A deallocated virtual machine is a stopped VM whose compute and networking resources have been released by the cloud provider. This state differs from a simple stopped state in which some billing and reserved capacity can continue. Deallocation usually reduces cost, but attached storage may still remain billable.
What a deallocated virtual machine actually is
A deallocated virtual machine is not merely powered off. The cloud provider has released its compute host allocation and, in many platforms, the VM no longer holds the same billed runtime state as a stopped instance.
That distinction matters because the operational meaning of “stopped” varies by cloud service. In one state, the guest OS is quiet but the platform may still reserve capacity or keep some compute charges attached. In the deallocated state, those compute resources are returned to the provider, which usually changes both billing behaviour and what infrastructure remains addressable.
How deallocation changes cost, capacity, and state
Deallocation is primarily a lifecycle and billing state, not a security control by itself. It usually reduces cost because the provider releases the VM’s compute footprint, but the associated storage, snapshots, public IP dependencies, or other attached resources may continue to exist and may still incur charges or retain data.
This is why deallocation should be understood as a state transition with consequences, not as a complete teardown. If a team assumes the VM is fully gone, they can miss leftover resources that still consume budget, preserve data, or remain tied to the original workload configuration.
Why the distinction from “stopped” matters in cloud operations
The practical difference between stopped and deallocated states is that deallocation usually removes the machine from active compute scheduling. That can affect whether the VM keeps its prior placement, how quickly it can be restarted, and whether certain network and host-level settings are preserved in the same way.
For operators, this means the term is useful when discussing lifecycle management, cost control, and workload suspension. It is also a reminder that cloud state is multi-layered: compute, network exposure, and storage persistence do not always end at the same moment.
What remains after deallocation
Even after a VM is deallocated, some related assets may remain in place. Attached disks, unmanaged snapshots, IP resources, backup copies, and metadata can survive the compute shutdown and continue to matter for billing, recovery, and exposure.
That persistence is important for both administration and security. A deallocated machine may no longer be running, but any retained storage or retained configuration can still carry sensitive data, historical credentials, or evidence of prior exposure if the environment was not cleaned up properly.
Risk and Threat Considerations
Deallocation can create false confidence if teams assume it is equivalent to disposal. The main risks are lingering cost from retained storage and the exposure created by resources that remain attached, discoverable, or recoverable after the VM itself is no longer running.
Failure mechanism: The compute instance is released, but disks, snapshots, IP assets, or configuration remnants remain active or accessible, so the workload is only partially retired.
Impact: Organisations can continue paying for resources they thought were gone, and they may leave behind data or recovery paths that still need protection, review, and eventual cleanup.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and CSA Cloud Controls Matrix set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-1 — Inventory and Control of Enterprise Assets | Deallocation is an asset lifecycle state that affects visibility and ownership of remaining cloud resources. |
| CIS-2 — Inventory and Control of Software Assets | VM state changes can leave persisted images, snapshots, or packaged software assets that still require governance. | |
| CIS-3 — Data Protection | Deallocated VMs may leave storage and backups that still contain sensitive data. | |
| Recommendation — Track deallocated VMs and attached assets so leftover resources are not missed in inventory. Review retained images and snapshots after deallocation to avoid unmanaged software residue. Protect and classify any retained disks or backups after deallocation so data exposure is controlled. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud lifecycle states intersect with control of retained access paths and resource ownership. |
| DCS — Datacenter Security | Deallocation changes where compute lives and what infrastructure remains under provider control. | |
| Recommendation — Revoke or reassign access to any retained cloud resources after a VM is deallocated. Confirm that deallocated workloads no longer depend on active compute capacity or placement assumptions. | ||
Practitioner Guidance
Governance implication: Treat deallocation as a defined lifecycle state with ownership, not as an informal “shutdown.” Teams should know which resources are expected to remain, which should be cleaned up, and which controls apply to the leftover storage and networking objects.
What to watch for: The most common mistake is assuming cost has stopped everywhere when only compute has stopped. Check the surrounding resource set, especially disks and other persisted assets, before closing the operational ticket or declaring the workload retired.
Related resources from NHI Mgmt Group
- What breaks when virtual machine backup is too dependent on agents inside the workload?
- How should security teams replace standing access with just-in-time access in cloud and virtual machine environments?
- What are the signs that virtual machine based abuse is distorting fraud detection signals?
- How should security teams apply service mesh controls to virtual machine workloads in hybrid environments?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org