domingo, outubro 05, 2025

Hyper-V - The key protector for the virtual machine 'VM' could not be unwrapped

I had an issue after exporting and importing a VM on a different Hyper-V host. Basically, I exported it from Hyper-V1 and imported the VM into Hyper-V2. When I tried to start the VM, I got this message:

The key protector for the virtual machine 'VM' could not be unwrapped. . Details are included in the HostGuardianService-Client event log. The parameter is incorrect. (0x80070057). (Virtual machine ID AXXXXX-CXXX-4XXXXXXXXXXXX)

This happened because TPM was enabled on the original Hyper-V host (VM settings).



You just need to import the SSL certificates into the new Hyper-V server under Shielded VM Local Certificates. If you don’t have them on your Hyper-V server (The destination Hyper-V), simply create a new VM and enable TPM, Windows will generate the SSL certificates for you automatically

The required SSL certificates are for Shielded VM Encryption, as shown in the image below: