# Identify VM scale-set NAT Pools before adding every V1 NAT rule to a retirement plan

> The September 2027 retirement applies to Inbound NAT Pools, not single-VM V1 inbound NAT rules.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-577-identify-vm-scale-set-nat-pools-before-adding-every-v1-nat-rule-to-a-retirement/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:19+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

The September 2027 retirement applies to Inbound NAT Pools, not single-VM V1 inbound NAT rules.

## Potentially affected

Azure Load Balancer inventories containing V1 single-VM rules or VM scale-set Inbound NAT Pools.

## DSE recommendation

Classify the actual resource properties before scheduling a NAT migration.

## Article

## Source facts

Microsoft schedules Inbound NAT Pools, the VM scale-set-specific V1 feature, for retirement on September 30, 2027. Single-VM V1 inbound NAT rules are outside that retirement and do not require migration because of it.

NAT Pools appear in inboundNatPools, while inbound NAT rules appear in inboundNatRules. A nonempty pool array identifies the affected feature. Migration interrupts active NAT-rule traffic, although load-balancing-rule and outbound-rule traffic are not affected by that migration process. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/load-balancer/load-balancer-nat-pool-migration).

## Applicability

Inspect the actual load balancer and associated scale-set configuration. Do not classify the entire population from the V1 label alone or mistake a single-VM port mapping for a scale-set pool.

## DSE recommendation

DSE recommends building the retirement worklist from nonempty pool configurations and recording excluded single-VM cases separately. For affected deployments, plan supported upgrade prerequisites, frontend-port capacity and a maintenance window using the complete migration guide. Avoid unnecessary changes to unaffected rules merely to make every object use the same version label.

## Verification

Before scheduling, confirm each work item contains the affected pool property and the expected scale-set association. After an approved migration, verify pools are absent, the new rule targets the intended backend pool and expected per-instance port mappings work. Retain the classification evidence for unaffected resources so later inventory reviews do not repeatedly reopen unnecessary migration work.

## Official references

[Microsoft Learn: Migrate from Inbound NAT rules version 1 to version 2](https://learn.microsoft.com/en-us/azure/load-balancer/load-balancer-nat-pool-migration). Source retrieved September 9, 2026.

## Primary reference

- Name: Migrate from Inbound NAT rules version 1 to version 2 | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/load-balancer/load-balancer-nat-pool-migration
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Identify VM scale-set NAT Pools before adding every V1 NAT rule to a retirement plan,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-577-identify-vm-scale-set-nat-pools-before-adding-every-v1-nat-rule-to-a-retirement/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
