purplegreen MDM

purplegreen MDM is being prepared for its first pilot. These pages describe the development release.

Staged rollouts and rolling back a version

A rollout tries a new version of a profile on part of your fleet first: some sites, some tablets with a tag, or both. Everything else stays on the profile's active version. When you are happy, promote the version for every tablet; if not, roll back the rollout. Each profile has at most one rollout running at a time.

Owners and admins start, promote and roll back rollouts and activate versions. Site managers and read-only members can watch.

Start a rollout

On the profile page, open the Rollouts tab and choose Start rollout:

  • Version: the version to try (not the active one).
  • Target sites: every tablet of these sites gets the version.
  • Target tags: "Devices with any of these tags get the version, wherever they are. Each such device gets its own policy." Up to 50 tags.
  • Note (optional): "Kept with the rollout in the history."

You need at least one site or one tag ("Pick at least one site or add at least one tag."). A tablet that matches both a target site and a target tag counts through its site. New tablets that enroll at a target site start on the active version for a moment and then switch to the rollout version.

The per-device limit with tags

Tablets reached only through a tag each get their own policy, which counts against the organisation's limit of tablets with their own policy (200 by default, shared with managed configurations that use device placeholders, see Apps and managed configurations). If a rollout would go over it, starting it is refused with a message that names the number of tablets and the limit. Use site targets instead (one shared policy per site), fewer tags, or ask the purplegreen MDM operator to raise the limit. The same check applies when you promote a rollout or change a tablet's tags.

Watch it

The rollout page shows how many tablets are in scope, how many already run the version (applied), how many are still pending, how many are offline and how many report a problem (non-compliant), and a list of the tablets with their desired and applied version. A tablet that is offline gets the version when it next connects.

On the Versions tab every version shows whether it is active or pinned by a rollout, and how many tablets should run it and actually run it (Desired / applied). Pick two versions and Compare them to see what changed in the settings and in the policy Google receives. Values that look like passwords in managed configurations are shown masked there.

The device page shows the tablet's Policy line: the desired and applied version, whether it comes from a rollout, and whether the tablet is behind (drift). The device list shows a rollout badge.

Promote or roll back

  • Promote version N makes it the active version: "Version N is now the active version for every device." The rollout ends as promoted.
  • Roll back rollout: "Rolled back: the targets return to the active version." The rollout ends as rolled back.

Both can carry a note and are recorded in the audit log. A finished rollout cannot be promoted or rolled back again. Its numbers keep being calculated from the tablets' current state, so they can change after the rollout ended.

Roll back the active version

If the active version itself causes trouble, open the Versions tab and choose Roll back to vN on an older version ("Why you roll back, for the audit log."). Every tablet on the profile moves to that version. The version history stays a straight line: nothing is deleted, the older version simply becomes active again, and later you can activate a newer one.

While a rollout of the profile is running, rolling back is refused: promote or roll back the rollout first. Archiving a profile with a running rollout is refused for the same reason.

When a site is archived

Archiving a site removes it from the targets of running rollouts. A rollout that has no site or tag left is closed as rolled back, and its tablets return to the active version.

What site managers see

A site manager sees a rollout only when it targets one of their sites or reaches a tablet on one of their sites. The target list shows only their own sites, plus how many other sites are targeted; the numbers and the tablet list cover only their sites.