{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
        "slug": "dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/"
        },
        "title": "Create a new gallery image definition when its platform identity must change",
        "summary": "Can a new Azure gallery image version change the existing definition's OS state or generation?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:25+00:00",
        "modified_at": "2026-09-10T00:35:08+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 243,
        "potentially_affected": "Azure Compute Gallery publishers whose intended source no longer matches an existing image definition.",
        "dse_recommendation": "Treat an image-definition mismatch as a lineage design decision, not a retryable version-upload error.",
        "primary_source": {
            "name": "Troubleshoot problems with shared images in Azure - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/troubleshooting-shared-images",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Compute Gallery does not permit changing an image definition&#8217;s OS type, OS state, Hyper-V generation, publisher, offer or SKU. Microsoft&#8217;s prescribed response is a new definition. A version&#8217;s source must match its definition&#8217;s generalized or specialized state and Hyper-V generation. Within one gallery, each definition must also have a unique publisher, offer and SKU combination. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/troubleshooting-shared-images\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this check when an image pipeline changes the source platform or preparation state but continues targeting an established definition. Keep the definition&#8217;s identity separate from the version number used for a particular build.</p>\n<h2>DSE recommendation</h2>\n<p>Treat an image-definition mismatch as a lineage design decision, not a retryable version-upload error. Have the image owner compare the proposed source with the definition before retrying publication. If a new definition is required, plan its identifier and the consumer-reference changes deliberately. Keep the old definition available under its approved lifecycle while consumers are evaluated; creating a replacement is not authorization to delete existing versions.</p>\n<h2>Verification</h2>\n<p>Publish an approved test version under the matching definition and verify its recorded state and generation. Exercise a representative consumer deployment with the intended identity and configuration inputs. Record any mismatch as a rejected publication condition rather than attempting to disguise it with another version number. Confirm that the new definition&#8217;s publisher-offer-SKU triplet is distinct within the gallery and that dependent automation uses the intended reference.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/troubleshooting-shared-images\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Troubleshoot images in an Azure Compute Gallery</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nAzure Compute Gallery does not permit changing an image definition’s OS type, OS state, Hyper-V generation, publisher, offer or SKU. Microsoft’s prescribed response is a new definition. A version’s source must match its definition’s generalized or specialized state and Hyper-V generation. Within one gallery, each definition must also have a unique publisher, offer and SKU combination. Microsoft Learn.\nApplicability\nUse this check when an image pipeline changes the source platform or preparation state but continues targeting an established definition. Keep the definition’s identity separate from the version number used for a particular build.\nDSE recommendation\nTreat an image-definition mismatch as a lineage design decision, not a retryable version-upload error. Have the image owner compare the proposed source with the definition before retrying publication. If a new definition is required, plan its identifier and the consumer-reference changes deliberately. Keep the old definition available under its approved lifecycle while consumers are evaluated; creating a replacement is not authorization to delete existing versions.\nVerification\nPublish an approved test version under the matching definition and verify its recorded state and generation. Exercise a representative consumer deployment with the intended identity and configuration inputs. Record any mismatch as a rejected publication condition rather than attempting to disguise it with another version number. Confirm that the new definition’s publisher-offer-SKU triplet is distinct within the gallery and that dependent automation uses the intended reference.\nOfficial references\nMicrosoft Learn: Troubleshoot images in an Azure Compute Gallery. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure Compute Gallery does not permit changing an image definition’s OS type, OS state, Hyper-V generation, publisher, offer or SKU. Microsoft’s prescribed response is a new definition. A version’s source must match its definition’s generalized or specialized state and Hyper-V generation. Within one gallery, each definition must also have a unique publisher, offer and SKU combination. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/troubleshooting-shared-images).\n\n## Applicability\n\nUse this check when an image pipeline changes the source platform or preparation state but continues targeting an established definition. Keep the definition’s identity separate from the version number used for a particular build.\n\n## DSE recommendation\n\nTreat an image-definition mismatch as a lineage design decision, not a retryable version-upload error. Have the image owner compare the proposed source with the definition before retrying publication. If a new definition is required, plan its identifier and the consumer-reference changes deliberately. Keep the old definition available under its approved lifecycle while consumers are evaluated; creating a replacement is not authorization to delete existing versions.\n\n## Verification\n\nPublish an approved test version under the matching definition and verify its recorded state and generation. Exercise a representative consumer deployment with the intended identity and configuration inputs. Record any mismatch as a rejected publication condition rather than attempting to disguise it with another version number. Confirm that the new definition’s publisher-offer-SKU triplet is distinct within the gallery and that dependent automation uses the intended reference.\n\n## Official references\n\n[Microsoft Learn: Troubleshoot images in an Azure Compute Gallery](https://learn.microsoft.com/en-us/azure/virtual-machines/troubleshooting-shared-images). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Create a new gallery image definition when its platform identity must change",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/",
                "headline": "Create a new gallery image definition when its platform identity must change",
                "description": "Can a new Azure gallery image version change the existing definition's OS state or generation?",
                "abstract": "Can a new Azure gallery image version change the existing definition's OS state or generation?",
                "articleBody": "Source facts\nAzure Compute Gallery does not permit changing an image definition’s OS type, OS state, Hyper-V generation, publisher, offer or SKU. Microsoft’s prescribed response is a new definition. A version’s source must match its definition’s generalized or specialized state and Hyper-V generation. Within one gallery, each definition must also have a unique publisher, offer and SKU combination. Microsoft Learn.\nApplicability\nUse this check when an image pipeline changes the source platform or preparation state but continues targeting an established definition. Keep the definition’s identity separate from the version number used for a particular build.\nDSE recommendation\nTreat an image-definition mismatch as a lineage design decision, not a retryable version-upload error. Have the image owner compare the proposed source with the definition before retrying publication. If a new definition is required, plan its identifier and the consumer-reference changes deliberately. Keep the old definition available under its approved lifecycle while consumers are evaluated; creating a replacement is not authorization to delete existing versions.\nVerification\nPublish an approved test version under the matching definition and verify its recorded state and generation. Exercise a representative consumer deployment with the intended identity and configuration inputs. Record any mismatch as a rejected publication condition rather than attempting to disguise it with another version number. Confirm that the new definition’s publisher-offer-SKU triplet is distinct within the gallery and that dependent automation uses the intended reference.\nOfficial references\nMicrosoft Learn: Troubleshoot images in an Azure Compute Gallery. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:25+00:00",
                "dateModified": "2026-09-10T00:35:08+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-091-create-a-new-gallery-image-definition-when-its-platform-identity-must-change/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Create a new gallery image definition when its platform identity must change"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 243,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Troubleshoot problems with shared images in Azure - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/troubleshooting-shared-images"
                }
            }
        ]
    }
}