# Choose Dedicated Host failure replacement before relying on automatic recovery

> What recovery obligation follows from disabling automatic replacement of a failed Dedicated Host?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-043-choose-dedicated-host-failure-replacement-before-relying-on-automatic-recovery/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:31:13+00:00
- Modified: 2026-09-10T00:32:00+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

What recovery obligation follows from disabling automatic replacement of a failed Dedicated Host?

## Potentially affected

Azure Dedicated Host owners choosing host-level automatic replacement behavior.

## DSE recommendation

Document the manual recovery owner before opting out of automatic host replacement.

## Article

## Source facts

Azure Dedicated Host normally service-heals an unhealthy host by moving its VMs to healthy hardware and restarting them, with downtime during that process. Disabling automatic replacement can instead leave the host pending deallocation after failure, requiring manual creation of a replacement host and VM movement. Microsoft describes auto-replacement as a creation-time setting that cannot later be changed. Manually stopped or deallocated VMs are not moved by automatic service healing. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/dedicated-hosts).

## Applicability

Use this decision when a host-affinity requirement is being weighed against automated recovery. Include deliberately stopped VMs in the recovery inventory instead of assuming every associated machine participates in service healing.

## DSE recommendation

Document the manual recovery owner before opting out of automatic host replacement. Have the workload and platform owners agree how failure will be detected, who will provision replacement capacity, and how each VM will be recovered under the chosen setting. Record the reason for any opt-out and the intended recovery procedure before host creation. Do not equate a dedicated physical boundary with uninterrupted service.

## Verification

Inspect the created host’s actual auto-replacement property and reconcile the VM inventory with the recovery plan. Rehearse the decision and authorized recovery steps in a controlled environment without manufacturing a production host failure. After a real or approved recovery event, verify each workload separately and account for machines that were stopped beforehand. Keep missing recovery evidence open rather than reporting host availability as complete application restoration.

## Official references

[Microsoft Learn: Azure Dedicated Hosts](https://learn.microsoft.com/en-us/azure/virtual-machines/dedicated-hosts). Source reviewed September 9, 2026.

## Primary reference

- Name: Overview of Azure Dedicated Hosts for virtual machines - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/dedicated-hosts
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Choose Dedicated Host failure replacement before relying on automatic recovery,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-043-choose-dedicated-host-failure-replacement-before-relying-on-automatic-recovery/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
