# Do not plan an in-place conversion to the direct shared gallery preview

> Can an existing Azure Compute Gallery be switched to direct subscription or tenant sharing?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-086-do-not-plan-an-in-place-conversion-to-the-direct-shared-gallery-preview/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:30+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can an existing Azure Compute Gallery be switched to direct subscription or tenant sharing?

## Potentially affected

Publishers evaluating direct shared galleries in supported non-government Azure clouds under the preview policy.

## DSE recommendation

Approve both the new gallery requirement and its broad target audience before adopting direct sharing.

## Article

## Source facts

The direct shared gallery preview requires a new gallery with sharingProfile.permissions set to Groups; an existing gallery cannot be reused or that property updated. Targeting a subscription or tenant makes image consumption available to all Azure users in that target, not just selected people. The preview excludes VM applications, encrypted image versions, and government clouds. Publishing requires preview registration, while consumption does not require extra preview access. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery-direct).

## Applicability

Use this review before treating direct sharing as a small permission edit on an established gallery. Confirm that broad distribution is actually required and inspect the current preview limitations and supported tooling.

## DSE recommendation

Approve both the new gallery requirement and its broad target audience before adopting direct sharing. Have the image owner identify which approved images could be published to the new gallery and which consumers are intentionally included. Review the subscription or tenant boundary with the identity owner. If the requirement is access for selected principals, reassess whether this distribution mode matches the requirement before creating another gallery.

## Verification

Validate the planned target IDs and new gallery configuration in a controlled trial. Confirm an intended consumer can locate and use the approved image through the supported path, and verify that an untargeted boundary is not included in the sharing configuration. Preserve the publisher-to-consumer mapping with the image identity. Keep the original gallery’s lifecycle separate rather than assuming direct-sharing setup has migrated or retired its consumers.

## Official references

[Microsoft Learn: Share a gallery with all users in a subscription or tenant preview](https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery-direct). Source reviewed September 9, 2026.

## Primary reference

- Name: Share Azure Compute Gallery Resources Directly with Subscriptions and Tenants - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/share-gallery-direct
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not plan an in-place conversion to the direct shared gallery preview,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-086-do-not-plan-an-in-place-conversion-to-the-direct-shared-gallery-preview/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
