What you need to know
Which networking assumptions should be checked when running Hyper-V inside a virtual machine?
Potentially affected
Administrators preparing supported nested Hyper-V test environments.
DSE recommendation
Draw the host, first-level VM, nested guests, switches, and proposed address path.
Source facts
Nested virtualization allows Hyper-V to run within a virtual machine. Microsoft performs the processor-exposure configuration while that virtual machine is powered off. For packets to traverse two virtual-switch layers, the documented approach enables MAC address spoofing at the first virtual-machine level. Microsoft also describes NAT as an alternative when spoofing cannot be used, including public-cloud scenarios. Microsoft documentation.
Applicability
Check the physical processor, host release, guest release, VM configuration, and platform restrictions against the source prerequisites. Define which nested guests require outside connectivity and which should remain isolated.
DSE recommendation
Draw the host, first-level VM, nested guests, switches, and proposed address path. Have the network owner approve the chosen method and its boundary. Schedule the required VM shutdown and retain the original processor and network settings before enabling the nested environment.
Verification
Test connectivity from a nested guest to each intended destination and check an explicitly disallowed path. Confirm the address observed outside the nested environment and record the forwarding configuration. Recheck the first-level VM after a restart, and preserve any difference from the approved network diagram as an unresolved finding.
Official references
Microsoft Learn: Run Hyper-V in a Virtual Machine with Nested Virtualization. Source reviewed September 8, 2026.
Review the official source
Run Hyper-V in a Virtual Machine with Nested Virtualization · Verified September 8, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE