# Reconcile the retained Gen1 image reference after a Trusted Launch upgrade

> Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:22+00:00
- Modified: 2026-09-10T00:35:08+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?

## Potentially affected

Operators of Azure Gen1 VMs upgraded through the supported Trusted Launch path, reviewing subsequent image-based operations.

## DSE recommendation

Flag the retained source-image reference in the VM's post-upgrade operating record before authorizing reimage.

## Article

## Source facts

Microsoft documents that a Gen1-to-Trusted-Launch upgrade can leave the VM’s image reference pointing to its original Gen1 image. The mismatch does not itself impair the upgraded VM or application, but automatic server guest patching uses that reference. Reimaging from the retained Gen1 reference causes boot failure. Fully returning to Gen1 requires restoring the pre-upgrade VM and disks from backup or a restore point. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1).

## Applicability

Apply this review after the supported upgrade of a Gen1 VM, not to every newly created Trusted Launch resource. Confirm the current guest, security type, original image reference, and recovery material. Review the source’s operating-system and conversion prerequisites separately before attempting an upgrade.

## DSE recommendation

Flag the retained source-image reference in the VM’s post-upgrade operating record before authorizing reimage. Have the patch owner review workflows that use the reference to select updates. Require the recovery owner to distinguish restoration of the old Gen1 resource from operations on the currently upgraded VM. Do not treat a successful first boot as acceptance of every later lifecycle action.

## Verification

Compare the running guest and current security configuration with the recorded source-image generation. Review any automation that may request reimage, and prevent an unreviewed operation from using the incompatible source. In an approved recovery exercise, validate the intended restoration path rather than deliberately reimaging production into a known failure. Preserve the upgrade and recovery identifiers so future operators can recognize this otherwise misleading metadata.

## Official references

[Microsoft Learn: Upgrade existing Gen1 VMs to Trusted Launch](https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1). Source reviewed September 9, 2026.

## Primary reference

- Name: Upgrade Gen1 VMs to Trusted launch - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/trusted-launch-existing-vm-gen-1
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Reconcile the retained Gen1 image reference after a Trusted Launch upgrade,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-094-reconcile-the-retained-gen1-image-reference-after-a-trusted-launch-upgrade/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
