Flamingo Raises $4.5M Seed Round

Skip to content

Updated: October 2026

Hyper-V won't install, WSL2 throws an error, or Docker Desktop refuses to start, and the fix is one switch buried three menus deep in the firmware. Every vendor names that switch differently and hides it somewhere new. Here's how to check whether it's already on, where Dell, HP, Lenovo, ASUS and MSI keep it, and how to flip it on a hundred machines without visiting any of them.

What You're Switching On

Modern Intel and AMD processors can run virtual machines at close to full speed, but only if the firmware lets them. That permission is one setting, and Intel and AMD call it different things. On Intel it's VT-x, often labelled "Intel Virtualization Technology". On AMD it's AMD-V, which many boards list as "SVM Mode".

A second setting often sits right next to it. Intel VT-d and AMD's IOMMU (sometimes "AMD-Vi") let the hypervisor control which memory each device can reach. You need it for passing a GPU or NVMe drive straight to a VM, and Windows security features use it to block DMA attacks. If you're in the menu anyway, turn both on.

The third piece, second-level address translation (SLAT), is built into every recent CPU and has no switch. Hyper-V requires it, per Microsoft's Hyper-V system requirements, so on very old hardware the answer can be "this machine can't do it" rather than "the setting is off". What those VMs are for is a separate question, covered at the end.

Check Whether It's Already On

Plenty of machines ship with it enabled, so check before you reboot anything. Open Task Manager, go to Performance, click CPU, and look for "Virtualization: Enabled" under the graph.

From a command prompt, systeminfo gives a fuller answer. Scroll to "Hyper-V Requirements". If every line says Yes, the firmware side is done.

There's one trap. If the line reads "A hypervisor has been detected. Features required for Hyper-V will not be displayed", virtualization is already on and in use. Hyper-V, WSL2 or memory integrity is running, and Windows hides the detail because the hypervisor has claimed the CPU extensions. That's a pass, not a failure.

Where Each Vendor Hides It

Getting into the firmware is the same everywhere: Settings > System > Recovery > Advanced startup > Restart now, then Troubleshoot > Advanced options > UEFI Firmware Settings. That route works when the boot key is too fast to catch. After that, the menus split by vendor. Names and paths vary by model and BIOS version, so treat these as the usual places to look, not guarantees.

VendorBoot keyUsual locationWhat it's called
DellF2Virtualization SupportEnable Intel Virtualization Technology, VT for Direct I/O
HPEsc, then F10Advanced > System Options (older: Security)Virtualization Technology (VTx), Virtualization Technology for Directed I/O (VTd)
Lenovo ThinkPadF1Security > VirtualizationIntel Virtualization Technology, Intel VT-d Feature, or AMD-V equivalents
ASUSF2 or DelAdvanced > CPU ConfigurationIntel Virtualization Technology, or SVM Mode on AMD
MSIDelOC > CPU FeaturesIntel Virtualization Tech, or SVM Mode on AMD
Microsoft Surface--Ships enabled

Save, exit, and check Task Manager again once Windows is back. If the option is greyed out, the usual cause is a BIOS supervisor password you haven't entered, or a BIOS so old it predates the setting. Our guide to BIOS updates covers the second case.

What Needs It

Four things on a modern Windows machine depend on this switch. Hyper-V needs it to run any VM. WSL2 needs it too, together with the Virtual Machine Platform Windows feature, which Microsoft's manual install steps enable with dism.exe /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart. Docker Desktop on Windows runs on WSL2 or Hyper-V, so it inherits both requirements.

The fourth is the one that matters most for a company fleet. Virtualization-based security (VBS) uses the Windows hypervisor to wall off parts of the OS, and features like memory integrity and Credential Guard run inside that wall. Microsoft's VBS hardware requirements list the CPU virtualization extensions and SLAT as required, and an IOMMU for protection against DMA attacks.

That answers the question in this r/sysadmin thread, which asks whether to leave virtualization off when users don't run VMs. Leaving it off also switches off the security features that run on the hypervisor. On a business laptop, that trade rarely makes sense.

Switch It On Across a Fleet

Walking to each desk and pressing F2 doesn't scale past a handful of machines. Dell, HP and Lenovo each ship a tool that changes firmware settings from inside Windows, so an RMM or Intune can push the change and the setting takes effect at the next reboot.

On Dell, Dell Command | Configure sets it from the command line with cctk --Virtualization=Enabled --VtForDirectIo=Enabled. On HP, the Client Management Script Library does it in PowerShell with Set-HPBIOSSettingValue -Name "Virtualization Technology (VTx)" -Value "Enable", and the older BIOS Configuration Utility takes a config file instead. On Lenovo, it's WMI: call SetBiosSetting("VirtualizationTechnology,Enable") on the Lenovo_SetBiosSetting class, then save once with Lenovo_SaveBiosSettings. Lenovo's guide warns to save once at the end, not after every setting.

Setting names differ between models, even within one vendor. Read the current value first, on a pilot machine of each model, before you push anything. The same habit applies to every firmware change, as our PowerShell commands guide puts it: get before you set.

If you'd rather see the single-PC version first, this short walkthrough goes through the menus and the Task Manager check.

OpenFrame can run the vendor script as a bulk operation across the machines that need it, with an approval gate before anything touches the firmware.

BIOS Passwords and Change Control

Business machines are usually locked with a BIOS supervisor password, and every vendor tool needs it to change a setting. That turns a one-line change into a secrets problem: the script has to carry the password without leaving it in plain text in a log or a deployment package.

Setting that password in the first place can be harder than using it. In this May 2026 thread, a tech with a Lenovo fleet already in the field quotes Lenovo's own WMI guide: WMI can't set an initial password from blank, only change or clear an existing one.

Treat a firmware change like any other change. Inventory which models you have, set or confirm the BIOS password, run the vendor tool on a pilot group, reboot, and verify with systeminfo before you widen the rollout. A firmware setting that half the fleet ignored because of a model mismatch is worse than one you never pushed, because the report says it's done. If the same models also need TPM switched on for BitLocker, bundle both into one change window. Our TPM guide covers that side.

One Switch, Four Features

Virtualization in BIOS is a single setting that four Windows features lean on: Hyper-V, WSL2, Docker Desktop and VBS. Check it before you reboot, turn on VT-d or IOMMU while you're there, and on a fleet, push it with the vendor's own tool behind a BIOS password you control.

For the part that comes after the switch, read our guide to what virtualization is and how to pick a hypervisor.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

Enable Virtualization in BIOS

Yes. Virtualization is a standard CPU feature, and Windows security features such as memory integrity and Credential Guard depend on it. Turning it on doesn't change anything until software like Hyper-V, WSL2 or VBS uses it, and on business laptops leaving it off also switches those protections off.
Turning the setting on by itself doesn't slow a PC down. Performance only changes when something runs on the hypervisor, such as a virtual machine or VBS, and that cost comes from the workload, not the switch.
A greyed-out setting usually means a BIOS supervisor password is set and you haven't entered it, or the firmware is locked by policy. On older machines it can also mean the BIOS predates the option, which a BIOS update may fix.
On Dell, HP and Lenovo business machines, yes: each vendor ships a tool that changes firmware settings from inside Windows, such as Dell Command | Configure, HP Client Management Script Library or Lenovo WMI. The change still applies at the next reboot and usually needs the BIOS password.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.
In the cloud, on US soil. Your data stays stateside.
Both. It's built for MSPs and MSSPs alike.