|
| 1 | +--- |
| 2 | +title: Automatic Guest Patching for Azure Virtual Machines |
| 3 | +description: Learn how to automatically patch your Azure Virtual Machines and Scale Sets using Azure Update Manager. This article provides an overview of supported OS images, configuration steps, and best practices for maintaining security compliance through automatic guest patching. |
| 4 | +ms.service: azure-update-manager |
| 5 | +author: SnehaSudhirG |
| 6 | +ms.author: sudhirsneha |
| 7 | +ms.date: 02/13/2025 |
| 8 | +ms.topic: overview |
| 9 | +--- |
| 10 | +# Automatic Guest Patching for Azure Virtual Machines |
| 11 | + |
| 12 | +**Applies to:** :heavy_check_mark: Linux VMs :heavy_check_mark: Windows VMs |
| 13 | + |
| 14 | +By enabling automatic guest patching for your Azure Virtual Machines (VMs), you can automatically and securely patch your VMs to ensure they remain compliant with security standards." |
| 15 | + |
| 16 | +## Supported OS images |
| 17 | + |
| 18 | +> [!NOTE] |
| 19 | +>- Automatic VM guest patching, on-demand patch assessment and on-demand patch installation are supported only on VMs created from images with the exact combination of publisher, offer and sku from the below supported OS images list. Custom images or any other publisher, offer, sku combinations aren't supported. More images are added periodically. Don't see your SKU in the list? Request support by filing out [Image Support Request](https://forms.microsoft.com/r/6vfSgT0mFx). |
| 20 | +>- If [automatic VM guest patching](/azure/virtual-machines/automatic-vm-guest-patching) is enabled on a VM, then the available Critical and Security patches are downloaded and applied automatically on the VM. |
| 21 | +
|
| 22 | + |
| 23 | +#### [Supported Windows Images (Hotpatchable)](#tab/win-hotpatch) |
| 24 | + |
| 25 | +| Publisher | OS Offer | Sku | |
| 26 | +|-------------------------|---------------|--------------------| |
| 27 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-azure-edition-core | |
| 28 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-azure-edition-core-smalldisk | |
| 29 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-azure-edition-hotpatch | |
| 30 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-azure-edition-hotpatch-smalldisk | |
| 31 | +| MicrosoftWindowsServer | WindowsServer | 2025-datacenter-azure-edition | |
| 32 | +| MicrosoftWindowsServer | WindowsServer | 2025-datacenter-azure-edition-smalldisk | |
| 33 | +| MicrosoftWindowsServer | WindowsServer | 2025-datacenter-azure-edition-core | |
| 34 | +| MicrosoftWindowsServer | WindowsServer | 2025-datacenter-azure-edition-core-smalldisk | |
| 35 | + |
| 36 | + |
| 37 | +#### [Supported Windows Images (non-Hotpatchable)](#tab/win-nonhotpatch) |
| 38 | + |
| 39 | +| Publisher | OS Offer | Sku | |
| 40 | +|-------------------------|---------------|--------------------| |
| 41 | +| MicrosoftWindowsServer | WindowsServer | 2008-R2-SP1 | |
| 42 | +| MicrosoftWindowsServer | WindowsServer | 2012-R2-Datacenter | |
| 43 | +| MicrosoftWindowsServer | WindowsServer | 2012-R2-Datacenter-gensecond | |
| 44 | +| MicrosoftWindowsServer | WindowsServer | 2012-R2-Datacenter-smalldisk | |
| 45 | +| MicrosoftWindowsServer | WindowsServer | 2012-R2-Datacenter-smalldisk-g2 | |
| 46 | +| MicrosoftWindowsServer | WindowsServer | 2016-Datacenter | |
| 47 | +| MicrosoftWindowsServer | WindowsServer | 2016-datacenter-gensecond | |
| 48 | +| MicrosoftWindowsServer | WindowsServer | 2016-Datacenter-Server-Core | |
| 49 | +| MicrosoftWindowsServer | WindowsServer | 2016-datacenter-smalldisk | |
| 50 | +| MicrosoftWindowsServer | WindowsServer | 2016-datacenter-with-containers | |
| 51 | +| MicrosoftWindowsServer | WindowsServer | 2019-Datacenter | |
| 52 | +| MicrosoftWindowsServer | WindowsServer | 2019-Datacenter-Core | |
| 53 | +| MicrosoftWindowsServer | WindowsServer | 2019-datacenter-gensecond | |
| 54 | +| MicrosoftWindowsServer | WindowsServer | 2019-datacenter-smalldisk | |
| 55 | +| MicrosoftWindowsServer | WindowsServer | 2019-datacenter-smalldisk-g2 | |
| 56 | +| MicrosoftWindowsServer | WindowsServer | 2019-datacenter-with-containers | |
| 57 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter | |
| 58 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-smalldisk | |
| 59 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-smalldisk-g2 | |
| 60 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-g2 | |
| 61 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-core | |
| 62 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-core-g2 | |
| 63 | +| MicrosoftWindowsServer | WindowsServer | 2022-datacenter-azure-edition | |
| 64 | + |
| 65 | +#### [Supported Linux Images](#tab/lin-img) |
| 66 | + |
| 67 | +| Publisher | OS Offer | Sku | |
| 68 | +|-------------------------|---------------|--------------------| |
| 69 | +| Canonical | UbuntuServer | 16.04-LTS | |
| 70 | +| Canonical | UbuntuServer | 16.04.0-LTS | |
| 71 | +| Canonical | UbuntuServer | 18.04-LTS | |
| 72 | +| Canonical | UbuntuServer | 18.04-LTS-gen2 | |
| 73 | +| Canonical | 0001-com-ubuntu-pro-bionic | pro-18_04-lts | |
| 74 | +| Canonical | 0001-com-ubuntu-server-focal | 20_04-lts | |
| 75 | +| Canonical | 0001-com-ubuntu-server-focal | 20_04-lts-gen2 | |
| 76 | +| Canonical | 0001-com-ubuntu-pro-focal | pro-20_04-lts | |
| 77 | +| Canonical | 0001-com-ubuntu-pro-focal | pro-20_04-lts-gen2 | |
| 78 | +| Canonical | 0001-com-ubuntu-server-jammy | 22_04-lts | |
| 79 | +| Canonical | 0001-com-ubuntu-server-jammy | 22_04-lts-gen2 | |
| 80 | +| microsoftcblmariner | cbl-mariner | cbl-mariner-1 | |
| 81 | +| microsoftcblmariner | cbl-mariner | 1-gen2 | |
| 82 | +| microsoftcblmariner | cbl-mariner | cbl-mariner-2 | |
| 83 | +| microsoftcblmariner | cbl-mariner | cbl-mariner-2-gen2 | |
| 84 | +| Redhat | RHEL | 7.2, 7.3, 7.4, 7.5, 7.6, 7.7, 7.8, 7_9, 7-RAW, 7-LVM | |
| 85 | +| Redhat | RHEL | 8, 8.1, 81gen2, 8.2, 82gen2, 8_3, 83-gen2, 8_4, 84-gen2, 8_5, 85-gen2, 8_6, 86-gen2, 8_7, 8_8, 8-lvm, 8-lvm-gen2 | |
| 86 | +| Redhat | RHEL | 9_0, 9_1, 9-lvm, 9-lvm-gen2 | |
| 87 | +| Redhat | RHEL-RAW | 8-raw, 8-raw-gen2 | |
| 88 | +| SUSE | sles-12-sp5 | gen1, gen2 | |
| 89 | +| SUSE | sles-15-sp2 | gen1, gen2 | |
| 90 | + |
| 91 | +--- |
| 92 | + |
| 93 | +For VMs created from customized images even if the Patch orchestration mode is set to `Azure Orchestrated/AutomaticByPlatform`, automatic VM guest patching doesn't work. We recommend that you use scheduled patching to patch the machines by defining your own schedules or install updates on-demand. |
| 94 | + |
| 95 | +## Next steps |
| 96 | + |
| 97 | +- [View updates for a single machine](view-updates.md) |
| 98 | +- [Deploy updates now (on-demand) for a single machine](deploy-updates.md) |
| 99 | +- [Schedule recurring updates](scheduled-patching.md) |
| 100 | +- [Manage update settings via the portal](manage-update-settings.md) |
0 commit comments