GuideInformationBusiness ContinuityIT

Reconcile the retained Gen1 image reference after a Trusted Launch upgrade

Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Why should reimage and guest-patching workflows be reviewed after a Gen1 VM becomes Trusted Launch?

Potentially affected

Operators of Azure Gen1 VMs upgraded through the supported Trusted Launch path, reviewing subsequent image-based operations.

DSE recommendation

Flag the retained source-image reference in the VM's post-upgrade operating record before authorizing reimage.

Source facts

Microsoft documents that a Gen1-to-Trusted-Launch upgrade can leave the VM’s image reference pointing to its original Gen1 image. The mismatch does not itself impair the upgraded VM or application, but automatic server guest patching uses that reference. Reimaging from the retained Gen1 reference causes boot failure. Fully returning to Gen1 requires restoring the pre-upgrade VM and disks from backup or a restore point. Microsoft Learn.

Applicability

Apply this review after the supported upgrade of a Gen1 VM, not to every newly created Trusted Launch resource. Confirm the current guest, security type, original image reference, and recovery material. Review the source’s operating-system and conversion prerequisites separately before attempting an upgrade.

DSE recommendation

Flag the retained source-image reference in the VM’s post-upgrade operating record before authorizing reimage. Have the patch owner review workflows that use the reference to select updates. Require the recovery owner to distinguish restoration of the old Gen1 resource from operations on the currently upgraded VM. Do not treat a successful first boot as acceptance of every later lifecycle action.

Verification

Compare the running guest and current security configuration with the recorded source-image generation. Review any automation that may request reimage, and prevent an unreviewed operation from using the incompatible source. In an approved recovery exercise, validate the intended restoration path rather than deliberately reimaging production into a known failure. Preserve the upgrade and recovery identifiers so future operators can recognize this otherwise misleading metadata.

Official references

Microsoft Learn: Upgrade existing Gen1 VMs to Trusted Launch. Source reviewed September 9, 2026.

Primary reference

Review the official source

Upgrade Gen1 VMs to Trusted launch - Azure Virtual Machines | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE