Microsoft Intune Adds Staged Deployments for Safer Windows Rollouts


intune staged rollout
Image credit: Microsoft

Microsoft has introduced a new Deployments experience in Intune that gives IT admins more control over how apps, policies, and configuration changes roll out across Windows devices.

Instead of pushing a change to every device at once, admins can create multiple deployment rings and decide when changes move between stages. This lets organizations test updates with smaller groups first, identify potential problems, and reduce the risk of widespread disruption.

The new deployment plans support Win32 apps, Enterprise App Catalog apps, Settings catalog policies, and Endpoint security policies.

Microsoft also supports integration with Multiple Admin Approval, adding another safeguard against unwanted changes reaching large device fleets.

Windows devices can trigger faster compliance checks

Microsoft is also adding client-driven compliance evaluation for supported Windows devices. The feature reduces reliance on scheduled Intune check-ins by allowing devices to request a new compliance evaluation when important security signals change.

These signals include firewall and antivirus status, BitLocker, Microsoft Defender, OS build, real-time protection, and Secure Boot. As a result, admins can receive updated compliance information faster for remediation, reporting, and access decisions.

Microsoft has been making several changes aimed at enterprise IT teams recently. The company is also encouraging organizations to adopt Windows Autopilot Device Preparation, while expanding Copilot with Claude Opus 5.5 and GPT-6 Sol. It has also again urged Entra ID customers to move from SMS authentication to passkeys.

Via Neowin

More about the topics: microsoft, microsoft intune

Readers help support Windows Report. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more

User forum

0 messages