Team: Huntress Managed Identity Security Posture Management (ISPM)
Product: Microsoft 365
Summary: Learn how Managed Deployments and Modified Deployments work in Huntress Managed ISPM, including policy selection, scheduling, and partner control options.
In this Article
Overview
Deployment Modes
How Scheduled Deployment Works
Organization-Level Skips
Learning Mode and Safety Checks
Common Support Scenarios
Frequently Asked Questions
Important: Managed Deployments are enabled by default for all organizations added on or after August 3, 2026. This includes trial accounts.
Overview
Managed Deployments allow partners to deploy a curated selection of policies from the Huntress policy library to a Microsoft 365 tenant.
Huntress maintains the managed selection, which evolves over time as controls are added or removed. The initial selection focuses on approximately 30 low-impact settings chosen for automatic deployment.
The full Huntress policy library is broader than the managed selection. Policies not included in the managed baseline remain available for partners to deploy manually.
Deployment Modes
Each organization can use one of three deployment modes. Deployment mode determines who owns the default policy selection.
| Mode | How the Default Selection Is Owned | How Future Huntress Additions Are Handled |
| Managed Deployment | Huntress owns and maintains the baseline selection. | New controls added to the managed selection are automatically available for deployment. |
| Modified Deployment* (Q3 2026) | The partner chooses the baseline selection at the account level. | New controls are not added automatically. The partner must add them manually. |
| Off | No policies are deployed through this feature. | No automatic deployment occurs. |
*Modified Deployments will be available in Q3 2026.
Managed Deployment
With Managed Deployment:
Huntress selects controls from the policy library for the managed baseline.
The selection focuses initially on low-impact settings.
Huntress updates the selection over time, adding or removing controls as needed.
Organizations inherit the evolving managed selection, subject to licensing, compliance, scheduling, and organization-level skips.
Controls outside the managed selection remain available for manual deployment.
Managed Deployment does not automatically deploy every control in the policy library.
Modified Deployment (Coming Q3 2026)
With Modified Deployment:
The partner pre-selects controls from the Huntress policy library at the account level.
New organizations inherit that account-level selection as a template.
The partner-defined selection does not inherit new additions to the Huntress-managed selection.
The partner can manually add controls when expanding the selection.
Modified Deployment is intended for partners who want to own the default baseline for all their organizations. It is not required if a partner only wants to exclude a single control for a specific organization.
How Scheduled Deployment Works
When selected controls are scheduled for deployment, the scheduler evaluates each organization and control. Controls deploy according to the configured schedule unless an exclusion applies.
A control is skipped if:
The organization is not licensed for the feature.
The organization is already compliant with the control.
The partner manually skipped the control for that organization.
The control is not part of the organization's active selection.
If an organization is already compliant, the control is skipped because no change is required. Skipping a compliance control is not a failure and does not change the organization's deployment mode.
Cadence
Scheduled deployments take place Monday through Thursday each week. This schedule minimizes the likelihood of issues over weekends when partner resources may be reduced.
Organization-Level Skips
Partners can skip an individual control for an individual organization. An organization-level skip acts as a final, organization-specific override.
An organization-level skip:
Prevents that control from deploying to that organization.
Does not change the organization from Managed Deployment to Modified Deployment.
Does not transfer ownership of the baseline selection to the partner.
Does not prevent the organization from inheriting future additions to the managed selection.
For example, an organization can remain on Managed Deployment while skipping one control that is unsuitable for that customer. The organization continues to receive the remaining eligible managed baseline and future additions.
Selection versus Exception
Managed or Modified determines the default policy selection.
Skip is an exception to that selection for a single organization and a single control.
Partners who want to exclude one control but continue receiving future Huntress-managed additions should keep the organization on Managed Deployment and use an organization-level skip. Partners should use Modified Deployment only when they want to define and own the default selection across their entire account.
Learning Mode and Safety Checks
Managed Deployments do not place controls into a tenant-level learning mode before enforcement. There is no per-tenant learning period or pre-deployment impact analysis.
Huntress deliberately selects controls in the managed library before making them available for automatic deployment. Once scheduled, the deployment process checks licensing, current compliance, and organization-level skips before applying eligible controls.
Common Support Scenarios
A partner wants to skip one control: Keep the organization on Managed Deployment and apply an organization-level skip to that control. Skipping a single control does not switch the organization to Modified Deployment.
A partner wants to define their own baseline: Use Modified Deployment. The partner selects controls at the account level, and new organizations inherit that custom baseline.
A partner wants to receive future Huntress additions: Use Managed Deployment. New controls added to the Huntress-managed selection become available automatically after passing deployment checks.
-
A control was not deployed: Verify the following items:
The organization's active deployment mode.
Whether the control is included in the active selection for that mode.
Whether the organization is licensed for the feature.
Whether the organization is already compliant with the control.
Whether the control is skipped at the organization level.
Whether the control is awaiting its scheduled deployment window.
Frequently Asked Questions
Q: Will Managed Deployments turn on settings that the organization is not licensed for?
A: No. Managed Deployments uses license-gating to ensure that only controls for licensed features are deployed. Note that this verification occurs at the tenant level and does not validate whether all individual users in the tenant are licensed. Partners remain responsible for Microsoft licensing compliance.
Q: Can I roll back a setting deployed by Managed Deployments?
A: Yes. On the Managed Deployments page, select Revert next to the control. Alternatively, go to the individual control page and revert the setting.
Q: Why don't I see Modified Deployments in my dashboard?
A: Modified Deployments will roll out to all partners in Q3 2026.