# Remove VM Application consumer references before deleting the published application

> Can a published VM Application be deleted safely while VM profiles still reference it?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-101-remove-vm-application-consumer-references-before-deleting-the-published-application/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:30:15+00:00
- Modified: 2026-09-10T00:52:38+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can a published VM Application be deleted safely while VM profiles still reference it?

## Potentially affected

Azure Compute Gallery owners retiring VM Applications deployed to VMs or scale sets.

## DSE recommendation

Approve application retirement only after reconciling its consumer profiles.

## Article

## Source facts

Deleting a deployed VM Application from Compute Gallery can make later VM or scale-set updates, scaling and reimaging fail while resources still reference it. Microsoft directs owners to remove those applicationProfile references before deletion. Deleting a published version removes that version and its replicas, but leaves the original application blob in the storage account. Deleting the application itself first requires deleting all its versions. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machines/vm-applications-manage).

## Applicability

Use this retirement review for gallery application resources, not for a local package cleanup alone. Distinguish the published definition, its versions, consumer profile entries and the original source blob in the retirement record.

## DSE recommendation

Approve application retirement only after reconciling its consumer profiles. Have the application and platform owners identify every intended consumer and approve the replacement or removal outcome. Update only the targeted profile entry through the documented workflow; preserve unrelated applications. Verify affected scale-set instances as well as the model before moving on to published-object deletion. Keep original-blob retention as a separate decision instead of assuming gallery cleanup handles it.

## Verification

In a controlled retirement exercise, inspect the resulting consumer profiles and application state before deleting the approved published object. Check a representative supported update or deployment afterward. Record any remaining reference as an unresolved dependency. Do not bypass a deletion blocker simply to finish cleanup, and do not use successful deletion as evidence that future consumer operations will still work.

## Official references

[Microsoft Learn: Manage Azure VM Applications](https://learn.microsoft.com/en-us/azure/virtual-machines/vm-applications-manage). Source reviewed September 9, 2026.

## Primary reference

- Name: Manage, Update, and Delete VM Applications on Azure - Azure Virtual Machines | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machines/vm-applications-manage
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Remove VM Application consumer references before deleting the published application,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-101-remove-vm-application-consumer-references-before-deleting-the-published-application/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
