# Fleet v4.71.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2025-07-23 - Version: v4.71.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.71.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.71.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Updated CIS benchmarks for Windows 10 to version 3 - **added** — Added support for IdP-based labels - **added** — Added last opened time for Windows applications - **added** — Added support for ingesting user's Department via SCIM and support to set the FLEET_VAR_HOST_END_USER_IDP_DEPARTMENT variable on configuration profiles - **added** — Added verification of user-scoped profiles on macOS - **added** — Added support for Host Vitals label, starting with IdP-based labels which update automatically - **added** — Added automatic refetches of host vitals and software inventory after a successful software install or uninstall - **added** — Added support for the Apple MDM user channel to send mobileconfig with User payloadscope to user channel connections - **added** — Added ability to add EULA end user sees during setup experience via gitops - **added** — Added user property api_only to backend activity details - **added** — Added a new avatar for API-only users in the activity feed - **added** — Added missing team_name property on /api/v1/fleet/hosts/identifier/:id endpoint - **added** — Added functionality for verifying installation of VPP apps - **changed** — Updated GET /hosts/:id/encryption_key to return most recently archived encryption key if current key is not available - **changed** — Updated Windows Custom OS Settings including Win32/Desktop Bridge ADMX policies to be marked verified after host acknowledges MDM install command - **changed** — Increased how often Fleet checks for new Fleet-maintained apps from once per day to once per hour - **changed** — Improved GitOps speed when managing software with hashes on a large number of teams - **changed** — Separated host details software list into two separate sections: Inventory and Library - **changed** — Updated Apple profile verification code to disallow uploading profiles with same identifier but differing PayloadScopes - **changed** — Recorded installer URL when a Fleet-maintained app is added via web UI or REST API - **changed** — Replaced own SAML implementation with crewjam/saml library ##### Fleet 4.71.0 (Jul 23, 2025) ###### Security Engineers - Updated CIS benchmarks for Windows 10 to version 3. - Added support for IdP-based labels. - Added last opened time for Windows applications. - Updated `GET /hosts/:id/encryption_key` to return most recently archived encryption key if current key is not available. - Added support for ingesting user's "Department" via SCIM and added support to set the `FLEET_VAR_HOST_END_USER_IDP_DEPARTMENT` variable on configuration profiles. - Cleaned up false-positive vulnerabilities on Amazon Linux 2 hosts reported in Fleet <= 4.55. ###### IT Admins - Added the verification of user-scoped profiles on macOS. - Added last opened time for Windows applications. - Updated Windows Custom OS Settings including Win32/Desktop Bridge ADMX policies to now be marked verified after the host has acknowledged the MDM install command. - Added support for "Host Vitals" label, starting with IdP-based labels which update automatically. - Added automatic refetches of host vitals and software inventory after a successful software install or uninstall. - Updated `GET /hosts/:id/encryption_key` to return most recently archived encryption key if current key is not available. - Increased how often Fleet checks for new Fleet-maintained apps, from once per day to once per hour. - Improved GitOps speed when managing software with hashes on a large number of teams. - Separated host details software list into two separate sections: Inventory (software installed on a host) and Library (software available for installation on a host). - Updated Apple profile verification code to disallow uploading profiles with the same identifier but differing PayloadScopes. - Recorded installer URL when a Fleet-maintained app is added via the web UI or REST API. - Added support for ingesting user's "Department" via SCIM and added support to set the `FLEET_VAR_HOST_END_USER_IDP_DEPARTMENT` variable on configuration profiles. - Added support for the Apple MDM user channel. When a mobileconfig with a payloadscope of User is targeted for a host with a user channel connection, it will now be sent to the user channel. - Added ability to add EULA end user sees during setup experience via gitops. ###### Other improvements and bug fixes - Switched VPP apps to show as installed only after MDM confirms the app is installed, instead of when the installation command is acknowledged. - Added user property `api_only` to backend activity details. - Replaced email with user full name for login activity. - Added a new avatar for API-only users in the activity feed. - Updated side navigation styles across the app. - Added premium tier messaging to the certificates section on the integrations page. - Removed ability to upload a EULA in the UI if gitops is enabled. - Migrated from `aws-sdk-go` v1 to `aws-sdk-go-v2`. - Optimized database queries for MDM enrollment checks when one host is being checked at a time. - Replaced own SAML implementation with https://github.com/crewjam/saml. - Increased page size for software versions shown on the software view page from 5 to 10. - Added retries in `PATCH` policies API requests to fix deadlock errors in "Manage automations" page. - Added missing team_name property on `/api/v1/fleet/hosts/identifier/:id` endpoint. - Added missing "url" parameter when exporting YAML on software packages that have a URL specified (thanks @drvcodenta!) - Improved performance when pulling team settings on osquery config and distributed read endpoints. - Allowed team selection and name updates when saving a copy of an existing query as a new query. - Updated Fleet maintained apps uninstall script to use `pkgutil` to remove applications files. - Added functionality for verifying installation of VPP apps. - Moved the SSO and Host status webhook settings from Settings > Organization to Settings > Integrations. - Updated software installed activities created during setup experience cor _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.71.0]_