Skip to content
drawing

πŸ‘‹ Introduction ​

If you've worked with Windows Autopatch and its deployment rings, the concept behind Intune Deployments will feel familiar. The basic idea is the same: instead of rolling out an app or setting to all devices at once, you define rings and gradually roll out deployments over time.

Intune separates the process into Deployment plans to define how a rollout should happen and Deployments wher you link the plan with a payload you want to deliver. This separation also makes it possible to standardize your rollout process and reuse the same timelines and rollout groups across different deliveries.

Technically, this works by assigning the groups set in your deployment plan directly to the payload once the time defined by the deployment rings arrives. This means it’s simply added as another assignment directly on the app or setting in your environment.

drawing

Key features at a glance

  • Gradual rollouts with deployment rings
  • Reusable rollout patterns with deployment plans
  • Pause, resume, or cancel active deployments
  • Support for apps and device configuration policies

Current support and limitations

WARNING

At the moment, Deployments are still in public preview, so the supported scenarios are still limited (October 2026).

  • Endpoint security policies
  • Settings catalog policies
  • Windows app (Win32)
  • Enterprise App Catalog apps
  • Required app installs only
  • Update with supersedence for Enterprise App Catalog apps
  • Deployments can only contain one payload

πŸ§‘β€πŸ”§ Configuration ​

The following built-in roles currently include permissions for Deployments.

Built-in roleDeployment permissions
Application ManagerCreate, Read, Update, Delete
Read Only OperatorRead
Endpoint Security ManagerCreate, Read, Update, Delete
Help Desk OperatorRead
Policy and Profile ManagerCreate, Read, Update, Delete
School AdministratorCreate, Read, Update, Delete


Create a Deployment Plan ​

The deployment plan is a reusable template that defines a standardized rollout pattern for delivering a payload in stages.

  1. To get started, open the Intune admin center -> Devices -> Deployments and select the Deployment plans tab.
  2. Here you click + Create plan to get started.
  3. On the Basics page, enter a Name and Description, and then click Next.
drawing
  1. On the Deployment schedule page, select a Platform from the list (Windows 10 and later / All platforms) and click Add rings to add one or more rings.

    INFO

    All platforms is for plans that you intend to also use with other platforms in the future. The only difference is that All platforms doesn't include the option to use an Assignment Filter on the payload.

drawing
  1. In the Manage rings flyout enter the Name for the first ring and then add additional rings with + Add ring. You can set the Wait time to next ring from the 2nd ring onwoards. After you created the needed rings, click Save to get back to the Deployment schedule page.
drawing
  1. The rings you just created are now shown and you can add groups to each one. You can also add user or device groups to exclude from the deployment, or use an Assignment Filter if you selected Windows as the platform.
drawing

    IMPORTANT

    When you select the All users or All devices virtual group, it will always be the last ring, because it overwrites all current assignments on the payload.

    In plain English, this removes all current assignments from the payload and replaces them with the virtual group.

    drawing
  1. When you're done, click Next, add your scope tags, and create the plan on the final page. Back on the Deployment plans page, you'll see an overview of all your created plans and their rings.
drawing

Create a Deployment ​

A deployment delivers one Intune payload to devices through a deployment plan.

  1. To get started, open the Intune admin center -> Devices -> Deployments and select the Deployment tab.
  2. Here you click + Create to get started.
  3. On the Basics page, enter a Name and Description, and then click Next.
drawing
  1. On the Payload Selection page, select the Payload type (Device configuration or Win32 App) and the Target payload, then click Next.
drawing
  1. On the Deployment Schedule page, choose whether to use a previously created deployment plan with Load deployment plans or create rings manually with Add rings.
drawing
    Load deployment plans

    To load a deployment plan, first select the Start date and Start time, then choose one of your previously created deployment plans from the list. After that, click Select.

    drawing
    Add rings

    To add rings manually, enter a Ring name, then select the Start date and Start time. Like this you can add as much rings as needed and then click Save.

    drawing
  1. Now that you can see the deployment rings loaded or created, you can add an Assignment filter, click Next to continue and then create the Deployment on the Review page.
drawing

INFO

If you're rolling out an app, you can also modify the app settings.

drawing
  1. Back on the Deployments page, you get an overview of all your Deployments, there Status, Rings and the Payload.
drawing
  1. Open a deployment to see its individual rings and their status. You can drill down further to see the individual groups in each ring and their status.
drawing

Details, Logs and troubleshooting ​

Deployment States

The different states in which a deployment can be found are listed below.

StatusOverviewDrill down
Not starteddrawingdrawing
Activedrawingdrawing
Pauseddrawingdrawing
Completeddrawingdrawing
Canceleddrawingdrawing

Audit Logs

In the Intune Audit Logs you can find deployment logs as follows:

    • Activity: [Acitvity] DeviceAndAppManagementDeployment
    • Category: Deployment
    • Actor: System

Note that deployments firing are always followed by the target payload getting the assigned group.

drawing

Deployment starts and is set to In Progress. Also the first Ring is set.

drawing

Deployment ends and is set to Completed. There is no next Ring to set, so its set to null.

drawing

Deployment is set to Canceld.

drawing

Common Problems

  • Creating a deployment for a group that is already assigned to the target payload will result in a colission.
drawing
  • If a collision hits when a ring starts, the deployment pauses with an error until you remove the problem and hit Resume.

  • After creating the deployment, you can edit the name and description, but everything else is locked.

  • Pausing or canceling stops future rings, but not the already activated ones. There assignments stay on the payload.

  • Canceling also won't remove already applied assignments.

  • If a group gets deleted while linked to a deployment:

    Group stateDeploymentsDeployment plans
    Permanently deleted groupActivation fails with Group deleted from Microsoft Entra ID. Cancel or delete the deployment.Plan opens with the same warning. Remove deleted groups before usage.
    Soft-deleted groupActivation fails and marks the group as Soft-deleted. Restore it or cancel/delete the deployment.Plan shows a banner and Soft-deleted status. Restore or remove groups before usage.
    Deleted groups leave an empty ringNot applicablePlan shows a deletion banner and empty-ring warning. Remove deleted groups and make sure each ring has at least one group.

πŸ’‘ Conclusion ​

Intune Deployments add a long-awaited way to roll out changes in controlled stages using deployment plans. Intune Deployments build on the existing way of assigning groups, using the same basic approach already introduced with Autopatch, so the implementation feels instantly familiar.

You can reuse deployment plans, track the rollout ring by ring and pause the deployment when needed. This gives you a more structured way to introduce changes gradually and catch issues before they reach all devices.

References