# Fleet v4.83.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2026-04-01 - Version: v4.83.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.83.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.83.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Added ability to deploy an Android web app via setup experience or self-service - **added** — Added ability to set and manually rotate Mac recovery lock passwords - **added** — Added ability to lock the pre-filled user information for macOS hosts that login via End User Authentication during Setup Experience - **added** — Added automatic retries for failed software installs, excluding VPP apps - **added** — Added retry functionality when adding software installers to Fleet via GitOps - **added** — Added `fleetctl new` command to initialize a GitOps folder - **added** — Added support for `paths:` key under `reports:`, `labels:` and `policies:` in GitOps files - **added** — Added glob support for `configuration_profiles` in GitOps files - **added** — Added support for referencing `.sh` or `.ps1` script files directly in the GitOps `path` field for software packages - **added** — Added `fleet_name` and `fleet_id` columns to hosts CSV export - **added** — Added resend button in the OS settings modal for iOS and iPadOS hosts - **added** — Added patch policies for Fleet-maintained apps that automatically update when the app is updated - **added** — Added support for NDES CA for Windows hosts - **added** — Added vulnerability scanning support for Windows Server 2025 hosts - **added** — Added OTEL instrumentation to Fleet's internal HTTP client - **fixed** — Fixed python package false positives on Ubuntu, such as `python3-setuptools` on Ubuntu 24.04 with version 68.1.2-2ubuntu1.2 - **fixed** — Fixed false positive vulnerabilities for Mattermost Desktop - **changed** — Updated host software library to always allow filtering - **changed** — Improved host search to always match against host email addresses, not only when the query looks like an email - **deprecated** — Deprecated configuration keys `custom_settings`, `macos_settings`, `macos_setup` and `macos_setup_assistant` in favor of `configuration_profiles`, `apple_settings`, `setup_experience` and `apple_setup_assistant` respectively ##### Fleet 4.83.0 (Apr 1, 2026) ###### IT Admins - Added ability to deploy an Android web app via setup experience or self-service. - Added ability to set and manually rotate Mac recovery lock passwords. - Added ability to lock the pre-filled user information for macOS hosts that login via End User Authentication during Setup Experience. - Added automatic retries for failed software installs, excluding VPP apps. - Updated host software library to always allow filtering. - Added retry functionality when adding software installers to Fleet via GitOps. - Added `fleetctl new` command to initialize a GitOps folder. - Added support for `paths:` key under `reports:`, `labels:` and `policies:` in GitOps files. - Added glob support for `configuration_profiles` in GitOps files. - Added support for referencing `.sh` or `.ps1` script files directly in the GitOps `path` field for software packages. - Implemented `webhooks_and_tickets_enabled` flag for policies in GitOps. - Added server config for allowing all Apple MDM declaration types. - Added ability to use `FLEET_JIT_USER_ROLE_FLEET_` as a prefix on SAML attributes. - Added `fleet_name` and `fleet_id` columns to hosts CSV export. - Added resend button in the OS settings modal for iOS and iPadOS hosts. - Added patch policies for Fleet-maintained apps that automatically update when the app is updated. ###### Security Engineers - Added support for NDES CA for Windows hosts. - Added vulnerability scanning support for Windows Server 2025 hosts. - Added OTEL instrumentation to Fleet's internal HTTP client. - Added Content-Type header to Smallstep authorization requests to prevent Cloudflare from blocking them. - Added ability to omit `secrets:` in GitOps files to retain existing enroll secrets on server. - Fixed python package false positives on Ubuntu, such as `python3-setuptools` on Ubuntu 24.04 with version 68.1.2-2ubuntu1.2. - Fixed false positive vulnerabilities for Mattermost Desktop. ###### Other improvements and bug fixes - Most top-level keys can now be omitted from GitOps files in place of supplying them with an empty value. - Improved host search to always match against host email addresses, not only when the query looks like an email. - Prevented a 500 error on the host details page when an MDM command reference in `host_mdm_actions` pointed to a non-existent command (orphan reference). - Allowed Fleet-maintained apps to be added if they have default categories configured that are not available in older builds from this point forward. - Migrated to using Policy `critical` option when disallowing Okta conditional access bypass. - Updated DEP enrollment flow to apply minimum macOS version check when specified. - Updated GitOps to fail runs when unknown keys are detected in files. - Updated default last opened time diff to 2m to increase the chances of updating the last opened time for software that is opened frequently. - Updated the host results endpoint URL to be consistent with the other URLs. - Added tooltip to batch run result host count to clarify that the count might include deleted hosts. - Updated table heading and result filter styles. - Reordered the columns on the Hosts page. - Updated Fleet desktop to surface custom transparency links to the device user. - Changed `PostJSONWithTimeout` to log response body in error case. - Removedd unused and confusingly-named --mdm_apple_scep_signer_allow_renewal_days config. - Refactored `NewActivity` functionality by moving it to the new activity bounded context. - Modified Android certificate renewal logic to make it easier to test. - Optimized `api/latest/fleet/software/titles` endpoint. - Trimmed incoming `ABM` suffix for Arch Linux hosts so Arch OSs are grouped together in the database and UI. - Updated determination process used for selecting which user email address to use when scheduling a maintenance event for a host failing policies. - Added license checks for `fleet-fre _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.83.0]_