Microsoft added more security features to Windows Server 2016 and one of them is the vTPM. You can now use a vTPM right inside the VM without using a physical TPM processor.
A virtual Trusted Platform Module (vTPM) is a software-based representation of a physical Trusted Platform Module that can generate keys. When a vTPM is added to a virtual machine, the guest operating system on the VM creates and stores keys that are private to it.
When the vTPM is enabled and the guest operating system is compromised the vTPM will greatly reduce the risk. The keys generated can be used by the operating system for encryption or signing purpose. Both the vTPM and Bitlocker can add a layer of protection to Windows Server 2016.
In this video, I will be showing you how to enable vTPM on Windows Server 2016 Hyper-V and enable BitLocker within your VM. Once this is done you can store your VM in any location without being afraid your VM files will be stolen or compromised.
Here is the link to the original blog post: https://techdirectarchive.com/2022/11...