# Do not treat a gallery image's end-of-life date as a deployment block

> Will setting an Azure Compute Gallery image end-of-life date prevent new VMs from using it?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-087-do-not-treat-a-gallery-image-s-end-of-life-date-as-a-deployment-block/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:29+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Will setting an Azure Compute Gallery image end-of-life date prevent new VMs from using it?

## Potentially affected

Image owners defining lifecycle rules for Azure Compute Gallery definitions and versions.

## DSE recommendation

Document the enforcement mechanism separately from the image's informational end-of-life metadata.

## Article

## Source facts

Azure Compute Gallery end-of-life dates are informational: users can still create VMs from image versions after those dates. A definition groups versions and carries their shared metadata, but deployment uses an image version rather than the definition itself. An informational lifecycle date is therefore separate from the decision to allow a particular version in deployment. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/shared-image-galleries).

## Applicability

Review both the image definition and the individual version referenced by a deployment workflow. Identify whether consumers pin a specific version or request latest. Clarify whether the business requirement is a notice, a preferred version, or an actual prohibition on new deployments.

## DSE recommendation

Document the enforcement mechanism separately from the image’s informational end-of-life metadata. Ask the image owner to map each consumer’s selection method before announcing that an old version is retired. Maintain an approved-version record and have the deployment owner demonstrate how its workflow applies that decision. Do not claim a date field alone satisfies a prohibition.

## Verification

In a nonproduction check, inspect which version a representative workflow actually selects and compare it with the approved-version record. Include a pinned reference and a latest request if both are used. Test the proposed lifecycle restriction directly under authorized conditions rather than merely checking that the date was saved. Preserve the selected version ID and outcome, and investigate any consumer that can still choose a disallowed version.

## Official references

[Microsoft Learn: Azure Compute Gallery images and versions](https://learn.microsoft.com/en-us/azure/virtual-machines/shared-image-galleries). Source reviewed September 9, 2026.

## Primary reference

- Name: Share VM images in a compute gallery - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/shared-image-galleries
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not treat a gallery image's end-of-life date as a deployment block,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-087-do-not-treat-a-gallery-image-s-end-of-life-date-as-a-deployment-block/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
