# Verify the image's NVMe capability before accepting a new VM deployment

> Is an NVMe-capable VM size enough to ensure the new VM uses an NVMe controller?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-076-verify-the-image-s-nvme-capability-before-accepting-a-new-vm-deployment/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:40+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: IT, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Is an NVMe-capable VM size enough to ensure the new VM uses an NVMe controller?

## Potentially affected

Image and deployment owners creating Azure VMs intended to use the NVMe storage interface.

## DSE recommendation

Validate the image's generation and NVMe marking together with the target size and requested controller.

## Article

## Source facts

Microsoft does not support NVMe disks on Generation 1 VMs. New NVMe deployments require a supported OS image marked for NVMe, from Marketplace or an organizational Azure Compute Gallery. The source warns that an unmarked image creates a SCSI-based VM. It also notes that some sizes support both interfaces while newer generations can be NVMe-only, making image and size compatibility a joint choice. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/nvme-overview).

## Applicability

Review the exact image version and VM size selected by the deployment process. Include custom gallery images, not only marketplace defaults. Distinguish eligibility to create a VM from evidence that its resulting controller is the interface required by the workload.

## DSE recommendation

Validate the image’s generation and NVMe marking together with the target size and requested controller. Make those properties part of image promotion and deployment review. Have the image owner resolve an unsupported OS or missing capability before changing production sizing. Avoid treating a deployment that silently uses another controller as an equivalent result merely because the VM starts.

## Verification

Create a representative test VM through the intended deployment path and inspect its resulting controller type. Compare the image version, size, and controller with the approved combination. Run the workload’s storage checks without promising a performance gain from the interface name alone. Repeat this acceptance when replacing the gallery image or moving to a size with different controller support, and retain mismatches as failed deployment requirements.

## Official references

[Microsoft Learn: NVMe overview](https://learn.microsoft.com/en-us/azure/virtual-machines/nvme-overview). Source reviewed September 9, 2026.

## Primary reference

- Name: NVMe Overview - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/nvme-overview
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Verify the image's NVMe capability before accepting a new VM deployment,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-076-verify-the-image-s-nvme-capability-before-accepting-a-new-vm-deployment/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
