{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
        "slug": "dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/"
        },
        "title": "Do not treat Manual scale-set upgrade mode as a freeze on automatic upgrades",
        "summary": "Does Manual upgrade mode stop enabled automatic OS image or extension upgrades?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:13+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 231,
        "potentially_affected": "Azure scale sets whose owners are reviewing upgrade controls while automatic image or extension upgrades are enabled.",
        "dse_recommendation": "Review upgrade mode and each enabled automatic-upgrade feature as separate controls.",
        "primary_source": {
            "name": "Configure rolling upgrades on Virtual Machine Scale Sets - Azure Virtual Machine Scale Sets | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>A scale set&#8217;s upgrade-policy mode and rolling-upgrade configuration are separate nested settings. A rolling-upgrade policy exists even with Automatic or Manual mode. The mode controls how scale-set model updates reach instances, but enabled automatic OS image and automatic extension upgrades do not use that mode; they use the rolling-upgrade policy&#8217;s configuration. <a href=\"https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this distinction when planning a change freeze or investigating an upgrade that occurred while the model&#8217;s mode was Manual. Identify what initiated the change before deciding which control should have prevented it.</p>\n<h2>DSE recommendation</h2>\n<p>Review upgrade mode and each enabled automatic-upgrade feature as separate controls. Have the platform owner list model-driven, OS-image and extension upgrade mechanisms independently. Document the authorized pause or continuation decision for each applicable mechanism using its own supported procedure. Preserve the existing rolling batch and health settings during the review, and do not assume selecting Manual has disabled unrelated automation.</p>\n<h2>Verification</h2>\n<p>In a controlled scale set, inspect both the mode and rolling policy together with the automatic-feature settings. During an approved test, identify the trigger and compare observed instance changes with the corresponding control. Retain upgrade history and actual configuration evidence. If the change source remains unclear, keep the freeze assessment unresolved instead of reporting Manual mode as proof that every instance-change path is blocked.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure rolling upgrades on Virtual Machine Scale Sets</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nA scale set’s upgrade-policy mode and rolling-upgrade configuration are separate nested settings. A rolling-upgrade policy exists even with Automatic or Manual mode. The mode controls how scale-set model updates reach instances, but enabled automatic OS image and automatic extension upgrades do not use that mode; they use the rolling-upgrade policy’s configuration. Microsoft Learn.\nApplicability\nUse this distinction when planning a change freeze or investigating an upgrade that occurred while the model’s mode was Manual. Identify what initiated the change before deciding which control should have prevented it.\nDSE recommendation\nReview upgrade mode and each enabled automatic-upgrade feature as separate controls. Have the platform owner list model-driven, OS-image and extension upgrade mechanisms independently. Document the authorized pause or continuation decision for each applicable mechanism using its own supported procedure. Preserve the existing rolling batch and health settings during the review, and do not assume selecting Manual has disabled unrelated automation.\nVerification\nIn a controlled scale set, inspect both the mode and rolling policy together with the automatic-feature settings. During an approved test, identify the trigger and compare observed instance changes with the corresponding control. Retain upgrade history and actual configuration evidence. If the change source remains unclear, keep the freeze assessment unresolved instead of reporting Manual mode as proof that every instance-change path is blocked.\nOfficial references\nMicrosoft Learn: Configure rolling upgrades on Virtual Machine Scale Sets. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nA scale set’s upgrade-policy mode and rolling-upgrade configuration are separate nested settings. A rolling-upgrade policy exists even with Automatic or Manual mode. The mode controls how scale-set model updates reach instances, but enabled automatic OS image and automatic extension upgrades do not use that mode; they use the rolling-upgrade policy’s configuration. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades).\n\n## Applicability\n\nUse this distinction when planning a change freeze or investigating an upgrade that occurred while the model’s mode was Manual. Identify what initiated the change before deciding which control should have prevented it.\n\n## DSE recommendation\n\nReview upgrade mode and each enabled automatic-upgrade feature as separate controls. Have the platform owner list model-driven, OS-image and extension upgrade mechanisms independently. Document the authorized pause or continuation decision for each applicable mechanism using its own supported procedure. Preserve the existing rolling batch and health settings during the review, and do not assume selecting Manual has disabled unrelated automation.\n\n## Verification\n\nIn a controlled scale set, inspect both the mode and rolling policy together with the automatic-feature settings. During an approved test, identify the trigger and compare observed instance changes with the corresponding control. Retain upgrade history and actual configuration evidence. If the change source remains unclear, keep the freeze assessment unresolved instead of reporting Manual mode as proof that every instance-change path is blocked.\n\n## Official references\n\n[Microsoft Learn: Configure rolling upgrades on Virtual Machine Scale Sets](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not treat Manual scale-set upgrade mode as a freeze on automatic upgrades",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/",
                "headline": "Do not treat Manual scale-set upgrade mode as a freeze on automatic upgrades",
                "description": "Does Manual upgrade mode stop enabled automatic OS image or extension upgrades?",
                "abstract": "Does Manual upgrade mode stop enabled automatic OS image or extension upgrades?",
                "articleBody": "Source facts\nA scale set’s upgrade-policy mode and rolling-upgrade configuration are separate nested settings. A rolling-upgrade policy exists even with Automatic or Manual mode. The mode controls how scale-set model updates reach instances, but enabled automatic OS image and automatic extension upgrades do not use that mode; they use the rolling-upgrade policy’s configuration. Microsoft Learn.\nApplicability\nUse this distinction when planning a change freeze or investigating an upgrade that occurred while the model’s mode was Manual. Identify what initiated the change before deciding which control should have prevented it.\nDSE recommendation\nReview upgrade mode and each enabled automatic-upgrade feature as separate controls. Have the platform owner list model-driven, OS-image and extension upgrade mechanisms independently. Document the authorized pause or continuation decision for each applicable mechanism using its own supported procedure. Preserve the existing rolling batch and health settings during the review, and do not assume selecting Manual has disabled unrelated automation.\nVerification\nIn a controlled scale set, inspect both the mode and rolling policy together with the automatic-feature settings. During an approved test, identify the trigger and compare observed instance changes with the corresponding control. Retain upgrade history and actual configuration evidence. If the change source remains unclear, keep the freeze assessment unresolved instead of reporting Manual mode as proof that every instance-change path is blocked.\nOfficial references\nMicrosoft Learn: Configure rolling upgrades on Virtual Machine Scale Sets. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:22:13+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not treat Manual scale-set upgrade mode as a freeze on automatic upgrades"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 231,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure rolling upgrades on Virtual Machine Scale Sets - Azure Virtual Machine Scale Sets | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades"
                }
            }
        ]
    }
}