# Fleet v4.81.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2026-02-20 - Version: v4.81.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.81.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.81.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Support for dynamic SCEP challenges for Okta certificates - **added** — Feature to allow IT admins to specify non-atomic Windows MDM profiles - **added** — GitOps support to apply display_name to software packages in fleet yaml - **added** — Enrollment support for iPod touch - **added** — hash_sha256 and package_name query parameters to the GET /api/v1/fleet/software/titles endpoint to check if a custom software package already exists before uploading - **added** — Ability to set default URL for Fleet Desktop - **added** — Logic to skip setup experience for hosts that were enrolled more than 1 day ago - **changed** — Maximum software installer size is now configurable with default bumped from 3 GB to 10 GiB - **added** — Check to fail any pending in-house app installs and cancel upcoming activities when unenrolling a host - **added** — gzip_responses server configuration option to gzip API responses when client indicates support through Accept-Encoding header - **added** — Ability to specify an Apple Connect JWT for interacting directly with Apple APIs when retrieving VPP app metadata - **added** — Logic to .pkg metadata extraction to match the root bundle identifier - **changed** — Moved Windows automatic enrollment configuration instructions out of the UI and into the Windows MDM setup guide - **added** — conditional_access.cert_serial_format server option to specify the Okta conditional access certificate serial format - **changed** — Improved authentication of POST /api/v1/osquery/carve/block requests by parsing and validating session_id and request_id before processing data - **changed** — Redirect users to device policy page when failing conditional access requirements - **changed** — Limited disk encryption key escrowing when global or team setting enabled - **fixed** — False negative for Adobe Reader DC CVE-2025-54257 and CVE-2025-54255 - **added** — Environment variable to revert to old behavior of installing the bootstrap package during macOS MDM migration - **added** — --with-table-sizes option to prepare command to get approximate row counts of all database tables after a migration completes ##### Fleet 4.81.0 (Feb 20, 2026) ###### IT Admins - Added support for dynamic SCEP challenges for Okta certs. - Added a feature to allow IT admins to specify non-atomic Windows MDM profiles. - Added GitOps support to fleet yaml to apply display_name to software package. - Added enrollment support for iPod touch. - Added `hash_sha256` and `package_name` query parameters to the `GET /api/v1/fleet/software/titles` endpoint to allow checking if a custom software package already exists before uploading. Both parameters require `team_id` to be specified. - Added ability to set default URL for Fleet Desktop. - Added logic to skip setup experience for hosts that were enrolled > 1 day ago. - Updated maximum software installer size to be configurable and bumped the default from 3 GB to 10 GiB. - Added a check to fail any pending in-house app installs and cancel upcoming activities when unenrolling a host. - Added `gzip_responses` server configuration option that allows the server to gzip API responses when the client indicates support through the `Accept-Encoding: gzip` request header. - Allowed specifying an Apple Connect JWT for interacting directly with Apple APIs when retrieving VPP app metadata. - Added logic to .pkg metadata extraction to match the root bundle identifier. - Moved Windows automatic enrollment configuration instructions out of the UI and into the Windows MDM setup guide. ###### Security Engineers - Added `conditional_access.cert_serial_format` server option to allow specifying the Okta conditional access certificate serial format. - Improved authentication of `POST /api/v1/osquery/carve/block` requests by parsing and validating `session_id` and `request_id` before processing `data`. - Redirected users to device policy page when failing conditional access requirements. - Limited disk encryption key escrowing when global or team setting enabled. - Differentiated IMP and Integrative Modeling Platform (IMP) while running vulnerability scanning. - Fixed false negative for Adobe Reader DC CVE-2025-54257 & CVE-2025-54255. ###### Other improvements and bug fixes - Added an environment variable to allow reverting to the old behavior of installing the bootstrap package during macOS MDM migration. - Added `--with-table-sizes` option to `prepare` command to get approximate row counts of all database tables after a migration completes. - Updated Fleet UI so that if software is detected as installed on software library page, hide any Fleet install/uninstall failures from page. Admin can view these failures from host details > activities. - Updated Android certificate app to re-enroll if the host was deleted in Fleet. - Updated `fleetctl generate-gitops` to output Fleet-maintained apps in a dedicated `fleet_maintained_apps` section of the YAML files. - When a host is deleted, any associated VPP software installation records are also deleted. - Global observers and maintainers can now officially read user details, which were already visible to them via the activity feed. - Iru (Kandji's new name) added to the list of well-known MDM platforms. - Improved error message when viewing disk encryption key fails because MDM has been turned off and the decryption certificate is no longer valid. - Updated UI to show VPP version for adding software during setup. - User sessions and password reset tokens are now cleared whenever a user's password is changed. - Disallowed use of FLEET_DEV_* environment variables unless `--dev` is passed when serving Fleet. - Handled the NotNow status from the device during DEP setup experience so it does not delay the release of the device. - Allowed overriding individual configuration variables for MySQL and object storage when `--dev` is passed when serving Fleet. - Updated DEP syncing code to use server-protocol-version 9 and handle THROTTLED responses. - Updated UI styling to the Packs flow. - Surfaced Google error message for Android profile failures after max _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.81.0]_