Fleet Release Notes

Follow

37 release notes curated from 23 sources by the Releasebot Team. Last updated: Jul 17, 2026

Get this feed:
  • Jul 17, 2026
    • Date parsed from source:
      Jul 17, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    Fleet logo

    Fleet

    orbit-v1.58.0

    Fleet fixes duplicate FDE TPM keyslots not getting caught in a cherry-pick update.

    Cherry-pick #49459: Fix duplicate FDE TPM keyslots not getting caught…

    Original source
  • Jul 16, 2026
    • Date parsed from source:
      Jul 16, 2026
    • First seen by Releasebot:
      Jul 17, 2026
    Fleet logo

    Fleet

    fleet-v4.89.1

    Fleet fixes Windows 11 25H2 MDM enrollment for fresh devices by accepting broader MS-MDE2 discovery RequestVersion values, resolving error 80180006 and improving compatibility with recent builds.

    Bug fixes

    Fixed a bug where fresh Windows 11 25H2 (and other recent builds) failed MDM enrollment with error 80180006 because the device's discovery RequestVersion (e.g. "9.0") was rejected by an exact-match allow-list. Fleet now accepts any MS-MDE2 discovery RequestVersion at or above the minimum supported version ("4.0").

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    72fb53b632048d94a475082050a3fb9ee147c120b90b4bd03407668b0643eb2f fleet_v4.89.1_linux.tar.gz
    5fdccf39237db3c96fa69468539e22c2cd69cfff5a4b147fdbcb5ca22ea1f2be fleetctl_v4.89.1_linux_amd64.tar.gz
    7a2316437e9183cfaf1b18047df6245e8a88b338f8879fbe2ebaf06a39a00cda fleetctl_v4.89.1_linux_amd64.zip
    ff6e4225004fb2db43d5f1f178ea780d82db0925258015a67379d52056aed092 fleetctl_v4.89.1_linux_arm64.tar.gz
    62617b3fec54ccf4d458b1f69ab0d82b91299594e802c9d27f5e3ce61789d5f2 fleetctl_v4.89.1_linux_arm64.zip
    a13f88800e59792af3480feb1ac0e6fe4f63775e87f237b5a47264a5e05f85e6 fleetctl_v4.89.1_macos.tar.gz
    faee6f1383eb9c745c8d225e2d8972b5c51c89b86db68da14e1cc84c641722ba fleetctl_v4.89.1_macos.zip
    e57afa95adbb86592495583fb61f6669d40629dd8ee16aebce426ab3443580c2 fleetctl_v4.89.1_windows_amd64.tar.gz
    1d9a5a250d5367a8252a3eefc016c3d83edfb5a1ef795809a215f6ad84df5948 fleetctl_v4.89.1_windows_amd64.zip
    39d7a5b4fe7533cb696bb6de6da42928801f96315bb98719d9225add5d650263 fleetctl_v4.89.1_windows_arm64.tar.gz
    df97595ce284ccb1ff86e27644ad337ed34af17b12350cefd12a0d4654ec7eb4 fleetctl_v4.89.1_windows_arm64.zip

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Fleet and hundreds of other software products.

    Create account
  • Jul 15, 2026
    • Date parsed from source:
      Jul 15, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    Fleet logo

    Fleet

    v4.89.0

    Fleet adds changes for v4.89.0.

    Adding changes for Fleet v4.89.0 (#48451)

    Original source
  • Jul 15, 2026
    • Date parsed from source:
      Jul 15, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    Fleet logo

    Fleet

    fleet-v4.89.0

    Fleet releases a major platform update with richer policy targeting, faster setup experience workflows, expanded app and vulnerability management, stronger Android and Windows MDM handling, and improved security, performance, and UI polish across the product.

    Fleet 4.89.0 (Jul 15, 2026)

    IT Admins

    Added the ability to target a policy to hosts using a combination of "include" and "exclude" labels.

    Added the ability to run a policy check before installing Windows and Linux setup experience software. When a team policy's install-software automation points at a setup experience installer, Fleet runs that policy during setup and skips the install when it passes (the software is already installed and up to date), speeding up the end user setup experience. When the policy fails, the software is installed as part of setup experience.

    Changed calendar remediation events to be scheduled on the next business day (skipping weekends) after a policy failure, instead of always being scheduled on the next Tuesday.

    Updated policy details page to show automations and labels as a single property. Also changed the layout of policy properties.

    Added automation runs table to the policy details page, showing per-host automation outcomes with filtering, search, and a reset policy action.

    Added per-host activity log entries when policy automations (webhook, tickets, Google Calendar, and Microsoft conditional access) fail or succeed.

    Added POST /api/v1/fleet/policies/:policy_id/reset endpoint to reset a policy's pass/fail results, clearing counts and membership immediately.

    Added GET /api/v1/fleet/policies/:id/automation_activities endpoint to list automation activities for a policy.

    Added the ability to keep Fleet-maintained apps automatically updated to the latest version, pin them to a specific version or major version, or roll back to a previously cached version, from the UI and via GitOps (Fleet Premium).

    Surfaced .sh script-only software packages on the macOS tab of Controls > Setup experience > Install software, with selections tracked independently from the Linux tab.

    Added setup_experience_platform on software packages in GitOps YAML so .sh script-only installers can be selected for the macOS setup experience declaratively, matching the per-platform UI selection. The value is authoritative on every batch apply and reconciles the cross-platform selection table.

    Added support for pre-install query, post-install script, and uninstall script on script-only packages (.sh and .ps1) via the UI, REST API, and GitOps.

    Added an error on the Windows enrollment status page (ESP) when setup experience software fails to install during automatic enrollment (Autopilot and other OOBE flows) and "Cancel setup if software fails" is turned off.

    Added "🛟 Support" as a new default self-service software category.

    Added support for $FLEET_VAR_HOST_* variables in Android configuration profiles.

    Added support for $FLEET_VAR_HOST_* variables in Android managed app configuration.

    Android certificate templates and managed app configurations are now automatically resent when IdP variable values change.

    Added support for defining the default fleet BYO Apple devices enroll into.

    Added a Google Workspace integration that maps identity provider (IdP) users to hosts, populating IdP host vitals directly from your Google Workspace directory.

    Added an activity feed entry when a user runs a custom Apple or Windows MDM command, visible in both the global activity feed and the host's activity feed.

    Added an activity when editing the managed local account setting using the update fleet endpoint or GitOps.

    Enabled tracking of mobile devices for the "hosts online" chart, and added default filtering to that chart that excludes mobile platforms.

    Added tooltips on the Settings > Users and My account pages to show assigned fleets and roles when a user has multiple.

    Security Engineers

    Started collecting non-critical CVEs, filtering them out of charts by default.

    Added the ability to filter vulnerable software by severity (CVSS score) and known exploit status on the Fleet Desktop My device > Software tab (Fleet Premium). The corresponding min_cvss_score, max_cvss_score, and exploit query parameters were added to the GET /device/{token}/software API endpoint.

    Added more filtering options for the Vulnerability Exposure chart.

    Added ability to set default Vulnerability Exposure chart filters via GitOps.

    Improved certificate renewal validation in the host identity SCEP service.

    Added support for all IdP variables and host platform in certificate template subject names and SANs.

    Improved input validation for conditional access SCEP enrollment.

    Validated that a custom SCEP proxy certificate authority challenge contains only printable characters, so Windows certificate enrollment no longer fails with "The string contains a non-printable character" (for example, when the challenge contains an underscore). Existing challenges are only re-validated when changed.

    Restricted authorization for team membership management operations.

    Made authorization more robust when creating labels from manual hosts.

    Improved fleet scope validation for software title lookups.

    Restricted authorization for conditional access Okta IdP asset endpoints so that observer and observer+ roles can no longer read them.

    Improved session handling during password reset flows.

    Cleared the SSO authentication cookie after successful authentication for fully-managed Android enrollment.

    Added private network IP blocking to Fleet's HTTP client. Loopback and cloud metadata addresses (127.0.0.0/8, 169.254.0.0/16) are always blocked. RFC 1918 and other private ranges are blocked by default; use --allow_private_network_integrations to allow them for environments with on-prem integrations (e.g. EJBCA, Jira, SCEP servers on private networks).

    Added the s3.carves_cleanup_disabled server setting to skip S3 file carve reconciliation for deployments that rely solely on the bucket's lifecycle policy to remove carve objects.

    Added the s3.carves_cleanup_max_per_run and s3.carves_cleanup_concurrency server settings to tune how many carves the S3 cleanup reconciles per run and how many concurrent S3 requests it makes.

    Updated the SigNoz OTEL dashboards under tools/signoz/ to template and filter on the deployment.environment resource attribute, with the environment variable defaulting to default, so multiple Fleet environments reporting to the same SigNoz backend can be scoped per environment.

    Bug fixes and improvements

    Updated Go to 1.26.5.

    Updated checkbox labels in the Fleet UI to use positive language, making it clearer what each setting enables rather than what it disables.

    Improved Windows MDM configuration profile performance. Changes to Windows profiles now reach hosts more quickly. Large changes that affect many hosts at once, such as adding or removing profiles across a team or transferring many hosts between teams, now finish faster and put significantly less load on Fleet's database, keeping the server responsive at scale.

    Improved validation on batch script executions.

    Updated golang.org/x/image to v0.42.0 to resolve CVE-2026-33813 (WebP decoder denial of service on 32-bit platforms).

    Redesigned in-app success and error notifications as toasts. Error notifications now persist until dismissed and can be expanded to show the server's raw response.

    Added configurable batch size FLEET_MDM_ANDROID_BATCH_SIZE (default: 1000 hosts) for Android MDM operations to prevent overwhelming the Google Android Management API.

    Added batching and staggered scheduling for Android software installation jobs to spread AMAPI load across multiple worker ticks.

    Improved the error message shown when saving a custom variable without the required server private key configured.

    Improved software tooltips on the host details page to display the human-friendly software name and correct action labels for scripts.

    Improved orbit check-in performance by deriving the Fleet MDM connection state from existing host MDM data instead of running a separate 3-table JOIN query on every check-in for every host.

    Improved fleetctl to detect when SSO is enabled on the Fleet server and display a helpful message directing users to authenticate using an API token instead of email and password.

    Refactored makeAndroidAppAvailable to use staggered job queuing instead of sleeping between batches inside a single worker job.

    Updated the checkerboard graph to make it clearer which square represents the current time and which squares are in the future.

    Windows configuration profiles are now queued immediately when a host enrolls in Windows MDM, instead of waiting for the next profile reconciliation cron pass.

    Improved query validation logic around policy creation.

    Updated the "installed during setup" tooltip on Controls > Setup experience > Install software to clarify that installation order depends on software name (0-9, then A-Z), and that software without a policy is installed before software with a policy.

    Navigate back to the report details page after saving changes to a report.

    Enabled automatic refreshing of report results when the window is refocused and every 5 seconds while waiting for results to arrive (skipped when report caching is disabled).

    Reduced database write pressure on the Windows MDM check-in path by gzip-compressing stored device response envelopes.

    Updated the Fleet-maintained apps item count to reflect the total number of apps, counting an app's macOS and Windows versions separately (for example, a search for "Zoom" that returns Zoom and Zoom Rooms on both platforms shows 4 items).

    Moved and updated tooltip from the Vulnerabilities column on the Software > OS page to "Not supported", explaining which platforms support vulnerability detection.

    Improved some GitOps error messages around bootstrap packages, setup assistant and scripts.

    Fixed fleet-scoped context when retrieving a list of users in a fleet.

    Fixed an issue where cleanup of expired file carves stored in S3 could stall on buckets containing a large number of objects, which prevented other scheduled cleanup and aggregation tasks from running.

    Fixed the MDM command details modal showing a generic error, instead of a clear message, for a command sent to a host that was later wiped and re-enrolled.

    Fixed SAML SSO callback URLs (both login and MDM end user authentication) duplicating the subpath when Fleet is deployed under a URL prefix, which broke authentication. The callback URL is now built so the subpath appears exactly once whether or not the server URL was configured with the prefix.

    Fixed the My device > Self-service page briefly showing the "Update" button again on apps that had just finished updating, instead of holding the "Updated" state while the software inventory refreshes.

    Fixed a bug where selecting a policy on the host details or self-service policies page reset the list back to the first page.

    Fixed a 500 error when a host reported a software install result for a deleted software installer. When an installer is deleted, records of its pending installations will be set to canceled instead of completely deleted.

    Fixed Copied! confirmation badges showing the wrong border color and clipping in dark mode.

    Fixed installers, VPP apps, and in-house apps sometimes missing from a host's software details page when more than one install or uninstall was queued for the same item.

    Fixed a server panic when validating a Windows configuration profile that mixes SCEP and non-SCEP <LocURI> elements with a non-SCEP element first. The profile is now rejected with a clear validation error.

    Fixed a bug where selected hosts could not be removed (the "X" did nothing) on the live report target selection screen.

    Fixed a bug where if a script-only package was provided with spaces in the path name in a GitOps run, it would fail validation.

    Fixed the GitOps mode tooltip on disabled settings fields so it points at the field's label instead of the center of the label, input, and help text.

    Fixed the dashboard "Hosts enrolled" chart showing an incorrect platform percentage breakdown.

    Fixed Windows MDM not re-installing fleetd on a wiped or re-imaged device that re-enrolls through Autopilot/Entra (OOBE). The server previously treated stale host orbit info as proof fleetd was present and skipped the install, leaving the device MDM-enrolled but without fleetd and hanging the Enrollment Status Page; it now re-delivers fleetd when the host has not checked in since the current enrollment.

    Fixed "My device" page to sort software by display name instead of installer filename when a custom display name is set.

    Fixed a bug where running many concurrent live queries that each target a small number of hosts could overload Redis and slow down host check-ins.

    Fixed browser Back button being trapped on the script batch progress and details pages.

    Fixed a bug where all MDM commands in the command list were incorrectly displayed as "custom MDM command". Only commands run via the custom MDM command API now display this label.

    Fixed fleet-mcp run_live_query returning a 403 error for users with the observer+ role. Multi-host live queries now run as an ad-hoc live query campaign (raw SQL, streamed over the results websocket) instead of creating a temporary saved query, so they require only the live-query permission that observer+ already has.

    Fixed GitOps volume_purchasing_program failing when using All fleets for the fleets field.

    Fixed Fleet-maintained apps that share a macOS bundle identifier (for example Firefox and Firefox ESR) so that adding one no longer renames its software title to the other, and no longer shows the other as already added.

    Fixed a generic error in the software install activity modal when using Fleet Free to show a Fleet Premium message instead.

    Fixed an unclear error message that happened when running fleetctl generate-gitops with an existing patch policy for an installer that no longer references a Fleet-maintained app because it was deleted from the catalog.

    Fixed the configuration profiles batch endpoint timing out when removing many Windows profiles from a team with a large number of hosts. Deleting Windows profiles (including clearing a team's profiles via GitOps, deleting individual profiles, and deleting a team) now returns quickly and the profiles are removed from hosts in the background by Fleet, the same way profile changes are already delivered.

    Fixed the policy and report details pages briefly showing the previously-viewed policy/report's content when navigating between them.

    Fixed horizontal scrollbar showing up when there is nothing to scroll in report and policy results tables.

    Fixed an issue where Windows and Linux hosts that had already enrolled were prompted for end user authentication (an SSO browser tab) when fleetd re-enrolled after a service restart. Re-enrollment of an already-enrolled host no longer requires end user authentication; only genuinely new devices are prompted.

    Fixed a bug where adding a script-only package via path in GitOps made fleetctl generate-gitops produce an invalid file.

    Fixed an issue where Missing hosts filter and dashboard card incorrectly reported iOS, iPadOS, and Android hosts.

    Fixed password reset, user invite, MFA login, change-email confirmation, and SMTP test emails to no longer duplicate the URL prefix in their links when Fleet is deployed under a subpath.

    Fixed software title details pages timing out for installers, VPP apps, and in-house apps with a large backlog of pending host activities.

    Fixed macOS configuration profiles getting stuck in "Verifying" when a host reported a profile install date in a 12-hour time format.

    Fixed the Fleet-maintained apps list being cut off so that apps near the end of the alphabet were unreachable. The list is now paginated (100 apps per page), and the platform and "Hide added apps" filters are applied across the full library instead of only the loaded apps.

    Fixed GitOps relative path lookup for controls.setup_experience.(apple_setup_assistant, macos_script, software.package_path) in unassigned.yml, and org_logo_paths under org_settings.

    Fixed a bug where a script executed in a scheduled batch would still execute on hosts that had been transferred to a different fleet between the time the batch was scheduled and the time it later executed

    Fixed a bug where the MDM command results endpoint might not return hostnames for all returned hosts

    Fixed the activity feed showing a focus outline when an activity was clicked. The outline now appears only when tabbing to an activity with the keyboard, matching the focus behavior used elsewhere in the UI.

    Fixed the agent settings YAML editor (global and fleet-level) hiding command_line_flags behind a comment when set to {} or null. Those values now render as-is, since they have special semantics (they clear all local osquery flags on hosts).

    Fixed "Select all matching hosts" to display the actual total host count instead of "50+" in both the hosts table header and the delete hosts modal.

    Fixed an issue where the macOS "Update new hosts to latest" OS update setting could stay enabled in GitOps after minimum_version and deadline were cleared; when update_new_hosts isn't explicitly set, it now defaults to enabled only while a minimum version and deadline are configured.

    Fixed an issue where more than 8 entries for OS versions would not be paginated.

    Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade.

    Fleet's agent

    The following version of Fleet's agent (fleetd) support the latest changes to Fleet:

    • orbit-v1.57.0
    • fleet-desktop-v1.57.0 (included with Orbit)
    • osquery-5.23.1 (included with Orbit)
    • fleetd-chrome-v1.3.5
    • fleetd-android-v1.5.0

    While newer versions of fleetd still function with older versions of Fleet, old versions of fleetd and osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet.

    Upgrading

    Please visit our upgrade guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    d715f4992d2769d7ab52647913598d454a7421d1db9f00ec4a1d1df453ca1723 fleet_v4.89.0_linux.tar.gz

    e77bee9862c630620ec17ace9cb4b0a206464c3dbe8e5e87098a0af5e850eea7 fleetctl_v4.89.0_linux_amd64.tar.gz

    a742a0dcc7d9d4b9018efc762ec296b0549c8b27ac973d46878fb41bb2c863d0 fleetctl_v4.89.0_linux_amd64.zip

    ed576fc4a644d31c1ea2ae439b43b7b91b1231d514d43235a85fd415bae7a266 fleetctl_v4.89.0_linux_arm64.tar.gz

    4bed2143c01a7ee0c77f71ba949a241d4d9d63555cdde5e0b8dcc03d566f5a7b fleetctl_v4.89.0_linux_arm64.zip

    acad49ecf66fbfe660951052011e902f4e5188fc069950f1c6405e794f1303e0 fleetctl_v4.89.0_macos.tar.gz

    c413a5d40b6f2183cc4791b14ed3e8fc7afc8223714c24b2788ab78edb6e4c67 fleetctl_v4.89.0_macos.zip

    c7485e2a5f50483482353461036f429048b6395b2b8e1e0dab44a451a5471a69 fleetctl_v4.89.0_windows_amd64.tar.gz

    1a8d686eae85afc63fe2c2323ccf6790b05b9e8f0d4bad3dfd3d340f19b65962 fleetctl_v4.89.0_windows_amd64.zip

    1a905eeaa14f3c9aa9799024b3870b5736691c4995076558da2fa6bccff5a996 fleetctl_v4.89.0_windows_arm64.tar.gz

    0943d521c18861abd37d6afe3c528074bcf86a89934e0c33ab14f5e5adb706d8 fleetctl_v4.89.0_windows_arm64.zip

    Original source
  • Jul 15, 2026
    • Date parsed from source:
      Jul 15, 2026
    • First seen by Releasebot:
      Jul 16, 2026
    Fleet logo

    Fleet

    Fleet 4.89.0 | Windows setup experience improvements, Android variables everywhere, and more...

    Fleet releases 4.89.0 with bigger setup, app, and security management across Windows, Android, iOS, and macOS. The update adds smoother enrollment, stronger policy and vulnerability visibility, more flexible script-only packages, and tighter control over Fleet-maintained apps, with many performance and reliability fixes.

    Highlights

    • Windows setup experience: continue past a failed install
    • Android: host vital variables everywhere
    • Default fleet for BYOD iOS/iPadOS enrollment
    • Auto-update, pin, and roll back Fleet-maintained apps
    • Filter and save the vulnerability exposure chart
    • Policy status page
    • Script-only packages: pre-install query, post-install, and uninstall scripts
    • IdP host vitals from Google Workspace

    Windows setup experience: continue past a failed install

    Available in Fleet Premium

    When required setup software fails to install during Windows automatic enrollment (Autopilot or non-Autopilot), end users now see exactly which software failed. If the IT admin hasn't checked Cancel setup if software fails, the end user can continue past the failure and install the missing software later from self-service. If that option is checked, setup stops and the end user is told to reset the device and try again. Either way, end users get a clear next step instead of a stuck setup screen, which means fewer support tickets for IT admins.

    GitHub issue: #45948

    Android: host vital variables everywhere

    IT admins can now use any host vital variable ($FLEET_VAR_HOST_), like a host's UUID or the end user's IdP email, in Android configuration profiles, certificate templates, and managed app configuration. This makes it possible to deploy a host-specific value as part of an app's configuration, for example, passing a host's UUID to Duo as a trusted endpoint identifier, or a user's email as the identity for EAP-TLS Wi-Fi authentication. For certificates, Fleet also detects when a host vital variable's value changes and automatically resends the certificate so it stays accurate. See all host vital variables in the built-in variables guide.

    GitHub issues: #45353, #41968, #37406

    Default fleet for BYOD iOS/iPadOS enrollment

    IT admins can now choose a default fleet for iOS and iPadOS hosts that enroll via Account-driven User Enrollment (BYOD). This means personal iPhones and iPads automatically land in the right fleet on enrollment, so they get the correct configuration profiles and software without an admin having to move them manually.

    GitHub issue: #30871

    Auto-update, pin, and roll back Fleet-maintained apps

    Available in Fleet Premium

    IT admins can now control exactly which version of a Fleet-maintained app their hosts run. Pin a Fleet-maintained app to a specific version to stop it from auto-updating, or roll back to the previous version if a new release causes problems, all from the software title's page. If you're relying on auto-update, Fleet checks for new versions hourly, so hosts stay current without an IT admin re-adding the app.

    GitHub issue: #38504

    Filter and save the vulnerability exposure chart

    Available in Fleet Premium

    Security Engineers can now filter the vulnerability exposure chart by software category (operating system, browsers, Microsoft Office, or Adobe apps), EPSS exploit probability, known active exploits (CISA KEV), and specific CVEs to exclude, so the chart reflects the risk registry they actually track instead of every vulnerability Fleet detects. These default filters can now be set and persisted via GitOps (YAML), so they load automatically the next time the chart opens. Filters changed directly in the Fleet UI aren't saved, whether GitOps mode is on or off.

    GitHub issues: #44746, #47327

    Policy status page

    IT admins get a historical view of policy automation runs: pass/fail status for every host, alongside the output of the software install or script run that the automation triggered. This makes it much faster to troubleshoot a host that keeps failing a policy, since admins no longer have to dig through separate activity logs to piece together what happened.

    GitHub issue: #38670

    Script-only packages: pre-install query, post-install, and uninstall scripts

    Available in Fleet Premium

    IT admins can now add a pre-install query, a post-install script, and an uninstall script to script-only software packages, matching the behavior already available for custom packages. This means script-only packages can now offer an uninstall option and the same install verification other packages already have.

    GitHub issue: #42797

    IdP host vitals from Google Workspace

    Available in Fleet Premium

    Fleet users who use Google Workspace (GW) as their identity provider (IdP) can now populate IdP host vitals (group, department, username, email, and full name) directly from GW, without building a custom integration. Since Google Workspace doesn't support the SCIM protocol, Fleet pulls directory data from Google's API on a schedule. Once connected, IT admins can scope configuration profiles, software, and policies using IdP host vital labels, the same way they would with an Okta or Entra SCIM integration.

    GitHub issue: #42915

    Changes

    IT Admins

    • Added the ability to target a policy to hosts using a combination of "include" and "exclude" labels.
    • Added the ability to run a policy check before installing Windows and Linux setup experience software. When a team policy's install-software automation points at a setup experience installer, Fleet runs that policy during setup and skips the install when it passes (the software is already installed and up to date), speeding up the end user setup experience. When the policy fails, the software is installed as part of setup experience.
    • Changed calendar remediation events to be scheduled on the next business day (skipping weekends) after a policy failure, instead of always being scheduled on the next Tuesday.
    • Updated policy details page to show automations and labels as a single property. Also changed the layout of policy properties.
    • Added automation runs table to the policy details page, showing per-host automation outcomes with filtering, search, and a reset policy action.
    • Added per-host activity log entries when policy automations (webhook, tickets, Google Calendar, and Microsoft conditional access) fail or succeed.
    • Added POST /api/v1/fleet/policies/:policy_id/reset endpoint to reset a policy's pass/fail results, clearing counts and membership immediately.
    • Added GET /api/v1/fleet/policies/:id/automation_activities endpoint to list automation activities for a policy.
    • Added the ability to keep Fleet-maintained apps automatically updated to the latest version, pin them to a specific version or major version, or roll back to a previously cached version, from the UI and via GitOps (Fleet Premium).
    • Surfaced .sh script-only software packages on the macOS tab of Controls > Setup experience > Install software, with selections tracked independently from the Linux tab.
    • Added setup_experience_platform on software packages in GitOps YAML so .sh script-only installers can be selected for the macOS setup experience declaratively, matching the per-platform UI selection. The value is authoritative on every batch apply and reconciles the cross-platform selection table.
    • Added support for pre-install query, post-install script, and uninstall script on script-only packages (.sh and .ps1) via the UI, REST API, and GitOps.
    • Added an error on the Windows enrollment status page (ESP) when setup experience software fails to install during automatic enrollment (Autopilot and other OOBE flows) and "Cancel setup if software fails" is turned off.
    • Added "🛟 Support" as a new default self-service software category.
    • Added support for $FLEET_VAR_HOST_* variables in Android configuration profiles.
    • Added support for $FLEET_VAR_HOST_* variables in Android managed app configuration.
    • Android certificate templates and managed app configurations are now automatically resent when IdP variable values change.
    • Added support for defining the default fleet BYO Apple devices enroll into.
    • Added a Google Workspace integration that maps identity provider (IdP) users to hosts, populating IdP host vitals directly from your Google Workspace directory.
    • Added an activity feed entry when a user runs a custom Apple or Windows MDM command, visible in both the global activity feed and the host's activity feed.
    • Added an activity when editing the managed local account setting using the update fleet endpoint or GitOps.
    • Enabled tracking of mobile devices for the "hosts online" chart, and added default filtering to that chart that excludes mobile platforms.
    • Added tooltips on the Settings > Users and My account pages to show assigned fleets and roles when a user has multiple.

    Security Engineers

    • Started collecting non-critical CVEs, filtering them out of charts by default.
    • Added the ability to filter vulnerable software by severity (CVSS score) and known exploit status on the Fleet Desktop My device > Software tab (Fleet Premium). The corresponding min_cvss_score, max_cvss_score, and exploit query parameters were added to the GET /device/{token}/software API endpoint.
    • Added more filtering options for the Vulnerability Exposure chart.
    • Added ability to set default Vulnerability Exposure chart filters via GitOps.
    • Improved certificate renewal validation in the host identity SCEP service.
    • Added support for all IdP variables and host platform in certificate template subject names and SANs.
    • Improved input validation for conditional access SCEP enrollment.
    • Validated that a custom SCEP proxy certificate authority challenge contains only printable characters, so Windows certificate enrollment no longer fails with "The string contains a non-printable character" (for example, when the challenge contains an underscore). Existing challenges are only re-validated when changed.
    • Restricted authorization for team membership management operations.
    • Made authorization more robust when creating labels from manual hosts.
    • Improved fleet scope validation for software title lookups.
    • Restricted authorization for conditional access Okta IdP asset endpoints so that observer and observer+ roles can no longer read them.
    • Improved session handling during password reset flows.
    • Cleared the SSO authentication cookie after successful authentication for fully-managed Android enrollment.
    • Added private network IP blocking to Fleet's HTTP client. Loopback and cloud metadata addresses (127.0.0.0/8, 169.254.0.0/16) are always blocked. RFC 1918 and other private ranges are blocked by default; use --allow_private_network_integrations to allow them for environments with on-prem integrations (e.g. EJBCA, Jira, SCEP servers on private networks).
    • Added the s3.carves_cleanup_disabled server setting to skip S3 file carve reconciliation for deployments that rely solely on the bucket's lifecycle policy to remove carve objects.
    • Added the s3.carves_cleanup_max_per_run and s3.carves_cleanup_concurrency server settings to tune how many carves the S3 cleanup reconciles per run and how many concurrent S3 requests it makes.
    • Updated the SigNoz OTEL dashboards under tools/signoz/ to template and filter on the deployment.environment resource attribute, with the environment variable defaulting to default, so multiple Fleet environments reporting to the same SigNoz backend can be scoped per environment.

    Bug fixes and improvements

    • Updated Go to 1.26.5.
    • Updated checkbox labels in the Fleet UI to use positive language, making it clearer what each setting enables rather than what it disables.
    • Improved Windows MDM configuration profile performance. Changes to Windows profiles now reach hosts more quickly. Large changes that affect many hosts at once, such as adding or removing profiles across a team or transferring many hosts between teams, now finish faster and put significantly less load on Fleet's database, keeping the server responsive at scale.
    • Improved validation on batch script executions.
    • Updated golang.org/x/image to v0.42.0 to resolve CVE-2026-33813 (WebP decoder denial of service on 32-bit platforms).
    • Redesigned in-app success and error notifications as toasts. Error notifications now persist until dismissed and can be expanded to show the server's raw response.
    • Added configurable batch size FLEET_MDM_ANDROID_BATCH_SIZE (default: 1000 hosts) for Android MDM operations to prevent overwhelming the Google Android Management API.
    • Added batching and staggered scheduling for Android software installation jobs to spread AMAPI load across multiple worker ticks.
    • Improved the error message shown when saving a custom variable without the required server private key configured.
    • Improved software tooltips on the host details page to display the human-friendly software name and correct action labels for scripts.
    • Improved orbit check-in performance by deriving the Fleet MDM connection state from existing host MDM data instead of running a separate 3-table JOIN query on every check-in for every host.
    • Improved fleetctl to detect when SSO is enabled on the Fleet server and display a helpful message directing users to authenticate using an API token instead of email and password.
    • Refactored makeAndroidAppAvailable to use staggered job queuing instead of sleeping between batches inside a single worker job.
    • Updated the checkerboard graph to make it clearer which square represents the current time and which squares are in the future.
    • Windows configuration profiles are now queued immediately when a host enrolls in Windows MDM, instead of waiting for the next profile reconciliation cron pass.
    • Improved query validation logic around policy creation.
    • Updated the "installed during setup" tooltip on Controls > Setup experience > Install software to clarify that installation order depends on software name (0-9, then A-Z), and that software without a policy is installed before software with a policy.
    • Navigate back to the report details page after saving changes to a report.
    • Enabled automatic refreshing of report results when the window is refocused and every 5 seconds while waiting for results to arrive (skipped when report caching is disabled).
    • Reduced database write pressure on the Windows MDM check-in path by gzip-compressing stored device response envelopes.
    • Updated the Fleet-maintained apps item count to reflect the total number of apps, counting an app's macOS and Windows versions separately (for example, a search for "Zoom" that returns Zoom and Zoom Rooms on both platforms shows 4 items).
    • Moved and updated tooltip from the Vulnerabilities column on the Software > OS page to "Not supported", explaining which platforms support vulnerability detection.
    • Improved some GitOps error messages around bootstrap packages, setup assistant and scripts.
    • Fixed fleet-scoped context when retrieving a list of users in a fleet.
    • Fixed an issue where cleanup of expired file carves stored in S3 could stall on buckets containing a large number of objects, which prevented other scheduled cleanup and aggregation tasks from running.
    • Fixed the MDM command details modal showing a generic error, instead of a clear message, for a command sent to a host that was later wiped and re-enrolled.
    • Fixed SAML SSO callback URLs (both login and MDM end user authentication) duplicating the subpath when Fleet is deployed under a URL prefix, which broke authentication. The callback URL is now built so the subpath appears exactly once whether or not the server URL was configured with the prefix.
    • Fixed the My device > Self-service page briefly showing the "Update" button again on apps that had just finished updating, instead of holding the "Updated" state while the software inventory refreshes.
    • Fixed a bug where selecting a policy on the host details or self-service policies page reset the list back to the first page.
    • Fixed a 500 error when a host reported a software install result for a deleted software installer. When an installer is deleted, records of its pending installations will be set to canceled instead of completely deleted.
    • Fixed Copied! confirmation badges showing the wrong border color and clipping in dark mode.
    • Fixed installers, VPP apps, and in-house apps sometimes missing from a host's software details page when more than one install or uninstall was queued for the same item.
    • Fixed a server panic when validating a Windows configuration profile that mixes SCEP and non-SCEP elements with a non-SCEP element first. The profile is now rejected with a clear validation error.
    • Fixed a bug where selected hosts could not be removed (the "X" did nothing) on the live report target selection screen.
    • Fixed a bug where if a script-only package was provided with spaces in the path name in a GitOps run, it would fail validation.
    • Fixed the GitOps mode tooltip on disabled settings fields so it points at the field's label instead of the center of the label, input, and help text.
    • Fixed the dashboard "Hosts enrolled" chart showing an incorrect platform percentage breakdown.
    • Fixed Windows MDM not re-installing fleetd on a wiped or re-imaged device that re-enrolls through Autopilot/Entra (OOBE). The server previously treated stale host orbit info as proof fleetd was present and skipped the install, leaving the device MDM-enrolled but without fleetd and hanging the Enrollment Status Page; it now re-delivers fleetd when the host has not checked in since the current enrollment.
    • Fixed "My device" page to sort software by display name instead of installer filename when a custom display name is set.
    • Fixed a bug where running many concurrent live queries that each target a small number of hosts could overload Redis and slow down host check-ins.
    • Fixed browser Back button being trapped on the script batch progress and details pages.
    • Fixed a bug where all MDM commands in the command list were incorrectly displayed as "custom MDM command". Only commands run via the custom MDM command API now display this label.
    • Fixed fleet-mcp run_live_query returning a 403 error for users with the observer+ role. Multi-host live queries now run as an ad-hoc live query campaign (raw SQL, streamed over the results websocket) instead of creating a temporary saved query, so they require only the live-query permission that observer+ already has.
    • Fixed GitOps volume_purchasing_program failing when using All fleets for the fleets field.
    • Fixed Fleet-maintained apps that share a macOS bundle identifier (for example Firefox and Firefox ESR) so that adding one no longer renames its software title to the other, and no longer shows the other as already added.
    • Fixed a generic error in the software install activity modal when using Fleet Free to show a Fleet Premium message instead.
    • Fixed an unclear error message that happened when running fleetctl generate-gitops with an existing patch policy for an installer that no longer references a Fleet-maintained app because it was deleted from the catalog.
    • Fixed the configuration profiles batch endpoint timing out when removing many Windows profiles from a team with a large number of hosts. Deleting Windows profiles (including clearing a team's profiles via GitOps, deleting individual profiles, and deleting a team) now returns quickly and the profiles are removed from hosts in the background by Fleet, the same way profile changes are already delivered.
    • Fixed the policy and report details pages briefly showing the previously-viewed policy/report's content when navigating between them.
    • Fixed horizontal scrollbar showing up when there is nothing to scroll in report and policy results tables.
    • Fixed an issue where Windows and Linux hosts that had already enrolled were prompted for end user authentication (an SSO browser tab) when fleetd re-enrolled after a service restart. Re-enrollment of an already-enrolled host no longer requires end user authentication; only genuinely new devices are prompted.
    • Fixed a bug where adding a script-only package via path in GitOps made fleetctl generate-gitops produce an invalid file.
    • Fixed an issue where Missing hosts filter and dashboard card incorrectly reported iOS, iPadOS, and Android hosts.
    • Fixed password reset, user invite, MFA login, change-email confirmation, and SMTP test emails to no longer duplicate the URL prefix in their links when Fleet is deployed under a subpath.
    • Fixed software title details pages timing out for installers, VPP apps, and in-house apps with a large backlog of pending host activities.
    • Fixed macOS configuration profiles getting stuck in "Verifying" when a host reported a profile install date in a 12-hour time format.
    • Fixed the Fleet-maintained apps list being cut off so that apps near the end of the alphabet were unreachable. The list is now paginated (100 apps per page), and the platform and "Hide added apps" filters are applied across the full library instead of only the loaded apps.
    • Fixed GitOps relative path lookup for controls.setup_experience.(apple_setup_assistant, macos_script, software.package_path) in unassigned.yml, and org_logo_paths under org_settings.
    • Fixed a bug where a script executed in a scheduled batch would still execute on hosts that had been transferred to a different fleet between the time the batch was scheduled and the time it later executed
    • Fixed a bug where the MDM command results endpoint might not return hostnames for all returned hosts
    • Fixed the activity feed showing a focus outline when an activity was clicked. The outline now appears only when tabbing to an activity with the keyboard, matching the focus behavior used elsewhere in the UI.
    • Fixed the agent settings YAML editor (global and fleet-level) hiding command_line_flags behind a comment when set to {} or null. Those values now render as-is, since they have special semantics (they clear all local osquery flags on hosts).
    • Fixed "Select all matching hosts" to display the actual total host count instead of "50+" in both the hosts table header and the delete hosts modal.
    • Fixed an issue where the macOS "Update new hosts to latest" OS update setting could stay enabled in GitOps after minimum_version and deadline were cleared; when update_new_hosts isn't explicitly set, it now defaults to enabled only while a minimum version and deadline are configured.
    • Fixed an issue where more than 8 entries for OS versions would not be paginated.

    Ready to upgrade?

    Visit our Upgrade guide in the Fleet docs to update to Fleet 4.89.0.

    Manage all your devices like it's 2026

    Open MDM, patching, and vuln management for every OS.

    Read case studies

    Try it yourself

    Original source
  • Similar to Fleet with recent updates:

  • Jul 10, 2026
    • Date parsed from source:
      Jul 10, 2026
    • First seen by Releasebot:
      Jul 11, 2026
    Fleet logo

    Fleet

    fleet-v4.88.1

    Fleet fixes several BYOD and enrollment bugs, including duplicate configuration profile enqueueing, recovery lock issues on personally owned macOS hosts, persisted BYOD selection after IdP authentication, and failed App Store or in-house app installs on manual BYOD iOS and iPadOS enrollments.

    Bug fixes

    Fixed an issue where a configuration profile could be enqueued multiple times for a single host.

    Fixed recovery lock password being enforced on personally-owned (BYOD) macOS hosts, where it would always fail because personal enrollments have device lock rights stripped. These hosts are now skipped.

    Fixed a bug where a user's BYOD selection was not persisted through IdP authentication

    Fixed a bug where installing App Store (VPP) or in-house apps on an iOS/iPadOS host enrolled with the manual (profile-driven) BYOD enrollment profile failed while trying to look up a VPP user. These device-channel hosts now install apps to the device, the same as company-owned manual enrollment; user-scoped licensing is reserved for Account-Driven User Enrollment.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    1adc9236a16edfdbaa321b3abcbea8fd93354bf348aa1984f1dbf41929f837be fleet_v4.88.1_linux.tar.gz
    c0e6db9c7559487036572a292c8a4acb586fa041524d4e59d76730b4932a7375 fleetctl_v4.88.1_linux_amd64.tar.gz
    3396a776f736513f511c7e8486838c0a4d6548d42329b66967d5abe33d8d1616 fleetctl_v4.88.1_linux_amd64.zip
    6587d56fa84b8b93a25bc26551c86170de61a3ff00f7ad2745b841522fb9cff9 fleetctl_v4.88.1_linux_arm64.tar.gz
    b79a62d090d562fd223b6674a9393f7276b5735fbae38ea5438927ba7a21554e fleetctl_v4.88.1_linux_arm64.zip
    c308cce437f2cca7b24e27aa3501f8da5b072192f31ab68bd763dd33de7facad fleetctl_v4.88.1_macos.tar.gz
    18256e18353febc7205cdaf5512ea820af282c0993ab8908704ee7a958814887 fleetctl_v4.88.1_macos.zip
    b6028f87ca1c9f0302f0c8fa496de8f36afb06aab5838131befede5b20d95e93 fleetctl_v4.88.1_windows_amd64.tar.gz
    6d67da0f5a97310abfd5772876d6baabe110bc8219e49e08cbea674f8086e60c fleetctl_v4.88.1_windows_amd64.zip
    ff8334a6c8527a7d9ae069492aecf67403197ef4761e99c5526038adf39cc202 fleetctl_v4.88.1_windows_arm64.tar.gz
    04db52fdd300cc55ffa94e84163551c0d8777414652ae995ab56fed778d1d873 fleetctl_v4.88.1_windows_arm64.zip

    Original source
  • Jul 9, 2026
    • Date parsed from source:
      Jul 9, 2026
    • First seen by Releasebot:
      Jul 11, 2026
    Fleet logo

    Fleet

    v4.88.1

    Fleet adds changes for v4.88.1.

    Adding changes for Fleet v4.88.1 (#49037)

    Original source
  • Jul 2, 2026
    • Date parsed from source:
      Jul 2, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    fleet-v4.88.0

    Fleet adds bug fixes for Apple and Windows MDM enrollment, including BYOD Apple support with per-host permissions that protect personal devices from remote wipe or lock, plus a fix for fleetd install issues that could stall Windows Autopilot enrollment.

    Bug fixes

    Added support for personal (BYOD) Apple MDM enrollment, tracking per-host enrollment permissions so that personal devices cannot be remotely wiped or locked, and preserving those permissions across SCEP/ACME certificate renewal.

    Fixed an issue where fleetd could intermittently fail to install during Windows MDM enrollment, which could cause the Windows Autopilot Enrollment Status Page to hang.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    85280edd8db7ad2212ba5456997cfacdfeeabaf5b6124732f6fb95df45324163 fleet_v4.88.0_linux.tar.gz

    847f9bfee46cd8a2f637975efbb4e8b5b2a5ed290af3759361721a4623338631 fleetctl_v4.88.0_linux_amd64.tar.gz

    8698436ad196fb0542705d9a1872f7f45a3804e40d87d5e66d889e5def928d73 fleetctl_v4.88.0_linux_amd64.zip

    80d52c9b38960a6ddbaf9e6b1545f2aba24210e5c9274efe716eaf7ec33183a5 fleetctl_v4.88.0_linux_arm64.tar.gz

    e2be3aa46de32dbde7e998ebf4ccf807021dec2468242f22f1efdd77e1f2014a fleetctl_v4.88.0_linux_arm64.zip

    e6cd3e2e28c955a9f64c8f12c50e1e78935b7a30dac0f9253726725633f19b5d fleetctl_v4.88.0_macos.tar.gz

    f192245fde09f6f9a2a14c34d443114104f55ec93841ec330d6149845b9a8794 fleetctl_v4.88.0_macos.zip

    3a113fdf800011ce006a1c68c00f039eaab5d3546c64d21b4bb02209391f55ff fleetctl_v4.88.0_windows_amd64.tar.gz

    109eda99ba889f9aa2d3e676748158cdacfa759125f8484817035beeae42a950 fleetctl_v4.88.0_windows_amd64.zip

    5b370cc2d208ce752b073fc11e24f77ad02294881b8ad01fc7ac6f4bc9518860 fleetctl_v4.88.0_windows_arm64.tar.gz

    4d029140b782793f5051068129410decfb19d819fb41f83880dccc2ee8304596 fleetctl_v4.88.0_windows_arm64.zip

    Original source
  • Jul 1, 2026
    • Date parsed from source:
      Jul 1, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    v4.88.0: For 4.88 RC: Fix S3 file carve cleanup hang and rework reconciliation

    Fleet ships cherry pick #48561.

    Cherry picks #48561

    Original source
  • Jun 27, 2026
    • Date parsed from source:
      Jun 27, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    fleet-v4.87.1

    Fleet fixes Apple SCEP profile retry handling, GitOps duplicate-entry errors in software categories, and a URL pagination bug in My device > Software, bringing cleaner behavior across certificates, GitOps, and device software views.

    Bug fixes

    Fixed a bug where an Apple SCEP certificate profile backed by NDES could be marked "failed" and consume one of the host's limited profile retry attempts when its challenge password expired, instead of being automatically resent with a fresh challenge.

    Fixed GitOps runs failing with a software_categories duplicate-entry error when a software category's name differed only by characters MySQL's collation treats as equal (such as the Unicode variation selector in default categories like "🖥️ Productivity").

    Fixed the My device > Software tab appending a macos_applications query parameter to the URL when paginating, even though that page has no /Applications filter.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    f2d4e41a21bb117adf090a5803866214ce976880fab0343252b8396d722c8447 fleet_v4.87.1_linux.tar.gz
    36adc7723f4b03eea01b287f1235010d036d7aa724dc6b1549150c43ce53c04d fleetctl_v4.87.1_linux_amd64.tar.gz
    c16fc64a4d82176d1f81eb3031024669a2c94f12a49eb2de081b9ca79986e399 fleetctl_v4.87.1_linux_amd64.zip
    634d314705e9f081a4a35c2eed0b689234b5883a18c88f2ca6129a251e685d43 fleetctl_v4.87.1_linux_arm64.tar.gz
    14bdf0e98f40e2620055cbf35dc7d2d2e51335a215a56290b74d1f4a5f162e25 fleetctl_v4.87.1_linux_arm64.zip
    a050f589a44152138527e42d0f2727f2f193eff3c9888f21805e6591b66ba14c fleetctl_v4.87.1_macos.tar.gz
    1901517bb3b62293c1666289795bd04438d43d0817a770a8e2655714c1300dc1 fleetctl_v4.87.1_macos.zip
    f1b86d55d567e56168b5760231aec16d1a7f3b6481bd077bdf96044e286958f5 fleetctl_v4.87.1_windows_amd64.tar.gz
    8bd5baa2ef829926b6539e935bdd34562018c640a28e53bdb14fcbf591b11db5 fleetctl_v4.87.1_windows_amd64.zip
    3fdccd663a6facd8b6dcd79d43c576b108090e7dcab9d00b8b3ffcd465781384 fleetctl_v4.87.1_windows_arm64.tar.gz
    08df1022f8fbd6b58995729697c6d520d7bda89253898f28ce405fcf169b4994 fleetctl_v4.87.1_windows_arm64.zip

    Original source
  • Jun 26, 2026
    • Date parsed from source:
      Jun 26, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    v4.87.1

    Fleet adds changes for Fleet v4.87.1.

    Adding changes for Fleet v4.87.1 (#48290)

    Original source
  • Jun 23, 2026
    • Date parsed from source:
      Jun 23, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    orbit-v1.57.0

    Fleet reverts its initial TPM-backed disk encryption support.

    Revert "Initial pass on TPM-backed disk encryption support (#46457)"

    Original source
  • Jun 20, 2026
    • Date parsed from source:
      Jun 20, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    v4.87.0

    Fleet adds changes for v4.87.0.

    Adding changes for Fleet v4.87.0 (#47109)

    Original source
  • Jun 20, 2026
    • Date parsed from source:
      Jun 20, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    fleet-v4.87.0

    Fleet releases a major platform update with hundreds of new Windows and macOS managed apps, stronger Android and Apple device controls, custom OS update profiles, Fleet Spotlight, technician fleet transfers, and broad performance, security, and reliability improvements.

    Fleet 4.87.0 (Jun 19, 2026)

    IT Admins

    Added 236 new Fleet-maintained apps for Windows, including Microsoft Office, PowerShell, PowerToys, Power BI, Power Automate, SQL Server Management Studio, Microsoft .NET Runtime 8 and 10, Git, Node.js, Python 3.13 and 3.14, PostgreSQL 15–18, Windsurf, Kiro, Dell Command Update, Lenovo Dock Manager, Nessus Agent, Bitwarden, Canva, Miro, Snagit, Tableau Desktop, VirtualBox, TortoiseGit, GitHub Desktop, and more.

    Added 727 new Fleet-maintained apps for macOS, including Kiro, Codex, OpenCode, Claude DevTools, Granola, Logitune, and hundreds more tools across development, security, productivity, and design.

    Added the ability to deploy custom OS update configuration profiles for Apple and Windows.

    Added support for issuing Lock, Wipe, and Clear passcode commands to Android hosts. Lock and Clear passcode work for both BYO (personal) and COBO (company-owned) Android hosts; Wipe is COBO-only. For BYO hosts, Unenroll now issues an AMAPI WIPE under the hood, which removes only the work profile and leaves personal data intact. All Android commands are issued with duration=315360000s (10 years), matching the pending-forever queue semantics Fleet uses for Apple and Windows MDM.

    Made the Wipe command available to Fleet Free users for Android (company-owned) hosts, in both the UI and the API. Wipe for macOS, iOS, iPadOS, Linux, and Windows hosts remains a Fleet Premium feature.

    Android host display name now uses "{IdP first name}'s {hardware model}" when an IdP account is associated.

    Reduced Windows MDM server and database load by relaxing the device management poll schedule from 1 minute to 8 hours for hosts running a version of fleetd that supports on-demand Windows MDM sync (1.57.0 and later). When commands are queued, the server wakes these devices through fleetd to start a management session, so command delivery stays near real-time. Hosts on older fleetd versions keep the previous poll behavior.

    Renamed Apple Business Manager (ABM) terminology to Apple Business (AB) in the API, GitOps YAML, and fleetctl CLI. The new /api/v1/fleet/ab_tokens and /api/v1/fleet/mdm/apple/ab_public_key endpoints, mdm.apple_business YAML key, and fleetctl get mdm-ab/fleetctl generate mdm-ab commands are canonical. The now-deprecated /abm_tokens, /mdm/apple/abm_public_key, apple_business_manager, mdm-apple-bm aliases continue to work for backwards compatibility and log a deprecation warning when used.

    labels_exclude_any can now be combined with labels_include_all or labels_include_any when uploading MDM configuration profiles, allowing hosts to be included by label membership and excluded by another set of labels simultaneously.

    Added support for setting the end user account type to standard for a standard (non-admin) user or none to skip end-user account creation, both requiring a local admin account.

    Added a "Continuous" option to policy automations that re-runs script and software automations on every subsequent policy failure, with editable automations now available directly on the policy create, edit, and details pages.

    Added the ability for users with the Technician role to transfer hosts between fleets (Fleet Premium only). Global technicians can transfer hosts via the Fleet UI (manage hosts and host details pages) and the REST API. Fleet-scoped technicians can transfer hosts between fleets they manage via the REST API.

    Added Self-service categories page (Premium) under Software > Library for managing custom categories per fleet, including add, edit, and delete flows.

    Added Categories button to the Software > Library page that navigates to the new categories page.

    Replaced the static category sidebar on the My device > Self-service page with a custom-category dropdown driven by the org's self-service categories, and added an "Install all (n)" button per category (with a confirmation modal) that posts to /device/{token}/software/install_all?category_id=:id.

    Added macos_applications filter for host software list.

    Added Fleet "Spotlight" - A command palette that opens when pressing Command + K or Control + K.

    Added a "My device" button on the host details User card so global admins can open the host's end-user My device page in a new tab; Fleet refreshes or generates the device auth token as needed so the link is always valid.

    Showed the end user's IdP full name (e.g. "Jane Doe's device") on the My device page header and browser tab when available; falls back to "My device" otherwise.

    Added support for configuring an optional SES sender domain.

    Security Engineers

    Added support for validating Microsoft Entra v2 access tokens during Windows MDM enrollment. Effective July 1, 2026, new on-premises MDM applications created via the Entra portal flow issue v2 access tokens whose audience (aud) is the application's client ID; adding the client ID lets these applications enroll Windows hosts. Existing v1 tokens (audience = Fleet server URL) continue to work unchanged.

    Hardened in-house iOS app distribution by requiring a per-install token in the manifest and package download URLs. The token is minted when an install is enqueued, bound to the target host, and expires after 6 hours, aligning the in-house download flow with the URL-token authentication already used by Fleet's MDM installer and software installer download endpoints.

    Added GCS IAM authentication support for software installers S3 storage using Google Application Default Credentials (ADC) bearer tokens instead of S3 HMAC keys. Configurable via s3_software_installers_gcs_iam_auth.

    Added GCS IAM authentication support for file carving S3 storage. Configurable via s3_carves_gcs_iam_auth.

    Added route-aware head sampling for OpenTelemetry trace export. When tracing_enabled is on, agent firehose endpoints (osquery distributed read/write, orbit ping/config, device desktop/ping) are sampled at 0.1% by default, admin reads at 2%, and everything else (enroll, SCEP, MDM checkin, cron jobs, GitOps batch) at 100%. Liveness probes (/healthz, /version, /metrics) are dropped unconditionally.

    Added GET/PATCH /debug/trace_sampler (admin only, behind the existing /debug auth) for adjusting ratios or flipping a 100% force_full debug window at runtime. Each Fleet replica polls the new trace_sampler_settings row every 60 seconds and applies changes without a restart.

    Updated the vulnerability processing guide to clarify Linux vulnerability scanning coverage, including a per-distribution table covering OS/kernel, system packages, and cross-platform packages and which scanner is used for each.

    Bug fixes and improvements

    Updated Go to 1.26.4.

    Significantly improved performance of the Apple profile and DDM reconciler.

    Improved the performance of listing labels with host counts by aggregating membership counts in a single pass instead of a per-label subquery, and skipping the unnecessary join to the hosts table when the requesting user can see all hosts.

    Android profiles now use content checksums to determine when to re-sync, avoiding unnecessary re-delivery on unrelated policy changes.

    Long policy resolution text now wraps on the policy details page instead of being truncated.

    Updated initialization semantics around api_endpoints. The catalog is now loaded from the embedded YAML once at package initialization time.

    Added Python 3.14 and Python 3.13 as Windows Fleet-maintained apps.

    Normalized Python's reported version on Windows (e.g. 3.14.5150.0 -> 3.14.5) so software inventory and vulnerability matching use the real version.

    Replaced the "Osquery" column with a richer "Agent" column on the Hosts page that shows Orbit version with a tooltip displaying osquery, Orbit, and Fleet Desktop versions.

    Hid "Issues" and "Private IP address" columns by default for new Fleet instances.

    Added hosts page tooltip to MDM status on hover.

    Added certificate rollover process to MDM assets tool.

    Added a migration cleanup tool for recovering failed starts after renumbered migrations.

    Added each platform's percentage of total enrolled hosts to the "Hosts enrolled" card tooltip on the dashboard.

    Updated conditional access policy query to use parameter binding for platform filter.

    Rejected Windows MDM configuration profiles that don't contain at least one supported SyncML top-level element (, , , or ), so non-XML or empty payloads are caught at upload instead of failing on devices.

    Updated to now prevent deleting a label that is in use by an MDM configuration profile or declaration, returning an error instead of silently breaking the profile's label targeting.

    Raised the default FLEET_REDIS_HOST_CACHE_TTL from 60s to 180s and removed the reverse-index GETs that the host-update invalidation path performed. Together these reduce DB reader load and lower Redis CPU usage.

    Surfaced continuous_automations_enabled in GitOps YAML (read and generated by fleetctl generate-gitops).

    Stopped the 1Password autofill icon from appearing on Fleet UI inputs that are not credential fields.

    Hid the "Rotate password" button in the Recovery Lock password modal for users with the Observer role, instead of showing it as disabled.

    Updated Android Enterprise connect to surface real error messages to the user.

    Updated self-service activity copy to passive voice without an "end user" actor (e.g. "GitHub Desktop was installed on this host (self-service).") on both the host activity feed and the dashboard global activity feed.

    Updated GitOps error message about exceptions to include the URL to visit to disable exceptions.

    Updated the error displayed when GitOps encounters an unknown env var to account for cases where the string is a literal that needs escaping.

    Removed orphaned duplicate SCEP certificates from the per-user keychain automatically after an Okta conditional access profile is reinstalled or renewed on macOS hosts.

    Reduced the Apple MDM lock state cleanup timeout from 5 minutes to 1 minute, decreasing the time a recently unlocked host may still appear as locked in Fleet.

    Rejected Windows MDM configuration profiles whose is empty, starts with /, or contains .. path traversal segments, so invalid OMA-DM URIs are caught at upload instead of failing on devices.

    Refactored ListHostSoftware and ModifyAppConfig into smaller helpers so nilaway can analyze them for nil-pointer dereferences.

    Refactored MDM profile label-targeting logic (include all/any, exclude any) into a shared platform-neutral package so Apple and Windows reconcilers use the same rules.

    Slimmed down the POST /api/v1/fleet/targets response to omit unused fields.

    GitOps now prints a message for each software package it will delete.

    Fixed the Add host modal so its read-only installer command fields can no longer be resized.

    Fixed an issue where the checkerboard would be colored based on relative percentages rather than relative absolute value.

    Fixed a race condition where deleting a policy while a host had an outstanding distributed query for that policy caused a foreign key constraint error during /api/v1/osquery/distributed/write.

    Fixed SCEP PKIOperation handler incorrectly decoding base64 + characters as spaces.

    Fixed software installer edits cancelling pending setup experience installs and causing setup experience to fail if all software is required.

    Fixed a bug where navigating to the Fleet root URL returned a 404 in subpath deployments.

    Fixed bug in apply to prevent setup_experience in software items from being renamed to macos_setup.

    Fixed a bug where the "Add custom variable" modal would clear entered values when switching focus to another browser tab or application window.

    Fixed fleetctl preview disabling dashboard chart data collection (Hosts online, Vulnerability exposure) on startup.

    Fixed a race condition after Windows BYOD MDM enrollment (Settings > Access work or school > Connect) where mdm_windows_enrollments.host_uuid stayed empty for several seconds, causing server-side enrollment lookups to miss. The enrollment is now linked to the Fleet host record at the first management session via OMA-DM DevDetail/SMBIOSSerialNumber instead of waiting for osquery's distributed-read backfill.

    Fixed MDM status column in the host table showing "On (automatic)" instead of "On (company-owned)".

    Fixed logout/login redirects to respect the URL prefix in subpath deployments.

    Fixed the mdm_unenrolled activity not appearing in a host's activity timeline on the host details page.

    Fixed software titles displaying the raw package name instead of the admin-set display name in the policy automations list and edit modal, the patch automation CTA, the hosts software filter pill, and the setup experience software row.

    Fixed an issue where ADE-enrolled macOS hosts didn't report FileVault until restarted.

    Fixed Android profiles temporarily failing when transferred to a team with certificates by ensuring certificates are provisioned before dependent profiles are applied.

    Fixed an issue where the "Get host's OS settings" API endpoint returned an error when only Android MDM was enabled.

    Fixed fleetctl get fleets (and fleetctl get teams) so the software section, including each app's setup_experience value, reflects the real configuration instead of being read from the (potentially stale) team config. Software is now fetched from the software titles and setup experience endpoints, which are the source of truth.

    Fixed an issue where GitOps would fail on the first run after deleting the bootstrap package in the UI.

    Fixed login failing with an "Authentication Required" error when Fleet is served over HTTP, by storing the auth token in a non-secure cookie outside of HTTPS contexts.

    Fixed Android devices losing their team assignment and certificate configuration when the host record is deleted and the device re-enrolls.

    Fixed a bug where host vitals labels (e.g. IdP group/department labels) scoped to a fleet/team never got any hosts. The membership cron only looked at global labels, and team-scoped IdP labels also failed to populate due to an incorrect SQL join.

    Fixed inline error for duplicate certificate name not showing when the conflicting certificate is on a different page.

    Fixed a server out-of-memory crash that could occur when Apple's VPP (App and Book Management) API repeatedly returned transient errors (HTTP 500 with Retry-After, or error 9646) during VPP API operations (e.g., app installs, user registration, license seat releases).

    Fixed Fedora wipe to delete btrfs snapshots (including read-only ones) before wiping the filesystem, preventing snapshots from surviving the wipe.

    Fixed Scripts library action buttons (edit, download, delete) being unreachable via keyboard navigation, and added accessible labels so screen readers can distinguish them.

    Fixed corrupted vulnerabilities download removing existing detections.

    Fixed iOS and iPadOS logos on the OS list in dark theme.

    Fixed a bug where deleting one of multiple duplicate DEP hosts did not resolve the duplicate. Fleet no longer recreates a pending host record when another host with the same serial and platform still exists.

    Fixed an issue where updating the device mapping for a host with no user, or a non-existent IdP user, would not resend config profiles using IdP variables.

    Fixed a bug where the carve cleanup cron job called the MySQL implementation instead of the S3-aware implementation on S3-configured deployments, meaning expired carves were never marked as expired in S3. Also fixed a panic in S3 carve cleanup that occurred when there were no non-expired carves.

    Fixed Android Enterprise page not refreshing after connecting or disconnecting Android MDM, so the Enterprise ID and card state are visible without a manual page reload.

    Fixed List certificate templates API docs: query parameter was incorrectly documented as fleet instead of fleet_id, causing the parameter to be silently ignored and returning no results.

    Fixed a bug where Android device check-ins could silently revert admin team transfers.

    Fixed GET /api/v1/fleet/vulnerabilities returning raw SQL errors when using cursor pagination (after) with order_key set to cve, hosts_count, or cve_published.

    Fixed a bug where patch policies with software install automations used an inactive, older installer and not the latest.

    Fixed "Show example payload" button being incorrectly disabled in GitOps mode on the "Other workflows" and "Calendar events" policy automation modals.

    Fixed stale pending MDM profiles reappearing after globally toggling Apple or Windows MDM off and back on.

    Fixed the live policy page not using the full page width like the live query page does.

    Fixed a bug where in GitOps, if a patch policy was specified with a different FMA slug for the install software automation, it would be used for the query instead of the slug for the patch policy itself.

    Fixed false positive vulnerability CVE-2017-17522 reported for Python (this CVE is disputed and not exploitable).

    Fixed false positive vulnerability CVE-2023-36632 reported for Python (this CVE is disputed; the reported behavior is intentional).

    Fixed false positive vulnerability CVE-2024-3219 reported for Python on macOS and Linux hosts (this CVE only affects Windows).

    Fixed the GET /api/v1/fleet/hosts endpoint so that filtering Android hosts by os_name=Android and os_version= returns the matching hosts. Android hosts now populate the operating_systems table on enrollment and on every status report, and also appear in the GET /api/v1/fleet/os_versions aggregation and OS list in the UI with the Android logo.

    Fixed "User email" in device_mapping being unset in GET /api/v1/fleet/hosts for Windows and Linux hosts enrolling with end-user authentication.

    Fixed GET /api/v1/fleet/software/versions returning HTTP 422 "too many placeholders" when called without a per_page parameter on instances with large software inventories.

    Fixed host software list surfacing stale installer metadata after a Fleet-maintained app was replaced, which caused label scope to be evaluated against the previous installer and disagree with the install endpoint.

    Fixed the "host is offline" banner on the My device page incorrectly appearing during the first few minutes after an enrollment.

    Fixed software title icon not-found errors (and other 4xx errors) being reported as server-side exceptions in OTEL traces, APM, Sentry, and the Redis-backed debug errors endpoint.

    Fixed the host's Software UI showing a date decades in the past (e.g. "over 46 years ago") instead of "Never" for apps reporting a sentinel last_opened_time such as 315532800 (1980-01-01 UTC) that were never opened. Added a migration to clear these sentinel values from previously ingested software.

    Fixed latency issues with /vulnerabilities and filtered /software/versions queries.

    Fixed fleetctl gitops to refuse to apply SSO / EUA config that is missing required fields, if SSO is enabled globally or EUA is enabled on any team.

    Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade.

    Fleet's agent

    The following version of Fleet's agent (fleetd) support the latest changes to Fleet:

    • orbit-v1.56.3
    • fleet-desktop-v1.56.3 (included with Orbit)
    • osquery-5.23.0 (included with Orbit)
    • fleetd-chrome-v1.3.5
    • fleetd-android-v1.5.0

    While newer versions of fleetd still function with older versions of Fleet, old versions of fleetd and osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet.

    Upgrading

    Please visit our upgrade guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    84c30873b5c5f19eb106af06b683d1417cfe31e6ea83d20d4accabbbbb0a30c6 fleet_v4.87.0_linux.tar.gz

    5e66cac64e638653d10408c0cb29a4347777c20f42918c71c44f401dcd5782c9 fleetctl_v4.87.0_linux_amd64.tar.gz

    582ca37fa6f8d346b76accc01ba54c84580b5226b4bcac1b77cf16acc0dca758 fleetctl_v4.87.0_linux_amd64.zip

    abfe74b1205db855d84089293e83f0da6879e9189b10d00e4b955103fabdb4ca fleetctl_v4.87.0_linux_arm64.tar.gz

    30dfe07dc79fa29f6041453f679eb0cf447a8ed9ead60ce2b8d3a78320654397 fleetctl_v4.87.0_linux_arm64.zip

    e120376970999454621c8681dd93e5550a8abc215cdaf0fc829e4fdf6920c721 fleetctl_v4.87.0_macos.tar.gz

    3bfa0dab428a5f16d663f01f04ad5a1470c6a717dc6d7c5ee8635f7fa6e27123 fleetctl_v4.87.0_macos.zip

    b90daa7e89a5650bc53ab44278da28a2a73caafcb9d33bce6d5eb9061aaa2c08 fleetctl_v4.87.0_windows_amd64.tar.gz

    0c5b67741f2b656e6ce3d25c363add56edf22b40c772a197a5c632d26da99752 fleetctl_v4.87.0_windows_amd64.zip

    149097c840c4561d9108689db2ac7c492cf52a57ff50b228148af4054fa2823f fleetctl_v4.87.0_windows_arm64.tar.gz

    df24bc4512030f99f58da991fc2f3712a82624ac3bb0b690d21966f4f4924f21 fleetctl_v4.87.0_windows_arm64.zip

    Original source
  • Jun 19, 2026
    • Date parsed from source:
      Jun 19, 2026
    • First seen by Releasebot:
      Jul 6, 2026
    Fleet logo

    Fleet

    Fleet 4.87.0 | 800+ new apps, custom OS updates, Android commands, and more...

    Fleet releases 4.87.0 with 800+ new Fleet-maintained apps, custom OS update profiles, richer configuration targeting, macOS setup assistant controls, Android lock/wipe/passcode commands, continuous policy retries, and a new command palette.

    Fleet 4.87.0 is now available. See the complete changelog or read on for highlights. For upgrade instructions, visit the upgrade guide in the Fleet docs.

    Highlights

    • 800+ new Fleet-maintained apps
    • Custom OS update profiles
    • Configuration profiles: Include + exclude
    • macOS local account: non-admin (standard) or skip
    • Self-service software categories
    • Android commands: Lock, wipe, & clear passcode
    • Policy automation continuous retry
    • Command palette

    800+ new Fleet-maintained apps

    Available in Fleet Premium

    Fleet 4.87 adds 800+ new Fleet-maintained apps which brings the catalog to over 1,250 apps. IT admins can add any of these under Software > Add software > Fleet-maintained and deploy with a single click.

    Windows gets its biggest catalog expansion yet. Highlights include:

    • Microsoft Office, PowerShell, PowerToys, Power BI, Power Automate, SQL Server Management Studio for Windows-centric environments
    • Git, Node.js, Python 3.13 and 3.14, PostgreSQL 15–18 for development teams
    • Windsurf and Kiro for developers using AI-powered coding IDEs
    • Dell Command Update and Lenovo Dock Manager for hardware fleet management
    • Nessus Agent for vulnerability scanning and Bitwarden for password management

    New macOS apps include Kiro, Codex, and OpenCode for AI-assisted development, plus hundreds more tools across productivity, design, security, and media.

    Custom OS update profiles

    Available in Fleet Premium

    Fleet now supports deploying custom Declarative Device Management (DDM) Software Update enforcement declarations on macOS, iOS, and iPadOS, as well as custom Windows profiles using the Windows Update CSPs. This gives IT admins full control over OS update enforcement, including the exact enforcement deadline time.

    Fleet enforces mutual exclusion with its built-in OS update controls: configuring both returns a clear error, so nothing conflicts silently.

    GitHub issue: #38802

    Configuration profiles: Include + exclude

    Available in Fleet Premium

    Configuration profiles now support combining the Include any label targeting, a host receives a profile if it matches any label in the include list, with the new Exclude any option. This way, IT admins can define broad inclusions and exclude specific hosts without writing complex label queries.

    For example: deliver a Wi-Fi profile to all macOS devices (include_any: macOS) while excluding hosts tagged "Guest" or "Loaner." Both options work across all platforms: macOS, iOS, iPadOS, Windows, and Android.

    GitHub issue: #32073

    macOS local account: non-admin (standard) or skip

    Available in Fleet Premium

    Building on the local admin account introduced in 4.85 and password rotation added in 4.86, Fleet now lets IT admins control the end-user account type during macOS Setup Assistant. On the Controls > Setup experience > Users page, choose Standard to create a non-admin end-user account, or Skip to skip end-user account creation entirely. This is useful when the hidden admin is the only local account the device needs. Selecting Standard or Skip automatically requires the hidden local admin to be created.

    GitHub issue: #41781

    Self-service software categories

    Available in Fleet Premium

    IT admins can now create custom software categories to bucket applications by team, role, or project (e.g., "Product development") so end users can get fully set up for their projects. End users see an Install all in category button that installs all apps in a category, in alphanumeric order, with a single click.

    GitHub issue: #39018

    Android commands: Lock, wipe, & clear passcode

    Available in Fleet Premium

    Fleet can now send lock, wipe, and clear passcode commands to Android hosts directly from the Host details page. For company-owned (fully managed) devices, all three commands are available. For personally-owned (BYOD) Android hosts, lock and clear passcode are available and scoped to the work profile. Each action is logged in Fleet's audit logs. The fleetctl CLI tool also supports these via fleetctl mdm lock, fleetctl mdm wipe, and fleetctl mdm clear-passcode commands.

    GitHub issue: #41683

    Policy automation continuous retry

    Available in Fleet Premium

    A new Run automation on every failure option lets IT admins trigger software installation or script-run automations every time a host fails a policy check, not just the first time. If a host falls back out of compliance after an initial remediation or the initial remediation fails, Fleet automatically runs the fix again without manual intervention.

    GitHub issue: #42651

    Command palette

    Fleet now includes a command palette. Press ⌘+K (or Ctrl+K on Windows and Linux) from anywhere in the app to instantly navigate to any page, trigger any action, or jump to any setting. The palette respects your role by showing or hiding items based on your permissions. Fleet Premium users with multiple fleets can jump directly to the fleet switcher with ⌘+Shift+F (Ctrl+Shift+F on Windows and Linux). Sub-pages let you search hosts, software titles, reports, and policies by name without leaving the keyboard.

    GitHub issue: #43757

    Changes

    IT Admins

    • Added 236 new Fleet-maintained apps for Windows, including Microsoft Office, PowerShell, PowerToys, Power BI, Power Automate, SQL Server Management Studio, Microsoft .NET Runtime 8 and 10, Git, Node.js, Python 3.13 and 3.14, PostgreSQL 15–18, Windsurf, Kiro, Dell Command Update, Lenovo Dock Manager, Nessus Agent, Bitwarden, Canva, Miro, Snagit, Tableau Desktop, VirtualBox, TortoiseGit, GitHub Desktop, and more.
    • Added 727 new Fleet-maintained apps for macOS, including Kiro, Codex, OpenCode, Claude DevTools, Granola, Logitune, and hundreds more tools across development, security, productivity, and design.
    • Added the ability to deploy custom OS update configuration profiles for Apple and Windows.
    • Added support for issuing Lock, Wipe, and Clear passcode commands to Android hosts. Lock and Clear passcode work for both BYO (personal) and COBO (company-owned) Android hosts; Wipe is COBO-only. For BYO hosts, Unenroll now issues an AMAPI WIPE under the hood, which removes only the work profile and leaves personal data intact. All Android commands are issued with duration=315360000s (10 years), matching the pending-forever queue semantics Fleet uses for Apple and Windows MDM.
    • Made the Wipe command available to Fleet Free users for Android (company-owned) hosts, in both the UI and the API. Wipe for macOS, iOS, iPadOS, Linux, and Windows hosts remains a Fleet Premium feature.
    • Android host display name now uses "{IdP first name}'s {hardware model}" when an IdP account is associated.
    • Reduced Windows MDM server and database load by relaxing the device management poll schedule from 1 minute to 8 hours for hosts running a version of fleetd that supports on-demand Windows MDM sync (1.57.0 and later). When commands are queued, the server wakes these devices through fleetd to start a management session, so command delivery stays near real-time. Hosts on older fleetd versions keep the previous poll behavior.
    • Renamed Apple Business Manager (ABM) terminology to Apple Business (AB) in the API, GitOps YAML, and fleetctl CLI. The new /api/v1/fleet/ab_tokens and /api/v1/fleet/mdm/apple/ab_public_key endpoints, mdm.apple_business YAML key, and fleetctl get mdm-ab / fleetctl generate mdm-ab commands are canonical. The now-deprecated /abm_tokens, /mdm/apple/abm_public_key, apple_business_manager, mdm-apple-bm aliases continue to work for backwards compatibility and log a deprecation warning when used.
    • labels_exclude_any can now be combined with labels_include_all or labels_include_any when uploading MDM configuration profiles, allowing hosts to be included by label membership and excluded by another set of labels simultaneously.
    • Added support for setting the end user account type to standard for a standard (non-admin) user or none to skip end-user account creation, both requiring a local admin account.
    • Added a "Continuous" option to policy automations that re-runs script and software automations on every subsequent policy failure, with editable automations now available directly on the policy create, edit, and details pages.
    • Added the ability for users with the Technician role to transfer hosts between fleets (Fleet Premium only). Global technicians can transfer hosts via the Fleet UI (manage hosts and host details pages) and the REST API. Fleet-scoped technicians can transfer hosts between fleets they manage via the REST API.
    • Added Self-service categories page (Premium) under Software > Library for managing custom categories per fleet, including add, edit, and delete flows.
    • Added Categories button to the Software > Library page that navigates to the new categories page.
    • Replaced the static category sidebar on the My device > Self-service page with a custom-category dropdown driven by the org's self-service categories, and added an "Install all (n)" button per category (with a confirmation modal) that posts to /device/{token}/software/install_all?category_id=:id.
    • Added macos_applications filter for host software list.
    • Added Fleet "Spotlight" - A command palette that opens when pressing Command + K or Control + K.
    • Added a "My device" button on the host details User card so global admins can open the host's end-user My device page in a new tab; Fleet refreshes or generates the device auth token as needed so the link is always valid.
    • Showed the end user's IdP full name (e.g. "Jane Doe's device") on the My device page header and browser tab when available; falls back to "My device" otherwise.
    • Added support for configuring an optional SES sender domain.

    Security Engineers

    • Added support for validating Microsoft Entra v2 access tokens during Windows MDM enrollment. Effective July 1, 2026, new on-premises MDM applications created via the Entra portal flow issue v2 access tokens whose audience (aud) is the application's client ID; adding the client ID lets these applications enroll Windows hosts. Existing v1 tokens (audience = Fleet server URL) continue to work unchanged.
    • Hardened in-house iOS app distribution by requiring a per-install token in the manifest and package download URLs. The token is minted when an install is enqueued, bound to the target host, and expires after 6 hours, aligning the in-house download flow with the URL-token authentication already used by Fleet's MDM installer and software installer download endpoints.
    • Added GCS IAM authentication support for software installers S3 storage using Google Application Default Credentials (ADC) bearer tokens instead of S3 HMAC keys. Configurable via s3_software_installers_gcs_iam_auth.
    • Added GCS IAM authentication support for file carving S3 storage. Configurable via s3_carves_gcs_iam_auth.
    • Added route-aware head sampling for OpenTelemetry trace export. When tracing_enabled is on, agent firehose endpoints (osquery distributed read/write, orbit ping/config, device desktop/ping) are sampled at 0.1% by default, admin reads at 2%, and everything else (enroll, SCEP, MDM checkin, cron jobs, GitOps batch) at 100%. Liveness probes (/healthz, /version, /metrics) are dropped unconditionally.
    • Added GET / PATCH /debug/trace_sampler (admin only, behind the existing /debug auth) for adjusting ratios or flipping a 100% force_full debug window at runtime. Each Fleet replica polls the new trace_sampler_settings row every 60 seconds and applies changes without a restart.
    • Updated the vulnerability processing guide to clarify Linux vulnerability scanning coverage, including a per-distribution table covering OS/kernel, system packages, and cross-platform packages and which scanner is used for each.

    Bug fixes and improvements

    • Updated Go to 1.26.4
    • Significantly improved performance of the Apple profile and DDM reconciler.
    • Improved the performance of listing labels with host counts by aggregating membership counts in a single pass instead of a per-label subquery, and skipping the unnecessary join to the hosts table when the requesting user can see all hosts.
    • Android profiles now use content checksums to determine when to re-sync, avoiding unnecessary re-delivery on unrelated policy changes.
    • Long policy resolution text now wraps on the policy details page instead of being truncated.
    • Updated initialization semantics around api_endpoints. The catalog is now loaded from the embedded YAML once at package initialization time.
    • Added Python 3.14 and Python 3.13 as Windows Fleet-maintained apps.
    • Normalized Python's reported version on Windows (e.g. 3.14.5150.0 -> 3.14.5) so software inventory and vulnerability matching use the real version.
    • Replaced the "Osquery" column with a richer "Agent" column on the Hosts page that shows Orbit version with a tooltip displaying osquery, Orbit, and Fleet Desktop versions.
    • Hid "Issues" and "Private IP address" columns by default for new Fleet instances.
    • Added hosts page tooltip to MDM status on hover.
    • Added certificate rollover process to MDM assets tool.
    • Added a migration cleanup tool for recovering failed starts after renumbered migrations.
    • Added each platform's percentage of total enrolled hosts to the "Hosts enrolled" card tooltip on the dashboard.
    • Updated conditional access policy query to use parameter binding for platform filter.
    • Rejected Windows MDM configuration profiles that don't contain at least one supported SyncML top-level element (, , , or ), so non-XML or empty payloads are caught at upload instead of failing on devices.
    • Updated to now prevent deleting a label that is in use by an MDM configuration profile or declaration, returning an error instead of silently breaking the profile's label targeting.
    • Raised the default FLEET_REDIS_HOST_CACHE_TTL from 60s to 180s and removed the reverse-index GETs that the host-update invalidation path performed. Together these reduce DB reader load and lower Redis CPU usage.
    • Surfaced continuous_automations_enabled in GitOps YAML (read and generated by fleetctl generate-gitops).
    • Stopped the 1Password autofill icon from appearing on Fleet UI inputs that are not credential fields.
    • Hid the "Rotate password" button in the Recovery Lock password modal for users with the Observer role, instead of showing it as disabled.
    • Updated Android Enterprise connect to surface real error messages to the user.
    • Updated self-service activity copy to passive voice without an "end user" actor (e.g. "GitHub Desktop was installed on this host (self-service).") on both the host activity feed and the dashboard global activity feed.
    • Updated GitOps error message about exceptions to include the URL to visit to disable exceptions.
    • Updated the error displayed when GitOps encounters an unknown env var to account for cases where the string is a literal that needs escaping.
    • Removed orphaned duplicate SCEP certificates from the per-user keychain automatically after an Okta conditional access profile is reinstalled or renewed on macOS hosts.
    • Reduced the Apple MDM lock state cleanup timeout from 5 minutes to 1 minute, decreasing the time a recently unlocked host may still appear as locked in Fleet.
    • Rejected Windows MDM configuration profiles whose is empty, starts with /, or contains .. path traversal segments, so invalid OMA-DM URIs are caught at upload instead of failing on devices.
    • Refactored ListHostSoftware and ModifyAppConfig into smaller helpers so nilaway can analyze them for nil-pointer dereferences.
    • Refactored MDM profile label-targeting logic (include all/any, exclude any) into a shared platform-neutral package so Apple and Windows reconcilers use the same rules.
    • Slimmed down the POST /api/v1/fleet/targets response to omit unused fields.
    • GitOps now prints a message for each software package it will delete.
    • Fixed the Add host modal so its read-only installer command fields can no longer be resized.
    • Fixed an issue where the checkerboard would be colored based on relative percentages rather than relative absolute value.
    • Fixed a race condition where deleting a policy while a host had an outstanding distributed query for that policy caused a foreign key constraint error during /api/v1/osquery/distributed/write.
    • Fixed SCEP PKIOperation handler incorrectly decoding base64 + characters as spaces.
    • Fixed software installer edits cancelling pending setup experience installs and causing setup experience to fail if all software is required.
    • Fixed a bug where navigating to the Fleet root URL returned a 404 in subpath deployments.
    • Fixed bug in apply to prevent setup_experience in software items from being renamed to macos_setup.
    • Fixed a bug where the "Add custom variable" modal would clear entered values when switching focus to another browser tab or application window.
    • Fixed fleetctl preview disabling dashboard chart data collection (Hosts online, Vulnerability exposure) on startup.
    • Fixed a race condition after Windows BYOD MDM enrollment (Settings > Access work or school > Connect) where mdm_windows_enrollments.host_uuid stayed empty for several seconds, causing server-side enrollment lookups to miss. The enrollment is now linked to the Fleet host record at the first management session via OMA-DM DevDetail/SMBIOSSerialNumber instead of waiting for osquery's distributed-read backfill.
    • Fixed MDM status column in the host table showing "On (automatic)" instead of "On (company-owned)".
    • Fixed logout/login redirects to respect the URL prefix in subpath deployments.
    • Fixed the mdm_unenrolled activity not appearing in a host's activity timeline on the host details page.
    • Fixed software titles displaying the raw package name instead of the admin-set display name in the policy automations list and edit modal, the patch automation CTA, the hosts software filter pill, and the setup experience software row.
    • Fixed an issue where ADE-enrolled macOS hosts didn't report FileVault until restarted.
    • Fixed Android profiles temporarily failing when transferred to a team with certificates by ensuring certificates are provisioned before dependent profiles are applied.
    • Fixed an issue where the "Get host's OS settings" API endpoint returned an error when only Android MDM was enabled.
    • Fixed fleetctl get fleets (and fleetctl get teams) so the software section, including each app's setup_experience value, reflects the real configuration instead of being read from the (potentially stale) team config. Software is now fetched from the software titles and setup experience endpoints, which are the source of truth.
    • Fixed an issue where GitOps would fail on the first run after deleting the bootstrap package in the UI.
    • Fixed login failing with an "Authentication Required" error when Fleet is served over HTTP, by storing the auth token in a non-secure cookie outside of HTTPS contexts.
    • Fixed Android devices losing their team assignment and certificate configuration when the host record is deleted and the device re-enrolls.
    • Fixed a bug where host vitals labels (e.g. IdP group/department labels) scoped to a fleet/team never got any hosts. The membership cron only looked at global labels, and team-scoped IdP labels also failed to populate due to an incorrect SQL join.
    • Fixed inline error for duplicate certificate name not showing when the conflicting certificate is on a different page.
    • Fixed a server out-of-memory crash that could occur when Apple's VPP (App and Book Management) API repeatedly returned transient errors (HTTP 500 with Retry-After, or error 9646) during VPP API operations (e.g., app installs, user registration, license seat releases).
    • Fixed Fedora wipe to delete btrfs snapshots (including read-only ones) before wiping the filesystem, preventing snapshots from surviving the wipe.
    • Fixed Scripts library action buttons (edit, download, delete) being unreachable via keyboard navigation, and added accessible labels so screen readers can distinguish them.
    • Fixed corrupted vulnerabilities download removing existing detections.
    • Fixed iOS and iPadOS logos on the OS list in dark theme.
    • Fixed a bug where deleting one of multiple duplicate DEP hosts did not resolve the duplicate. Fleet no longer recreates a pending host record when another host with the same serial and platform still exists.
    • Fixed an issue where updating the device mapping for a host with no user, or a non-existent IdP user, would not resend config profiles using IdP variables.
    • Fixed a bug where the carve cleanup cron job called the MySQL implementation instead of the S3-aware implementation on S3-configured deployments, meaning expired carves were never marked as expired in S3. Also fixed a panic in S3 carve cleanup that occurred when there were no non-expired carves.
    • Fixed Android Enterprise page not refreshing after connecting or disconnecting Android MDM, so the Enterprise ID and card state are visible without a manual page reload.
    • Fixed List certificate templates API docs: query parameter was incorrectly documented as fleet instead of fleet_id, causing the parameter to be silently ignored and returning no results.
    • Fixed a bug where Android device check-ins could silently revert admin team transfers.
    • Fixed GET /api/v1/fleet/vulnerabilities returning raw SQL errors when using cursor pagination (after) with order_key set to cve, hosts_count, or cve_published.
    • Fixed a bug where patch policies with software install automations used an inactive, older installer and not the latest.
    • Fixed "Show example payload" button being incorrectly disabled in GitOps mode on the "Other workflows" and "Calendar events" policy automation modals.
    • Fixed stale pending MDM profiles reappearing after globally toggling Apple or Windows MDM off and back on.
    • Fixed the live policy page not using the full page width like the live query page does.
    • Fixed a bug where in GitOps, if a patch policy was specified with a different FMA slug for the install software automation, it would be used for the query instead of the slug for the patch policy itself.
    • Fixed false positive vulnerability CVE-2017-17522 reported for Python (this CVE is disputed and not exploitable).
    • Fixed false positive vulnerability CVE-2023-36632 reported for Python (this CVE is disputed; the reported behavior is intentional).
    • Fixed false positive vulnerability CVE-2024-3219 reported for Python on macOS and Linux hosts (this CVE only affects Windows).
    • Fixed the GET /api/v1/fleet/hosts endpoint so that filtering Android hosts by os_name=Android and os_version= returns the matching hosts. Android hosts now populate the operating_systems table on enrollment and on every status report, and also appear in the GET /api/v1/fleet/os_versions aggregation and OS list in the UI with the Android logo.
    • Fixed "User email" in device_mapping being unset in GET /api/v1/fleet/hosts for Windows and Linux hosts enrolling with end-user authentication.
    • Fixed GET /api/v1/fleet/software/versions returning HTTP 422 "too many placeholders" when called without a per_page parameter on instances with large software inventories.
    • Fixed host software list surfacing stale installer metadata after a Fleet-maintained app was replaced, which caused label scope to be evaluated against the previous installer and disagree with the install endpoint.
    • Fixed the "host is offline" banner on the My device page incorrectly appearing during the first few minutes after an enrollment.
    • Fixed software title icon not-found errors (and other 4xx errors) being reported as server-side exceptions in OTEL traces, APM, Sentry, and the Redis-backed debug errors endpoint.
    • Fixed the host's Software UI showing a date decades in the past (e.g. "over 46 years ago") instead of "Never" for apps reporting a sentinel last_opened_time such as 315532800 (1980-01-01 UTC) that were never opened. Added a migration to clear these sentinel values from previously ingested software.
    • Fixed latency issues with /vulnerabilities and filtered /software/versions queries.
    • Fixed fleetctl gitops to refuse to apply SSO / EUA config that is missing required fields, if SSO is enabled globally or EUA is enabled on any team.

    Ready to upgrade?

    Visit our Upgrade guide in the Fleet docs to update to Fleet 4.87.0.

    Manage all your devices like it's 2026
    Open MDM, patching, and vuln management for every OS.
    Read case studies
    Try it yourself

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.