# Fleet v4.82.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2026-03-12 - Version: v4.82.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.82.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.82.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Support for enrolling fully managed Android hosts without a work profile - **added** — Capability to uninstall Android apps on the device and removal from self-service in the managed Google Play store when an app is removed from Fleet - **added** — Ability to allow or disallow end-users to bypass conditional access on a per-policy basis - **added** — Filtering by platform and add status to the Software > Add Fleet-maintained apps table - **changed** — Android status reports to re-verify profiles that previously failed - **added** — Ability to roll back to previously added versions of Fleet-maintained apps - **added** — New Technician role designed for help desk and IT support teams with capability to run scripts, view results, and install or uninstall software - **added** — Support for JIT provisioning of the Technician role via SSO SAML attributes - **added** — Automatic retries for failed software operations - **added** — Ability to scan for kernel vulnerabilities on RHEL based hosts - **added** — AWS GovCloud RDS CA certificates to the RDS MySQL TLS bundle, enabling IAM authentication for Fleet deployments connecting to RDS in AWS GovCloud regions - **added** — CVE alias for python visual studio code extension - **added** — New activity for edited enroll secrets - **changed** — Renamed teams and queries to fleets and reports in the UI, API, CLI, and GitOps - **deprecated** — no-team.yml in GitOps in favor of unassigned.yml - **deprecated** — Certain API field names to reflect the renaming of teams to fleets and queries to reports - **added** — Configurable body size limits for the /api/osquery/log and /api/osquery/distributed/write endpoints - **added** — Ability to specify allowed Entra tenant IDs for enrollments - **changed** — Increased the maximum script execution timeout from 1 hour to 5 hours - **fixed** — Adding Windows Fleet maintained apps failing when a software title with the same upgrade code already exists ##### Fleet 4.82.0 (Mar 11, 2026) ###### IT Admins - Added support for enrolling fully managed Android hosts without a work profile. - Added capability to uninstall Android apps on the device (and removal from self-service in the managed Google Play store) when an app is removed from Fleet. - Added ability to allow or disallow end-users to bypass conditional access on a per-policy basis. - Added filtering by platform and add status to the Software > Add Fleet-maintained apps table. - Updated Android status reports to re-verify profiles that previously failed. - Added ability to roll back to previously added versions of Fleet-maintained apps. - Added new Technician role designed for help desk and IT support teams. Technicians can run scripts, view results, and install or uninstall software. - Added support for JIT provisioning of the Technician role via SSO SAML attributes. - Added automatic retries for failed software operations. ###### Security Engineers - Added ability to scan for kernel vulnerabilities on RHEL based hosts. - Added AWS GovCloud RDS CA certificates to the RDS MySQL TLS bundle, enabling IAM authentication for Fleet deployments connecting to RDS in AWS GovCloud regions (us-gov-east-1, us-gov-west-1). - Added CVE alias for python visual studio code extension. - Added new activity for edited enroll secrets. ###### Other improvements and bug fixes - Renamed teams and queries to fleets and reports in the UI, API, CLI, and GitOps. - Deprecated no-team.yml in GitOps in favor of unassigned.yml. - Deprecated certain API field names to reflect the renaming of "teams" to "fleets" and "queries" to "reports". - Updated Android MDM profiles to show up as pending on upload, the same as Apple MDM profiles. - Improved the speed of a database query that runs every minute to avoid database locking. - Added configurable body size limits for the `/api/osquery/log` and `/api/osquery/distributed/write` endpoints. - Updated logic to trigger vulnerability webhook when on Fleet free tier. - Updated storage of the auth token used in the UI. - Dynamically alphabetized vitals on the host details page. - Reworked how we handle server/worker delays to fix flaky tests. - Disabled "Calendar" dropdown option in Policy > Manage automations for Unassigned. - Added Go slog logging infrastructure and migrated a portion of the code from go-kit/log to slog. - Added CTA to turn on Android MDM for Android software setup experience if MDM is not configured. - Left-aligned "Critical" checkbox in Save policy form. - Improved spacing on the Controls > OS Settings page. - Updated to not allow editing Fleet-maintained app in the UI while GitOps mode is enabled. - Updated to accept the previous device authentication token for up to one rotation cycle, so the My Device page URL remains valid after token refresh. - Updated default macOS, iOS, and iPadOS update deadline time to 7PM (19:00) local time. - Updated UI to enable adding/removing multiple Microsoft Entra tenant ids. - Added additional logging for SCEP proxy requests and SCEP profile renewals. - Added warning message on gitops label rename to clarify to users that renaming a label implies a delete operation. - Added the ability to specify allowed Entra tenant IDs for enrollments. - Updated the DEP syncer to properly reassign a profile when ABM unilaterally removes it. - Increased the maximum script execution timeout from 1 hour (3600 seconds) to 5 hours (18000 seconds). - Improved error handling on AWS DB failover. Fleet will now fail health check if the primary DB is read-only, or trigger graceful shutdown when write operations encounter read-only errors. - Generated a server-side device token in the Okta conditional access flow when none exists or the current token is expired. - Moved the copy button for text areas out of the text area itself and in line with its label. - Removed unnecessary calls to `svc.ds.BulkSetPendingMDMHostProfiles` in `POST /ap _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.82.0]_