# Fleet v4.68.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2025-05-22 - Version: v4.68.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.68.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.68.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Built Fleet integration with Microsoft Entra to conditionally prevent single sign-on for hosts failing policies - **added** — Added ability to set conditional access per policy and update host policy UI to incorporate conditional access data - **added** — Added CVE ID as matching criteria for host software queries in addition to software name - **changed** — Updated Fleet-managed DigiCert, NDES, and SCEP certificates to be renewed 30 days before expiry for those valid longer than 30 days or when half the validity period remains for certificates valid 30 days or less - **added** — Added webhook as a logging configuration option - **added** — Added webhook query automation logging - **added** — Added shell and Powershell syntax highlighting when editing scripts - **added** — Added ability to run a script on a batch of hosts with a single user flow - **added** — Added download validation and existing-installer matching in GitOps via a new hash_sha256 field in software YAML - **added** — Added hash_sha256 field to the response for the GET /software/titles API - **added** — Added fleetctl generate-gitops command to generate gitops YAML files based on current Fleet configuration - **added** — Added the ability to upload and install tarball archives (.tar.gz) - **added** — Added support for Fleet-maintained apps in GitOps - **added** — Added ability to add FMA via fleetctl YAML files - **added** — Added query ID to query automation logs - **added** — Added UI for the manual agent install of a bootstrap package - **added** — Added categorization for self-service software including filtering on the My device page - **added** — Added number of policies triggering automatic install of software in software table - **added** — Added support for FLEET_VAR_HOST_END_USER_IDP_USERNAME, FLEET_VAR_HOST_END_USER_IDP_USERNAME_LOCAL_PART and FLEET_VAR_HOST_END_USER_IDP_GROUPS fleet variables in macOS MDM configuration profiles ##### Fleet 4.68.0 (May 22, 2025) ###### Security Engineers - Built Fleet integration with Microsoft Entra to conditionally prevent single sign-on for hosts failing policies. - Added ability to set conditional access per policy, and update host policy UI to incorporate conditional access data. - Added CVE ID as matching criteria for host software queries, in addition to software name. Also rebuild host software querying for better maintainability. - Updated Fleet-managed DigiCert, NDES, and SCEP certificates to be renewed 30 days before expiry for those valid longer than 30 days or when half the validity period remains for certificates valid 30 days or less. Applies to certificates requested using this release or later. - Added webhook as a logging configuration option. - Added webhook query automation logging. - Added shell and Powershell syntax highlighting when editing scripts. - Added ability to run a script on a batch of hosts with a single user flow. - Added download validation and existing-installer matching in GitOps via a new `hash_sha256` field in software YAML. - Added `hash_sha256` field to the response for the `GET /software/titles` API. - Added `fleetctl generate-gitops` command to generate gitops YAML files based on current Fleet configuration. - Enabled saving Integrations > Advanced in GitOps mode. ###### IT Admins - Added ability to run a script on a batch of hosts with a single user flow. - Added the ability to upload and install tarball archives (.tar.gz). - Added support for Fleet-maintained apps in GitOps. - Added ability to add FMA via `fleetctl` YAML files. - Added shell and Powershell syntax highlighting when editing scripts. - Added query ID to query automation logs. - Added UI for the manual agent install of a bootstrap package. - Added categorization for self-service software, including filtering on the "My device" page. - Added number of policies triggering automatic install of software in software table. - Added webhook as a logging configuration option. - Added webhook query automation logging. - Added download validation and existing-installer matching in GitOps via a new `hash_sha256` field in software YAML. - Added `hash_sha256` field to the response for the `GET /software/titles` API. - Added support for `FLEET_VAR_HOST_END_USER_IDP_USERNAME`, `FLEET_VAR_HOST_END_USER_IDP_USERNAME_LOCAL_PART` and `FLEET_VAR_HOST_END_USER_IDP_GROUPS` fleet variables in macOS MDM configuration profiles. - Added `last_mdm_enrolled_at` and `last_mdm_checked_in_at` to host detail endpoints to return the last time a host enrolled, or re-enrolled in MDM and the last time a host checked in via MDM, respectively. - Added `fleetctl generate-gitops` command to generate gitops YAML files based on current Fleet configuration. - Updated Fleet-managed DigiCert, NDES, and SCEP certificates to be renewed 30 days before expiry for those valid longer than 30 days or when half the validity period remains for certificates valid 30 days or less. Applies to certificates requested using this release or later. - Updated host certificates with serial numbers below 2^63 will now display the decimal represntation of the serial number in addition to hex so that it is easier to match them up to what is displayed in the macOS keychain. - Updated Install Status to correctly display available for self-service VPP apps. - Logged invalid Windows MDM SOAP message and return 400 instead of 5XX. This change helps debug Windows MDM issues. - Added `macos_setup.manual_agent_install` option in Mac setup experience to bypass fleetd install. Instead, fleetd should be installed via customer-customized bootstrap package. - Allowed uploading VPP apps when GitOps mode is enabled. - Allowed viewing the status details for an (un)install via the "My device" page. - Updated Apple MDM enrollment flow to improve device-to-user mapping. - Updated verification of Windows Wireless profiles to avoid resending already-app _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.68.0]_