# Check gallery and scale-set compatibility before enabling image soft delete

> Does the Azure Compute Gallery soft-delete preview cover this image layout and its consumers?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-088-check-gallery-and-scale-set-compatibility-before-enabling-image-soft-delete/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:28+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Checklist
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Does the Azure Compute Gallery soft-delete preview cover this image layout and its consumers?

## Potentially affected

Image owners evaluating the Azure Compute Gallery soft-delete preview outside National Clouds rather than assuming general recovery coverage.

## DSE recommendation

Inventory gallery locations and consuming scale-set orchestration before approving this preview protection.

## Article

## Source facts

Compute Gallery soft delete is a preview for images, not VM application recovery. Its seven-day retention period cannot currently be changed. Microsoft excludes Flexible-orchestration scale sets and prevents enablement when gallery, definition, and version locations differ. A gallery or definition containing soft-deleted resources cannot be deleted. The feature also requires registration and API version 2024-03-03 or newer. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/soft-delete-gallery).

## Applicability

The preview is not supported in National Clouds. Evaluate it only under the organization’s preview policy and check the remaining platform limitations. Identify the gallery’s resource hierarchy, image consumers, and intended recovery object. Do not interpret image protection as coverage for VM applications or every scale-set design.

## DSE recommendation

Inventory gallery locations and consuming scale-set orchestration before approving this preview protection. Have the recovery owner document excluded assets and choose a separate recovery approach for them. Review gallery cleanup procedures so a blocked parent deletion prompts investigation of retained children rather than an automatic permanent-delete step. Record the fixed recovery interval in the operating procedure.

## Verification

On an eligible nonproduction gallery, rehearse the supported image deletion and recovery path with a disposable version. Verify the recovered image’s intended use and record the actual result. Inspect the soft-deleted inventory before any parent-resource cleanup. Treat permanent deletion and disabling protection as separately authorized decisions, not troubleshooting defaults, and preserve the compatibility review with the recovery evidence.

## Official references

[Microsoft Learn: Soft Delete in Azure Compute Gallery preview](https://learn.microsoft.com/en-us/azure/virtual-machines/soft-delete-gallery). Source reviewed September 9, 2026.

## Primary reference

- Name: Soft Delete in Azure Compute Gallery (Preview) - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/soft-delete-gallery
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check gallery and scale-set compatibility before enabling image soft delete,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-088-check-gallery-and-scale-set-compatibility-before-enabling-image-soft-delete/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
