Skip to main content

Rollout Statuses

This page lists every status an endpoint can show in the agents table on a deployment ring's rollout page. The same definitions appear when you select a status badge in the table.

The table has three status columns:

  • Status is the endpoint's overall state for its latest execution in this ring.
  • App and System are the results of the application update and system update channels for that execution. -- means that channel was not part of the execution.

Only Failed counts toward a ring's failure numbers and emergency-halt thresholds. Every other status on this page is either a success, still in progress, or neutral.

Status column​

Completed​

The latest execution finished and every included update applied. Select the badge to see why each update was judged successful.

Failed​

The latest execution reported a failure. This counts toward the ring's emergency-halt thresholds.

If the ring is paused or halted, the badge explains that automatic retries are on hold and resume once the ring resumes.

Retry scheduled​

The latest attempt failed, but the ring retries it automatically. The badge shows the error, the time of the next attempt, and how many attempts have been made. Failed endpoints keep retrying every deployment window until they succeed. This is not a stopping point.

In Progress​

An execution is currently running on the endpoint. The row shows how long it has been running.

Pending​

The endpoint is queued and waiting to be dispatched in an open deployment window.

Scheduled​

Shown when you view an upcoming window in the window picker. The endpoint is expected to receive updates when that window opens.

Cancelled​

The execution ended without installing anything. It was stopped administratively, held back by a pre-install safety check, or skipped because equivalent work was already in progress. The App and System columns show the specific reason (for example Gated or Superseded).

Cancelled does not count as a success or a failure. The endpoint is retried at the next deployment window.

Abandoned​

The endpoint stopped reporting during the execution (for example, it went offline or restarted mid-install), so the execution was closed without a result.

Abandoned does not count as a failure. The endpoint becomes eligible again at the next deployment window.

Not Converged​

The endpoint reported that the update installed successfully, but a follow-up check found the update is still needed. The install did not take effect.

Not Converged does not count as a success. The update is retried automatically at the next deployment window, up to 3 attempts.

Not Targeted​

The endpoint belongs to a policy assigned to this ring but has not been dispatched yet. Select the badge to see the reason, such as the endpoint being offline, already up to date, or waiting for the next deployment window.

App and System columns​

Success​

Every update in this channel installed and was verified. Select the badge to see the evidence for each update.

Partial​

Some updates in this channel installed and others did not. Select the badge to see which updates landed and which did not complete.

Failed​

The updates in this channel did not install. Select the badge to see the result for each update.

Pending and In Progress​

The channel is queued or its updates are installing now.

Gated​

A pre-install safety check on the endpoint stopped the install before it started, for example because there was not enough free disk space or a reboot was already pending. Nothing was installed.

Gated does not count as a failure. The check runs again at the next deployment window and the install proceeds once the endpoint is ready.

When free disk space is the cause, the result shows how much space the endpoint has and how much the install needs.

Superseded​

Another install of the same type was already running on the endpoint, so this execution stepped aside instead of interfering. The install already in progress handles the update work.

Superseded does not count as a failure. The endpoint is checked again at the next deployment window.

Unjudged​

Every update in this execution reports its own install result and leaves no record that can be verified afterwards (the Windows Malicious Software Removal Tool is a common example). Success or failure cannot be confirmed from outside the endpoint.

Unjudged results do not count toward the rollout's success or failure numbers and cannot trigger a halt. This is expected behavior, not an error.

Not Converged​

The same condition as Not Converged in the Status column, shown for the channel it happened in.

Not Applicable​

Windows reported every update in this execution as not applicable to the endpoint in its current state. Nothing was installed and nothing failed.

Not Applicable does not count as a failure and cannot trigger a halt. The updates are set aside for this endpoint and offered again automatically if its state changes.

Reboot skipped​

An update needed a reboot, or the ring is set to Force Reboot, but the endpoint has opted out of automatic reboots, so it was not rebooted. The endpoint reboots on its own schedule.

Why endpoints did not update​

When endpoints in a maintenance window did not update, the rollout page shows a Why endpoints did not update panel above the agents table. It groups those endpoints by reason and counts each one, so you can see, for example, that 10 endpoints ran out of disk space and 3 have a full EFI partition. The count includes endpoints that installed some updates but not all of them.

Select a reason to filter the agents table to those endpoints. The Reason column shows the reason for each endpoint's latest run.

On the Rollout Status page, each ring shows how many endpoints did not update in its latest window, with the most common reasons under its progress bar. Select a reason there to open that ring's rollout page, already filtered to it.

Each reason has an info icon that explains what to do about it. The reasons are:

Endpoint condition​

  • Not enough disk space: The system drive did not have enough free space to install. Free up space; the next window retries.
  • EFI partition full: The EFI system partition is too full for the update to write its boot files. Free space on that partition, then retry.
  • Component store damaged: Windows reported damage in its component store. Repair it with DISM /Online /Cleanup-Image /RestoreHealth, then retry.
  • Reboot pending: The endpoint is waiting on a reboot from an earlier change. Reboot it; the next window retries.
  • Recovery environment misconfigured: The Windows Recovery Environment is disabled or its partition is too small for this update. Check the Servicing Health card on the endpoint.
  • Update service disabled: A Windows service that installing updates needs is disabled. Re-enable it; the Servicing Health card names the service.
  • Endpoint busy (another install or package lock): Another install was running, or the package manager was locked, when this one started. It retries next window.

Delivery​

  • Download failed: The endpoint could not download the update. Check its network path to the update source.
  • No download source: No download location was available for the updates this endpoint needs, so nothing was sent.
  • Held for disk space: Some updates were held back because they would not fit in the free disk space. Free up space to receive them.

Install​

  • Not applicable: Windows or the package manager reported that the update does not apply to this endpoint.
  • Installer error (exit code shown): The installer failed with the exit code shown on the endpoint row. Open the endpoint history for details.

Run​

  • No result from endpoint: The endpoint never reported a result for this run, usually because it went offline.
  • Endpoint restarted during install: The endpoint or its agent restarted before the install reported back. It retries next window.
  • Maintenance window ended: The maintenance window closed before this endpoint finished. It continues in the next window.
  • Cancelled by an operator: Someone cancelled this run or marked patching as done for the window.
  • Withheld by rollout rules: The rollout rules held these updates back from this endpoint for now.
  • Upgrade prerequisites missing: The endpoint does not yet meet the feature upgrade requirements, such as hardware or a required earlier update.
  • Blocked by policy (update on the tenant blocklist): Every update for this endpoint is on your blocklist, so nothing was installed.
  • Stopped by the rollout (reset, cleanup or validation): The rollout itself stopped this run, for example after a reset or a failed install check.

Older runs are grouped from their recorded error where possible; anything that cannot be placed shows as Other. Open the endpoint's history for the full error.