# Fleet v4.86.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2026-05-29 - Version: v4.86.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.86.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Add automatic rotation of managed local admin account passwords after they have been viewed - **added** — Add `require_all_software_windows` setting to cancel the Windows setup experience if any software install fails during Autopilot enrollment - **added** — Add GitOps support for uploading custom org logos with `org_logo_path_dark_mode` and `org_logo_path_light_mode` keys - **added** — Add support for installing VPP and in-house apps on iOS and iPadOS hosts enrolled via Account-Driven User Enrollment - **added** — Enable self-service software installs from the My device page for user-enrolled iOS and iPadOS hosts - **added** — Enable setup experience software to install automatically on user-enrolled iOS and iPadOS hosts at enrollment - **added** — Add managed app configuration for iOS and iPadOS apps with `$FLEET_VAR_*` substitution - **added** — Add support for VPP apps purchased from non-US-based Apple Business accounts - **added** — Add ability to upload custom organization logos for light and dark modes hosted by Fleet - **added** — Add `include_all` label scope to policies and `include_all` and `include_any` label scopes to reports - **added** — Add 'Custom' target dropdown when creating or updating reports under the premium tier - **added** — Add 'Include all' option to the 'Custom' target dropdown on Policies for premium users - **added** — Add permissions for the GitOps user to list software titles - **added** — Add support for setting `gitops_mode_enabled` and `repository_url` via GitOps - **added** — Add output to GitOps for scripts indicating how many scripts would be applied or were applied - **added** — Add activity entries for retried software installs and script runs from policy automations - **added** — Add activity when hosts fail enrollment profile renewal - **added** — Add activity entries when users create, edit, or delete labels - **added** — Add 'Hosts online', 'Hosts enrolled', and 'Vulnerability exposure' charts to the dashboard - **added** — Add option to convert and return a PEM-encoded X.509 certificate instead of a PEM-encoded PKCS7 envelope from the Request a Certificate endpoint - **added** — Add macOS 26 CIS Benchmark v1.0.0 - **added** — Add SVG support for custom organization logos with strict server-side sanitization - **added** — Add support for the `subject_alternative_name` field on Android certificate templates - **added** — Release `fleetctl` as a `pkg` for macOS - **added** — Release `fleetctl` as an `msi` for Windows - **changed** — Update CIS Windows 11 Enterprise benchmark policies from v4.0.0 to v5.0.1, adding 17 new L1 policies and updating 42 existing policy titles - **changed** — Update OS version reporting for iOS and iPadOS to include the Rapid Security Response suffix - **changed** — Update fleetd and MDM enroll activities to display the serial number and preserve the osquery-provided display name - **changed** — Update the default automatic enrollment profile and add ability to download and view the applied default profile - **changed** — Update Go to 1.26.3 - **changed** — Improve Windows MDM performance when transferring large numbers of hosts between teams or applying bulk profile changes - **changed** — Add Redis-backed cache for host lookups on the osquery and orbit authentication paths - **deprecated** — Deprecate `setup_experience.software` or `macos_setup.software` keys in config - **deprecated** — Deprecate `GET /api/v1/fleet/commands` without a `host_identifier` - **fixed** — Surface hardware-bound ACME certificates on macOS host vitals by retrieving them via the MDM `CertificateList` command - **fixed** — Optimize OSV vulnerability scanning to query distinct software per OS version rather than per host - **fixed** — Improve vulnerability scanning performance by using a per-vendor product cache during CVE matching - **fixed** — Reduce database load from `GET /api/latest/fleet/device/{token}/desktop` and other Fleet Desktop endpoints when invalid or expired device auth tokens are presented - **fixed** — Remove debug symbols from fleet and fleetctl executables to reduce binary size - **fixed** — Add missing uninstall option on the host software library when an installer has no matching software in the host's inventory - **removed** — Remove `GET /api/v1/fleet/commands` endpoint when called without a `host_identifier` ##### Fleet 4.86.0 (May 29, 2026) ###### IT Admins - Added automatic rotation of managed local admin account passwords after they have been viewed. - Added a `require_all_software_windows` setting to cancel the Windows setup experience if any software install fails during Autopilot enrollment, matching the existing macOS behavior. - Added GitOps support for uploading custom org logos. `fleetctl gitops` accepts `org_logo_path_dark_mode` and `org_logo_path_light_mode` keys to upload local files, and `fleetctl generate-gitops` exports Fleet-hosted logos as local files alongside path keys while keeping external URLs as `org_logo_url_*_mode` keys. - Added support for installing VPP and in-house (`.ipa`) apps on iOS and iPadOS hosts enrolled via Account-Driven User Enrollment with a Managed Apple Account. - Enabled self-service software installs from the My device page for user-enrolled iOS and iPadOS hosts. - Enabled setup experience software in Controls > Setup experience to install automatically on user-enrolled iOS and iPadOS hosts at enrollment. - Provisioned a VPP client user per Managed Apple Account on first install, and associated VPP licenses to the user rather than the device, supporting Apple's up-to-5-devices-per-user licensing semantics. - Added managed app configuration for iOS and iPadOS apps (VPP and in-house), configurable via UI, REST API, and GitOps, with `$FLEET_VAR_*` substitution. - Added support for VPP apps purchased from non-US-based Apple Business accounts. - Added the ability to upload a custom organization logo for light and dark modes, hosted by Fleet, replacing the previous URL-only flow on the setup screen and organization settings page. - Added `include_all` label scope to policies, and `include_all` and `include_any` label scopes to reports, including support via GitOps and `fleetctl`. - Added a "Custom" target dropdown when creating or updating reports under the premium tier. - Added an "Include all" option to the "Custom" target dropdown on Policies for premium users only. - Added permissions for the GitOps user to list software titles. - Added support for setting `gitops_mode_enabled` and `repository_url` via GitOps. - Added output to GitOps for scripts, indicating how many scripts would be applied (dry run) or were applied. - Added activity entries for retried software installs and script runs from policy automations. - Added an activity when hosts fail enrollment profile renewal. - Added activities when users create, edit, or delete labels (`created_label`, `edited_label`, and `deleted_label`). - Added "Hosts online", "Hosts enrolled", and "Vulnerability exposure" charts to the dashboard. - Added an option to convert and return a PEM-encoded X.509 certificate instead of a PEM-encoded PKCS7 envelope from the Request a Certificate endpoint. - Added a deprecation warning when using `setup_experience.software` or `macos_setup.software` keys in config. - Released `fleetctl` as a `pkg` for macOS. - Released `fleetctl` as an `msi` for Windows. - Enabled wiping a host to cancel all of its upcoming activities. - Updated the default automatic enrollment profile, and added the ability to download and view the applied default profile. - Updated OS version reporting for iOS and iPadOS to include the Rapid Security Response suffix (e.g. `(a)`) when the device reports a `SupplementalOSVersionExtra` field via MDM. - Updated fleetd and MDM enroll activities to display the serial number and preserve the osquery-provided display name. - Required the `--host` flag for `fleetctl get mdm-commands`, and deprecated `GET /api/v1/fleet/commands` without a `host_identifier`. - Cleared host vitals on ABM host re-enrollment, with a config option to preserve past host activities. ###### Security Engineers - Added macOS 26 CIS Benchmark v1.0.0. - Updated CIS Windows 11 Enterprise benchmark policies from v4.0.0 to v5.0.1, adding 17 new L1 policies and updating 42 existing policy tit _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.0]_