# Separate extension install-time version selection from ongoing Azure upgrades

> Why are AutoUpgradeMinorVersion and EnableAutomaticUpgrade separate decisions for an Azure VM extension?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-024-separate-extension-install-time-version-selection-from-ongoing-azure-upgrades/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:32+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why are AutoUpgradeMinorVersion and EnableAutomaticUpgrade separate decisions for an Azure VM extension?

## Potentially affected

Operators configuring supported extensions on Azure virtual machines or virtual machine scale sets.

## DSE recommendation

Record the creation-time and ongoing-upgrade settings separately for each extension, with an explicit major-version change owner.

## Article

## Source facts

AutoUpgradeMinorVersion selects the latest stable minor extension version during VM creation or a configuration update. EnableAutomaticUpgrade governs later upgrades on existing VMs instead. Neither setting automatically crosses a major-version boundary. Each supported extension is enrolled separately. For a scale set using manual upgrade mode, changing its model does not propagate the setting to existing instances without an instance update. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/automatic-extension-upgrade).

## Applicability

Review the extension’s publisher, type, configured version, and automatic-upgrade support before deciding its policy. Distinguish an individual Azure VM from a scale-set model and its currently deployed instances. Do not use an extension-version decision as the approval for an operating-system image replacement.

## DSE recommendation

Record the creation-time and ongoing-upgrade settings separately for each extension, with an explicit major-version change owner. Ask that owner to explain any pinned minor version and the condition for removing the pin. For manually managed scale sets, add a deliberate instance-update step to the change record rather than stopping after the model edit. Keep exceptions extension-specific instead of assigning one unexplained fleet-wide value.

## Verification

Inspect the configured properties and the installed version on a representative existing instance and on an approved newly created instance. Compare both observations with the intended policy. Where a manual scale-set update is needed, confirm propagation on each targeted instance. Preserve failures and version mismatches for investigation; absence of a major-version change is not evidence that the minor-version controls failed.

## Official references

[Microsoft Learn: Automatic Extension Upgrade for VMs and scale sets in Azure](https://learn.microsoft.com/en-us/azure/virtual-machines/automatic-extension-upgrade). Source reviewed September 9, 2026.

## Primary reference

- Name: Automatic Extension Upgrade for VMs and scale sets in Azure - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/automatic-extension-upgrade
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate extension install-time version selection from ongoing Azure upgrades,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-024-separate-extension-install-time-version-selection-from-ongoing-azure-upgrades/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
