UAM: Manage deployment policies

Nerdio Manager allows you to manage Unified Application Management deployment policies.

Deployment of applications can be achieved via the deployment of an application policy, or via instant deployment from the host pool options menu. Support for individual host and image deployment will be added in future.

Policies may be created with multiple applications, and targeted to multiple host pools, both personal and pooled. A policy can include both install and uninstall tasks, however it is recommended that these are not mixed in a single policy.

Once a policy is created, it automatically begins the process of deploying the applications in the policy to the in-scope desktops. The status of individual desktops within the scope of the policy can be discovered from the detailed info menu option in the policy edit menu.

Note

Before you can create deployment policies, you must be sure that you have configured Nerdio Manager for Unified Application Management. See Configure Nerdio Manager for Unified Application Management for details.

Add a new deployment policy

Nerdio Manager allows you to add deployment policies.

To add a new deployment policy:
  1. Navigate to Applications > Deployment > Deployment Policies.

  2. Select New.

  3. Enter the following information:

    Policy information

    UI Element

    Type

    Description

    Status

    Toggle

    Enable or disable the deployment policy. New policies are enabled by default.

    Name

    Text field

    Type the policy's name.

    Description

    Text field

    Type the policy's description. Select Generate with AI to automatically generate the description for the deployment policy.

    To generate a meaningful description, configure the rest of the policy first, then select Generate with AI just before you save it. See Overview of AI-Powered Description Generation for details about enabling AI.

    Applications

    UI Element

    Type

    Description

    Install app / Uninstall app / Install group / Uninstall group

    Radio buttons

    Select whether the policy installs or uninstalls the selected applications or groups:

    • Install app: Install the selected applications.

    • Uninstall app: Uninstall the selected applications.

    • Install group: Install the selected application groups.

    • Uninstall group: Uninstall the selected application groups.

    It is recommended that install and uninstall tasks are not mixed in a single policy.

    Applications list

    List

    Select Add new application, then use the search field and the drop-down list on the right to select the application to include in the policy.

    • You can add an unlimited number of applications.

    • Filter the list by repository: at the top of the drop-down, select the repository/ies you want results from, or select All to show results from any repository.

    • Drag and drop an application in the list to change its order.

    • Select the "X" next to an application to remove it from the list.

    Show favorites only

    Checkbox

    Select this option to only display applications marked as favorites in the search list. Otherwise, you may search the full list of applications.

    Reboot after installation

    Checkbox

    Select this option to place the host in drain mode and restart it once no sessions are present. This behavior applies to all targeted hosts — ensure it does not conflict with your desktop capacity requirements.

    This option is only available when Install app or Install group is selected above; it is hidden when an uninstall action is selected.

    Do not uninstall if upgrade fails

    Checkbox

    Select this option to prevent Nerdio Manager from uninstalling and reinstalling a WinGet application when an upgrade fails. When enabled, a failed upgrade is marked as failed and the existing installation is left in place.

    Deploy to

    UI Element

    Type

    Description

    Azure Virtual Desktop / Intune

    Radio buttons

    Select whether to deploy this policy to Azure Virtual Desktop or to Intune. The fields available below change depending on your selection.

    Target list

    List

    Search for and select the targets to deploy the applications to, using the fields on the right. If additional scopes are required, select Add new target... in the list to add another entry. To remove a scope, select the "x" next to its name in the list.

    Azure Virtual Desktop

    Intune

    UI Element

    Type

    Description

    Target type

    Drop-down list

    For the selected target in the list, select the type of AVD target to deploy to. The field(s) that appear below depend on your selection:

    • AVD Workspace

    • Global Pool

    • Global Pool / Pool Groups

    • Host Pool / Multi-session

    • Host Pool / Single-session

    AVD Workspace

    Global Pool

    Global Pool / Pool Groups

    Host Pool / Multi-session

    Host Pool / Single-session

    UI Element

    Type

    Description

    Search for workspaces

    Drop-down list

    Select the AVD workspace(s) to target.

    UI Element

    Type

    Description

    Search for NGPs

    Drop-down list

    Select the Global Pool(s) to target.

    UI Element

    Type

    Description

    Search for NGP groups

    Drop-down list

    Select the Global Pool group(s) to target.

    UI Element

    Type

    Description

    Search for host pools

    Drop-down list

    Select the host pool(s) to target.

    UI Element

    Type

    Description

    Identity tenant

    Drop-down list

    Optional. If you have multiple Entra ID tenants configured, select the tenant to target.

    Any user or group

    Drop-down list (multi-select)

    Optional. Select the user(s) or group(s) to target. Leave as Any user or group to target all.

    Any host pool

    Drop-down list (multi-select)

    Optional. Select the host pool(s) to target. Leave as Any host pool to target all.

    UI Element

    Type

    Description

    Any user or group

    Drop-down list (multi-select)

    Optional. Select the user(s) or group(s) to target. Leave as Any user or group to target all.

    Any device group

    Drop-down list (multi-select)

    Optional. Select the device group(s) to target. Leave as Any device group to target all.

    Use Task Worker

    Checkbox (Public preview)

    Select this option to enable Task Worker for enhanced task processing and management capabilities. Task Worker is used for non-Intune applications only — applications deployed via Intune are not affected by this setting.

    Note

    While the Task Worker feature is in Public Preview, UAM picks the first 1,000 devices only.

    Scheduling

    Note

    The following options apply only when Deploy to is set to Azure Virtual Desktop; they do not apply to Intune targets.

    UI Element

    Type

    Description

    Concurrency balancer

    Drop-down list

    Specify the maximum number of concurrent tasks for this policy or scripted sequence run. This feature only applies to AVD pools.

    • Global: The Maximum jobs value below is the maximum number of tasks for this policy or scripted sequence run across all host pools.

    • By host pool: The field below becomes Maximum jobs per pool, and the value is the maximum number of tasks for this policy or scripted sequence run, per host pool.

    Maximum jobs / Maximum jobs per pool

    Text field

    Type the maximum number of concurrent deployment jobs. The field is labeled Maximum jobs when Concurrency balancer is set to Global, and Maximum jobs per pool when it is set to By host pool.

    Maintenance Window

    Toggle

    Optionally, toggle on to configure a maintenance window. The maintenance window controls when application tasks are performed — if configured, no application tasks are performed outside of the specified window, ensuring that the user experience is not disrupted.

    When enabled, configure:

    • Use pool maintenance windows: Select this option to force the policy to run only during the configured maintenance window for the target pool(s). If no maintenance window is configured on the pool, the task respects the manual maintenance window set below instead.

    • Manual maintenance window: Select the day(s) of the week and time zone, then set the start and end time of the window during which application tasks are allowed to run.

    Drain Mode

    Toggle

    Optionally, toggle on to force desktops to enter drain mode before application tasks occur. Tasks do not begin until no sessions are present on the target hosts.

    When enabled, configure the messaging sent to users before the host is placed into drain mode:

    • Delay: Select the number of minutes to wait, after sending the message to all users and setting the host to drain mode, before the task runs.

    • Message: Type the message to send to all users.

    Desired host state

    Drop-down list

    Choose the host state in which application changes will be applied to the target hosts:

    • All (default): Changes are applied immediately to all AVD hosts, regardless of whether they have active user sessions. Some operations (such as OS updates) may require an immediate restart that disrupts user sessions.

    • Shutdown only: Changes are applied only to hosts that are currently shut down.

    • No sessions: Changes are applied only to hosts on which there are no active user sessions.

  4. Once you have entered all the desired information, select Save.

    The new deployment policy is created.

Manage deployment policies

Nerdio Manager allows you to manage deployment policies. This includes editing, activating/deactivating, deleting, and more.

To manage deployment policies:
  1. Navigate to Applications > Deployment > Deployment Policies.

  2. Locate the deployment policy you wish to work with.

  3. Optionally, perform any of the following:

    Note

    Detailed logging for the status of an application management task can be seen from the host, host pool, and policy details pages.

    • Select Edit to change the deployment policy.

    • From the action menu, select Deactivate to deactivate the deployment policy.

    • From the action menu, select Run now to request policy re-evaluation for in-scope desktops.

      • Ignore current device status: Optionally, select this option to force failed devices to re-attempt to apply the policy.

        Note

        By default, Nerdio Manager waits 24 hours before attempting to redeploy applications to allow administrators time to review the failure.

    • From the action menu, select Details... to view the deployment policy's detailed information. See Track Application Status below for details.

    • From the action menu, select Delete to delete the deployment policy.

    • In the Status column, select the button to toggle the activate (green) and deactivate(gray) status of the deployment policy.

Track application status

The deployment status of applications can be tracked by performing the following steps:

To track an application status:
  1. Navigate to Applications > Deployment > Deployment Policies.

  2. Locate the application you wish to work with.

  3. From the action menu, select Details... to review the status of the individual devices in the scope of the policy.

  4. Optionally, select Details to see additional information.

If a device fails in the deployment of one or more application tasks in a policy, this device is skipped for re-assessment for a period of 24 hours, allowing the administrator to investigate the issue. Re-assessment and deployment tasks can be forcibly started against devices.

In Nerdio Manager, application policies perform assessment and compliance tasks until the device is confirmed to be compliant. Devices are not currently inventoried after a successful completion.

Note

If another tool is used to add or remove an application, this is not be reflected in the UAM policies console. In this event, the issue may be worked around by creating a new policy to perform the required action, or by editing the existing policy to match the current state of the device (for example, change an Install task to an Uninstall task), allowing the policy tasks to complete successfully, then converting the policy back to the actual desired state (for example, revert the uninstall task to an install task). This task then runs successfully and creates your desired state configuration.

Was this article helpful?

0 out of 1 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Article is closed for comments.