Multi-CloudHow-To & HardeningRetrospectives

How to Track Hypervisor and Guest Patching for Azure and AWS VMs

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from January 2018, written in 2026 with the benefit of hindsight.

When a major vulnerability affects cloud hosts, providers patch the hypervisor — but your virtual machines are still yours to patch. Here is how to track both layers in Azure and AWS.

Understand the split

  • Provider responsibility: physical hosts, hypervisors, firmware, managed service infrastructure.
  • Your responsibility: guest operating systems, applications, container images, and settings such as kernel mitigations.

Step 1: Track provider maintenance

  • Azure: use Azure Service Health and resource health alerts for planned maintenance and security advisories affecting your resources. Scheduled Events let VMs react to upcoming reboots.
  • AWS: use the AWS Health Dashboard and EventBridge rules for scheduled events such as instance retirements and maintenance.

Step 2: Track guest patching

  • Azure: Azure Update Manager for Azure VMs and Arc-enabled servers, with periodic assessment and scheduled patching.
  • AWS: Systems Manager Patch Manager with patch baselines and maintenance windows, and Amazon Inspector for vulnerability visibility.

Step 3: Set a common report

Produce a single monthly view: percentage of VMs patched within SLA, by environment and owner, across both clouds. Defender for Cloud can show vulnerability posture for AWS as well as Azure if you connect your AWS accounts.

Step 4: Plan for performance impact

Some security patches change performance. Test critical workloads in staging and keep capacity headroom.

Step 5: Design for reboots

Use availability sets, availability zones and auto-scaling so a host reboot does not take an application down.

Common mistakes

  • Assuming "the cloud provider handles patching."
  • Golden images that are never refreshed, so every new VM starts out of date.
cloud vm patchingMeltdown & Spectre2018

More on this story