Description
Disabling automatic updates on Windows VMs or scale sets without another patching process can delay security fixes. The setting alone does not guarantee successful installation, so manage the actual patch mode, schedule and failures together.
Potential impact
- Known operating-system vulnerabilities can remain unpatched.
- Unplanned reboots or failed updates can affect workloads.
Remediation
- Consider
automatic_updates_enabled = trueor the olderenable_automatic_updates = true, according to the provider version. If another patching tool is used, verify that it meets the same security-update deadlines. - Configure patch mode, maintenance windows and reboot policy for the workload, then monitor actual installation results and failures. Check Terraform replacement plans for existing VMs.
Examples
These excerpts compare only the automatic-update property. Supply omitted image, disk and compatible patch-mode settings separately.
Before
hcl
resource "azurerm_windows_virtual_machine" "example" {
name = "example-vm"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
size = "Standard_F2"
admin_username = var.admin_username
admin_password = var.admin_password
network_interface_ids = [azurerm_network_interface.example.id]
automatic_updates_enabled = false
}
After
hcl
resource "azurerm_windows_virtual_machine" "example" {
name = "example-vm"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
size = "Standard_F2"
admin_username = var.admin_username
admin_password = var.admin_password
network_interface_ids = [azurerm_network_interface.example.id]
automatic_updates_enabled = true
}
Explanation:
- Before: OS automatic updates are disabled. A separate patch-management process is needed.
- After: OS automatic updates are enabled. Verify successful patch installation separately.