Again, not an expert on Private Access Tokens, but I assumed the entire point is that it's a proprietary black box piece of hardware that's authenticating your device. If it's just passing a token generated in software, it would be trivial to bypass even without a VM.
Could you explain to me better what the VM would accomplish in this situation?