{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
        "slug": "dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/"
        },
        "title": "Reconcile the retained Gen1 image reference after a Trusted Launch upgrade",
        "summary": "Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:30:22+00:00",
        "modified_at": "2026-09-10T00:35:08+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 253,
        "potentially_affected": "Operators of Azure Gen1 VMs upgraded through the supported Trusted Launch path, reviewing subsequent image-based operations.",
        "dse_recommendation": "Flag the retained source-image reference in the VM's post-upgrade operating record before authorizing reimage.",
        "primary_source": {
            "name": "Upgrade Gen1 VMs to Trusted launch - Azure Virtual Machines | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Microsoft documents that a Gen1-to-Trusted-Launch upgrade can leave the VM&#8217;s image reference pointing to its original Gen1 image. The mismatch does not itself impair the upgraded VM or application, but automatic server guest patching uses that reference. Reimaging from the retained Gen1 reference causes boot failure. Fully returning to Gen1 requires restoring the pre-upgrade VM and disks from backup or a restore point. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review after the supported upgrade of a Gen1 VM, not to every newly created Trusted Launch resource. Confirm the current guest, security type, original image reference, and recovery material. Review the source&#8217;s operating-system and conversion prerequisites separately before attempting an upgrade.</p>\n<h2>DSE recommendation</h2>\n<p>Flag the retained source-image reference in the VM&#8217;s post-upgrade operating record before authorizing reimage. Have the patch owner review workflows that use the reference to select updates. Require the recovery owner to distinguish restoration of the old Gen1 resource from operations on the currently upgraded VM. Do not treat a successful first boot as acceptance of every later lifecycle action.</p>\n<h2>Verification</h2>\n<p>Compare the running guest and current security configuration with the recorded source-image generation. Review any automation that may request reimage, and prevent an unreviewed operation from using the incompatible source. In an approved recovery exercise, validate the intended restoration path rather than deliberately reimaging production into a known failure. Preserve the upgrade and recovery identifiers so future operators can recognize this otherwise misleading metadata.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Upgrade existing Gen1 VMs to Trusted Launch</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nMicrosoft documents that a Gen1-to-Trusted-Launch upgrade can leave the VM’s image reference pointing to its original Gen1 image. The mismatch does not itself impair the upgraded VM or application, but automatic server guest patching uses that reference. Reimaging from the retained Gen1 reference causes boot failure. Fully returning to Gen1 requires restoring the pre-upgrade VM and disks from backup or a restore point. Microsoft Learn.\nApplicability\nApply this review after the supported upgrade of a Gen1 VM, not to every newly created Trusted Launch resource. Confirm the current guest, security type, original image reference, and recovery material. Review the source’s operating-system and conversion prerequisites separately before attempting an upgrade.\nDSE recommendation\nFlag the retained source-image reference in the VM’s post-upgrade operating record before authorizing reimage. Have the patch owner review workflows that use the reference to select updates. Require the recovery owner to distinguish restoration of the old Gen1 resource from operations on the currently upgraded VM. Do not treat a successful first boot as acceptance of every later lifecycle action.\nVerification\nCompare the running guest and current security configuration with the recorded source-image generation. Review any automation that may request reimage, and prevent an unreviewed operation from using the incompatible source. In an approved recovery exercise, validate the intended restoration path rather than deliberately reimaging production into a known failure. Preserve the upgrade and recovery identifiers so future operators can recognize this otherwise misleading metadata.\nOfficial references\nMicrosoft Learn: Upgrade existing Gen1 VMs to Trusted Launch. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nMicrosoft documents that a Gen1-to-Trusted-Launch upgrade can leave the VM’s image reference pointing to its original Gen1 image. The mismatch does not itself impair the upgraded VM or application, but automatic server guest patching uses that reference. Reimaging from the retained Gen1 reference causes boot failure. Fully returning to Gen1 requires restoring the pre-upgrade VM and disks from backup or a restore point. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1).\n\n## Applicability\n\nApply this review after the supported upgrade of a Gen1 VM, not to every newly created Trusted Launch resource. Confirm the current guest, security type, original image reference, and recovery material. Review the source’s operating-system and conversion prerequisites separately before attempting an upgrade.\n\n## DSE recommendation\n\nFlag the retained source-image reference in the VM’s post-upgrade operating record before authorizing reimage. Have the patch owner review workflows that use the reference to select updates. Require the recovery owner to distinguish restoration of the old Gen1 resource from operations on the currently upgraded VM. Do not treat a successful first boot as acceptance of every later lifecycle action.\n\n## Verification\n\nCompare the running guest and current security configuration with the recorded source-image generation. Review any automation that may request reimage, and prevent an unreviewed operation from using the incompatible source. In an approved recovery exercise, validate the intended restoration path rather than deliberately reimaging production into a known failure. Preserve the upgrade and recovery identifiers so future operators can recognize this otherwise misleading metadata.\n\n## Official references\n\n[Microsoft Learn: Upgrade existing Gen1 VMs to Trusted Launch](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Reconcile the retained Gen1 image reference after a Trusted Launch upgrade",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/",
                "headline": "Reconcile the retained Gen1 image reference after a Trusted Launch upgrade",
                "description": "Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?",
                "abstract": "Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?",
                "articleBody": "Source facts\nMicrosoft documents that a Gen1-to-Trusted-Launch upgrade can leave the VM’s image reference pointing to its original Gen1 image. The mismatch does not itself impair the upgraded VM or application, but automatic server guest patching uses that reference. Reimaging from the retained Gen1 reference causes boot failure. Fully returning to Gen1 requires restoring the pre-upgrade VM and disks from backup or a restore point. Microsoft Learn.\nApplicability\nApply this review after the supported upgrade of a Gen1 VM, not to every newly created Trusted Launch resource. Confirm the current guest, security type, original image reference, and recovery material. Review the source’s operating-system and conversion prerequisites separately before attempting an upgrade.\nDSE recommendation\nFlag the retained source-image reference in the VM’s post-upgrade operating record before authorizing reimage. Have the patch owner review workflows that use the reference to select updates. Require the recovery owner to distinguish restoration of the old Gen1 resource from operations on the currently upgraded VM. Do not treat a successful first boot as acceptance of every later lifecycle action.\nVerification\nCompare the running guest and current security configuration with the recorded source-image generation. Review any automation that may request reimage, and prevent an unreviewed operation from using the incompatible source. In an approved recovery exercise, validate the intended restoration path rather than deliberately reimaging production into a known failure. Preserve the upgrade and recovery identifiers so future operators can recognize this otherwise misleading metadata.\nOfficial references\nMicrosoft Learn: Upgrade existing Gen1 VMs to Trusted Launch. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:30:22+00:00",
                "dateModified": "2026-09-10T00:35:08+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Reconcile the retained Gen1 image reference after a Trusted Launch upgrade"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 253,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Upgrade Gen1 VMs to Trusted launch - Azure Virtual Machines | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1"
                }
            }
        ]
    }
}