# Read the Windows VM creation flag before planning a patch-mode transition

> Can an existing Azure Windows VM switch freely between AutomaticByOS and Manual patch modes?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-025-read-the-windows-vm-creation-flag-before-planning-a-patch-mode-transition/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:31+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can an existing Azure Windows VM switch freely between AutomaticByOS and Manual patch modes?

## Potentially affected

Azure Windows VMs using the documented supported platform images and reviewing patch-orchestration transitions.

## DSE recommendation

Include enableAutomaticUpdates in the before-state record for a Windows patch-mode change.

## Article

## Source facts

An Azure Windows VM’s enableAutomaticUpdates property is set only when the VM is created. With that property false, Microsoft supports transitions between AutomaticByPlatform and Manual; with it true, transitions are between AutomaticByPlatform and AutomaticByOS. Switching between AutomaticByOS and Manual is unsupported. AutomaticByOS uses native Windows updates, while Manual disables them. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/automatic-vm-guest-patching).

## Applicability

Use this check before planning the return path from platform-orchestrated guest patching. The source limits automatic guest patching to its listed platform-image combinations and excludes custom images, so validate the image as well as the Windows configuration.

## DSE recommendation

Include enableAutomaticUpdates in the before-state record for a Windows patch-mode change. Have the patch owner identify the current value and the supported destination mode before approving the change. Record who will manage updates after platform orchestration is disabled. Do not assume that selecting a different label can override a creation-time property, and do not leave the replacement update mechanism unspecified.

## Verification

In a representative approved test, compare the resource’s actual patch settings with the planned transition and inspect the resulting guest update configuration. Verify an authorized assessment or update outcome through the intended mechanism. If the requested transition is unsupported, redesign the plan rather than repeatedly editing the immutable flag. Preserve the selected mode and its operational owner in the maintenance record.

## Official references

[Microsoft Learn: Automatic Guest Patching for Azure Virtual Machines and Scale Sets](https://learn.microsoft.com/en-us/azure/virtual-machines/automatic-vm-guest-patching). Source reviewed September 9, 2026.

## Primary reference

- Name: Automatic Guest Patching for Azure Virtual Machines and Scale Sets - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/automatic-vm-guest-patching
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Read the Windows VM creation flag before planning a patch-mode transition,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-025-read-the-windows-vm-creation-flag-before-planning-a-patch-mode-transition/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
