Skip to main content
compliance · azure

Azure VMs still on unmanaged VHD disks after their 31 March 2026 retirement

resource types
1
rule IDs covered
1
severity
medium

What does ZopNight detect here?

ZopNight flags an Azure VM whose OS disk is an unmanaged VHD page blob in a storage account rather than a managed disk. Unmanaged disks were fully retired on 31 March 2026: VMs that still use them cannot be started, and running ones are stopped and deallocated. Migrating with `az vm convert` is mandatory, not optional.

Signal and threshold

How ZopNight evaluates Azure VMs still on unmanaged VHD disks after their 31 March 2026 retirement.
Field Value
Rule IDsRC-1307
Categorycompliance
Severitymedium
Metricnone — pure configuration read
ThresholdOS disk is not a managed disk
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read

Unmanaged disks are past their retirement date

Before managed disks arrived in 2017, a VM disk was a VHD file stored as a page blob in a storage account you created and sized yourself. Microsoft announced the retirement of unmanaged disks on 13 September 2022, and the retirement completed on 31 March 2026. After that date, IaaS VMs that use unmanaged disks cannot be started, and any that were running or allocated are stopped and deallocated.

A VM that still fires this rule is either already down or one stop away from being unable to come back.

Finding VMs on unmanaged disks

Terminal window
az vm list \
--query "[?storageProfile.osDisk.managedDisk==null].{name:name, rg:resourceGroup, vhd:storageProfile.osDisk.vhd.uri}" \
-o table

A vhd URI pointing at a blob.core.windows.net address confirms an unmanaged OS disk.

What makes ZopNight fire

ZopNight looks at whether the VM’s OS disk definition includes a managed disk and fires when Azure reports that it does not. The check reads the OS disk only; there is no metric or window.

When no finding appears

If the OS disk’s managed state could not be determined, the VM is left alone. Tags are not read. VMs with a managed OS disk are clear, even if they have unmanaged data disks attached, so check data disks separately with az vm show --query storageProfile.dataDisks.

An availability emergency, not a saving

No saving is claimed, and although ZopNight lists the finding at medium severity, the consequence of ignoring it is a VM that cannot run. Managed disks also remove the storage account capacity planning that unmanaged disks required.

Converting to managed disks

  1. Snapshot or back up the VHD blobs if you have no recent copy.
  2. Deallocate the VM: az vm deallocate --resource-group my-rg --name my-vm.
  3. Convert all its disks: az vm convert --resource-group my-rg --name my-vm.
  4. Start the VM and verify the application.
  5. Once you are satisfied, delete the old VHD blobs; they keep billing as storage until removed.

See Migrate Azure VMs to managed disks for availability set and scale set specifics.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·