Skip to main content

Rollout Phases and Safety Halts on Policies

When your organization uses per-update rollout, each update moves through its own sequence of phases on its own schedule. Rollout phases and safety halts are set on the System Update Policy or Application Policy that installs the update, instead of on a deployment ring.

This page covers the new Rollout phases and Safety halts sections on both policy pages and what changes on the Deployment Rings page. To follow an update through its phases, see Rollout Status Updates.

Rollout phases​

Open a System Update Policy or an Application Policy and find the Rollout phases section. Each phase is a step in the pipeline that an update passes through before it reaches every endpoint the policy covers.

For each phase you choose:

  • Phase Name: how the phase appears on Rollout Status and in notifications.
  • Targeting Mode: percentage-based or tag-based.
  • Advancement Type: automatic (the update moves on after a wait time and its success criteria are met) or manual (an administrator approves each update into the phase).
  • Wait Time (hours), Min Agents and Max Failures: the success criteria that must hold before an update advances automatically. For Min Agents: The phase includes at least this many machines, even when its percentage works out to fewer.
  • Excluded tags: endpoints that carry these tags never receive the update in this phase. The editor shows how many machines each excluded tag removes from the phase. Those counts overlap when an endpoint carries more than one excluded tag, so do not add them together.

The deployment ring attached to the policy still controls when updates are sent: its deployment window, dispatch pacing and reboot settings are unchanged. Phases decide who is eligible, and the ring decides when.

Preview​

As you edit, a preview shows how many machines each phase reaches. It updates a moment after you stop typing. Warnings appear under the pipeline when the settings cannot do what you might expect:

  • Safety halts are on, but no phase has success criteria: the policy can never halt an update. Add success criteria to at least one phase.
  • Machines tagged with an excluded tag skip phases: those machines join the rollout in a later phase. When an update is needed only by them, it goes straight to the final phase, with no canary.

If the preview is unavailable, you can still save.

Saving​

Rollout phases save with the page's existing Save button. If the policy has no deployment ring, or the policy is disabled, the section tells you that its updates do not roll out automatically.

Safety halts​

Turn on Halt an update for the whole organization when it fails a phase's success criteria to let a failing update stop itself. On a System Update Policy, the Include Microsoft Office updates switch decides whether Microsoft Office updates can be halted too. It is available while safety halts are on.

When an update exceeds a phase's allowed failures:

  • The update is halted for your whole organization, not just that policy. No automated install sends it anywhere until the halt is released.
  • Every policy that includes the update shows it as halted.
  • You receive one notification, "N updates halted", that links to the halted updates on Rollout Status.
  • Installing a halted update by hand asks you to confirm first. See Installing Halted Updates Through the API for the API behavior.

To lift a halt once its cause is fixed, use Release halt on Rollout Status > Updates. You need permission to approve updates, a reason is required, and the release is recorded in the audit log.

What changes on Deployment Rings​

For organizations using per-update rollout:

  • The ring editor no longer holds rollout phases or safety settings. A note on the page points you to the policy that carries them, and the ring keeps its deployment window, dispatch, pre-staging, reboot and execution-limit settings.
  • A ring's page on Rollout Status links to View this ring's updates in Rollout Status, which opens the Updates tab filtered to the policies that use the ring.
  • The Update Problems tab is removed from Rollout Status. Halted updates, updates awaiting approval and the Not taking effect list appear at the top of the Updates tab, which sits after Rings and Calendar.
  • Package Catalog no longer has a Progression tab. Everything it showed is on Rollout Status > Updates.
  • The phase column is removed from the Rollout Status list. A ring that is outside its deployment window reads Waiting for window. A ring whose window is open, but where an update has been sent to each endpoint still waiting for it the maximum number of times set under the ring's execution limits, reads At execution limit. Those endpoints get the update in the next window.