Skip to main content

Deployments

A deployment installs or uninstalls one package on many devices; the wizard can deploy several packages at once. Each device is a target with its own status, attempts and output.

Create a deployment​

Under Deployments → New deployment (technicians and tenant admins), the wizard has four steps.

1. Which packages?​

Pick one or more packages (yours or global ones, at most 20) and the action: Install or Uninstall. The chosen packages are listed in the order you picked them; remove one with its ×.

2. Which devices?​

ChoiceMeaning
All devicesEvery device of the tenant.
Choose computersComputers you pick: search by name, user, IP address or serial number and tick them (or Select all shown), or tick one or more Active Directory OUs to add all their computers (sub-OUs included). Click an OU's name to list its computers and untick the ones to leave out; the OU then shows as partly chosen, and unticking it removes its computers. The chosen ones stay listed above the search and can be removed. Devices selected in the device list start out chosen.
FilterThe same filter as the device list (status, site, OS, OU, tags, agent version, source), plus has / does not have software with an optional version condition.

A preview shows how many devices match and how many are excluded (devices without an agent and decommissioned devices are never targets). A deployment can have at most 20,000 targets.

Targets are fixed when the deployment starts. For a filter deployment, Add new devices later re-runs the filter and adds devices that match now.

3. When and how?​

SettingMeaning
Now / At a time / Maintenance windowStart immediately, at a date and time, or only inside a daily window such as 22:00–05:00 in each device's local time (its site's time zone, or the tenant default). A window that ends before it starts wraps midnight.
Devices at a timeConcurrency: how many targets may be downloading or installing at once (1–1000).
RetriesHow often a failed target is retried (0–10).
Retry after (minutes)Back-off before the first retry; it doubles with every attempt.
Give up after (hours)When the deployment expires; pending targets then time out.
RestartReboot policy: never, if required (exit code 3010/1641 or a pending-reboot flag), or always. Signed-in users see the branded restart notice with a countdown (see Device actions).

4. Review​

Check the summary and start.

Several packages at once​

Choosing more than one package creates one deployment per package, all with the same devices, schedule and options, named · ; afterwards the deployment list shows them. A computer installs them one after another in the order chosen (never two installers at once). A package waiting for the one before it does not time out; its execution timeout starts when it starts. When a reboot policy asks for a restart and more packages are still waiting on the computer, the restart is postponed to after the last of them, so the computer restarts once.

API: POST /tenants/{tenantID}/deployments/batch with package_ids (see the Portal API).

Follow the progress​

The deployment page shows live counts and every target:

  • Offline devices stay pending and are done when they come back.
  • Pause stops new targets from starting; Resume continues.
  • Cancel stops the deployment; queued jobs are cancelled on the agents. Installers that already run finish.
  • Retry a failed, timed-out or cancelled target from its row.

The deployment's status is scheduled, running, paused, completed, failed (targets failed or timed out and none succeeded or was skipped) or cancelled.

What the agent does​

For each target the agent: checks detection (skip if present) → downloads the file to its cache and verifies the SHA-256 → runs the installer → checks the exit code → checks detection again → applies the reboot policy → reports the result with the last 64 KB of output. Details: Protocol → install_package.

Files are cached per device by hash (up to 2 GiB), so a retry or a second deployment of the same file does not download it again.

Tips​

  • For large roll-outs use a maintenance window and a moderate concurrency.
  • Two deployments of the same package to one device are allowed.
  • Several deployments on one device run one after another, in the order their jobs were created.
  • The deployment failed alert rule opens an alert when more than 20 % of a recent deployment's targets failed.
  • Error codes of failed targets are explained in Error codes.