This article answers common questions about Azure Marketplace image deprecation, what operations are affected, and what actions you need to take.
Overview
Image deprecation is a controlled process for retiring VM images from Azure Marketplace. It allows publishers to safely phase out unsupported images while giving customers time to transition. Existing VMs continue running normally—deprecation only affects new deployments and certain scale-out operations for Virtual Machine Scale Sets (VMSS).
Deprecation lifecycle
Image deprecation progresses through these stages:
- Scheduled deprecation: The publisher schedules deprecation, typically 90–180 days in advance. You receive email notifications and Azure Advisor recommendations.
- Enforcement: After the enforcement date, the image can no longer be used for new VM or VMSS deployments. Existing VMs continue to run.
Deprecation levels
Deprecation occurs at three levels, each with different impact:
| Level | What's deprecated | Impact |
|---|---|---|
| Version | A specific image version | New deployments using that version are blocked. VMSS scale-out might fail if pinned to the deprecated version. |
| Plan/SKU | An entire SKU and all versions within it | All versions under the SKU become unavailable. VMSS scale-out fails. |
| Offer | The entire image offer, including all SKUs and versions | All SKUs and versions are removed. New VM creation and VMSS scale-out are blocked. |
Key points
- No action required for existing VMs. Once created, VMs boot from their OS disk, not the Marketplace image. Deprecation doesn't affect running VMs.
- VMSS customers are most impacted. Scale-out operations are blocked after deprecation. Plan necessary updates proactively. For migration steps, see How do I update my VMSS to prevent scale-out failures after image deprecation?
- Automatic OS upgrades apply only to version-level deprecation. They can update a VM Scale Set to a newer image version within the same active SKU. For plan/SKU or offer-level deprecation, migrate the VM Scale Set manually to a supported SKU or offer. For more information, see Automatic OS image upgrades.
- Third-party images with a purchase plan have extra restrictions. Backup restore and reimage operations might fail after deprecation because of Marketplace enforcement checks.
What does it mean when I receive an image deprecation notice?
You receive an email notification when your VM or VMSS runs on an image scheduled for deprecation. Publishers deprecate images for various reasons, including security concerns or the image reaching end of life.
The notification includes the enforcement date, the affected image details, and the recommended replacement image. You typically have at least 90 days to take action.
How do I receive email notifications about image deprecation?
Azure sends deprecation notifications through:
- Email: Sent to subscription administrators with the Owner or Account Admin role.
- Azure Advisor: Deprecation recommendations appear in Azure Advisor.
To notify other team members, create an Advisor alert with an action group that specifies additional email addresses, SMS numbers, or webhooks.
What is the deprecation timeline?
The deprecation timeline varies by publisher but follows a standard process:
| Phase | Typical timeframe | What happens |
|---|---|---|
| Notification | 90–180 days before enforcement | You receive email alerts and Azure Advisor recommendations identifying affected resources. |
| Grace period | Until the enforcement date | You can still deploy new VMs and scale out VM Scale Sets using the image. Use this time to plan and test migration. |
| Enforcement | After the enforcement date | New VM creation and VMSS scale-out using the deprecated image are blocked. Existing VMs continue to run. |
The enforcement date is listed in your deprecation notification email and in Azure Advisor. To check whether a specific image is already deprecated, see How do I check if a specific image is deprecated?
Tip
Don't wait until the enforcement date. Test your migration in a non-production environment early to avoid disruption.
Which operations are affected by image deprecation?
Operations that continue to work after deprecation
| Operation | Notes |
|---|---|
| Existing VMs | VMs boot from their OS disk, not the Marketplace image. |
| Start, stop, restart, deallocate, redeploy, resize | These operations don't require the source image. |
| VMSS existing instances | Existing instances aren't affected. |
| VM backup and restore | Continues to work for images without a purchase plan. |
| Azure Site Recovery and disaster recovery | Continues to work for Microsoft-endorsed images. |
Operations that are blocked after deprecation
| Operation | Notes |
|---|---|
| New VM creation | Blocked for all deprecated images. |
| Reimage | Blocked because it requires recreating the OS disk from the source image. |
| VMSS scale-out | Blocked if new instances must use the deprecated image. Scale-out with automatic OS upgrade or latest version continues to work for version-level deprecation. |
| Backup restore (purchase plan images) | Might fail for third-party images that require Marketplace purchase validation. |
Note
Snapshots and disk-level backups aren't affected by deprecation. Keep the following in mind:
- Existing VMs remain unaffected because they run from the OS disk.
- Creating VMs from disks or snapshots works for Microsoft first-party and core images.
- For third-party images with purchase plans, VM creation, restore, or Azure Compute Gallery usage might fail because of Marketplace plan validation.
- Managed image and Azure Compute Gallery usage generally continue to work unless blocked by plan enforcement.
Note
The VM's image reference property might disappear from the Azure portal, but this doesn't affect VM operation. The OS disk is authoritative for boot.
What is the impact of image deprecation on existing VMs?
Image deprecation doesn't affect existing running VMs. After a virtual machine is created, it runs from its OS disk, not from the original Marketplace image. As a result, deprecating the image doesn't affect the operation, availability, or functionality of existing VMs. For a full list of affected and unaffected operations, see Which operations are affected by image deprecation?
What continues to work
- Start, stop, restart, and redeploy
- Resize operations, such as changing the VM size or SKU
- Patching and updates through Windows Update or guest OS mechanisms
- Snapshots, backups, and disk-based operations for images without purchase plan requirements
These operations don't require access to the original Marketplace image.
What is affected after deprecation
Image deprecation affects only operations that require access to the original image:
- New VM creation from the deprecated image is blocked.
- VM Scale Set scale-out might fail if new instances require the deprecated image.
- Reimage operations are blocked because they recreate the OS disk from the source image.
- Backup, restore, or recovery scenarios might fail for third-party images that require purchase plan validation.
How do I check if a specific image is deprecated?
Azure CLI
az vm image show --location eastus --urn MicrosoftWindowsServer:WindowsServer:2016-Datacenter:14393.4169.2101090332 --query [imageDeprecationStatus]
PowerShell
Get-AzVMImage -Location "eastus" -PublisherName "MicrosoftWindowsServer" -Offer "WindowsServer" -Skus "2016-Datacenter" -Version "14393.4169.2101090332" | Select-Object -ExpandProperty "ImageDeprecationStatus"
You can also run Get-AzVMImageDeprecationStatus.ps1 to check all VMs and VMSS in a subscription.
How do I update my VMSS to prevent scale-out failures after image deprecation?
The required action depends on the deprecation level described in your notification. Deprecation doesn't automatically migrate existing VM Scale Sets—you must take action.
Warning
If you don't migrate before the enforcement date, scale-out operations fail, new deployments are blocked, and you might lose security update support.
| Deprecation level | Auto OS upgrade helps? | Required action |
|---|---|---|
| Version | Yes | Set version to latest and enable automatic OS upgrade |
| Plan/SKU | No | Update VMSS to a supported SKU, then update all instances |
| Offer | No | Update VMSS to a supported offer and SKU, then update all instances |
Version deprecation
For version deprecation, set the image version to latest so Azure resolves to the newest available version automatically. Enable automatic OS image upgrade so future version deprecations are handled without manual intervention.
Note
Automatic OS upgrade only works when the underlying plan/SKU is still active. If the plan or SKU is also deprecated, automatic OS upgrade can't resolve to a valid image. Follow the Plan/SKU deprecation or Offer deprecation steps instead.
If you're using a pinned version, update the image reference to use latest:
Azure CLI:
az vmss update \
--resource-group <resource-group> \
--name <vmss-name> \
--set virtualMachineProfile.storageProfile.imageReference.version=latest
PowerShell:
$vmss = Get-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Version = "latest"
Update-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" -VirtualMachineScaleSet $vmss
Then update existing instances to apply the change:
Azure CLI:
az vmss update-instances \
--resource-group <resource-group> \
--name <vmss-name> \
--instance-ids "*"
PowerShell:
Update-AzVmssInstance -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" -InstanceId "*"
Plan/SKU deprecation
Automatic OS upgrade doesn't apply when the SKU is removed. You must update the VMSS model to a supported SKU and then update all instances.
Step 1: Identify affected VM Scale Sets
Check your deprecation email for the affected SKU. Use Azure Resource Graph or the Get-AzVMImageDeprecationStatus.ps1 script to list affected scale sets.
Step 2: Update the VMSS model to a supported SKU
Azure CLI:
az vmss update \
--resource-group <resource-group> \
--name <vmss-name> \
--set virtualMachineProfile.storageProfile.imageReference.sku=<new-sku> \
virtualMachineProfile.storageProfile.imageReference.version=latest
PowerShell:
$vmss = Get-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Sku = "<new-sku>"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Version = "latest"
Update-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" -VirtualMachineScaleSet $vmss
This updates the VMSS model so all future VM creations use the supported SKU. Existing VM instances aren't automatically upgraded.
Step 3: Update all VM instances
Apply the new image to existing instances:
Azure CLI:
az vmss update-instances \
--resource-group <resource-group> \
--name <vmss-name> \
--instance-ids "*"
PowerShell:
Update-AzVmssInstance -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" -InstanceId "*"
Important
Updating instances replaces their OS disks. Back up any data stored on OS disks before running this command.
You can also use a rolling upgrade policy to gradually replace instances with minimal impact to availability.
Step 4: Validate
Confirm that all instances reference the new SKU. See Validate migration.
Offer deprecation
Automatic OS upgrade doesn't change the image offer or SKU—it only updates image versions within the same SKU. When an offer is deprecated, you must update the VMSS image reference to a supported offer and SKU, and then update all VM instances. Updating the VMSS model alone isn't sufficient.
Important
Offer deprecation doesn't automatically upgrade existing VM Scale Sets. You must explicitly migrate to a supported offer by completing all of the following steps.
Step 1: Identify affected VM Scale Sets
Inspect the image reference for your VM Scale Set to determine if migration is required.
Azure CLI:
az vmss show \
--resource-group <resource-group> \
--name <vmss-name> \
--query "virtualMachineProfile.storageProfile.imageReference"
PowerShell:
$vmss = Get-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference
If the offer or sku in the output matches a deprecated value from your notification email, migration is required.
Step 2: Update the VMSS image reference to a supported offer
Update the VMSS model to reference a supported offer and SKU. The following example migrates to Windows Server 2022.
Azure CLI:
az vmss update \
--resource-group <resource-group> \
--name <vmss-name> \
--set virtualMachineProfile.storageProfile.imageReference.publisher=MicrosoftWindowsServer \
virtualMachineProfile.storageProfile.imageReference.offer=WindowsServer \
virtualMachineProfile.storageProfile.imageReference.sku=2022-datacenter \
virtualMachineProfile.storageProfile.imageReference.version=latest
PowerShell:
$vmss = Get-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Publisher = "MicrosoftWindowsServer"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Offer = "WindowsServer"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Sku = "2022-datacenter"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference.Version = "latest"
Update-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" -VirtualMachineScaleSet $vmss
This updates the VMSS model so all future VM creations use the supported offer. Existing VM instances aren't automatically upgraded.
Step 3: Update all VM instances
After updating the VMSS model, existing VM instances still run the deprecated image. Apply the new image to all instances:
Azure CLI:
az vmss update-instances \
--resource-group <resource-group> \
--name <vmss-name> \
--instance-ids "*"
PowerShell:
Update-AzVmssInstance -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" -InstanceId "*"
Important
Updating instances replaces their OS disks. Back up any data stored on OS disks before running this command.
You can also use a rolling upgrade policy to gradually replace instances with minimal impact to availability.
Confirm that all VM instances are running the supported image.
Check the VMSS model:
Azure CLI:
az vmss show \
--resource-group <resource-group> \
--name <vmss-name> \
--query "virtualMachineProfile.storageProfile.imageReference"
PowerShell:
$vmss = Get-AzVmss -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>"
$vmss.VirtualMachineProfile.StorageProfile.ImageReference
Verify that the offer and sku values match the supported replacement, not the deprecated image.
Check individual instances:
Azure CLI:
az vmss list-instances \
--resource-group <resource-group> \
--name <vmss-name> \
--query "[].{instanceId:instanceId, imageOffer:storageProfile.imageReference.offer, imageSku:storageProfile.imageReference.sku}"
PowerShell:
Get-AzVmssVM -ResourceGroupName "<resource-group>" -VMScaleSetName "<vmss-name>" |
Select-Object InstanceId, @{Name="ImageOffer"; Expression={$_.StorageProfile.ImageReference.Offer}}, @{Name="ImageSku"; Expression={$_.StorageProfile.ImageReference.Sku}}
Important considerations
- Auto OS upgrades don't migrate offers or SKUs. Automatic OS upgrade only updates image versions within the same SKU. Plan/SKU and offer deprecation always require a manual VMSS image reference update.
- Avoid pinned image versions. Pinning a specific image version increases the risk of scale-out failures and blocked deployments after deprecation. Use
version=latestunless you have a strict compliance requirement. - Check Marketplace purchase plan requirements. Some deprecated offers include a purchase plan. Migrating to a new offer might require accepting a new plan or redeploying workloads. Validate plan requirements before migration to avoid deployment failures. For more information, see Marketplace purchase plan.
- Test before production. Validate extensions, automation, startup scripts, and scale behavior on the new image in a non-production environment before migrating production workloads.
- Consider custom images. To avoid future dependency on Marketplace image availability, capture your workload as a custom image in Azure Compute Gallery. Custom images aren't subject to Marketplace deprecation except in some cases where the original image has a purchase plan.
How do I list active (non-deprecated) image versions?
Use the following commands to filter for active image versions. Replace the publisher, offer, and SKU values with the image you're investigating.
Azure CLI
az vm image list --location eastus --publisher "MicrosoftWindowsServer" --offer "WindowsServer" --sku "2022-Datacenter" --all --query "[?imageDeprecationStatus.imageState=='Active']"
PowerShell
Get-AzVMImage -Location "westus" `
-PublisherName "center-for-internet-security-inc" `
-Offer "cis-rocky" `
-Skus "cis-rockylinux-9-l1-gen2-azure-observability" `
-Expand "properties/imageDeprecationStatus" |
Where-Object { $_.ImageDeprecationStatus.ImageState -eq "Active" } |
Select-Object Version
What happens to SQL Server if a SQL Server image is deprecated?
Your SQL Server remains unaffected. The Azure VM and SQL Server instance continue to run normally. You can't deploy new VMs using the deprecated image, but existing deployments require no action.