Cloud Update rollout waves show only ~50 devices although Entra device group has ~11K — Inventory/eligibility evaluation mismatch

ZTS 65 Reputation points
2026-04-28T12:15:19.29+00:00

Cloud Update rollout waves show only ~50 devices although Entra device group has ~11K — Inventory/eligibility evaluation mismatch

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-04-28T12:15:33.5566667+00:00

    Cloud Update evaluates eligibility based on Cloud Update inventory and Microsoft Entra group requirements, not just the raw object count in the Entra group. A large discrepancy between the ~11K devices in the Entra device group and ~50 devices visible in rollout waves typically indicates that most group members are not eligible or not recognized by Cloud Update.

    Key points to verify:

    1. Device join type and Entra group requirements
      Cloud Update only recognizes device objects that meet the Microsoft Entra group requirements:
      • Device objects must be Microsoft Entra joined or hybrid joined.
      • Devices that are Microsoft Entra registered / Workplace joined are not recognized when the group is processed.
      • Both device and user objects can be in the same group, but each object must meet the requirements.
      If the ~11K group contains many registered-only devices, those will not appear as eligible in Cloud Update rollout waves, which can explain why only ~50 devices show up.
    2. Channel and profile eligibility
      Cloud Update only manages devices on Current Channel and Monthly Enterprise Channel. Devices on other channels or excluded from Cloud Update are not onboarded and will not appear in the Monthly Enterprise profile’s rollout waves.
      Use the security update status page in the Microsoft 365 Apps admin center to confirm how many devices are actually on Current or Monthly Enterprise Channel and therefore eligible for Cloud Update.
    3. Group size and nesting limits
      When using Microsoft Entra groups with Cloud Update:
      • A single group should contain no more than 20,000 objects.
      • Nested groups are supported up to three levels deep.
        If the 11K devices are spread across nested groups deeper than three levels, or if the group structure exceeds these limits, Cloud Update may not resolve all members.
    4. Rollout waves scope vs. tenant-wide coverage
      Rollout waves apply only to devices managed by the Monthly Enterprise profile:
      • Ensure that the devices expected to appear are actually in the Monthly Enterprise profile (not Current Channel only, not excluded, and not unmanaged).
      • Rollout waves support groups, but you do not need to include every device in a custom wave; any devices not explicitly in waves fall into the default final wave. If only ~50 devices are in the groups assigned to waves 1–3, that is all that will show there.
    5. Exclusions and tenant settings
      Check whether devices are being excluded at the tenant level:
      • Exclude groups: Any devices or users in tenant-level exclude groups are always excluded from Cloud Update and will not appear in rollout waves.
      • Exclusion windows: These prevent updates during certain dates but do not remove devices from inventory; however, they can affect when devices actually receive updates.
    6. Inventory reflection and timing
      Cloud Update inventory and status are not instantaneous:
      • Excluded devices are reflected in device inventory within 24 hours.
      • Changes such as exclusion or ignoreGPO updates can take up to 24 hours to apply.
        If the Entra group membership or device state was recently changed, wait for the inventory to refresh and then re-check the Monthly Enterprise profile and rollout waves.
    7. Troubleshooting steps
      1. In Microsoft 365 Apps admin center, verify the device’s Cloud Update Status and channel in device inventory. Confirm that a sample of the missing devices:
        • Are on Current or Monthly Enterprise Channel.
        • Are not marked as excluded.
        • Are Microsoft Entra joined or hybrid joined.
      2. Review the Entra group used for rollout waves:
        • Confirm that the majority of members are device objects that are Entra joined/hybrid joined.
        • Remove or adjust any Workplace-joined / registered-only devices or rely on user objects instead.
      3. Confirm that the rollout waves configuration is pointing to the correct group(s) and that those groups comply with the size and nesting limits.

    If, after validating join type, channel, exclusions, and group structure, the mismatch persists, collect a few affected Device IDs from device inventory and open a support ticket so the Cloud Update service can be investigated for that tenant.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.