Azure VMs still on unmanaged VHD disks after their 31 March 2026 retirement
What does ZopNight detect here?
ZopNight flags an Azure VM whose OS disk is an unmanaged VHD page blob in a storage account rather than a managed disk. Unmanaged disks were fully retired on 31 March 2026: VMs that still use them cannot be started, and running ones are stopped and deallocated. Migrating with `az vm convert` is mandatory, not optional.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1307 |
| Category | compliance |
| Severity | medium |
| Metric | none — pure configuration read |
| Threshold | OS disk is not a managed disk |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read |
Where it applies
Unmanaged disks are past their retirement date
Before managed disks arrived in 2017, a VM disk was a VHD file stored as a page blob in a storage account you created and sized yourself. Microsoft announced the retirement of unmanaged disks on 13 September 2022, and the retirement completed on 31 March 2026. After that date, IaaS VMs that use unmanaged disks cannot be started, and any that were running or allocated are stopped and deallocated.
A VM that still fires this rule is either already down or one stop away from being unable to come back.
Finding VMs on unmanaged disks
az vm list \ --query "[?storageProfile.osDisk.managedDisk==null].{name:name, rg:resourceGroup, vhd:storageProfile.osDisk.vhd.uri}" \ -o tableA vhd URI pointing at a blob.core.windows.net address confirms an unmanaged OS disk.
What makes ZopNight fire
ZopNight looks at whether the VM’s OS disk definition includes a managed disk and fires when Azure reports that it does not. The check reads the OS disk only; there is no metric or window.
When no finding appears
If the OS disk’s managed state could not be determined, the VM is left alone. Tags are not read.
VMs with a managed OS disk are clear, even if they have unmanaged data disks attached, so check
data disks separately with az vm show --query storageProfile.dataDisks.
An availability emergency, not a saving
No saving is claimed, and although ZopNight lists the finding at medium severity, the consequence of ignoring it is a VM that cannot run. Managed disks also remove the storage account capacity planning that unmanaged disks required.
Converting to managed disks
- Snapshot or back up the VHD blobs if you have no recent copy.
- Deallocate the VM:
az vm deallocate --resource-group my-rg --name my-vm. - Convert all its disks:
az vm convert --resource-group my-rg --name my-vm. - Start the VM and verify the application.
- Once you are satisfied, delete the old VHD blobs; they keep billing as storage until removed.
See Migrate Azure VMs to managed disks for availability set and scale set specifics.