Updated: October 2026
Hyper-V won't install, WSL2 throws an error, or Docker Desktop refuses to start, and the fix is one switch buried three menus deep in the firmware. Every vendor names that switch differently and hides it somewhere new. Here's how to check whether it's already on, where Dell, HP, Lenovo, ASUS and MSI keep it, and how to flip it on a hundred machines without visiting any of them.
What You're Switching On
Modern Intel and AMD processors can run virtual machines at close to full speed, but only if the firmware lets them. That permission is one setting, and Intel and AMD call it different things. On Intel it's VT-x, often labelled "Intel Virtualization Technology". On AMD it's AMD-V, which many boards list as "SVM Mode".
A second setting often sits right next to it. Intel VT-d and AMD's IOMMU (sometimes "AMD-Vi") let the hypervisor control which memory each device can reach. You need it for passing a GPU or NVMe drive straight to a VM, and Windows security features use it to block DMA attacks. If you're in the menu anyway, turn both on.
The third piece, second-level address translation (SLAT), is built into every recent CPU and has no switch. Hyper-V requires it, per Microsoft's Hyper-V system requirements, so on very old hardware the answer can be "this machine can't do it" rather than "the setting is off". What those VMs are for is a separate question, covered at the end.
Check Whether It's Already On
Plenty of machines ship with it enabled, so check before you reboot anything. Open Task Manager, go to Performance, click CPU, and look for "Virtualization: Enabled" under the graph.
From a command prompt, systeminfo gives a fuller answer. Scroll to "Hyper-V Requirements". If every line says Yes, the firmware side is done.
There's one trap. If the line reads "A hypervisor has been detected. Features required for Hyper-V will not be displayed", virtualization is already on and in use. Hyper-V, WSL2 or memory integrity is running, and Windows hides the detail because the hypervisor has claimed the CPU extensions. That's a pass, not a failure.
Where Each Vendor Hides It
Getting into the firmware is the same everywhere: Settings > System > Recovery > Advanced startup > Restart now, then Troubleshoot > Advanced options > UEFI Firmware Settings. That route works when the boot key is too fast to catch. After that, the menus split by vendor. Names and paths vary by model and BIOS version, so treat these as the usual places to look, not guarantees.
| Vendor | Boot key | Usual location | What it's called |
|---|---|---|---|
| Dell | F2 | Virtualization Support | Enable Intel Virtualization Technology, VT for Direct I/O |
| HP | Esc, then F10 | Advanced > System Options (older: Security) | Virtualization Technology (VTx), Virtualization Technology for Directed I/O (VTd) |
| Lenovo ThinkPad | F1 | Security > Virtualization | Intel Virtualization Technology, Intel VT-d Feature, or AMD-V equivalents |
| ASUS | F2 or Del | Advanced > CPU Configuration | Intel Virtualization Technology, or SVM Mode on AMD |
| MSI | Del | OC > CPU Features | Intel Virtualization Tech, or SVM Mode on AMD |
| Microsoft Surface | - | - | Ships enabled |
Save, exit, and check Task Manager again once Windows is back. If the option is greyed out, the usual cause is a BIOS supervisor password you haven't entered, or a BIOS so old it predates the setting. Our guide to BIOS updates covers the second case.
What Needs It
Four things on a modern Windows machine depend on this switch. Hyper-V needs it to run any VM. WSL2 needs it too, together with the Virtual Machine Platform Windows feature, which Microsoft's manual install steps enable with dism.exe /online /enable-feature /featurename:VirtualMachinePlatform /all /norestart. Docker Desktop on Windows runs on WSL2 or Hyper-V, so it inherits both requirements.
The fourth is the one that matters most for a company fleet. Virtualization-based security (VBS) uses the Windows hypervisor to wall off parts of the OS, and features like memory integrity and Credential Guard run inside that wall. Microsoft's VBS hardware requirements list the CPU virtualization extensions and SLAT as required, and an IOMMU for protection against DMA attacks.
That answers the question in this r/sysadmin thread, which asks whether to leave virtualization off when users don't run VMs. Leaving it off also switches off the security features that run on the hypervisor. On a business laptop, that trade rarely makes sense.
Switch It On Across a Fleet
Walking to each desk and pressing F2 doesn't scale past a handful of machines. Dell, HP and Lenovo each ship a tool that changes firmware settings from inside Windows, so an RMM or Intune can push the change and the setting takes effect at the next reboot.
On Dell, Dell Command | Configure sets it from the command line with cctk --Virtualization=Enabled --VtForDirectIo=Enabled. On HP, the Client Management Script Library does it in PowerShell with Set-HPBIOSSettingValue -Name "Virtualization Technology (VTx)" -Value "Enable", and the older BIOS Configuration Utility takes a config file instead. On Lenovo, it's WMI: call SetBiosSetting("VirtualizationTechnology,Enable") on the Lenovo_SetBiosSetting class, then save once with Lenovo_SaveBiosSettings. Lenovo's guide warns to save once at the end, not after every setting.
Setting names differ between models, even within one vendor. Read the current value first, on a pilot machine of each model, before you push anything. The same habit applies to every firmware change, as our PowerShell commands guide puts it: get before you set.
If you'd rather see the single-PC version first, this short walkthrough goes through the menus and the Task Manager check.
OpenFrame can run the vendor script as a bulk operation across the machines that need it, with an approval gate before anything touches the firmware.
BIOS Passwords and Change Control
Business machines are usually locked with a BIOS supervisor password, and every vendor tool needs it to change a setting. That turns a one-line change into a secrets problem: the script has to carry the password without leaving it in plain text in a log or a deployment package.
Setting that password in the first place can be harder than using it. In this May 2026 thread, a tech with a Lenovo fleet already in the field quotes Lenovo's own WMI guide: WMI can't set an initial password from blank, only change or clear an existing one.
Treat a firmware change like any other change. Inventory which models you have, set or confirm the BIOS password, run the vendor tool on a pilot group, reboot, and verify with systeminfo before you widen the rollout. A firmware setting that half the fleet ignored because of a model mismatch is worse than one you never pushed, because the report says it's done. If the same models also need TPM switched on for BitLocker, bundle both into one change window. Our TPM guide covers that side.
One Switch, Four Features
Virtualization in BIOS is a single setting that four Windows features lean on: Hyper-V, WSL2, Docker Desktop and VBS. Check it before you reboot, turn on VT-d or IOMMU while you're there, and on a fleet, push it with the vendor's own tool behind a BIOS password you control.
For the part that comes after the switch, read our guide to what virtualization is and how to pick a hypervisor.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
