Rollout Status Updates
The Updates tab on Rollout Status shows every update that is rolling out across your System Update Policies and Application Policies, and where each one stands in each policy. If your organization still rolls updates out by deployment ring, the tab lists only halted updates. See Rollout Phases and Safety Halts on Policies.
Rollout Status opens on the Rings tab. The tabs run in this order: Rings, Calendar, Updates, One-Time Deployments. Links from notifications and from the update badge in the menu open the Updates tab directly.
What needs your attention
A strip at the top of the tab counts the updates that need you:
- Halted: updates stopped for your whole organization because they failed a phase's success criteria.
- Awaiting approval: updates waiting for someone to approve them into a phase.
- Not taking effect: updates that install but are still needed afterward.
Select a count to open a panel with the matching updates and the actions you can take on each. A count of zero is dimmed.
Reading the grid
Below the strip, the grid has one row for each update and one column for each policy. Use the System and Application filters to switch between operating system updates and application updates. Halted updates carry a Halted badge on their row.
Each cell shows where the update stands in that policy:
- Phase 2 of 3: the phase the update has reached.
- Awaiting approval: the update is waiting for approval to enter the next phase.
- Halted: the update is stopped.
- Done: the update has reached every phase it applies to.
- Not in this policy: the policy does not include the update.
A note beside the status explains a wait, such as Waiting for window, Waiting for next window, Waiting for results, Endpoints offline, or Failing, not halted (the policy's safety halts are off).
Select an update to open its panel. It lists one line for each policy that includes the update, with how many endpoints have finished, failed or are still waiting, and why anything is waiting. A note appears when a policy is disabled or has no deployment ring, because that policy does not roll the update out. Expand a line to see each endpoint's result: Succeeded or Failed, with the reason the endpoint reported.
Below the grid, three links summarize what is not shown in it: updates not needed in your environment, updates resolved in the last 30 days, and updates that repeat regularly.
Actions on an update
The panel offers the actions that apply to each line and that you have permission for.
With permission to approve updates:
- Approve: send the update into the phase that is waiting for approval.
- Advance now: move the update to the next phase without waiting for its criteria.
- Skip phases: send the update to every remaining phase. A halted update must be released first.
- Approve all: approve every waiting update in one policy. It works on one policy at a time.
With permission to edit policies:
- Reject for this policy: stop this policy from installing the update.
- Block everywhere: stop every policy from installing the update.
A disabled policy, or a policy with no deployment ring, does not offer Approve, Advance now or Skip phases, because it cannot send the update.
Releasing a halt
A halt applies to your whole organization, so it appears once on the update and not once for each policy. Releasing a halt needs permission to approve updates. After you have fixed the cause:
- Open the Halted panel, or the halted update, and select Release halt.
- Enter a Reason. It is required and is recorded in the audit log.
- Confirm. If your account requires it, you are asked for a step-up verification first, with a passkey or an authenticator code.
Every halted rollout of the update then resumes at its current phase with a fresh phase window.
Resolved updates
Open resolved in the last 30 days to see updates that finished, along with past halts: which update, who released it and when, and the reason they gave. Halts that were carried into your organization when it merged with another are listed here too.
Updates that keep reinstalling
Not taking effect lists updates that install but are still needed afterward. Microsoft re-releases some updates regularly, some daily and some monthly, so they install again on schedule. If you already know why, select Dismiss on the row. Dismissing hides the update and its count for your whole organization without changing what is installed.
Navigation badge and notifications
The badge on Rollout Status counts updates that are halted or waiting for approval. The notification bell and the dashboard count them the same way:
- each halted update counts once for your whole organization
- each update waiting for approval counts once, however many policies it is waiting in, and only when a policy that has a deployment ring and is enabled is waiting for it
These counts can be lower than the counts in the grid, which also include updates that are rolling out or finished.
If your organization switches back to ring-based phases while an update is still halted, the halt stays visible until it is released.