v4.79.0
Added 14
- Added ability to view past and upcoming MDM commands for a host in Fleet
- Added ability to apply Android app configurations
- Added support for resending Windows MDM profiles
- Added support for renewal of custom SCEP profiles for Windows
- Added support for team-specific labels
- Implemented ability to create, list, and delete Android certs from the UI
- Added Android agent application to support automated installation of SCEP certificates on Android hosts
- Added messaging around Apple VPP update failures due to the application being open
- Added ability to indicate that new MacOS hosts enrolling via ADE should be updated to the latest operating system version
- Added ability to edit Android software config in UI
- Added support for ingesting Windows certificates via osquery
- Added activities for when certificates templates are created or deleted
- Added ability to search teams in dropdown when transferring teams
- Added pagination metadata to the GET /mdm/commands endpoint
Changed 2
- Implemented streaming for the GET /hosts API to improve performance
- Changed the host details page to hide builtin labels in-line with other areas such as the label filter
Fixed 4
- Fixed host query report to display 'Report clipped' when a query has reached the 1k result limit
- Fixed an issue where batch uploading .mobileconfig profiles failed due to display name checks
- Fixed an issue where GitOps would fail if $FLEET_SECRET contained XML characters in XML files due to not escaping the value
- Fixed a bug where iOS and iPadOS hosts enrolling via ABM MDM Migration did not have VPP apps installed
Fleet 4.79.0 (Jan 14, 2025)
IT Admins
- Added ability to view past and upcoming MDM commands for a host in Fleet.
- Added ability to apply Android app configurations.
- Added support for resending Windows MDM profiles.
- Added support for renewal of custom SCEP profiles for Windows.
- Added support for team-specific labels. Currently team-specific labels must be created via spec endpoints, used by GitOps.
- Implemented ability to create, list, and delete Android certs from the UI.
- Added Android agent application (automatically deployed via Android MDM) to support automated installation of SCEP certificates on Android hosts.
- Added messaging around Apple VPP update failures due to the application being open.
- Added ability to indicate that new MacOS hosts enrolling via ADE should be updated to the latest operating system version.
- Added ability to edit Android software config in UI.
Security Engineers
- Added support for ingesting Windows certificates via osquery.
- Added activities for when certificates templates are created/deleted.
Other improvements and bug fixes
- Implemented streaming for the
GET /hosts("list hosts") API to improve performance. - Updated API and GitOps to support
AppleOSUpdateSettings.UpdateNewHosts. - Added ability to search teams in dropdown when transferring teams.
- Added pagination metadata to the
GET /mdm/commandsendpoint. - Updated the
refresh_vpp_app_versionscron job to only attempt to refresh versions for Apple app store apps. - Improved edit VPP UX by disabling a form that hasn't been edited.
- Updated logic used for determining whether to update a macOS host during DEP enrollment based solely on UpdateNewHosts flag.
- Added note to descriptions on schema tables using "count" as column name.
- Aligned Android MDM unenrollment endpoint with the already existing endpoint,
DELETE /api/latest/fleet/hosts/{id}/mdm, for consistency across MDM platforms. - Added migration for adding
update_new_hostsflag to both App and Team configs. - Changed the host details page to hide builtin labels in-line with other areas such as the label filter.
- Changed iOS/iPadOS and Android enrollment links on Add hosts modal to monospaced font to improve readability.
- Improved software upload progress modal.
- Improved consistency of
gitopsoutput language. - Added loading state to turn off Android modal UI.
- Updated the
migrate_to_per_host_policycron job to no-op if Android MDM is not enabled. - Updated software table so that all teams selection will now remove any unsupported url params.
- Improved unclear error message when uploading an APNS certificate if the CSR was not downloaded.
- Refactored RDS IAM authentication logic into a dedicated
rdsauthpackage. - Modified the automatic enrollment profile verification logic to only verify with Apple when a profile changes
- Updated S3 username/password when running in dev mode to remove outdated mentions of MinIO.
- Hid option to transfer hosts to their current team.
- Updated setup experience links to point to add software page relevant to platform.
- Revised auth requirements for /debug endpoints.
- Added additional validation to URL parameter for MS MDM auth endpoint.
- Improved SOAP message validation on Windows MDM endpoints.
- Fixed host query report to display "Report clipped" when a query has reached the 1k result limit.
- Fixed UI error message regarding adding software to a team with a duplicate title.
- Fixed an issue where batch uploading .mobileconfig profiles failed due to display name checks.
- Fixed an issue where certificate details modal overflowed the screen.
- Fixed click area of edit software file button.
- Fixed an issue where GitOps would fail if
$FLEET_SECRETcontained XML characters in XML files, due to not escaping the value. - Fixed query behind
fleetctl get mdm-commandsto correctly get completed Windows MDM commands. - Fixed MDM install command output to correctly display UTF-8 characters in the UI.
- Fixed missing upgrade code persistence when adding Windows software to Fleet via GitOps.
- Fixed duplicate entry error when updating upgrade_code during software ingestion
- Fixed case sensitivity mismatches causing duplicate titles during software ingestion
- Fixed a bug where iOS and iPadOS hosts enrolling via ABM MDM Migration did not have VPP apps installed.
Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade.
Fleet's agent
The following version of Fleet's agent (fleetd) support the latest changes to Fleet:
- orbit-v1.50.2
fleet-desktop-v1.50.2(included with Orbit)osquery-5.21.0(included with Orbit)- fleetd-chrome-v1.3.3
- fleetd-android-v1.0.2
While newer versions of
fleetdstill function with older versions of Fleet, old versions offleetdand osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet.
Upgrading
Please visit our upgrade guide for upgrade instructions.
Documentation
Documentation for Fleet is available at fleetdm.com/docs.
Binary Checksum
SHA256
532857020b0f1a46cdb5ad16f215d3b3264ebf0bb97754b302b6cce97255927a fleet_v4.79.0_linux.tar.gz
51c169304d14383a38e74b81e19b34c562c91e14ef0f23037062a66721611415 fleetctl_v4.79.0_linux_amd64.tar.gz
ed128983f454c39cdb93b7e204c90fc9f172db81b8e98c9f754be9430a53b9a3 fleetctl_v4.79.0_linux_amd64.zip
d996e16bf6de750815a536a9c3e1bf0821bcc71e7d4a2fddaa705cdfa6558876 fleetctl_v4.79.0_linux_arm64.tar.gz
7fa1cbbb2234855321f840c41bd7935fe292615dde2c4af214f2e65ed3e9b56d fleetctl_v4.79.0_linux_arm64.zip
3ccf4c1b47992574a88938bbb3064e729e93886c392af55a417fb57abfb22605 fleetctl_v4.79.0_macos.tar.gz
d03d43987893597d2c45bafa268bcfe7f89331f41ba93fec1415aa303f68a16e fleetctl_v4.79.0_macos.zip
7438b13ae5be9ad38e647a7880ea74220a801e4573db99a41de3b17641cb3dae fleetctl_v4.79.0_windows_amd64.tar.gz
99469dc84555612ebcc31e0a24ad806891f2a9d46fa96f6b1e7790297fa54858 fleetctl_v4.79.0_windows_amd64.zip
91ff4bc4936dabe7ee183d2fdc30b55cc3c2d8eefd3247ba52071039ecf038b2 fleetctl_v4.79.0_windows_arm64.tar.gz
af67a95a3195d4bcb8719612dc823705183736aa6d68b596d1c3dcf3bcb738ee fleetctl_v4.79.0_windows_arm64.zip