Azure VMs set to the Manual patch mode, where no OS updates install automatically
What does ZopNight detect here?
ZopNight flags an Azure VM whose `patchMode` is `Manual`, the Windows patch mode in which nothing installs OS updates automatically. VMs on `AutomaticByOS`, `ImageDefault` or `AutomaticByPlatform` are left alone, as are VMs that report no patch mode. Unpatched guests accumulate known vulnerabilities, and no saving is claimed for this finding.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1303 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | patchMode = Manual |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read |
Where it applies
Four patch modes, one of which does nothing
Every Azure VM has a patch orchestration mode in its OS profile. The automatic guest patching reference defines them:
AutomaticByPlatform: Azure orchestrates patch installation.AutomaticByOS: Windows Automatic Updates installs patches (a Windows mode).ImageDefault: the Linux image’s own update configuration applies.Manual: a Windows mode with automatic updates turned off.
In Manual, no mechanism in the VM or the platform applies OS updates. Unless someone runs
patching by hand or another tool does it, the VM falls further behind every patch Tuesday.
Finding Manual-mode VMs
az vm list \ --query "[?osProfile.windowsConfiguration.patchSettings.patchMode=='Manual'].{name:name, rg:resourceGroup}" \ -o tableaz vm assess-patches --resource-group my-rg --name my-vm shows how many updates a VM is missing.
Only the Manual value fires
ZopNight reads the raw patch mode from the VM’s OS profile and fires only on Manual, compared
without regard to case. It does not rely on a simpler “automatic patching on or off” reading,
which would lump the Windows and Linux defaults together with Manual and wrongly report VMs
that do update themselves.
VMs that are not flagged
VMs on AutomaticByOS, ImageDefault or AutomaticByPlatform are never flagged. A VM with no
patch mode in its definition is treated as unknown rather than unpatched. Tags are ignored;
there is no tag that stands in for the real patch mode.
Vulnerability exposure, not spend
No saving is attached. The risk is a VM carrying publicly known, already-fixed vulnerabilities because nothing installed the fixes.
Getting the VM patched automatically
- Switch to Azure-orchestrated patching. Microsoft supports moving between
ManualandAutomaticByPlatformon VMs where automatic updates are disabled:
az vm update --resource-group my-rg --name my-vm \ --set osProfile.windowsConfiguration.patchSettings.patchMode=AutomaticByPlatform- Or manage the VM in Azure Update Manager with a maintenance schedule that suits the workload.
- Run
az vm assess-patchesagain after the first cycle to confirm updates landed.