Don't throw Windows away. Confine it.
Your Chapter 4 inventory left some items in category A, "won't run." A government or bank's dedicated software, a business app used only in your industry, the setup tool for an old peripheral, something you open a few times a year. Even after Chapter 11's search for substitutes, the things that genuinely need Windows count on one hand.
This book does not take the dual-boot route (Prologue). It takes a virtual machine. Build one small Windows inside Debian and put that handful in it. Debian is home; Windows is the storeroom. You open the storeroom only when you need to.
Draw the line first.
- Goes in: anything with no substitute that you definitely need, even a few times a year — dedicated software, business apps, peripheral utilities
- Stays out: browser, mail, office, everyday files. Chapter 11 moved these to the Debian side
- Stays out: things with another route, such as LINE and games (Chapter 11)
Carry daily life into the storeroom and the migration never ends. Keep the list of what goes into the VM as one extra column in the Chapter 4 inventory table.
Section 1 — The tool is virt-manager (KVM)
For virtualization, use Debian's standard KVM (built into the kernel), libvirt to drive it, and virt-manager for the screen. Not VirtualBox. It installs from apt, it is the same tool Chapter 17 uses for the experiment machine, and it updates together with the kernel — reason enough.
Windows 11 has requirements that a virtual machine must meet too. Microsoft's requirements page (July 2026 edition) lists UEFI firmware that is Secure Boot capable, TPM 2.0, 4 GB or more of memory, 64 GB or more of disk, and two or more cores, and states explicitly that Windows 11 is supported on a virtual machine. Debian needs two extra parts.
- ovmf: UEFI firmware for virtual machines, with Secure Boot support (Debian 13 package)
- swtpm: emulates TPM 2.0 in software. No physical TPM needed (Debian 13 package)
# the virtualization core, plus the parts that satisfy Windows 11
sudo apt install qemu-system libvirt-daemon-system virt-manager ovmf swtpm swtpm-tools
# let your own user manage VMs (log out and back in)
sudo adduser $USER libvirt
# is CPU virtualization support on? (0 means enable VT-x / AMD-V in UEFI/BIOS)
grep -c -E 'vmx|svm' /proc/cpuinfo
Ask Claude ①: Will it run on my machine?
My PC is [paste my-system.md]. I want to run a Windows 11 virtual machine with KVM and virt-manager on Debian 13. (1) With this CPU and memory, can I run a Windows 11 VM (4 GB+, 2 cores+) while still doing my daily work on the Debian side? (2) What to check or change in UEFI/BIOS (virtualization support) (3) The Debian packages to install and the libvirt group setup (4) Whether I have room for 64 GB+ of disk, and where to put it Check the official Debian 13 procedure first, then answer for my machine.
Section 2 — Obtaining Windows, and the license
Download the Windows 11 ISO directly from Microsoft's site. Not from a third-party site.
Decide the license after checking your own edition. Whether the Windows that came with your old PC (an OEM license) can move into a virtual machine depends on the edition and its terms. This book does not pronounce on it. Check the product key and edition you have (Home / Pro, OEM / retail), read the terms on Microsoft's pages, and if they don't fit, buy one. Buying one license for a handful of apps is cheaper than keeping Windows as your home.
One more condition from Microsoft's requirements page worth knowing: Windows 11 Home needs an internet connection and a Microsoft account to complete first-time setup. The same holds in a VM.
Section 3 — Building the virtual machine
The details of the procedure change with every version. Here we write down only the decisions; the steps, you have Claude check against the current official documentation.
In virt-manager's "New virtual machine," point it at the Windows ISO and choose customize configuration before install. Six decisions.
- Firmware: UEFI. Pick ovmf's Secure Boot-capable firmware
- TPM: add an emulated TPM, version 2.0
- Memory and CPU: the minimum is 4 GB and 2 cores. For real use, aim for 8 GB and 4 cores, within what your machine allows
- Disk: qcow2, 64 GB or more. Actual space grows only as it is used
- Disk and network type: virtio. Fast, but Windows carries no driver for it out of the box
- A second CD: the virtio-win ISO. If the disk is not visible during installation, load the driver from here
virtio-win is the Windows driver collection distributed by the Fedora project; download the stable ISO once and attach it as a CD. Its drivers for Windows 10 and later carry Microsoft signatures, so Secure Boot can stay on. When installation is done, install the guest tools from the same ISO — networking, display resizing, and clipboard sharing all come together.
Ask Claude ②: Have it write the procedure
I am creating a Windows 11 virtual machine in virt-manager on Debian 13. My decisions: UEFI (ovmf, Secure Boot capable), emulated TPM 2.0 (swtpm), [ ] GB memory, [ ] CPU cores, a [ ] GB qcow2 disk, virtio for disk and network, and the stable virtio-win ISO as a second CD. (1) What to select in virt-manager's screens, in order (2) How to load the viostor driver when the disk is not visible during installation (3) How to install the virtio-win guest tools after installation (4) The settings that make display resizing and clipboard sharing work Check the current official procedures for Debian 13 and virt-manager first, then write it for my setup.
Section 4 — Storeroom manners
Once the VM exists, settle three habits.
Take a snapshot before installing anything
Use virt-manager's snapshots to keep one copy of the clean state before any app goes in. If something you install breaks it, go back there. This is the VM's greatest advantage — a freedom the physical Windows never had.
Decide on one way to pass files
Pick a single route for moving files between the Debian side and the Windows side. If the clipboard (guest tools) is enough, use only that. If you need a shared folder, create exactly one in virt-manager (virtiofs). Add routes and you stop knowing where anything is.
Open it only when you need it
If you use it a few times a year: start it, run Windows Update first, do the job, close it. Don't keep it running. Leave the network on NAT and open no port from outside. Don't keep Debian's files on the Windows side.
Ask Claude ③: Drawing the line
Here is the inventory table I made in Chapter 4 [paste]. My migration to Debian is nearly done, and I have built one Windows 11 virtual machine. (1) Which items in the table should go into the VM (no substitute, definitely needed) (2) Which should not (handled on the Debian side, or with another route) (3) The ones that are hard to call, and why (4) The list of what goes into the VM, as a new column of the inventory table Answer as a table.
Section 5 — The day the storeroom is empty
Review what is in the VM once a year. Drop what moved to a web version, what you stopped using, and what now runs on Debian. When the list is empty, delete the VM. A storeroom is built to be emptied one day.
What we did in this chapter
- Drew the line between what goes into the VM and what stays out
- Installed KVM, libvirt and virt-manager, plus ovmf and swtpm to meet Windows 11's requirements
- Settled where to obtain Windows and how to check the license
- Fixed the VM configuration (UEFI, TPM 2.0, virtio, virtio-win) and had Claude write the steps
- Settled the habits: snapshots, one file route, open-and-close
Where you are now:
- A Windows 11 virtual machine holding only the apps with no substitute
- A "virtual machine" column in the inventory table
In Chapter 13, "Understanding and Managing Configuration," we cover where Debian's configuration files live, dotfiles management, backup, and tracking with Git. Get into the practice of leaving your environment as documentation.
The full series can be navigated from Learning Debian with Claude — All chapters. Comments and discussion go to the Facebook group: AISeed — Biodiversity, Food, AI and Life.