ExplainerInformationITNetworks & Infrastructure

Separate extension install-time version selection from ongoing Azure upgrades

Why are AutoUpgradeMinorVersion and EnableAutomaticUpgrade separate decisions for an Azure VM extension?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureExplainer · 2 min read
Executive summary

What you need to know

Why are AutoUpgradeMinorVersion and EnableAutomaticUpgrade separate decisions for an Azure VM extension?

Potentially affected

Operators configuring supported extensions on Azure virtual machines or virtual machine scale sets.

DSE recommendation

Record the creation-time and ongoing-upgrade settings separately for each extension, with an explicit major-version change owner.

Source facts

AutoUpgradeMinorVersion selects the latest stable minor extension version during VM creation or a configuration update. EnableAutomaticUpgrade governs later upgrades on existing VMs instead. Neither setting automatically crosses a major-version boundary. Each supported extension is enrolled separately. For a scale set using manual upgrade mode, changing its model does not propagate the setting to existing instances without an instance update. Microsoft Learn.

Applicability

Review the extension’s publisher, type, configured version, and automatic-upgrade support before deciding its policy. Distinguish an individual Azure VM from a scale-set model and its currently deployed instances. Do not use an extension-version decision as the approval for an operating-system image replacement.

DSE recommendation

Record the creation-time and ongoing-upgrade settings separately for each extension, with an explicit major-version change owner. Ask that owner to explain any pinned minor version and the condition for removing the pin. For manually managed scale sets, add a deliberate instance-update step to the change record rather than stopping after the model edit. Keep exceptions extension-specific instead of assigning one unexplained fleet-wide value.

Verification

Inspect the configured properties and the installed version on a representative existing instance and on an approved newly created instance. Compare both observations with the intended policy. Where a manual scale-set update is needed, confirm propagation on each targeted instance. Preserve failures and version mismatches for investigation; absence of a major-version change is not evidence that the minor-version controls failed.

Official references

Microsoft Learn: Automatic Extension Upgrade for VMs and scale sets in Azure. Source reviewed September 9, 2026.

Primary reference

Review the official source

Automatic Extension Upgrade for VMs and scale sets in Azure - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE