how to fix broken VM with no remote access after July update,
the July KB5062553 update was applied to our 2025 Azure VM servers, These are now breaking with no access via RDP, it appears they are just hanging but are in a running state.
the agent status is not ready and agent version is unknown
This is affecting our exchange server and Domain Controllers
We cannot apply KB5064489 as we cannot connect to the servers and there is no access to the CMD via serial Console
Azure Virtual Machines
-
Nikhil Duserla • 8,515 Reputation points • Microsoft External Staff • Moderator
2025-07-18T16:12:44.0966667+00:00 Hello @Mike Collins - admin,
It seems that the July KB5062553 update has caused significant issues with your Azure VM servers, particularly affecting RDP access and the Virtual Machine Agent status. Please share details as request in Private message.
Thank you!
-
Mike Collins • 5 Reputation points
2025-07-18T16:37:54.5966667+00:00 I have sent a PM :)
-
Mike Collins • 5 Reputation points
2025-07-21T14:31:05.5433333+00:00 can i get some help please Nikhil
-
Nikhil Duserla • 8,515 Reputation points • Microsoft External Staff • Moderator
2025-07-23T17:41:54.0433333+00:00 Hello @Mike Collins,Thank you for your time on call.
A fix has been released on the catalog- https://support.microsoft.com/en-us/topic/july-13-2025-kb5064489-os-build-26100-4656-out-of-band-14a82ab2-100f-4dd4-8141-f490ec90c8f4
Multiple reports of the issue being resolved by enabling Trusted Launch or resizing VMs to compatible SKUs, allowing successful boot after the update
If you're unable to apply the update via RDP, I recommend using the Azure Serial Console as an alternative-https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/serial-console-overview
If you have any further queries, do let us know.
-
Mike Collins • 5 Reputation points
2025-07-23T20:40:39.9+00:00 Nikhil, You know I cannot use RDP, and as I told you on the Call, I have already applied this patch on EXCH server and as you already know and have the screenshots Trusted Launch is already enabled. it has not fixed it
-
Nikhil Duserla • 8,515 Reputation points • Microsoft External Staff • Moderator
2025-07-23T20:44:22.5133333+00:00 @Mike Collins Did you tried by resizing the VM?
-
Mike Collins • 5 Reputation points
2025-07-23T21:02:22.2433333+00:00 Can you tell me what 'compatible SKUs' are correct ? we opted for a default size of our VM's they are D4as_v6 size
-
Mike Collins • 5 Reputation points
2025-07-23T21:10:40.25+00:00 I have just resized it to D4alds and still have the same issue
-
Mike Collins • 5 Reputation points
2025-07-23T21:48:49.14+00:00 I have switched back to D4as_v6 and still the same
-
Mike Collins • 5 Reputation points
2025-07-24T15:41:49.6033333+00:00 This July KB5062553 issue has been ongoing since last Friday now and we still cannot access our VM's is there any update to fix this properly.
Again, these have always been our security settings
Security
Security type Trusted launch
Enable secure boot Enabled
Enable vTPM Enabled
We have already applied the KB5064489 fix on 1 of our VM's
We have also tried resizing the same VM
I even have forced TCP only over the RDP
but every time we try and access the VM's by RDP the VM Agent stops and becomes in a Not Ready state, and after it enters the Not ready state we can no longer access the VM by serial console either. The Only way is to Stop and Start the VM and then the Agent becomes Ready and we can access it by Serial Console again.
This all only started happening after the July KB5062553 update was applied and is affecting both azure domain controllers, the azure exchange server and 2 other servers.
-
Mike Collins • 5 Reputation points
2025-07-30T13:41:20.4166667+00:00 Hi Can anyone else help, so far I am getting almost nowhere. altho I have figured a little more out but it does not resolve the issue.
The Original VM had 3 disks attached.
I have taken a snapshot of the original OS Disk and created a new drive from it
I then built a new VM and swapped the OS drive with the one I built from the snapshot of the original VM.
This new VM boots fine and I can login at this point.
I then created snapshots of the 2 additional disks and created drives from them too.
If I attach them to the running new VM I can see all the data fine on them.
However, if I shutdown the new VM from the OS and then stop the VM in the portal then restart the VM I am back to the original issue.
When I try to login to the server using RDP, the VM freezes after login as its loading server manager and after sometime the VM agent will go not ready.
If I disconnect the 2 additional disks, the VM unfreezes.
I have also tried simply creating a new disk from the portal and attaching that to the VM.
I then start the VM and can login fine.
I go to disk management and initialise the disk and format it.
after formatting I can see the new drive in file explorer fine.
If I then shutdown the server from the OS then stop the VM from the portal, Then restart the VM from the portal.
I am again back to the same issue when I login, It again freezes at the server manager screen.
while its frozen if I detach the new disk it will unfreeze and allow me to login fully and runs ok.
again these issues only started after the July KB5062553 update
-
kobulloc-MSFT • 26,826 Reputation points • Microsoft Employee • Moderator
2025-07-30T20:51:34.46+00:00 Hello, @Mike Collins ! Following up on my PM, this is what I see so far:
- You originally reported that the July KB5062553 update was applied to your 2025 Azure VM servers which resulted in:
- Agent is now in "Not Ready" state; agent version is "Unknown"
- Loss of RDP access
- VMs are hung in a running state
- Impact is to exchange server and domain controllers
- Applying KB5064489 does not resolve the issue:
- Originally could not connect to the servers; no access to the CMD via serial console
- Subsequent attempt was successful in installing the KB, however logging in via the GUI results in the VM freezing and the agent dying
- Other troubleshooting steps included:
- Redeploy to move to a different host. RDP briefly enabled until connected and then unresponsive moving forward.
- Attempted to log in via Bastion, but disconnected as system is not responsive.
- Resizing did not work
- Snapshot works, but only without the data disks
- Attaching data disks results in VM freeze; removing data disks unfreezes VM
- You originally reported that the July KB5062553 update was applied to your 2025 Azure VM servers which resulted in:
-
Mike Collins • 5 Reputation points
2025-07-30T20:53:37.59+00:00 This is all correct but the connecting data disks
if connected to an already running vm they can be read and the vm is ok.
if the vm is then restarted, then it will freeze again
-
kobulloc-MSFT • 26,826 Reputation points • Microsoft Employee • Moderator
2025-07-31T20:09:12.6366667+00:00 Thank you for the additional troubleshooting results, @Mike Collins ! I'm going to include some of the results here so that we have a record of it.
There seems to be an issue with deallocating the VM that is causing it to go into a bad state.
The VM will work normally if you:
- Add 1 attached data disk at a time (not 2, as that will result in the same freezing behavior)
- Then either reboot the server or shut down the server (from the OS) and start the VM from the portal
The VM will not work normally if you:
- Deallocate (stop) the VM and then boot it again
-
Sebastian Cerazy • 321 Reputation points
2025-08-11T14:02:50.2+00:00 VM (not Azure) on local Hyper-V 2016 does not boot. Tested on multiple separate VMs. Literally no way to do anything (but restore from backup, before it got fully buggered!)
-
kobulloc-MSFT • 26,826 Reputation points • Microsoft Employee • Moderator
2025-08-11T22:08:28.7133333+00:00 Hello, @Sebastian Cerazy ! This thread is limited in scope to addressing Azure VMs that have been impacted by the July security update, KB5062553 (for which the current resolution should be to install KB5064489).
Sign in to comment