Review Windows VM automatic updates

Do not disable automatic updates without a replacement patching process; verify actual results.

Description

Disabling automatic updates on Windows VMs or scale sets without another patching process can delay security fixes. The setting alone does not guarantee successful installation, so manage the actual patch mode, schedule and failures together.

Potential impact

  • Known operating-system vulnerabilities can remain unpatched.
  • Unplanned reboots or failed updates can affect workloads.

Remediation

  • Consider automatic_updates_enabled = true or the older enable_automatic_updates = true, according to the provider version. If another patching tool is used, verify that it meets the same security-update deadlines.
  • Configure patch mode, maintenance windows and reboot policy for the workload, then monitor actual installation results and failures. Check Terraform replacement plans for existing VMs.

Examples

These excerpts compare only the automatic-update property. Supply omitted image, disk and compatible patch-mode settings separately.

Before

hcl
resource "azurerm_windows_virtual_machine" "example" {
  name                = "example-vm"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  size                = "Standard_F2"
  admin_username      = var.admin_username
  admin_password      = var.admin_password
  network_interface_ids = [azurerm_network_interface.example.id]

  automatic_updates_enabled = false
}

After

hcl
resource "azurerm_windows_virtual_machine" "example" {
  name                = "example-vm"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location
  size                = "Standard_F2"
  admin_username      = var.admin_username
  admin_password      = var.admin_password
  network_interface_ids = [azurerm_network_interface.example.id]

  automatic_updates_enabled = true
}

Explanation:

  • Before: OS automatic updates are disabled. A separate patch-management process is needed.
  • After: OS automatic updates are enabled. Verify successful patch installation separately.

References