
π Introduction β
If you've worked with Windows Autopatch and its deployment rings, the concept behind Intune Deployments will feel familiar. The basic idea is the same: instead of rolling out an app or setting to all devices at once, you define rings and gradually roll out deployments over time.
Intune separates the process into Deployment plans to define how a rollout should happen and Deployments wher you link the plan with a payload you want to deliver. This separation also makes it possible to standardize your rollout process and reuse the same timelines and rollout groups across different deliveries.
Technically, this works by assigning the groups set in your deployment plan directly to the payload once the time defined by the deployment rings arrives. This means itβs simply added as another assignment directly on the app or setting in your environment.

Key features at a glance
- Gradual rollouts with deployment rings
- Reusable rollout patterns with deployment plans
- Pause, resume, or cancel active deployments
- Support for apps and device configuration policies
Current support and limitations
WARNING
At the moment, Deployments are still in public preview, so the supported scenarios are still limited (October 2026).
- Endpoint security policies
- Settings catalog policies
- Windows app (Win32)
- Enterprise App Catalog apps
- Required app installs only
- Update with supersedence for Enterprise App Catalog apps
- Deployments can only contain one payload
π§βπ§ Configuration β
The following built-in roles currently include permissions for Deployments.
| Built-in role | Deployment permissions |
|---|---|
| Application Manager | Create, Read, Update, Delete |
| Read Only Operator | Read |
| Endpoint Security Manager | Create, Read, Update, Delete |
| Help Desk Operator | Read |
| Policy and Profile Manager | Create, Read, Update, Delete |
| School Administrator | Create, Read, Update, Delete |
Create a Deployment Plan β
The deployment plan is a reusable template that defines a standardized rollout pattern for delivering a payload in stages.
- To get started, open the Intune admin center -> Devices -> Deployments and select the Deployment plans tab.
- Here you click
+ Create planto get started. - On the Basics page, enter a Name and Description, and then click
Next.

On the Deployment schedule page, select a Platform from the list (Windows 10 and later / All platforms) and click
Add ringsto add one or more rings.INFO
All platforms is for plans that you intend to also use with other platforms in the future. The only difference is that All platforms doesn't include the option to use an Assignment Filter on the payload.

- In the Manage rings flyout enter the Name for the first ring and then add additional rings with
+ Add ring. You can set the Wait time to next ring from the 2nd ring onwoards. After you created the needed rings, clickSaveto get back to the Deployment schedule page.

- The rings you just created are now shown and you can add groups to each one. You can also add user or device groups to exclude from the deployment, or use an Assignment Filter if you selected Windows as the platform.

IMPORTANT
When you select the All users or All devices virtual group, it will always be the last ring, because it overwrites all current assignments on the payload.
In plain English, this removes all current assignments from the payload and replaces them with the virtual group.

- When you're done, click
Next, add your scope tags, and create the plan on the final page. Back on the Deployment plans page, you'll see an overview of all your created plans and their rings.

Create a Deployment β
A deployment delivers one Intune payload to devices through a deployment plan.
- To get started, open the Intune admin center -> Devices -> Deployments and select the Deployment tab.
- Here you click
+ Createto get started. - On the Basics page, enter a Name and Description, and then click
Next.

- On the Payload Selection page, select the Payload type (
Device configurationorWin32 App) and the Target payload, then clickNext.

- On the Deployment Schedule page, choose whether to use a previously created deployment plan with
Load deployment plansor create rings manually withAdd rings.

Load deployment plans
To load a deployment plan, first select the Start date and Start time, then choose one of your previously created deployment plans from the list. After that, click Select.

Add rings
To add rings manually, enter a Ring name, then select the Start date and Start time. Like this you can add as much rings as needed and then click Save.

- Now that you can see the deployment rings loaded or created, you can add an Assignment filter, click
Nextto continue and then create the Deployment on the Review page.

INFO
If you're rolling out an app, you can also modify the app settings.

- Back on the Deployments page, you get an overview of all your Deployments, there Status, Rings and the Payload.

- Open a deployment to see its individual rings and their status. You can drill down further to see the individual groups in each ring and their status.

Details, Logs and troubleshooting β
Deployment States
The different states in which a deployment can be found are listed below.
| Status | Overview | Drill down |
|---|---|---|
| Not started | ![]() | ![]() |
| Active | ![]() | ![]() |
| Paused | ![]() | ![]() |
| Completed | ![]() | ![]() |
| Canceled | ![]() | ![]() |
Audit Logs
In the Intune Audit Logs you can find deployment logs as follows:
- Activity: [Acitvity] DeviceAndAppManagementDeployment
- Category: Deployment
- Actor: System
Note that deployments firing are always followed by the target payload getting the assigned group.

Deployment starts and is set to In Progress. Also the first Ring is set.

Deployment ends and is set to Completed. There is no next Ring to set, so its set to null.

Deployment is set to Canceld.

Common Problems
- Creating a deployment for a group that is already assigned to the target payload will result in a colission.

If a collision hits when a ring starts, the deployment pauses with an error until you remove the problem and hit
Resume.After creating the deployment, you can edit the name and description, but everything else is locked.
Pausing or canceling stops future rings, but not the already activated ones. There assignments stay on the payload.
Canceling also won't remove already applied assignments.
If a group gets deleted while linked to a deployment:
Group state Deployments Deployment plans Permanently deleted group Activation fails with Group deleted from Microsoft Entra ID. Cancel or delete the deployment. Plan opens with the same warning. Remove deleted groups before usage. Soft-deleted group Activation fails and marks the group as Soft-deleted. Restore it or cancel/delete the deployment. Plan shows a banner and Soft-deleted status. Restore or remove groups before usage. Deleted groups leave an empty ring Not applicable Plan shows a deletion banner and empty-ring warning. Remove deleted groups and make sure each ring has at least one group.
π‘ Conclusion β
Intune Deployments add a long-awaited way to roll out changes in controlled stages using deployment plans. Intune Deployments build on the existing way of assigning groups, using the same basic approach already introduced with Autopatch, so the implementation feels instantly familiar.
You can reuse deployment plans, track the rollout ring by ring and pause the deployment when needed. This gives you a more structured way to introduce changes gradually and catch issues before they reach all devices.
References









