# Plan workload movement separately from scale-set zone expansion

> Does adding zones to an existing scale set move its current instances and their data into those zones?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-298-plan-workload-movement-separately-from-scale-set-zone-expansion/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:58+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Does adding zones to an existing scale set move its current instances and their data into those zones?

## Potentially affected

Owners expanding an eligible Azure scale set into additional availability zones.

## DSE recommendation

Create a workload-transition plan in addition to the scale set's zone-property change.

## Article

## Source facts

Adding zones to a scale set does not migrate its original instances or data. New instances created during scale-out use the expanded zone selection, and subsequent scale-in removes regional instances first. Added zones cannot later be removed or replaced. Expansion requires API 2023-03-01 or later and fault-domain count 1 or 5; capacity reservations during expansion, Dedicated Host deployments, Service Fabric RP, and AKS scale sets are excluded. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-customer-selected-zones).

## Applicability

Review the source’s full eligibility and zone-availability checks before planning this transition. Identify which existing instances hold state and how the application will transfer or replicate it to new instances.

## DSE recommendation

Create a workload-transition plan in addition to the scale set’s zone-property change. Have the workload owner define when a new zonal instance is ready to serve and when an original instance can be retired. Coordinate capacity increases, data movement, and removals explicitly. Do not describe the property update as an in-place migration or promise to reverse it by removing a zone.

## Verification

Inspect instance locations before and after an authorized staged expansion. Verify that intended new instances are serving the correct data before approving scale-in, and check which original instances remain. Preserve the instance-to-zone inventory with application results. If the control-plane update succeeds but the workload has not moved, report the transition as incomplete and leave the original service path protected.

## Official references

[Microsoft Learn: Customer-selected availability zones for Virtual Machine Scale Sets](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-customer-selected-zones). Source reviewed September 9, 2026.

## Primary reference

- Name: Customer-selected availability zones for Virtual Machine Scale Sets - Azure Virtual Machine Scale Sets | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-customer-selected-zones
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan workload movement separately from scale-set zone expansion,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-298-plan-workload-movement-separately-from-scale-set-zone-expansion/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
