> ## Documentation Index
> Fetch the complete documentation index at: https://docs.microsandbox.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Enterprise deployment

> Choose a deployment approach for employee devices or your own infrastructure

Use microsandbox on employee devices or in your own infrastructure. Choose the deployment approach that fits your workloads and operational requirements.

## Choose your deployment

| Deployment | Purpose | Next step |
| - | - | - |
| Employee devices | Standardize local development and team settings | [Rollout guides](#roll-out-to-employee-devices) |
| Runtime on your infrastructure | Run sandboxes on your servers or clusters | [Discuss your deployment](/enterprise/contact) |
| Private cloud deployment | Run the microsandbox cloud platform in your infrastructure | [Discuss requirements](/enterprise/contact) |

For our hosted service, see [microsandbox Cloud](/cloud/overview).

## Roll out to employee devices

Start with one working installation, connect it to company services, then apply policy and roll it out to a pilot group.

| Step | Outcome |
| - | - |
| [Prepare your environment](/enterprise/prepare-environment) | Approved SDKs, runtime files, and images work on the target devices, including offline installations. |
| [Configure company networking](/enterprise/corporate-networking) | Sandboxes can reach approved services through company routing, DNS, and certificate trust. |
| [Enforce team settings](/enterprise/managed-configuration) | A protected policy defines which supported settings employees cannot override. |
| [Deploy and verify](/enterprise/deploy-and-verify) | A tested pilot, repeatable device deployment, and an update and rollback process. |

### Deployment responsibilities

| microsandbox provides | Your organization manages |
| - | - |
| Local sandbox isolation and network controls | Device security, host permissions, and approved workloads |
| Managed overrides for supported CLI and SDK settings | Policy distribution, file protection, and supported client versions |
| Runtime and image installation tools | Package approval, distribution, and updates |
| Configuration for company network access | VPN/proxy enrollment, credentials, DNS, and corporate certificates |

Managed settings apply through supported CLI and SDK clients. They are not a replacement for device security: local administrators can remove policy or replace the runtime.

These guides focus on local sandboxes on company-managed devices. Some managed settings also apply to outgoing cloud requests, as described in [Enforce team settings](/enterprise/managed-configuration). They do not reconfigure the cloud service.

## Discuss your deployment

Planning a runtime rollout or private cloud deployment? [Contact our team](/enterprise/contact) with a short description of your workloads and deployment needs.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.