How to Track Hypervisor and Guest Patching for Azure and AWS VMs
Retrospective: this article looks back at events from January 2018, written in 2026 with the benefit of hindsight.
When a major vulnerability affects cloud hosts, providers patch the hypervisor — but your virtual machines are still yours to patch. Here is how to track both layers in Azure and AWS.
Understand the split
- Provider responsibility: physical hosts, hypervisors, firmware, managed service infrastructure.
- Your responsibility: guest operating systems, applications, container images, and settings such as kernel mitigations.
Step 1: Track provider maintenance
- Azure: use Azure Service Health and resource health alerts for planned maintenance and security advisories affecting your resources. Scheduled Events let VMs react to upcoming reboots.
- AWS: use the AWS Health Dashboard and EventBridge rules for scheduled events such as instance retirements and maintenance.
Step 2: Track guest patching
- Azure: Azure Update Manager for Azure VMs and Arc-enabled servers, with periodic assessment and scheduled patching.
- AWS: Systems Manager Patch Manager with patch baselines and maintenance windows, and Amazon Inspector for vulnerability visibility.
Step 3: Set a common report
Produce a single monthly view: percentage of VMs patched within SLA, by environment and owner, across both clouds. Defender for Cloud can show vulnerability posture for AWS as well as Azure if you connect your AWS accounts.
Step 4: Plan for performance impact
Some security patches change performance. Test critical workloads in staging and keep capacity headroom.
Step 5: Design for reboots
Use availability sets, availability zones and auto-scaling so a host reboot does not take an application down.
Common mistakes
- Assuming "the cloud provider handles patching."
- Golden images that are never refreshed, so every new VM starts out of date.
- Meltdown and Spectre (Jan 2018): When the CPU Itself Was the Vulnerability Incident Teardowns
- Patch Verification Queries for CPU Vulnerabilities Across Azure and AWS VMs Detection & Response
- CIO Brief: Shared Responsibility When the Flaw Is in the Hardware CIO Briefings