Skip to main content
compliance · azure

Azure VMs set to the Manual patch mode, where no OS updates install automatically

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure VM whose `patchMode` is `Manual`, the Windows patch mode in which nothing installs OS updates automatically. VMs on `AutomaticByOS`, `ImageDefault` or `AutomaticByPlatform` are left alone, as are VMs that report no patch mode. Unpatched guests accumulate known vulnerabilities, and no saving is claimed for this finding.

Signal and threshold

How ZopNight evaluates Azure VMs set to the Manual patch mode, where no OS updates install automatically.
Field Value
Rule IDsRC-1303
Categorycompliance
Severitymedium
Metricnone — pure configuration read
ThresholdpatchMode = Manual
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read

Four patch modes, one of which does nothing

Every Azure VM has a patch orchestration mode in its OS profile. The automatic guest patching reference defines them:

  • AutomaticByPlatform: Azure orchestrates patch installation.
  • AutomaticByOS: Windows Automatic Updates installs patches (a Windows mode).
  • ImageDefault: the Linux image’s own update configuration applies.
  • Manual: a Windows mode with automatic updates turned off.

In Manual, no mechanism in the VM or the platform applies OS updates. Unless someone runs patching by hand or another tool does it, the VM falls further behind every patch Tuesday.

Finding Manual-mode VMs

Terminal window
az vm list \
--query "[?osProfile.windowsConfiguration.patchSettings.patchMode=='Manual'].{name:name, rg:resourceGroup}" \
-o table

az vm assess-patches --resource-group my-rg --name my-vm shows how many updates a VM is missing.

Only the Manual value fires

ZopNight reads the raw patch mode from the VM’s OS profile and fires only on Manual, compared without regard to case. It does not rely on a simpler “automatic patching on or off” reading, which would lump the Windows and Linux defaults together with Manual and wrongly report VMs that do update themselves.

VMs that are not flagged

VMs on AutomaticByOS, ImageDefault or AutomaticByPlatform are never flagged. A VM with no patch mode in its definition is treated as unknown rather than unpatched. Tags are ignored; there is no tag that stands in for the real patch mode.

Vulnerability exposure, not spend

No saving is attached. The risk is a VM carrying publicly known, already-fixed vulnerabilities because nothing installed the fixes.

Getting the VM patched automatically

  1. Switch to Azure-orchestrated patching. Microsoft supports moving between Manual and AutomaticByPlatform on VMs where automatic updates are disabled:
Terminal window
az vm update --resource-group my-rg --name my-vm \
--set osProfile.windowsConfiguration.patchSettings.patchMode=AutomaticByPlatform
  1. Or manage the VM in Azure Update Manager with a maintenance schedule that suits the workload.
  2. Run az vm assess-patches again after the first cycle to confirm updates landed.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·