📁 last tech Posts

Build a Hyper-V Lab for Windows Server 2025: 6-Step Guide

Hyper-V lab for Windows Server 2025 shown in Hyper-V Manager on Windows 11 with four virtual machines ready for an AZ-800 home lab

A complete Windows Server 2025 lab running inside Hyper-V on one Windows 11 PC — the exact topology you will build in this guide.

Most Hyper-V tutorials end the moment one empty virtual machine boots — and that is exactly why so many Windows Server 2025 labs collapse the first time someone adds a second domain controller. To build a Hyper-V lab for Windows Server 2025 that survives a real Active Directory build-out, you need the three things most guides skip: a stable internal virtual switch with NAT, a memory plan sized for four VMs instead of one, and checkpoints that let you undo any mistake in seconds.

This is Lesson 004 of the Windows Server 2025: Zero to Admin series, and it walks you through the complete build: enabling Hyper-V on Windows 11, planning an AZ-800-ready topology, understanding virtual switch types the way they actually behave, provisioning your first VMs through both the GUI and PowerShell, and protecting every step with checkpoints. By the end, your host will be ready for Lesson 007, where we install Windows Server 2025 into these machines.

I'm Mostafa Amaan, and on Valley4Techs I write practical, hands-on engineering guides for systems administrators and IT professionals. I've spent more than 16 years managing Windows environments — from multi-branch medical networks (PACS/RIS) to domain controllers serving hundreds of clients — and the habits in this lesson are the same ones I rely on to keep risky experiments inside a disposable lab, never on production servers.

📚 Stage 1 · Lesson 004 of 66 Windows Server 2025: Zero to Admin

This is Lesson 004 of our complete 66-lesson engineering roadmap. In Lesson 003: Hyper-V vs VMware vs Proxmox we chose the hypervisor — today we build the Hyper-V lab itself. If your hardware suits VMware Workstation or Proxmox better, dedicated build guides arrive in Lessons 005 and 006, and Lesson 001 covers what makes Windows Server 2025 worth installing in the first place.

How Do You Build a Hyper-V Lab for Windows Server 2025?

⚡ Quick Answer: Enable Hyper-V on Windows 11 Pro or Enterprise, create an internal virtual switch backed by NAT, provision Generation 2 virtual machines with 2–4 GB of RAM each, attach the Windows Server 2025 ISO, and snapshot every VM with checkpoints. A 16 GB host runs a starter domain lab; 32 GB is comfortable.

The whole build breaks down into six steps. Each one follows this series' dual-track method: the graphical way and the PowerShell way, so you learn the tools the AZ-800 exam actually tests.

  1. Enable Hyper-V on your Windows 11 host (GUI or PowerShell).
  2. Plan the lab topology — which VMs, how much RAM, which subnet.
  3. Create the virtual switches and NAT network your domain will live on.
  4. Create the Windows Server 2025 virtual machines (shells only — installation comes in Lesson 007).
  5. Protect everything with checkpoints before touching configuration.
  6. Optional: build a template disk with differencing VHDXs so new VMs take seconds, not gigabytes.

Before You Start: Lab Requirements and Prerequisites

Hyper-V is built into Windows as an optional feature — there is no separate download — but your host still has to meet a few hard requirements. From my experience, most "Hyper-V is missing" support questions trace back to one of these four items, so check them now and save yourself an hour of troubleshooting later.

  • Windows edition: Windows 11 (or Windows 10) Pro, Enterprise, or Education, 64-bit. The Hyper-V role cannot be installed on Windows Home editions.
  • Processor: a 64-bit CPU with Second Level Address Translation (SLAT) — any Intel VT-x or AMD-V processor from roughly the last decade qualifies — with virtualization enabled in UEFI/BIOS.
  • Memory: 16 GB is the practical minimum for a starter lab; 32 GB for the full AZ-800 topology below. Lesson 002 covers full hardware sizing in depth.
  • Storage: at least 120 GB of free SSD/NVMe space (about 15–30 GB per Server VM plus the ISO).
  • Installation media: the free 180-day evaluation ISO from the Microsoft Evaluation Center — choose Windows Server 2025 | 64-bit ISO.
⚠️ Windows Home users: Hyper-V Manager and the Hyper-V platform are not available on Home editions at all. Your cleanest options are upgrading to Pro, or following Lesson 003's recommendation and using VMware Workstation Pro, which is now free and runs fine on Home.

One more note before we start: if you also use VMware Workstation or VirtualBox on this machine, they will coexist with Hyper-V through the Windows Hypervisor Platform, but you should pick one primary hypervisor per lab machine to avoid CPU scheduling overhead. That decision is exactly what Lesson 003 was for — from here on, this host is Hyper-V territory.

Step 1: Enable Hyper-V on Windows 11 (GUI & PowerShell)

Enabling Hyper-V installs the hypervisor layer plus the two tools you will live in: Hyper-V Manager (GUI) and the Hyper-V PowerShell module. Your PC will restart to complete the installation, so save your work first.

Method A: Turn Windows Features On or Off (GUI)

This is the route you'll see in every screenshot-laden tutorial, and it's perfectly fine for a one-time setup:

  1. Press Start, type Control Panel, and open it.
  2. Go to Programs → Programs and Features.
  3. Select Turn Windows features on or off.
  4. Expand the Hyper-V entry and make sure Hyper-V Management Tools and Hyper-V Platform are both checked.
  5. Select OK, then restart the PC when prompted.

Method B: PowerShell (One Command)

Faster, scriptable, and it installs the exact same components. Open PowerShell as Administrator (right-click Start → Terminal (Admin)) and run:

Enable-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V -All

Type Y to let the computer restart. If you prefer the classic DISM tool, this is equivalent:

DISM /Online /Enable-Feature /All /FeatureName:Microsoft-Hyper-V

After the restart, verify that everything is in place. The feature should report Enabled:

Get-WindowsOptionalFeature -Online -FeatureName Microsoft-Hyper-V
Get-VMHost

When Get-VMHost returns your host's name and default paths without errors, the hypervisor is running. For reference, this matches the official Microsoft Learn instructions for installing Hyper-V.

Enabling Hyper-V on Windows 11 through Turn Windows features on or off to build a Windows Server 2025 lab

Figure 1: Both Hyper-V sub-components must be checked — tools alone will install the Manager but not the hypervisor itself.

Step 2: Plan Your Lab Topology (The AZ-800 Blueprint)

Creating VMs one at a time with random names is how labs become junk drawers. Before touching Hyper-V Manager, decide what you're building. This series targets the AZ-800 skill set, which means a small Active Directory domain: two domain controllers, one member server, and a Windows 11 client.

VM Role in the Lab vCPU RAM (Dynamic) Disk
DC1 Primary DC, DNS, DHCP 2 512 MB – 4 GB (start 2 GB) 60 GB dynamic VHDX
DC2 Secondary DC (replication) 2 512 MB – 4 GB (start 2 GB) 60 GB dynamic VHDX
SRV1 Member server (file/print, later roles) 2 512 MB – 4 GB (start 2 GB) 60 GB dynamic VHDX
CL1 Windows 11 client (GPO tests) 2 1 GB – 6 GB (start 4 GB) 80 GB dynamic VHDX

With Dynamic Memory enabled, these four VMs idle at roughly 5–6 GB combined and burst toward 18 GB under load — which is why a 32 GB host is comfortable and 16 GB works if you run two VMs at a time. Keep every VM in one dedicated folder tree so you can move or back up the entire lab in a single operation:

D:\Lab\
├── ISOs\          ← Windows Server 2025 & Windows 11 evaluation ISOs
├── Templates\     ← clean sysprepped base VHDX (Step 6)
└── VMs\
    ├── DC1\
    ├── DC2\
    ├── SRV1\
    └── CL1\

Finally, fix your IP plan now, before any VM exists. We will place the whole lab on an internal network behind NAT: the switch itself uses 192.168.200.0/24, the host gateway is 192.168.200.1, and VMs get static addresses starting at .11 (DC1 .11, DC2 .12, SRV1 .21, CL1 .31). Writing this down today is what prevents the classic "why can't DC1 reach DC2?" mystery when we promote the domain in Lesson 014.

📥 Planning a bigger, multi-subnet lab? In Lesson 010 — Design Your Windows Server 2025 Lab: Topology, IP Scheme & Sizing — we publish a printable Lab Topology & IP Subnetting Planning Sheet so you can architect multi-site Active Directory environments on paper before provisioning a single VM. Subscribe below to get the free toolkit ↓

Step 3: Hyper-V Virtual Switch Types Explained (Default vs Internal vs External)

Networking is where most Hyper-V labs are built wrong. Hyper-V gives you four switch types, and picking the wrong one doesn't fail immediately — it fails two weeks later when your domain controllers reboot. Here is what each type actually allows:

Switch Type VM ↔ VM VM ↔ Host Internet Best Use in Your Lab
Default Switch ✔ ✔ ✔ (NAT) One quick VM that just needs internet
Internal ✔ ✔ Only if you add NAT Stable AD lab network (our choice)
Private ✔ ✘ ✘ Isolated test segments (malware labs)
External ✔ ✔ ✔ (bridged) VMs that must appear on your real LAN

The Default Switch Problem in an Active Directory Lab

The Default Switch that appears automatically after enabling Hyper-V is a NAT switch: your VMs get an IP from an internal DHCP and share the host's internet connection. For a single throwaway VM, it's magic. For a domain lab, it's a trap — its subnet changes every time the host reboots or switches Wi-Fi networks (it may be 172.20.x.x today and 192.168.137.x tomorrow). Any static IP you assigned to a domain controller silently stops working, DNS breaks, and the whole domain falls over.

That's why the standard default switch vs internal switch decision for labs is not really a decision: an internal switch gives you a subnet you fully control, keeps VM-to-host communication, and — once you attach a NAT gateway — still reaches the internet. This is the design we'll implement now.

Create the Internal Switch and NAT Gateway (GUI & PowerShell)

GUI: open Hyper-V Manager → Virtual Switch Manager → select Internal → Create Virtual Switch → name it LabSwitch → OK. The NAT gateway itself can only be configured in PowerShell:

# 1. Create the internal switch (skip if created via GUI)
New-VMSwitch -SwitchName "LabSwitch" -SwitchType Internal

# 2. Find the new adapter's InterfaceAlias
Get-NetAdapter

# 3. Give the host side of the switch its gateway IP
New-NetIPAddress -IPAddress 192.168.200.1 -PrefixLength 24 `
  -InterfaceAlias "vEthernet (LabSwitch)"

# 4. Turn the subnet into a NAT network
New-NetNat -Name "LabNat" `
  -InternalIPInterfaceAddressPrefix 192.168.200.0/24
⚠️ One NAT per host: Windows (WinNAT) supports only a single NAT network per machine. If New-NetNat fails or Docker/WSL already owns a NAT, check with Get-NetNat and remove the stale entry with Get-NetNat | Remove-NetNat first. Details are in Microsoft's NAT network guide.

Your VMs will use static IPs in 192.168.200.0/24 with gateway 192.168.200.1. For name resolution until DNS exists, point them temporarily at 1.1.1.1; once DC1 is promoted in Stage 2, your own DNS server takes over. For deeper switch configuration options, see Microsoft's virtual switch documentation.

Creating the LabSwitch internal virtual switch in Hyper-V Virtual Switch Manager for a Windows Server 2025 lab network

Figure 2: LabSwitch is internal — the NAT gateway that gives it internet access is added with PowerShell in the next command block.

Step 4: Create Your Windows Server 2025 Virtual Machines

In this lesson we build the VM shells and attach the ISO; the actual operating system installation happens in Lesson 007. Always choose Generation 2 for new VMs — it uses UEFI, supports Secure Boot and VHDX boot, and is what modern Windows Server expects. Generation 1 exists only for legacy 32-bit guests you will never need in this series.

Method A: New Virtual Machine Wizard (GUI)

  1. In Hyper-V Manager, select Action → New → Virtual Machine, then Next.
  2. Name it DC1 and (optionally) tick Store the virtual machine in a different location, pointing to D:\Lab\VMs\DC1.
  3. Choose Generation 2.
  4. Assign 2048 MB startup memory and tick Use Dynamic Memory.
  5. On the networking page, connect it to LabSwitch.
  6. Create a 60 GB virtual hard disk (dynamic is fine for labs).
  7. On Installation Options, choose Install an operating system from a bootable image file and select your Windows Server 2025 ISO, then Finish.

Method B: PowerShell (Build DC1 in Six Commands)

New-VM -Name "DC1" -Generation 2 -MemoryStartupBytes 2GB `
  -NewVHDPath "D:\Lab\VMs\DC1\DC1.vhdx" -NewVHDSizeBytes 60GB `
  -SwitchName "LabSwitch" -Path "D:\Lab\VMs\DC1"

Set-VMProcessor -VMName "DC1" -Count 2
Set-VMMemory -VMName "DC1" -DynamicMemoryEnabled $true `
  -MinimumBytes 512MB -StartupBytes 2GB -MaximumBytes 4GB
Add-VMDvdDrive -VMName "DC1" -Path "D:\Lab\ISOs\WindowsServer2025.iso"
Set-VMFirmware -VMName "DC1" -FirstBootDevice (Get-VMDvdDrive -VMName "DC1")

Repeat the same pattern for the rest of the lab — only the names, memory ceiling, and ISO change:

"DC2","SRV1" | ForEach-Object {
  New-VM -Name $_ -Generation 2 -MemoryStartupBytes 2GB `
    -NewVHDPath "D:\Lab\VMs\$_\$_.vhdx" -NewVHDSizeBytes 60GB `
    -SwitchName "LabSwitch" -Path "D:\Lab\VMs\$_"
  Set-VMProcessor -VMName $_ -Count 2
}

New-VM -Name "CL1" -Generation 2 -MemoryStartupBytes 4GB `
  -NewVHDPath "D:\Lab\VMs\CL1\CL1.vhdx" -NewVHDSizeBytes 80GB `
  -SwitchName "LabSwitch" -Path "D:\Lab\VMs\CL1"

Two details worth knowing before you power anything on. First, Generation 2 VMs ship with Secure Boot enabled using the Microsoft UEFI certificate authority, which Windows Server 2025 accepts out of the box — leave it on. Second, unlike Windows 11 clients, Windows Server 2025 does not require a virtual TPM; you can enable one later under VM → Security if you want to experiment with BitLocker or Virtualization-Based Security. The full New-VM parameter reference lives on Microsoft Learn if you want to customize paths or boot devices further.

Creating a Generation 2 Windows Server 2025 virtual machine in Hyper-V Manager with the evaluation ISO attached

Figure 3: Attaching the ISO now means the VM boots straight into Windows Setup in Lesson 007.

Step 5: Protect Your Lab with Checkpoints (Your Undo Button)

A checkpoint captures a VM's disk (and, optionally, memory) state so you can roll back after a broken Group Policy experiment or a failed promotion — the superpower that makes lab learning fearless. Hyper-V offers two types, and the distinction matters for domain controllers:

  • Production checkpoints (the default) use Volume Shadow Copy Service to take a data-consistent snapshot — the right choice for DCs, because they boot cleanly after restore.
  • Standard checkpoints freeze the exact memory state too — great for a paused mid-setup VM, but restoring a domain controller from one can create AD database inconsistencies.

GUI: right-click the VM → Checkpoint. It appears under Checkpoints in the bottom pane; right-click it → Apply to roll back. PowerShell:

# Take a pre-configuration snapshot of the whole lab
Checkpoint-VM -Name "DC1" -SnapshotName "Clean Install"
Get-VMCheckpoint -VMName "DC1"

# Roll back when an experiment goes wrong
Restore-VMCheckpoint -Name "Clean Install" -VMName "DC1" -Confirm:$false

# Force production-only checkpoints on your DCs
Set-VM -Name "DC1" -CheckpointType ProductionOnly
A Clean Install checkpoint taken on a Windows Server 2025 VM in Hyper-V Manager to protect the lab before configuration

Figure 4: One checkpoint per VM before any configuration change means every risky experiment is reversible.

Step 6 (Bonus): Stop Reinstalling — Template VHDX & Differencing Disks

Installing Server 2025 four times is a waste of an evening, and it's the gap most lab guides never close. After you finish Lesson 007 and have one clean, updated, sysprepped server disk, turn it into a parent template. Every new VM then gets a tiny differencing disk that stores only its changes on top of the template — new servers take seconds and gigabytes of disk instead of an hour and 30 GB each.

# One-time: prepare the parent (install OS + updates, then sysprep /generalize
# from inside the VM before shutting it down — full walkthrough in Lesson 007)

# Then spin up any number of children against the parent
New-VHD -Path "D:\Lab\VMs\SRV1\SRV1.vhdx" `
  -ParentPath "D:\Lab\Templates\WS2025-Base.vhdx" -Differencing

New-VM -Name "SRV1" -Generation 2 -MemoryStartupBytes 2GB `
  -VHDPath "D:\Lab\VMs\SRV1\SRV1.vhdx" -SwitchName "LabSwitch" `
  -Path "D:\Lab\VMs\SRV1"

The rule that keeps this safe: the parent disk is read-only forever. Never boot a VM from the template itself, and never delete it while children exist. When a major update lands, build a new template version rather than patching the old one.

Common Hyper-V Lab Problems and How to Fix Them

These are the six failures I see most often when engineers build their first Hyper-V lab — and each has a two-minute fix if you know the cause.

1. Hyper-V Doesn't Appear in Windows Features

Either you're on a Home edition (see the prerequisite warning above) or virtualization is disabled in UEFI/BIOS. Reboot into firmware settings and enable Intel VT-x / AMD-V (often under "Intel Virtualization Technology" or "SVM Mode"), then re-check the feature list.

2. VM Fails to Start After a Third-Party Hypervisor Was Installed

If VMware or VirtualBox uninstalled Hyper-V's launcher, force it back with bcdedit /set hypervisorlaunchtype auto and reboot. The reverse — bcdedit /set hypervisorlaunchtype off — hands the CPU back when you temporarily need the other tool.

3. VMs Lose Their IPs After Every Host Reboot

You're on the Default Switch, whose subnet changes automatically. Migrate the VMs to LabSwitch and assign the static plan from Step 2 — this is the single most common reason beginner domains "randomly" die.

4. New-NetNat Fails or Internet Stops Working

Another NAT already exists (WSL2 and Docker are usual suspects). Run Get-NetNat to list them, remove the stale one, and recreate LabNat. Remember: one NAT per host.

5. VM Has No Internet on the Internal Switch

Check three things in order: the VM's gateway is 192.168.200.1 (the host's vEthernet adapter), the host still holds a Get-NetNat entry covering 192.168.200.0/24, and the VM has a DNS server configured (1.1.1.1 until your DC takes over).

6. External Switch on Wi-Fi Is Unstable

Bridging to wireless adapters is flaky by design — many Wi-Fi NICs reject foreign MAC addresses, so VMs drop connectivity. On a laptop, skip the external switch entirely and use LabSwitch + NAT; reserve external switches for wired desktop hosts.

👥 SysAdmin Community & Study Group

Join the Windows Server 2025 Study Cohort

Hit a wall while building your Hyper-V lab — a missing Hyper-V entry, a stubborn New-NetNat error, or a VM that refuses to get an IP? Don't troubleshoot it in isolation; post the exact error and a screenshot, and build your lab alongside admins solving the same problems today.

  • ✓ Post server error logs & get rapid peer troubleshooting
  • ✓ Collaborate on Microsoft AZ-800 / AZ-801 scenario questions
  • ✓ Direct feedback & Q&A discussions on each weekly lesson
  • ✓ Download exclusive templates, scripts, and exam cheat sheets
Windows Server 2025 Study Cohort

Free Private Study Community

Join Facebook Study Group →

Summary and Actionable Checklist

Your Hyper-V host is now a genuine lab platform, not just a VM launcher. Before moving to Lesson 005 (or straight to installing the OS), confirm every box below:

✅ Lab Readiness Checklist

  • Hyper-V Management Tools and Platform enabled; Get-VMHost answers cleanly.
  • Windows Server 2025 evaluation ISO (and Windows 11 ISO for CL1) downloaded into D:\Lab\ISOs\.
  • Four VM shells created: DC1, DC2, SRV1, CL1 — all Generation 2, all on LabSwitch, Dynamic Memory on.
  • Internal switch + NAT verified: host holds 192.168.200.1 and one Get-NetNat entry.
  • "Clean Install" production checkpoints taken on every VM.
  • IP plan (192.168.200.0/24) written down and saved with the lab folder.
❤️

Support Our Content

Your donation helps us keep going

🧠 Quick Knowledge Check: You add DC2 to your lab and copy every setting from DC1, but after the next host reboot both VMs lose their static IP configuration and the domain breaks. Which networking design decision is the likely culprit, and what should you have used instead? Drop your answer in the comments below. 🧪 Bonus challenge: build all four VM shells entirely in PowerShell and time yourself — report your record in the comments.
📚 Stage 1 · Lesson 004 of 66 Windows Server 2025: Zero to Admin

🏁 This closes Lesson 004. Your Hyper-V lab host is built, networked, and protected by checkpoints — every experiment inside it is now reversible. Use the buttons below to step back to the hypervisor comparison or forward to the next build guide in the series.

← Lesson 003: Hyper-V vs VMware vs Proxmox Lesson 005: Build a VMware Workstation Lab (Soon) →

Frequently Asked Questions About Building a Hyper-V Lab

These are the questions readers ask most when building their first Hyper-V lab for Windows Server 2025 — quick, direct answers to the doubts that most tutorials leave hanging.

❓ Can I enable Hyper-V on Windows 11 Home?

No. The Hyper-V platform and Hyper-V Manager require Pro, Enterprise, or Education. Home users should either upgrade the edition or use the free VMware Workstation Pro covered in Lesson 005, which runs comfortably on Home.

❓ What's the difference between the Default Switch and an internal switch?

The Default Switch is an auto-created NAT switch whose subnet changes after reboots and network changes, silently breaking static IPs. An internal switch keeps a subnet you control, supports VM-to-host traffic, and gets internet access through a NAT gateway you create — making it the stable choice for a domain lab.

❓ How much RAM do I need for a Windows Server 2025 Hyper-V lab?

A starter lab with two VMs runs on 16 GB of host RAM. The full AZ-800 topology — two domain controllers, a member server, and a Windows 11 client — idles around 6 GB with Dynamic Memory and bursts near 18 GB, so 32 GB keeps everything running simultaneously without pressure.

❓ Why did my lab VMs lose their IP addresses after a restart?

They were connected to the Default Switch, which assigns a new subnet whenever the host reboots or changes networks. Move the VMs to an internal switch like LabSwitch, assign your static IP plan (192.168.200.0/24), and the problem disappears permanently.

❓ Can I run Hyper-V and VMware Workstation on the same PC?

Yes. Modern VMware builds coexist with Hyper-V through Microsoft's Windows Hypervisor Platform API. There is a small scheduling overhead, so for serious lab work choose one primary hypervisor per machine and treat the other as an occasional tool.

❓ Do Windows Server 2025 VMs need a TPM or Secure Boot in Hyper-V?

Secure Boot is enabled by default on Generation 2 VMs and Windows Server 2025 accepts it out of the box, so keep it on. A virtual TPM is not required for Server 2025 — unlike Windows 11 clients — but you can add one under VM Security settings if you want to test BitLocker or VBS.

❓ How do my lab VMs get internet access through the internal switch?

Through NAT: the host side of LabSwitch holds the gateway IP (192.168.200.1) and a New-NetNat rule translates VM traffic out through your physical connection. Remember Windows allows only one NAT network per host, so remove stale NATs from WSL or Docker first if the command fails.

📬
Free Hyper-V Lab Guides & Scripts

Build Your Server Lab Faster

Get weekly Hyper-V and Windows Server 2025 lab guides with ready-to-run PowerShell commands, checkpoint strategies, and AZ-800 study blueprints — straight to your inbox.

🔒 100% free. No spam, ever. Unsubscribe with one click anytime.

Add Valley4Techs as a Preferred Source

Follow us on Google News for the latest updates

Add Now
Mostafa Amaan
Mostafa Amaan
Technical educational content creator on my blog and YouTube channel. My goal with this content is to eradicate information technology literacy.
Comments