# Fleet v4.69.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2025-06-14 - Version: v4.69.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.69.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.69.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Vulnerability detection via OVAL for Ubuntu 24.10 and 25.04 - **added** — Ability to sync end user's IdP information with Microsoft Entra ID using SCIM protocol - **added** — Ability to sync end user's IdP information with Authentik using SCIM protocol - **changed** — Updated Windows 11 Enterprise CIS policies to version 4.0 - **added** — New Detail Query 'luks_verify' to verify if the stored LUKS key is valid - **added** — Additional checks to vulnerability feed validation to prevent deploying an un-enriched NVD feed - **added** — SHA256 hash of Mac applications to signature information in host software response - **added** — FLEET_AUTH_SSO_SESSION_VALIDITY_PERIOD environment variable for overriding how long end users have to complete SSO - **added** — Ability to execute scripts on up to 5,000 hosts at a time using filters - **added** — Ability to run a script on all hosts that match the current set of supported filters - **added** — New API GET /scripts/batch/summary/:batch_execution_id endpoint for retrieving a summary of the current state of a batch script execution - **added** — API endpoint POST /api/v1/fleet/configuration_profiles/resend/batch to resend a profile to all hosts that satisfy the filter - **added** — Starter library that is automatically applied to all new Fleet instances during setup - **added** — Ability to uninstall software via Self-service tab of My device - **added** — FLEET_MDM_SSO_RATE_LIMIT_PER_MINUTE environment variable to allow increasing MDM SSO endpoint rate limit from 10 per minute - **changed** — Apple MDM enrollment now skips webview popup when end user authentication is disabled - **added** — UI to filter hosts by config profile status - **added** — UI for seeing custom profile status and to batch resend to hosts it failed on - **added** — Filtering for hosts endpoints by MFM config profile and status - **added** — Immediate cancellation of profile delivery when a profile is deleted; if it had already been installed then its removal will be pending ##### Fleet 4.69.0 (June 14, 2025) ###### Security Engineers - Added vulnerability detection via OVAL for Ubuntu 24.10 and 25.04. - Added ability to sync end user's IdP information with Microsoft Entra ID using SCIM protocol. - Added ability to sync end user's IdP information with Authentik using SCIM protocol. - Updated Windows 11 Enterprise CIS policies to version 4.0. - Added new Detail Query 'luks_verify' used to verify if the stored LUKS key is valid. - Added additional checks to vulnerability feed validation to prevent deploying an un-enriched NVD feed. - Added SHA256 hash of Mac applications to signature information in host software response. - Added `FLEET_AUTH_SSO_SESSION_VALIDITY_PERIOD` environment variable for overriding how long end users have to complete SSO. - Added ability to execute scripts on up to 5,000 hosts at a time using filters. - Added ability to run a script on all hosts that match the current set of supported filters. - Added a new API `GET /scripts/batch/summary/:batch_execution_id` endpoint for retrieving a summary of the current state of a batch script execution. - Added the endpoint `POST /api/v1/fleet/configuration_profiles/resend/batch` to resend a profile to all hosts that satisfy the filter. - Added a starter library that is automatically applied to all new Fleet instances during setup. ###### IT Admins - Added ability to execute scripts on up to 5,000 hosts at a time using filters. - Added ability to run a script on all hosts that match the current set of supported filters. - Added a new API `GET /scripts/batch/summary/:batch_execution_id` endpoint for retrieving a summary of the current state of a batch script execution. - Added the endpoint `POST /api/v1/fleet/configuration_profiles/resend/batch` to resend a profile to all hosts that satisfy the filter. - Added ability to uninstall software via Self-service tab of My device. - Added a starter library that is automatically applied to all new Fleet instances during setup. - Added `FLEET_MDM_SSO_RATE_LIMIT_PER_MINUTE` environment variable to allow increasing MDM SSO endpoint rate limit from 10 per minute. When supplied, this parameter also splits MDM SSO into its own rate limit bucket (default is shared with login endpoints). - Added ability to sync end user's IdP information with Microsoft Entra ID using SCIM protocol. - Added ability to sync end user's IdP information with Authentik using SCIM protocol. - Updated Apple MDM enrollment to skip webview popup when end user authentication is disabled. - Added SHA256 hash of Mac applications to signature information in host software response. - Added UI to filter hosts by config profile status. - Added UI for seeing custom profile status and to batch resend to hosts its failed on. - Added filtering for hosts endpoints by MFM config profile and status. - Added immediate cancellation of profile delivery when a profile is deleted; if it had already been installed then its removal will be pending. - Added ability to turn off MDM for iPhone and iPad hosts on the hosts details page. - Added ability for gitops mode to add a custom package on the software page to then copy/paste the YAML needed for packages that cannot be referenced with a URL. ###### Other improvements and bug fixes - Fixed issue where SSO settings, SMTP settings, Features and MDM end-user authentication settings would not be cleared if they were omitted from YAML files used in a GitOps run. > **GITOPS USERS:** If you have these settings configured via the Fleet web application and you use GitOps to manage your configuration, be sure settings are present in your global YAML settings file before your next GitOps run. - Added Neon to the list of platforms that are detected as Linux distributions. - Updated scripts so that editing will now cancel queued executions. - Warn users of consequences when updating script contents. - Improved effectiveness of app-wide text-truncation-into-tooltip funct _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.69.0]_