247-IT Guide
Automatically shutting down Hyper-V VMs during a power outage
Hyper-V takes care of its VMs when the host shuts down. But during a power outage the host doesn't shut down on its own. Something has to read the UPS, recognise the right moment and stop the VMs in a sensible order while the battery still lasts. How to do that reliably.
The automatic stop action: save, shut down or turn off
Every Hyper-V VM has an automatic stop action
(AutomaticStopAction). It defines what happens to the VM when the host server
shuts down. There are three options, and the default is Save:
| Setting | What happens | Suitable for |
|---|---|---|
| Savedefault | The VM's memory is written to disk; on the next start the VM resumes where it left off. | VMs with little RAM on fast storage. Needs free disk space equal to the assigned RAM and takes correspondingly long for large VMs. |
| Shut downShutDown | Hyper-V shuts the guest OS down cleanly through the "Shutdown" integration service. | Most server VMs. Requires the integration service to be enabled and the guest to respond to it. |
| Turn offTurnOff | Like pulling the plug: the VM is switched off immediately. | Only stateless VMs that safely survive a hard power-off. |
PowerShell on the host shows and changes the setting for your VMs:
Get-VM | Select-Object Name, State, AutomaticStopAction
Set-VM -Name "SQL01" -AutomaticStopAction ShutDown
Important: the stop action only applies when the host is shut down. It is a useful fallback, but no protection against a power outage. Without a trigger, the host keeps running until the UPS battery is empty, and then host and VMs go down hard at the same time.
Why the stop action alone is not enough
-
There is no trigger
The host knows nothing about the UPS. Something has to detect battery operation, evaluate the remaining runtime and start the shutdown, via USB cable on a single server or over the network via SNMP or NUT. -
Time is limited
During shutdown, Windows waits for the stop actions of all VMs. How long that takes depends on their number, memory and disk speed. Trigger too late and the battery runs out before every VM is saved or shut down. -
No order
The stop action runs for all VMs of a host at roughly the same time. Dependencies such as "application servers before the database, domain controllers last" cannot be expressed, let alone across several hosts. -
Several hosts, one UPS
If several Hyper-V hosts share one UPS, each needs a trigger. Software installed per host works independently: every host decides on its own, nobody coordinates. -
Power comes back
Short outages are more common than long ones. Shutting everything down at the first battery signal takes the environment down even for a twenty-second dip. Thresholds, several confirmations and an abort window make sense.
In which order VMs should be shut down
The basic rule: first the VMs nothing else depends on, last the ones others need. A proven order for typical Windows environments:
- Terminal and application servers — Remote Desktop, ERP, web servers. They write to databases and file shares and should close their connections cleanly while the other side is still running.
- Database and mail servers — SQL Server, Exchange. Both are crash-safe but come back faster after a clean stop. Details in the guide SQL Server & Exchange on Hyper-V.
- File and print servers
- Domain controllers last — so that authentication and DNS keep working for the remaining VMs until the end. Why a hard power-off of a DC is usually no disaster anyway is covered in Active Directory & power outages.
- Finally the host itself — only once every VM is off or saved.
On restart the order is reversed. Hyper-V provides the automatic start action with a delay in seconds for this: the domain controller starts immediately, all other VMs a few minutes later.
The value that matters is Start. The default StartIfRunning
(“Automatically start if it was running when the service stopped”) only starts VMs that were
still running when the host shut down. If a tool shuts the VMs down individually beforehand,
they stay off afterwards.
Set-VM -Name "DC01" -AutomaticStartAction Start -AutomaticStartDelay 0
Set-VM -Name "SQL01" -AutomaticStartAction Start -AutomaticStartDelay 120
Set-VM -Name "APP01" -AutomaticStartAction Start -AutomaticStartDelay 240
Failover clusters add quorum and Cluster Shared Volumes to the picture, see Hyper-V failover cluster power outage.
Calculating the right moment
The trigger threshold has to cover the complete shutdown plus a reserve. Work backwards, using measured rather than estimated times:
| Step | Duration |
|---|---|
| Detectionpoll every 30 s, 3 confirmations | 1.5 min |
| VM group 1: application serversin parallel, the slowest VM counts | 2 min |
| VM group 2: SQL Server, Exchange | 3 min |
| VM group 3: domain controllers | 1 min |
| Host shutdown | 2 min |
| Subtotal | 9.5 min |
| Reserve 50 %battery age, load, temperature | ≈ 5 min |
| Runtime threshold | ≈ 15 min |
The reserve is not a luxury: the runtime a UPS reports is an estimate by its firmware and becomes increasingly optimistic as the battery ages. It therefore pays to add a minimum battery charge as well, with both values active: whichever is crossed first triggers the shutdown. Why datasheets and displays are often off is explained in Calculating UPS runtime.
Automatic, ordered, no agents on the hosts
The UPS Hyper-V Shutdown Monitor runs as a Windows Service on one machine in the network, polls the UPS via SNMP or NUT and controls the Hyper-V hosts via WinRM, without extra software on the hosts:
- Trigger with thresholds — battery charge and remaining runtime, default 20 % and 300 seconds, freely adjustable. It only triggers after three consecutive confirmations (adjustable), so a short dip does not shut anything down.
- Order across hosts and VMs — hosts and VMs get an order. VMs at the same level shut down in parallel; the next level only starts when the previous one has finished.
- Shut down or save per VM — choose per VM: clean shutdown (
Stop-VM) or save state (Save-VM). If a VM does not respond within the time limit (default 120 seconds per host), it is turned off so the host can shut down safely. - One machine coordinates every host — including physical servers without Hyper-V and, if desired, the local machine at the very end.
- Abort window — if power returns shortly after the trigger, the shutdown is cancelled (default 15 seconds).
- Test first — readiness check, dry run with estimated total duration and a test mode that logs the whole sequence without shutting anything down.
Everything above is included in every edition. Multiple UPS units with host assignment and live migration to a host that still has power come with the Pro edition. More in the feature list and the setup guide.
Check before the next power outage
- "Shutdown" integration service enabled —
Get-VMIntegrationService -VMName <name>lists it per VM. Linux guests need the Hyper-V integration (hv_utils), which current distributions include. - Set the automatic stop action deliberately — as a fallback in case the host is ever shut down without stopping the VMs first. With "Save", plan enough free disk space.
- Document the order — which VM depends on which, and which domain controller shuts down last and starts first?
- Measure times instead of guessing — shut every VM down once during a maintenance window and note the duration. That gives you the threshold (section 04).
- Set start delays — domain controllers without delay, dependent VMs with delay.
- Protect the monitoring itself — the machine that watches the UPS and shuts everything down must keep running until the end: not as a VM on one of the hosts it shuts down, or at least in the very last stage.
- Test once — in test mode or during a maintenance window. The first real power outage should not be the first test.
Frequently asked questions
Does Hyper-V shut down the VMs automatically when the host shuts down?
Yes, according to each VM's automatic stop action. The default is "Save": Hyper-V writes the memory to disk. Alternatives are "Shut down" via the integration service or "Turn off". This only applies when the host is actually shut down, though. During a power outage you need a trigger that monitors the UPS.
Is "Save" or "Shut down" better for power outages?
For most server VMs "Shut down": applications stop cleanly, and after the restart there is no stale clock or leftover connections from the saved state. "Save" is worth it for VMs that shut down poorly, for example because of pending Windows updates, and needs disk space equal to the assigned memory.
Do I need UPS software on every Hyper-V host?
Not necessarily. A solution that polls the UPS over the network (SNMP or NUT) and controls the hosts via WinRM needs no agents on the hosts and can coordinate the order across all of them. This also works with Hyper-V Server and Server Core.
What happens if power comes back during the shutdown?
It depends on the timing. Within an abort window right after the trigger, the shutdown can be stopped. VMs that are already shut down only start the next time the host boots if their automatic start action is set to Start, ideally with staggered delays.
More guides
Replacing UPS batteries
Ageing, warning signs and swapping without a protection gap.
Restarting after a power outage
Starting servers, storage and VMs automatically when power returns.
Eaton IPM alternative for Hyper-V
Node licensing, editions and Hyper-V integration compared.
Hyper-V on Server Core
Protect hosts without a desktop via WinRM or a web interface.
SNMPv3 on a UPS network card
authPriv with SHA and AES instead of a plain-text community.
NUT on Windows
Query a UPS via Network UPS Tools from a NAS or Linux server.
Hyper-V failover cluster power outage
Coordinating quorum, CSV and live migration.
Active Directory & power outages
The USN rollback myth and the real risks for domain controllers.
SQL Server & Exchange on Hyper-V
Protecting databases during a power outage.
Calculating UPS runtime
Why the datasheet runtime rarely holds.
PowerChute alternative for Hyper-V
UPS shutdown without vendor lock-in.
Monitoring UPS units from multiple vendors
One tool instead of several silos.
Set up an ordered shutdown yourself
30 days free, every feature included. With test mode and dry run, so the first real power outage is not the first test.