{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
        "slug": "dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/"
        },
        "title": "Preserve Azure's provisioning media path in a generalized Windows image",
        "summary": "Which guest restrictions can obstruct the first boot of an Azure VM created from a generalized Windows image?",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "managed-it",
            "label": "Managed IT operations",
            "alt": "A controlled technology lifecycle progressing from assessment to approved production.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/managed-it-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/managed-it-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:55+00:00",
        "modified_at": "2026-09-10T00:35:07+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 252,
        "potentially_affected": "Image maintainers preparing generalized Windows VMs for Azure deployment.",
        "dse_recommendation": "Check DVD-ROM availability and removable-storage restrictions on the image copy before running Sysprep.",
        "primary_source": {
            "name": "Deprovision or generalize a VM before creating an image - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/generalize",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure mounts an ISO through the DVD-ROM when creating a Windows VM from a generalized image; disabling that device can leave the guest stuck in the out-of-box experience. Microsoft also directs image authors to check for policies denying removable-storage access. Generalization is irreversible, and the source says not to restart the VM after Sysprep. Installed applications must support the preparation process, as must the server roles. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/generalize\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this check for a Windows image intended to be generalized, not a specialized image retaining its existing machine state. Identify policies and hardening settings applied to the image, including those inherited from another environment. Review the complete Sysprep prerequisites before scheduling the preparation.</p>\n<h2>DSE recommendation</h2>\n<p>Check DVD-ROM availability and removable-storage restrictions on the image copy before running Sysprep. Have the image and security owners agree on a preparation configuration that permits Azure provisioning. Review application-specific preparation requirements rather than assuming every installed agent supports cloning. Preserve an approved working source and perform the irreversible operation only on the designated image-production copy.</p>\n<h2>Verification</h2>\n<p>Deploy a representative new VM from the resulting generalized image and confirm that initial provisioning finishes. Test expected application startup and the intended post-provisioning security configuration. Retain the image version, preparation settings, and first-boot outcome together. If the guest stalls during initial setup, compare the media-access path and policies with the documented prerequisites before repeatedly rebuilding or restarting the generalized source VM.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/generalize\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Deprovision or generalize a VM before creating an image</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nAzure mounts an ISO through the DVD-ROM when creating a Windows VM from a generalized image; disabling that device can leave the guest stuck in the out-of-box experience. Microsoft also directs image authors to check for policies denying removable-storage access. Generalization is irreversible, and the source says not to restart the VM after Sysprep. Installed applications must support the preparation process, as must the server roles. Microsoft Learn.\nApplicability\nUse this check for a Windows image intended to be generalized, not a specialized image retaining its existing machine state. Identify policies and hardening settings applied to the image, including those inherited from another environment. Review the complete Sysprep prerequisites before scheduling the preparation.\nDSE recommendation\nCheck DVD-ROM availability and removable-storage restrictions on the image copy before running Sysprep. Have the image and security owners agree on a preparation configuration that permits Azure provisioning. Review application-specific preparation requirements rather than assuming every installed agent supports cloning. Preserve an approved working source and perform the irreversible operation only on the designated image-production copy.\nVerification\nDeploy a representative new VM from the resulting generalized image and confirm that initial provisioning finishes. Test expected application startup and the intended post-provisioning security configuration. Retain the image version, preparation settings, and first-boot outcome together. If the guest stalls during initial setup, compare the media-access path and policies with the documented prerequisites before repeatedly rebuilding or restarting the generalized source VM.\nOfficial references\nMicrosoft Learn: Deprovision or generalize a VM before creating an image. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure mounts an ISO through the DVD-ROM when creating a Windows VM from a generalized image; disabling that device can leave the guest stuck in the out-of-box experience. Microsoft also directs image authors to check for policies denying removable-storage access. Generalization is irreversible, and the source says not to restart the VM after Sysprep. Installed applications must support the preparation process, as must the server roles. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/generalize).\n\n## Applicability\n\nUse this check for a Windows image intended to be generalized, not a specialized image retaining its existing machine state. Identify policies and hardening settings applied to the image, including those inherited from another environment. Review the complete Sysprep prerequisites before scheduling the preparation.\n\n## DSE recommendation\n\nCheck DVD-ROM availability and removable-storage restrictions on the image copy before running Sysprep. Have the image and security owners agree on a preparation configuration that permits Azure provisioning. Review application-specific preparation requirements rather than assuming every installed agent supports cloning. Preserve an approved working source and perform the irreversible operation only on the designated image-production copy.\n\n## Verification\n\nDeploy a representative new VM from the resulting generalized image and confirm that initial provisioning finishes. Test expected application startup and the intended post-provisioning security configuration. Retain the image version, preparation settings, and first-boot outcome together. If the guest stalls during initial setup, compare the media-access path and policies with the documented prerequisites before repeatedly rebuilding or restarting the generalized source VM.\n\n## Official references\n\n[Microsoft Learn: Deprovision or generalize a VM before creating an image](https://learn.microsoft.com/en-us/azure/virtual-machines/generalize). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve Azure's provisioning media path in a generalized Windows image",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/",
                "headline": "Preserve Azure's provisioning media path in a generalized Windows image",
                "description": "Which guest restrictions can obstruct the first boot of an Azure VM created from a generalized Windows image?",
                "abstract": "Which guest restrictions can obstruct the first boot of an Azure VM created from a generalized Windows image?",
                "articleBody": "Source facts\nAzure mounts an ISO through the DVD-ROM when creating a Windows VM from a generalized image; disabling that device can leave the guest stuck in the out-of-box experience. Microsoft also directs image authors to check for policies denying removable-storage access. Generalization is irreversible, and the source says not to restart the VM after Sysprep. Installed applications must support the preparation process, as must the server roles. Microsoft Learn.\nApplicability\nUse this check for a Windows image intended to be generalized, not a specialized image retaining its existing machine state. Identify policies and hardening settings applied to the image, including those inherited from another environment. Review the complete Sysprep prerequisites before scheduling the preparation.\nDSE recommendation\nCheck DVD-ROM availability and removable-storage restrictions on the image copy before running Sysprep. Have the image and security owners agree on a preparation configuration that permits Azure provisioning. Review application-specific preparation requirements rather than assuming every installed agent supports cloning. Preserve an approved working source and perform the irreversible operation only on the designated image-production copy.\nVerification\nDeploy a representative new VM from the resulting generalized image and confirm that initial provisioning finishes. Test expected application startup and the intended post-provisioning security configuration. Retain the image version, preparation settings, and first-boot outcome together. If the guest stalls during initial setup, compare the media-access path and policies with the documented prerequisites before repeatedly rebuilding or restarting the generalized source VM.\nOfficial references\nMicrosoft Learn: Deprovision or generalize a VM before creating an image. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:55+00:00",
                "dateModified": "2026-09-10T00:35:07+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-061-preserve-azure-s-provisioning-media-path-in-a-generalized-windows-image/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/managed-it-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve Azure's provisioning media path in a generalized Windows image"
                },
                "articleSection": [
                    "IT",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "IT",
                    "Networks & Infrastructure",
                    "Checklist",
                    "Information priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 252,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Deprovision or generalize a VM before creating an image - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/generalize"
                }
            }
        ]
    }
}