial, and it's perfectly fine for a one-time setup:
- Press Start, type Control Panel, and open it.
- Go to Programs → Programs and Features.
- Select Turn Windows features on or off.
- Expand the Hyper-V entry and make sure Hyper-V Management Tools and Hyper-V Platform are both checked.
- Select OK, then restart the PC when prompted.
Method B: PowerShell (One Command)
Faster, scriptable, and it installs the exact same components. Open PowerShell as Administrator (right-click Start → Terminal (Admin)) and run:
Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All
Type Y to let the computer restart. If you prefer the classic DISM tool, this is equivalent:
DISM /Online /Enable-Feature /All /FeatureName:Microsoft-Hyper-V
After the restart, verify that everything is in place. The feature should report Enabled:
Get-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V
Get-VMHost
When Get-VMHost
returns your host's name and default paths without errors, the hypervisor is running. For reference, this
matches the official
Microsoft
Learn instructions for installing Hyper-V.
Figure 1: Both Hyper-V sub-components must be checked — tools alone will install the Manager but not the hypervisor itself.
Step 2: Plan Your Lab Topology (The AZ-800 Blueprint)
Creating VMs one at a time with random names is how labs become junk drawers. Before touching Hyper-V Manager, decide what you're building. This series targets the AZ-800 skill set, which means a small Active Directory domain: two domain controllers, one member server, and a Windows 11 client.
| VM | Role in the Lab | vCPU | RAM (Dynamic) | Disk |
|---|---|---|---|---|
| DC1 | Primary DC, DNS, DHCP | 2 | 512 MB – 4 GB (start 2 GB) | 60 GB dynamic VHDX |
| DC2 | Secondary DC (replication) | 2 | 512 MB – 4 GB (start 2 GB) | 60 GB dynamic VHDX |
| SRV1 | Member server (file/print, later roles) | 2 | 512 MB – 4 GB (start 2 GB) | 60 GB dynamic VHDX |
| CL1 | Windows 11 client (GPO tests) | 2 | 1 GB – 6 GB (start 4 GB) | 80 GB dynamic VHDX |
With Dynamic Memory enabled, these four VMs idle at roughly 5–6 GB combined and burst toward 18 GB under load — which is why a 32 GB host is comfortable and 16 GB works if you run two VMs at a time. Keep every VM in one dedicated folder tree so you can move or back up the entire lab in a single operation:
D:\Lab\
├── ISOs\ ← Windows Server 2025 & Windows 11 evaluation ISOs
├── Templates\ ← clean sysprepped base VHDX (Step 6)
└── VMs\
├── DC1\
├── DC2\
├── SRV1\
└── CL1\
Finally, fix your IP plan now, before any VM exists. We will place the whole lab on an internal network behind NAT: the switch itself uses 192.168.200.0/24, the host gateway is 192.168.200.1, and VMs get static addresses starting at .11 (DC1 .11, DC2 .12, SRV1 .21, CL1 .31). Writing this down today is what prevents the classic "why can't DC1 reach DC2?" mystery when we promote the domain in Lesson 014.
📥 Planning a bigger, multi-subnet lab? In Lesson 010 — Design Your Windows Server 2025 Lab: Topology, IP Scheme & Sizing — we publish a printable Lab Topology & IP Subnetting Planning Sheet so you can architect multi-site Active Directory environments on paper before provisioning a single VM. Subscribe below to get the free toolkit ↓
Step 3: Hyper-V Virtual Switch Types Explained (Default vs Internal vs External)
Networking is where most Hyper-V labs are built wrong. Hyper-V gives you four switch types, and picking the wrong one doesn't fail immediately — it fails two weeks later when your domain controllers reboot. Here is what each type actually allows:
| Switch Type | VM ↔ VM | VM ↔ Host | Internet | Best Use in Your Lab |
|---|---|---|---|---|
| Default Switch | ✔ | ✔ | ✔ (NAT) | One quick VM that just needs internet |
| Internal | ✔ | ✔ | Only if you add NAT | Stable AD lab network (our choice) |
| Private | ✔ | ✘ | ✘ | Isolated test segments (malware labs) |
| External | ✔ | ✔ | ✔ (bridged) | VMs that must appear on your real LAN |
The Default Switch Problem in an Active Directory Lab
The Default Switch that appears automatically after enabling Hyper-V is a NAT switch: your VMs get an IP from an internal DHCP and share the host's internet connection. For a single throwaway VM, it's magic. For a domain lab, it's a trap — its subnet changes every time the host reboots or switches Wi-Fi networks (it may be 172.20.x.x today and 192.168.137.x tomorrow). Any static IP you assigned to a domain controller silently stops working, DNS breaks, and the whole domain falls over.
That's why the standard default switch vs internal switch decision for labs is not really a decision: an internal switch gives you a subnet you fully control, keeps VM-to-host communication, and — once you attach a NAT gateway — still reaches the internet. This is the design we'll implement now.
Create the Internal Switch and NAT Gateway (GUI & PowerShell)
GUI: open Hyper-V Manager → Virtual Switch Manager → select Internal → Create Virtual Switch → name it LabSwitch → OK. The NAT gateway itself can only be configured in PowerShell:
# 1. Create the internal switch (skip if created via GUI)
New-VMSwitch -SwitchName "LabSwitch" -SwitchType Internal
# 2. Find the new adapter's InterfaceAlias
Get-NetAdapter
# 3. Give the host side of the switch its gateway IP
New-NetIPAddress -IPAddress 192.168.200.1 -PrefixLength 24 `
-InterfaceAlias "vEthernet (LabSwitch)"
# 4. Turn the subnet into a NAT network
New-NetNat -Name "LabNat" `
-InternalIPInterfaceAddressPrefix 192.168.200.0/24
New-NetNat
fails or Docker/WSL already owns a NAT, check with
Get-NetNat
and remove the stale entry with
Get-NetNat | Remove-NetNat
first. Details are in Microsoft's
NAT
network guide.
Your VMs will use static IPs in 192.168.200.0/24 with gateway 192.168.200.1. For name resolution until DNS exists, point them temporarily at 1.1.1.1; once DC1 is promoted in Stage 2, your own DNS server takes over. For deeper switch configuration options, see Microsoft's virtual switch documentation.
Figure 2: LabSwitch is internal — the NAT gateway that gives it internet access is added with PowerShell in the next command block.
Step 4: Create Your Windows Server 2025 Virtual Machines
In this lesson we build the VM shells and attach the ISO; the actual operating system installation happens in Lesson 007. Always choose Generation 2 for new VMs — it uses UEFI, supports Secure Boot and VHDX boot, and is what modern Windows Server expects. Generation 1 exists only for legacy 32-bit guests you will never need in this series.
Method A: New Virtual Machine Wizard (GUI)
- In Hyper-V Manager, select Action → New → Virtual Machine, then Next.
- Name it DC1 and (optionally) tick Store the virtual machine in a different location, pointing to D:\Lab\VMs\DC1.
- Choose Generation 2.
- Assign 2048 MB startup memory and tick Use Dynamic Memory.
- On the networking page, connect it to LabSwitch.
- Create a 60 GB virtual hard disk (dynamic is fine for labs).
- On Installation Options, choose Install an operating system from a bootable image file and select your Windows Server 2025 ISO, then Finish.
Method B: PowerShell (Build DC1 in Six Commands)
New-VM -Name "DC1" -Generation 2 -MemoryStartupBytes 2GB `
-NewVHDPath "D:\Lab\VMs\DC1\DC1.vhdx" -NewVHDSizeBytes 60GB `
-SwitchName "LabSwitch" -Path "D:\Lab\VMs\DC1"
Set-VMProcessor -VMName "DC1" -Count 2
Set-VMMemory -VMName "DC1" -DynamicMemoryEnabled $true `
-MinimumBytes 512MB -StartupBytes 2GB -MaximumBytes 4GB
Add-VMDvdDrive -VMName "DC1" -Path "D:\Lab\ISOs\WindowsServer2025.iso"
Set-VMFirmware -VMName "DC1" -FirstBootDevice (Get-VMDvdDrive -VMName "DC1")
Repeat the same pattern for the rest of the lab — only the names, memory ceiling, and ISO change:
"DC2","SRV1" | ForEach-Object {
New-VM -Name $_ -Generation 2 -MemoryStartupBytes 2GB `
-NewVHDPath "D:\Lab\VMs\$_\$_.vhdx" -NewVHDSizeBytes 60GB `
-SwitchName "LabSwitch" -Path "D:\Lab\VMs\$_"
Set-VMProcessor -VMName $_ -Count 2
}
New-VM -Name "CL1" -Generation 2 -MemoryStartupBytes 4GB `
-NewVHDPath "D:\Lab\VMs\CL1\CL1.vhdx" -NewVHDSizeBytes 80GB `
-SwitchName "LabSwitch" -Path "D:\Lab\VMs\CL1"
Two details worth knowing before you power anything on. First, Generation 2 VMs ship with Secure Boot enabled using the Microsoft UEFI certificate authority, which Windows Server 2025 accepts out of the box — leave it on. Second, unlike Windows 11 clients, Windows Server 2025 does not require a virtual TPM; you can enable one later under VM → Security if you want to experiment with BitLocker or Virtualization-Based Security. The full New-VM parameter reference lives on Microsoft Learn if you want to customize paths or boot devices further.
Figure 3: Attaching the ISO now means the VM boots straight into Windows Setup in Lesson 007.
Step 5: Protect Your Lab with Checkpoints (Your Undo Button)
A checkpoint captures a VM's disk (and, optionally, memory) state so you can roll back after a broken Group Policy experiment or a failed promotion — the superpower that makes lab learning fearless. Hyper-V offers two types, and the distinction matters for domain controllers:
- Production checkpoints (the default) use Volume Shadow Copy Service to take a data-consistent snapshot — the right choice for DCs, because they boot cleanly after restore.
- Standard checkpoints freeze the exact memory state too — great for a paused mid-setup VM, but restoring a domain controller from one can create AD database inconsistencies.
GUI: right-click the VM → Checkpoint. It appears under Checkpoints in the bottom pane; right-click it → Apply to roll back. PowerShell:
# Take a pre-configuration snapshot of the whole lab
Checkpoint-VM -Name "DC1" -SnapshotName "Clean Install"
Get-VMCheckpoint -VMName "DC1"
# Roll back when an experiment goes wrong
Restore-VMCheckpoint -Name "Clean Install" -VMName "DC1" -Confirm:$false
# Force production-only checkpoints on your DCs
Set-VM -Name "DC1" -CheckpointType ProductionOnly
Figure 4: One checkpoint per VM before any configuration change means every risky experiment is reversible.
Step 6 (Bonus): Stop Reinstalling — Template VHDX & Differencing Disks
Installing Server 2025 four times is a waste of an evening, and it's the gap most lab guides never close. After you finish Lesson 007 and have one clean, updated, sysprepped server disk, turn it into a parent template. Every new VM then gets a tiny differencing disk that stores only its changes on top of the template — new servers take seconds and gigabytes of disk instead of an hour and 30 GB each.
# One-time: prepare the parent (install OS + updates, then sysprep /generalize
# from inside the VM before shutting it down — full walkthrough in Lesson 007)
# Then spin up any number of children against the parent
New-VHD -Path "D:\Lab\VMs\SRV1\SRV1.vhdx" `
-ParentPath "D:\Lab\Templates\WS2025-Base.vhdx" -Differencing
New-VM -Name "SRV1" -Generation 2 -MemoryStartupBytes 2GB `
-VHDPath "D:\Lab\VMs\SRV1\SRV1.vhdx" -SwitchName "LabSwitch" `
-Path "D:\Lab\VMs\SRV1"
The rule that keeps this safe: the parent disk is read-only forever. Never boot a VM from the template itself, and never delete it while children exist. When a major update lands, build a new template version rather than patching the old one.
Common Hyper-V Lab Problems and How to Fix Them
These are the six failures I see most often when engineers build their first Hyper-V lab — and each has a two-minute fix if you know the cause.
1. Hyper-V Doesn't Appear in Windows Features
Either you're on a Home edition (see the prerequisite warning above) or virtualization is disabled in UEFI/BIOS. Reboot into firmware settings and enable Intel VT-x / AMD-V (often under "Intel Virtualization Technology" or "SVM Mode"), then re-check the feature list.
2. VM Fails to Start After a Third-Party Hypervisor Was Installed
If VMware or VirtualBox uninstalled Hyper-V's launcher, force it back with
bcdedit /set hypervisorlaunchtype auto
and reboot. The reverse —
bcdedit /set hypervisorlaunchtype off
— hands the CPU back when you temporarily need the other tool.
3. VMs Lose Their IPs After Every Host Reboot
You're on the Default Switch, whose subnet changes automatically. Migrate the VMs to LabSwitch and assign the static plan from Step 2 — this is the single most common reason beginner domains "randomly" die.
4. New-NetNat Fails or Internet Stops Working
Another NAT already exists (WSL2 and Docker are usual suspects). Run
Get-NetNat
to list them, remove the stale one, and recreate LabNat. Remember: one NAT per host.
5. VM Has No Internet on the Internal Switch
Check three things in order: the VM's gateway is 192.168.200.1 (the host's vEthernet
adapter), the host still holds a Get-NetNat
entry covering 192.168.200.0/24, and the VM has a DNS server configured (1.1.1.1 until your DC takes over).
6. External Switch on Wi-Fi Is Unstable
Bridging to wireless adapters is flaky by design — many Wi-Fi NICs reject foreign MAC addresses, so VMs drop connectivity. On a laptop, skip the external switch entirely and use LabSwitch + NAT; reserve external switches for wired desktop hosts.
Join the Windows Server 2025 Study Cohort
Hit a wall while building your Hyper-V lab — a missing Hyper-V entry, a stubborn New-NetNat error, or a VM that refuses to get an IP? Don't troubleshoot it in isolation; post the exact error and a screenshot, and build your lab alongside admins solving the same problems today.
- ✓ Post server error logs & get rapid peer troubleshooting
- ✓ Collaborate on Microsoft AZ-800 / AZ-801 scenario questions
- ✓ Direct feedback & Q&A discussions on each weekly lesson
- ✓ Download exclusive templates, scripts, and exam cheat sheets
Summary and Actionable Checklist
Your Hyper-V host is now a genuine lab platform, not just a VM launcher. Before moving to Lesson 005 (or straight to installing the OS), confirm every box below:
✅ Lab Readiness Checklist
- Hyper-V Management Tools and Platform enabled;
Get-VMHostanswers cleanly. - Windows Server 2025 evaluation ISO (and Windows 11 ISO for CL1) downloaded into
D:\Lab\ISOs\. - Four VM shells created: DC1, DC2, SRV1, CL1 — all Generation 2, all on LabSwitch, Dynamic Memory on.
- Internal switch + NAT verified: host holds 192.168.200.1 and one
Get-NetNatentry. - "Clean Install" production checkpoints taken on every VM.
- IP plan (192.168.200.0/24) written down and saved with the lab folder.
🏁 This closes Lesson 004. Your Hyper-V lab host is built, networked, and protected by checkpoints — every experiment inside it is now reversible. Use the buttons below to step back to the hypervisor comparison or forward to the next build guide in the series.
Frequently Asked Questions About Building a Hyper-V Lab
These are the questions readers ask most when building their first Hyper-V lab for Windows Server 2025 — quick, direct answers to the doubts that most tutorials leave hanging.
We'd love to hear your thoughts! Leave a comment below
and share your experience or questions.