Runbooks
Roll out a policy change
Try a change on a few devices before everyone gets it.
Time needed: 10 minutes to set up, then a day of watching.
A policy change reaches every device in its groups. Piloting gives it to one group first, so a mistake reaches a handful of devices rather than all of them.
Step 1: have a pilot group
Piloting needs the policy assigned to at least two groups, one of them small. For example, assign
Staff Phones and a small Staff Phones Pilot group with three volunteers' devices in it.
Step 2: make the change
- Open the policy and select Edit.
- Make your change.
- Watch Checks on the right for anything unexpected.
Step 3: publish to the pilot only
- Select Review changes.
- Read the settings turned on and the checks. Tick the acknowledgement if there is a danger you mean.
- Under Rollout, choose Pilot group first and pick the pilot group.
- Publish.
The policy page now says Piloting in the pilot group. Only that group gets the new version.
Step 4: watch for a day
- On Alerts, filter by the pilot group. New findings mean the change asks for something devices can't do.
- Ask the volunteers whether anything they rely on stopped working.
Step 5: promote or roll back
- All good: select Promote to all groups. Everyone gets the new version.
- Something wrong: select End pilot and restore. The previous settings come back as a new version, and the history keeps a record of what happened.
To undo a change that was published to everyone, open Version history, select the last good version and Restore it.