# Do not treat Manual scale-set upgrade mode as a freeze on automatic upgrades

> Does Manual upgrade mode stop enabled automatic OS image or extension upgrades?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:13+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Does Manual upgrade mode stop enabled automatic OS image or extension upgrades?

## Potentially affected

Azure scale sets whose owners are reviewing upgrade controls while automatic image or extension upgrades are enabled.

## DSE recommendation

Review upgrade mode and each enabled automatic-upgrade feature as separate controls.

## Article

## Source facts

A scale set’s upgrade-policy mode and rolling-upgrade configuration are separate nested settings. A rolling-upgrade policy exists even with Automatic or Manual mode. The mode controls how scale-set model updates reach instances, but enabled automatic OS image and automatic extension upgrades do not use that mode; they use the rolling-upgrade policy’s configuration. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades).

## Applicability

Use this distinction when planning a change freeze or investigating an upgrade that occurred while the model’s mode was Manual. Identify what initiated the change before deciding which control should have prevented it.

## DSE recommendation

Review upgrade mode and each enabled automatic-upgrade feature as separate controls. Have the platform owner list model-driven, OS-image and extension upgrade mechanisms independently. Document the authorized pause or continuation decision for each applicable mechanism using its own supported procedure. Preserve the existing rolling batch and health settings during the review, and do not assume selecting Manual has disabled unrelated automation.

## Verification

In a controlled scale set, inspect both the mode and rolling policy together with the automatic-feature settings. During an approved test, identify the trigger and compare observed instance changes with the corresponding control. Retain upgrade history and actual configuration evidence. If the change source remains unclear, keep the freeze assessment unresolved instead of reporting Manual mode as proof that every instance-change path is blocked.

## Official references

[Microsoft Learn: Configure rolling upgrades on Virtual Machine Scale Sets](https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades). Source reviewed September 9, 2026.

## Primary reference

- Name: Configure rolling upgrades on Virtual Machine Scale Sets - Azure Virtual Machine Scale Sets | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-configure-rolling-upgrades
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Do not treat Manual scale-set upgrade mode as a freeze on automatic upgrades,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-583-do-not-treat-manual-scale-set-upgrade-mode-as-a-freeze-on-automatic-upgrades/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
