Microsoft’s September Intune update brings Microsoft Intune deployments into public preview. The feature gives administrators a native way to stage supported Windows apps and configuration policies through rings, with reusable deployment plans, exclusions, timing, and the ability to pause, resume, or cancel an active rollout.
That makes the feature valuable as a change-control layer. It does not remove the need for good assignments, testing, or a rollback plan. A ring can spread a bad configuration just as efficiently as a good one if the payload is not reviewed and the groups are not understood.
What is new in the preview
Microsoft’s deployment overview separates the feature into two parts. A deployment plan is a reusable rollout template. A deployment is the execution of one app or policy through that template or through a one-time ring configuration.
| Object | What it controls | Important boundary |
|---|---|---|
| Deployment plan | Platform, rings, groups, filters, exclusions, and deferral time between rings. | It does not contain or deliver a payload. |
| Deployment | One selected app or policy delivered gradually to groups in defined rings. | The selected payload, ring names, schedule, groups, and scope tags cannot be edited after creation. |
During public preview, Microsoft documents support for Windows 10 and later with Endpoint security policies, Settings catalog policies, Win32 apps, and Enterprise App Catalog apps. For Win32 and Enterprise App Catalog apps, only the Required install intent is supported; Available and Uninstall are not.
Design the rings before you select the payload
A ring is a change boundary, not just a percentage. Give each ring a purpose, owner, success signal, and stop condition. A practical starting pattern for a growing business is:
| Ring | Audience | Exit signal |
|---|---|---|
| 0 — Lab | IT test devices and representative hardware. | Install or policy application succeeds, restart and dependency behavior are known, and the support runbook is ready. |
| 1 — IT and service desk | Administrators, help desk, and a small set of power users. | No unresolved critical incident, support scripts work, and telemetry is understandable. |
| 2 — Pilot business group | A representative 5–10% of users or devices with explicit exclusions. | Business workflow, performance, compliance, and rollback checks pass. |
| 3 — Broad deployment | The remaining approved population. | Change owner and service owner accept the evidence and the monitoring window. |
The numbers are an operating recommendation, not a Microsoft requirement. Keep the interval between rings at least one hour because Microsoft documents that as a deployment rule, and make the waiting period long enough to observe the signal that matters for your payload.
Understand assignment behavior and collision failure
Deployment assignments are cumulative as rings activate. Existing Required assignments remain, and each activated ring adds its include groups. Exclude groups apply across all rings. A payload remains the source of truth for assignments, so a direct payload change can take precedence over the deployment.
Microsoft also checks for group-assignment collisions when a deployment is created and when a ring activates. If the same group is assigned directly to the payload and appears in a ring, the deployment can enter an error state and pause. Resolve the collision before resuming; do not treat “resume” as a workaround for an unclear assignment model.
Keep a simple assignment map in the change record: payload, existing assignments, each ring’s include groups, global exclusions, scope tags, and the owner who approves the next activation.
Keep RBAC and approval controls in the design
Microsoft says existing Intune RBAC and scope tags continue to apply. Scope tags determine which deployment plans and payloads delegated administrators can see. The permissions guidance also documents Multi Admin Approval for protected actions such as create, resume, cancel, and delete.
- Plan ownership: let a platform or endpoint team own reusable plans rather than allowing every application owner to invent a new ring model.
- Payload ownership: require the app or policy owner to provide dependencies, test evidence, support notes, and rollback instructions.
- Approval boundary: protect broad-ring activation and destructive actions with the existing approval workflow where the tenant uses it.
- Scope review: verify that delegated admins can see only the plans, payloads, and groups within their responsibility.
A 30-day Intune deployment pilot
| Window | Work | Exit evidence |
|---|---|---|
| Days 1–5 | Confirm public-preview eligibility, supported payload types, RBAC roles, scope tags, and the tenant’s approval model. | Feature owner, access matrix, supported-payload list, and pilot decision. |
| Days 6–12 | Create one reusable plan with lab, IT, pilot, and broad rings. Add explicit exclusions and a minimum one-hour interval. | Plan review, group map, dependency list, and stop conditions. |
| Days 13–20 | Run a low-risk Win32 app or Settings catalog policy through the first two rings. Test a pause, collision handling, and resume path. | Deployment timeline, device results, support feedback, and rollback evidence. |
| Days 21–30 | Expand one approved payload to the pilot ring, capture change metrics, and decide whether the plan is safe to reuse. | Pilot decision, monitoring owner, change record, and documented next review. |
Frequently asked questions
What is an Intune deployment plan? It is a reusable template for rings, groups, filters, exclusions, and timing. It does not contain or deliver a payload by itself.
What can the preview deploy? Microsoft documents Windows 10 and later support for Endpoint security policies, Settings catalog policies, Win32 apps, and Enterprise App Catalog apps.
Can a deployment be paused? Yes. Deployments can be paused, resumed, or canceled. Assignment collisions can also put a deployment into an error state and pause it.
Should every app move to deployments? No. Start with a payload where staged exposure reduces risk and the success signal is measurable. Keep the existing assignment model for simple, low-risk changes until the preview proves useful for your team.
Need a safer endpoint rollout model?
Accred Consulting can map your Intune assignments, define ring criteria, and pilot deployments with the RBAC, approval, monitoring, and rollback controls your service desk can operate.
Plan an Endpoint Review