Skip to content

Azure Virtual Machines Footguns

1. Stopping inside the guest is not the same as deallocating

A VM in Stopped can still be allocated and billed for compute. Use az vm deallocate or confirm Stopped (deallocated) when the intent is to stop compute billing. Disks and some network resources still cost money.

2. Deallocation can lose placement

Restarting a deallocated VM requires fresh capacity. A rare SKU/zone may fail to allocate later unless capacity is reserved.

3. Quota is not capacity

Having vCPU quota does not mean the SKU is available in the requested zone.

4. Temporary disks are disposable

Never store databases, logs needed for forensics, package caches required for recovery, or irreplaceable state there.

5. Disk performance is capped twice

Effective performance is the lower of the disk's limits and the VM size's aggregate limits. Bursting can make a benchmark look healthy before sustained workloads throttle.

6. Host caching can corrupt assumptions

Read/write caching choices interact with database durability requirements. Follow the database vendor's Azure-specific disk guidance.

7. Deleting a VM can leave billable resources

Verify delete options for OS disk, data disks, NIC, and public IP. Orphan detection should be automated with Resource Graph/Policy.

8. Availability Set and Availability Zone are not interchangeable

An availability set only spreads hardware/update risk within one datacenter scope. It is not a substitute for multi-zone design.

9. Single-zone dependencies negate multi-zone compute

A three-zone VMSS behind a zone-redundant load balancer can still fail if it depends on a zonal NAT gateway, disk, firewall, database, or private endpoint design with no equivalent resilience.

10. VMSS orchestration mode is immutable

Choosing Uniform versus Flexible incorrectly generally means rebuilding the scale set.

11. Extensions can wedge provisioning

A failing extension can leave the VM in a failed provisioning state even if the OS is running. Extension versions, outbound access, package repositories, DNS, and proxy behavior must be treated as deployment dependencies.

12. latest image references are not reproducible

Pin an Azure Compute Gallery image version in production pipelines, then promote versions deliberately.

13. System-assigned identity deletion is destructive

Recreating the VM creates a new principal object ID. Role assignments tied to the old identity do not magically follow.

14. Spot deallocation still consumes quota and disk cost

A Spot VM evicted with the Deallocate policy remains stopped-deallocated, keeps disks, and counts against quota. The Delete policy removes the VM and its associated disks according to configuration. (Microsoft Learn: Spot VMs)

15. Resize is not purely a CPU/RAM change

A size may be unavailable on the current cluster; resizing can require deallocation and can discard temporary-disk data.

16. Guest firewall and NSG can disagree

Azure Network Watcher may show the NSG path as allowed while nftables, iptables, Windows Firewall, SELinux, or the service bind address blocks the connection.

17. Backup success is not restore proof

Regularly perform isolated restores and application-level validation.