Note: This Feature Pack deployment is applicable to build 11.5.2627.01 and later. If you are using an earlier build, refer to this page.
Without a centralized feature pack deployment, OS upgrades become difficult to standardize and control. You may often face issues like upgrade failures due to missing prerequisites, compatibility conflicts with applications, unexpected reboots, user disruption during manual updates, language or regional mismatches, and challenges in managing and distributing the correct ISO files across endpoints.
There is also no easy way to enforce an N-1 strategy (keeping systems on the previous stable version), which is important to avoid early adoption risks. Without this control, some devices may upgrade too early while others lag behind, leading to version fragmentation.
Feature Pack deployment in Endpoint Central allows you to centrally manage and upgrade Windows OS versions (like Windows 10/11 feature updates) across endpoints. From the Feature Pack view, you can directly identify available upgrades, track missing and installed systems, and monitor download status and prerequisites. You can first ensure the OS binaries are downloaded, verify prerequisites, and then deploy the feature pack to selected systems. The dashboard provides visibility into deployment status (missing, installed, declined), helping you plan staged rollouts and ensure systems are upgraded before reaching end-of-life.
You can manage feature pack approvals by configuring manual approval, automatic approval, or approval after testing in a pilot group of computers. This also allows you to validate and deploy either the latest (N) feature pack or follow an N-1 approach by deploying the previous stable version based on your organization’s upgrade strategy.
You can automate feature pack deployment by configuring an Automate Patch Deployment (APD) task, enabling scheduled rollouts, and enforcing an N-1 strategy to ensure systems remain on a stable and supported version. This reduces manual effort, maintains version consistency, and enables controlled, phased upgrades across the environment.
Go to Theats & Patches -> Patches -> Feature Packs -> Feature Pack Upgrade (or) Patch Mgmt -> Patches -> Feature Packs -> Feature Pack Upgrade. In this view, you can manage, track, and control the deployment of OS feature pack upgrades across Windows endpoints, and select any feature pack to mark it as Approved, Declined, or Not Approved. This view also provides key details to help you evaluate and plan deployments effectively:
Note: Previously, these feature packs were displayed under other patch views such as Missing Patches, Supported Patches, or Latest Patches views. They are now consolidated and available only within this dedicated Feature Packs view for better visibility and control.

By clicking on any of the feature pack, you can view detailed information for that particular feature pack, such as:
Note: The Endpoint Central server downloads required OS binaries (ISO) from the vendor websites. If the ISO download failed, you need to manually download and upload the ISO file from the vendor website for that specific feature pack. If the ISO for that feature pack is not uploaded, a warning message will be displayed. Upgrade requirements details are also mentioned to help you prepare systems before deployment.
Under each of these system tabs, you can see details such as:
You can select the required systems and click Install Feature Pack to initiate the deployment using a manual deployment task. Before proceeding, ensure that the systems you select accurately match your deployment requirement, as these selected targets will be carried forward for deployment. For broader rollouts, you can select all applicable systems from this view, whereas for controlled or specific deployments, you can choose specific systems accordingly.

This page displays all OS files that are either downloaded from the server or uploaded manually, helping you ensure that the required binaries are available before initiating upgrades. OS files displayed are based on applicability. By default, the view is filtered to show only Applicable OS files, ensuring that you see only the required binaries for your environment. You can also upload OS files if the server fails to download the required file.
You can refine the view using filters such as All and Applicable OS, allowing you to control whether all OS files or only applicable ones are displayed. You can also filter based on the Operating System to view specific OS versions and use the Feature Pack Version filter to narrow down results by Service Pack (SP) versions. By default, the page displays All OS and All Service Packs.
Note: If Endpoint Central server fails to download the OS files automatically, you must upload the ISO files manually for each combination of Feature Pack, Edition, Architecture, and Language. Ensure that the correct ISO file is used, as uploading an incorrect file can lead to deployment failures. This page helps you verify that all required OS binaries are available before initiating Feature Pack deployment.
You can upload the required OS file manually using the Upload option when automatic download fails or is not preferred. The Delete option can be used to remove incorrectly uploaded or unnecessary ISO files, and once a file is deleted, the Upload option becomes available again for that entry.
By default, OS files are automatically removed when the associated Feature Pack version reaches End of Life (EOL), when the Service Pack version is no longer required, or when the corresponding Language, Architecture, or Edition is removed from the configuration. You can also manually delete OS files only if an incorrect ISO was uploaded or if the file is no longer required.

To configure feature pack approval settings, go to Deployment -> Test and Approve. Under Feature Pack Approval Settings, by default, the Approve Feature Patches feature will be configured as Automatically without testing. This means whenever a new feature pack gets released, it will get approved automatically if it passes the evaluation performed by ManageEngine Security Research Team. Those feature packs' approval status will automatically be listed as Approved . This is useful if your enterprise has less critical machines and you want to automatically deploy all the released feature packs immediately.
If you wish to re-evaluate the compatibility or integrity of the feature packs, click on Modify and change it to Test and Approve. Once you select this, you need to configure for retaining approval status under the section For the Existing Feature Packs. Select Retain Approval Status if you prefer to keep the current approval status of the existing feature packs. The newly released feature packs will be marked as Not Approved; which can be tested and later approved.
If you wish to move existing patches to Not Approved status and test for its authenticity again, select Mark Patch as Not Approved.
After configuring these settings, click on Save.
If you have selected Test and Approve as the approval mode, create a test group of pilot computers to test the deployment before rolling it out to all endpoints. To create a test group, click on Add Group and select Feature Pack.

Now under Test Group Settings page, under Group Name, select the Target Group of pilot computers where you want to test the feature pack. If you want to know how to create custom groups, refer to this page.
In Deployment Option section, choose to deploy Latest (N) or N-1 feature pack in the test group under Upgrade Computer Version. You can also review and verify the OS Version, Scheduled Version, and Approval Status for the selected computer version upgrade.
By enabling Deploy Feature Pack update only on Compatible machines, the upgrade is applied only to machines that meet all prerequisites, ensuring a smooth deployment. If not enabled, the feature pack is attempted on all targets, including incompatible machines, which can lead to deployment failures, unnecessary retries, increased network and system load, and potential disruption to end users. Hence, it is recommended to enable this option to ensure reliable and efficient deployments. If you wish to test how the deployment behaves on incompatible machines, you can deselect this option and perform the deployment on a pilot group.

Once you have completed configuring Deployment Option, configure other test group settings such as Deployment Settings, Notification Settings and Approval mode in the same way when you are configuting a test group settings for testing a patch. To learn more about this, refer to this page.
Navigate to Deployment -> Automate Patch Deployment and then click on Automate Task and choose Windows as Operating System and select Feature Pack option to automate Feature Pack Deployments.

Under Select Deployment Method tab, choose to whether to deploy the Latest (N) or N-1 feature pack under Upgrade Computer Version option. Only approved patches will get deployed using this task. You can also review and verify the OS Version, Scheduled Version, and Approval Status from this section before proceeding.
Choose the number of days after the release of a feature pack, after which you want to automatically deploy it, under Apply latest Feature pack version after option.
By enabling Deploy Feature Pack update only on Compatible machines, the upgrade is applied only to machines that meet all prerequisites, ensuring a smooth deployment. If not enabled, the feature pack is attempted on all targets, including incompatible machines, which can lead to deployment failures and unnecessary retries, leading to increased network and system load, and potential disruption to end users due to unsuccessful upgrade attempts. Hence, it is recommended to enable this option to ensure reliable and efficient deployments.

After you have configured the above settings, click on Next and configure other settings of the Automate Patch Deployment task by referring to this page.
Go to Threats & Patches --> Dashboard --> Feature Packs (or) Patch Mgmt --> Dashboard --> Feature Packs. This feature pack dashboard provides a holistic view with all key information in one place such as:
By clicking on any of the above-mentioned, you can access detailed information related to the respective data.

If you have any further questions, please refer to our Frequently Asked Questions section for more information.