Preview of v4.77.0 doc changes (#35924)

This PR will remain in draft as a preview of upcoming documentation
changes for 4.77.0

---------

Co-authored-by: Marko Lisica <83164494+marko-lisica@users.noreply.github.com>
Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
Co-authored-by: Victor Lyuboslavsky <2685025+getvictor@users.noreply.github.com>
Co-authored-by: Ian Littman <iansltx@gmail.com>
Co-authored-by: Noah Talerman <noahtal@umich.edu>
Co-authored-by: Lucas Manuel Rodriguez <lucas@fleetdm.com>
Co-authored-by: Magnus Jensen <magnus@fleetdm.com>
Co-authored-by: Jordan Montgomery <elijah.jordan.montgomery@gmail.com>
Co-authored-by: Janis Watts <184028114+jmwatts@users.noreply.github.com>
Co-authored-by: Allen Houchins <32207388+allenhouchins@users.noreply.github.com>
Co-authored-by: Gabriel Hernandez <ghernandez345@gmail.com>
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
Co-authored-by: Scott Gress <scottmgress@gmail.com>
Co-authored-by: Carlo <1778532+cdcme@users.noreply.github.com>
This commit is contained in:
Rachael Shaw
2025-12-02 17:24:15 -06:00
committed by GitHub
co-authored by Marko Lisica Noah Talerman Victor Lyuboslavsky Ian Littman Noah Talerman Lucas Manuel Rodriguez Magnus Jensen Jordan Montgomery Janis Watts Allen Houchins Gabriel Hernandez Mike Thomas Scott Gress Carlo
parent 818b1811a1
commit 25191f3054
33 changed files with 1013 additions and 438 deletions
+54 -19
View File
@@ -10,9 +10,9 @@ To turn on Windows MDM features, head to this [Windows MDM setup article](https:
Apple uses APNs to authenticate and manage interactions between Fleet and hosts.
To connect Fleet to APNs or renew APNs, head to the **Settings > Integrations > Mobile device management (MDM)** page.
To connect Fleet to APNs or renew APNs, head to the **Settings > Integrations > Mobile device management (MDM)** page.
Then click **Turn on** under the Apple (macOS, iOS, iPadOS) MDM section.
Then select **Turn on** under the Apple (macOS, iOS, iPadOS) MDM section.
> Apple requires that APNs certificates are renewed annually.
> - The recommended approach is to use a shared admin account to generate the CSR ensuring it can be renewed regardless of individual availability.
@@ -25,44 +25,79 @@ Then click **Turn on** under the Apple (macOS, iOS, iPadOS) MDM section.
Connect Fleet to your ABM to allow automatic enrollment for company-owned and [Account-driven User Enrollment](https://fleetdm.com/guides/enroll-personal-byod-ios-ipad-hosts-with-managed-apple-account) for personal (BYOD) macOS, iOS, and iPadOS hosts.
To connect Fleet to ABM, you have to add an ABM token to Fleet. To add an ABM token:
To connect Fleet to ABM, you have to add an ABM token to Fleet. To add an ABM token:
1. Navigate to the **Settings > Integrations > Mobile device management (MDM)** page.
2. Under "Automatic enrollment", click "Add ABM", and then follow the instructions in the modal to upload an ABM token to Fleet.
2. Under **Automatic enrollment**, select **Add ABM**, and then follow the instructions in the modal to upload an ABM token to Fleet.
When one of your uploaded ABM tokens has expired or is within 30 days of expiring, you will see a warning banner at the top of page reminding you to renew your token.
To renew an ABM token:
1. Navigate to the **Settings > Integrations > Mobile device management (MDM)** page.
2. Under "Automatic enrollment", click "Edit", and then find the token that you want to renew. Token status is indicated in the "Renew date" column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Click the "Actions" dropdown for the token and then click "Renew". Follow the instructions in the modal to download a new token from Apple Business Manager and then upload the new token to Fleet.
2. Under **Automatic enrollment**, select **Edit**, and then find the token that you want to renew. Token status is indicated in the **Renew date** column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Select the **Actions** dropdown for the token and then select **Renew**. Follow the instructions in the modal to download a new token from Apple Business Manager and then upload the new token to Fleet.
After connecting Fleet to ABM, set Fleet to be the MDM for all Macs:
After connecting Fleet to ABM, set Fleet to be the MDM for all Macs:
1. Log in to [Apple Business Manager](https://business.apple.com)
2. Click your profile icon in the bottom left
3. Click **Preferences**
4. Click **MDM Server Assignment** and click **Edit** next to **Default Server Assignment**.
2. Select your profile icon in the bottom left
3. Select **Preferences**
4. Select **MDM Server Assignment** and select **Edit** next to **Default Server Assignment**.
5. Switch **Mac**, **iPhone**, and **iPad** to Fleet.
macOS, iOS, and iPadOS hosts listed in ABM and associated to a Fleet instance with MDM enabled will sync to Fleet and appear in the Hosts view with the **MDM status** label set to "Pending".
macOS, iOS, and iPadOS hosts listed in ABM and associated to a Fleet instance with MDM enabled will sync to Fleet and appear in the Hosts view with the **MDM status** label set to "Pending".
Hosts that automatically enroll will be assigned to a default team. You can configure the default team for macOS, iOS, and iPadOS hosts by:
Hosts that automatically enroll will be assigned to a default team. You can configure the default team for macOS, iOS, and iPadOS hosts:
1. Creating teams, if you have not already, following [this guide](https://fleetdm.com/guides/teams#basic-article). Our [best practice](#best-practice) recommendation is to have a team for each device type.
2. Navigating to the **Settings > Integrations > Mobile device management (MDM)** page and clicking "Edit" under "Automatic enrollment".
3. Clicking on the "Actions" dropdown for the ABM token you want to update, and then clicking "Edit teams".
4. Using the dropdowns in the modal to select the default team for each type of host, and clicking "Save" to save your selections.
1. Create a team, if you have not already, following [this guide](https://fleetdm.com/guides/teams).
2. Navigate to the **Settings > Integrations > Mobile device management (MDM)** page and select **Edit** under **Automatic enrollment**.
3. Select the **Actions** dropdown for the ABM token you want to update, and then select **Edit teams**.
4. Select the default team for each platform, and select **Save** to save your selections.
> If no default team is set for a host platform (macOS, iOS, or iPadOS), then newly enrolled hosts of that platform will be placed in "No team".
> If no default team is set for a host platform (macOS, iOS, or iPadOS), then newly enrolled hosts of that platform will be placed in "No team".
> A host can be transferred to a new (not default) team before it enrolls. In the Fleet UI, you can do this under **Settings** > **Teams**.
## Turn on MDM on a host
Fleet supports manually turning on MDM for macOS hosts that are already enrolled in Fleet.
End users can turn on MDM from their **Fleet Desktop > My device** page.
### Host is in Apple Business Manager (ABM)
If a macOS host is listed in ABM:
1. The end user will see a **Turn on MDM** banner at the top of their **My device** page.
2. Clicking **Turn on MDM** opens a modal with a step-by-step instruction on how to turn on MDM on their host.
3. After completing the steps, the host has MDM features turned on.
### Host isn't in ABM
If the host isnt in ABM, users can still turn on MDM:
1. On the **My device** page, the end user sees the same **Turn on MDM** banner.
2. Clicking **Turn on MDM** opens a new tab.
- If [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication) is enabled, the end user is prompted to sign in with your organizations identity provider (IdP).
- If authentication is successful, or if end user authentication is disabled, the end user is taken to a page with instructions to download the manual enrollment profile and install it on their macOS host.
## Volume Purchasing Program (VPP)
> Available in Fleet Premium
To connect Fleet to Apple's VPP, follow the instructions in our [VPP guide](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet#prerequisites).
Connect Fleet to VPP to deploy [Apple App Store apps](https://fleetdm.com/guides/install-app-store-apps) to your hosts:
1. In Fleet, select your avatar on the far right of the main navigation menu, and then **Settings > Integrations > Mobile device management (MDM)**
2. In the **Volume Purchasing Program (VPP)** section, select **Add VPP**, and then select **Add VPP** again on the following page. Follow the directions on the modal to get your VPP token from Apple Business Manager, and then select the **Upload** button at the bottom to upload it to Fleet.
3. To assign the VPP token to a specific team, find the token in the table of VPP tokens. Select the **Actions** dropdown, and then select **Edit teams**. Use the picker to select which team(s) this VPP token should be assigned to.
To renew a VPP token:
1. Navigate to the **Settings > Integrations > Mobile device management (MDM)** page
2. Under **Volume Purchasing Program (VPP)**, select **Edit** and then find the token that you want to renew. Token status is indicated in the **Renew date** column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Select the **Actions** dropdown for the token and then select **Renew**. Follow the instructions in the modal to download a new token from Apple Business Manager and then upload the new token to Fleet.
## Best practice
@@ -72,9 +107,9 @@ These organizations may need multiple ABM and VPP tokens:
- Managed Service Providers (MSPs)
- Enterprises that acquire new businesses and as a result inherit new hosts
- Umbrella organizations that preside over entities with separated purchasing authority (i.e. a hospital or university)
- Umbrella organizations that preside over entities with separated purchasing authority (i.e. a hospital or university)
For **MSPs**, the best practice is to have one ABM and VPP connection per client.
For **MSPs**, the best practice is to have one ABM and VPP connection per client.
The default teams in Fleet for each client's ABM token in Fleet will look like this:
- macOS: 💻 Client A - Workstations
@@ -2,10 +2,11 @@
_Available in Fleet Premium_
Fleet can help your end users connect to Wi-Fi or VPN by deploying certificates from your certificate authority (CA). Fleet currently supports [DigiCert](https://www.digicert.com/digicert-one), [Microsoft NDES](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/network-device-enrollment-service-overview), [Hydrant](https://www.hidglobal.com/solutions/pki-service), [Smallstep](https://smallstep.com/) and custom [SCEP](https://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_Protocol) servers.
Fleet can help your end users connect to Wi-Fi or VPN by deploying certificates from your certificate authority (CA). Fleet currently supports [DigiCert](#digicert), [Microsoft NDES](#microsoft-ndes),[Smallstep](#smallstep), [Hydrant](#hydrant), and a custom [SCEP](#custom-scep-simple-certificate-enrollment-protocol) or [EST](#custom-est-enrollment-over-secure-transport) server.
Fleet will automatically renew certificates on Apple (macOS, iOS, iPadOS) hosts before expiration. Learn more in the [Renewal section](#renewal).
## DigiCert
The following steps show how to connect end users to Wi-Fi or VPN with DigiCert certificates.
@@ -104,7 +105,7 @@ When Fleet delivers the profile to your hosts, Fleet will replace the variables.
## Microsoft NDES
The following steps show how to connect end users to Wi-Fi or VPN with Microsoft NDES certificates.
The following steps show how to connect end users to Wi-Fi or VPN with [Microsoft NDES](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/network-device-enrollment-service-overview) certificates.
### Step 1: Connect Fleet to NDES
@@ -192,99 +193,9 @@ When the profile is delivered to your hosts, Fleet will replace the variables. I
</dict>
</plist>
```
## Custom SCEP server
The following steps show how to connect end users to Wi-Fi or VPN with a custom SCEP server.
### Step 1: Connect Fleet to a custom SCEP server
1. In Fleet, head to **Settings > **Integrations > Certificates**.
2. Select the **Add CA** button and select **Custom** in the dropdown.
3. Add a **Name** for your certificate authority. The best practice is to create a name based on your use case in all caps snake case (for example, "WIFI_AUTHENTICATION"). This name will be used later as a variable name in a configuration profile.
4. Add your **SCEP URL** and **Challenge**.
6. Select **Add CA**. Your custom SCEP certificate authority (CA) should appear in the list in Fleet.
### Step 2: Add SCEP configuration profile to Fleet
1. Create a [configuration profile](https://fleetdm.com/guides/custom-os-settings) with the SCEP payload. In the profile, for `Challenge`, use`$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_<CA_NAME>`. For, `URL`, use `$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_<CA_NAME>`, and make sure to add `$FLEET_VAR_SCEP_RENEWAL_ID` to `OU`.
2. Replace the `<CA_NAME>` with the name you created in step 3. For example, if the name of the CA is "WIFI_AUTHENTICATION", the variables will look like this: `$FLEET_VAR_CUSTOM_SCEP_PASSWORD_WIFI_AUTHENTICATION` and `FLEET_VAR_CUSTOM_SCEP_DIGICERT_DATA_WIFI_AUTHENTICATION`.
3. If your Wi-Fi or VPN requires certificates that are unique to each host, update the `Subject`. You can use `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` if your hosts automatically enrolled (via ADE) to Fleet with [end user authentication](https://fleetdm.com/docs/rest-api/rest-api#get-human-device-mapping) enabled. You can also use any of [Apple's built-in variables](https://support.apple.com/en-my/guide/deployment/dep04666af94/1/web/1.0).
4. In Fleet, head to **Controls > OS settings > Custom settings** and add the configuration profile to deploy certificates to your hosts.
When the profile is delivered to your hosts, Fleet will replace the variables. If something goes wrong, errors will appear on each host's **Host details > OS settings**.
#### Example configuration profile
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
<dict>
<key>PayloadContent</key>
<dict>
<key>Challenge</key>
<string>$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_CA_NAME</string>
<key>Key Type</key>
<string>RSA</string>
<key>Key Usage</key>
<integer>5</integer>
<key>Keysize</key>
<integer>2048</integer>
<key>Subject</key>
<array>
<array>
<array>
<string>CN</string>
<string>%SerialNumber% WIFI</string>
</array>
</array>
<array>
<array>
<string>OU</string>
<string>$FLEET_VAR_SCEP_RENEWAL_ID</string>
</array>
</array>
</array>
<key>URL</key>
<string>$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_CA_NAME</string>
</dict>
<key>PayloadDisplayName</key>
<string>WIFI SCEP</string>
<key>PayloadIdentifier</key>
<string>com.apple.security.scep.9DCC35A5-72F9-42B7-9A98-7AD9A9CCA3AC</string>
<key>PayloadType</key>
<string>com.apple.security.scep</string>
<key>PayloadUUID</key>
<string>9DCC35A5-72F9-42B7-9A98-7AD9A9CCA3AC</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</array>
<key>PayloadDisplayName</key>
<string>SCEP proxy cert</string>
<key>PayloadIdentifier</key>
<string>Fleet.WiFi</string>
<key>PayloadType</key>
<string>Configuration</string>
<key>PayloadUUID</key>
<string>4CD1BD65-1D2C-4E9E-9E18-9BCD400CDEDC</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</plist>
```
## Smallstep
The following steps show how to connect end users to Wi-Fi or VPN with Smallstep certificates.
The following steps show how to connect end users to Wi-Fi or VPN with [Smallstep](https://smallstep.com/) certificates.
### Step 1: Configure Smallstep with Fleet information
@@ -314,7 +225,7 @@ We're currently working with Smallstep to develop a specific Smallstep-Fleet con
1. Create a [configuration profile](https://fleetdm.com/guides/custom-os-settings) with the SCEP payload.
- For `Challenge`, use`$FLEET_VAR_SMALLSTEP_SCEP_CHALLENGE_<CA_NAME>`.
- For, `URL`, use `$FLEET_VAR_SMALLSTEP_SCEP_PROXY_URL_<CA_NAME>`, and make sure to add `$FLEET_VAR_SCEP_RENEWAL_ID` to `OU`.
- For `URL`, use `$FLEET_VAR_SMALLSTEP_SCEP_PROXY_URL_<CA_NAME>`, and make sure to add `$FLEET_VAR_SCEP_RENEWAL_ID` to `OU`.
2. Replace the `<CA_NAME>` with the name you created in step 2. For example, if the name of the CA is "WIFI_AUTHENTICATION", the variables will look like this: `$FLEET_VAR_SMALLSTEP_SCEP_CHALLENGE_WIFI_AUTHENTICATION` and `FLEET_VAR_SMALLSTEP_SCEP_PROXY_URL_WIFI_AUTHENTICATION`.
@@ -390,7 +301,7 @@ When the profile is delivered to your hosts, Fleet will replace the variables. I
## Hydrant
The following steps show how to connect end users to Wi-Fi or VPN with Hydrant.
The following steps show how to connect end users to Wi-Fi or VPN with [Hydrant](https://www.hidglobal.com/solutions/pki-service).
The flow for Hydrant differs from the other certificate authorities (CA's). While other CAs in Fleet use a configuration profile to request a certificate, Hydrant uses:
- A custom script that makes a request to Fleet's [`POST /request_certificate`](https://fleetdm.com/docs/rest-api/rest-api#request-certificate) API endpoint.
@@ -414,11 +325,11 @@ The flow for Hydrant differs from the other certificate authorities (CA's). Whil
### Step 3: Create a custom script
To automatically deploy certificates to Linux hosts when they enroll, we'll create a custom script to write a certificate to a location. This script will be triggered by a policy that checks for the existence of a certificate.
To deploy certificates automatically to Linux hosts at enrollment, create a script that writes the certificate to the filesystem. Use a policy to trigger this script on any host that doesnt have a certificate.
This custom script will create a certificate signing request (CSR) and make a request to Fleet's "Request certificate" API endpoint.
1. Create an API-only user with the global maintainer role. Learn more how to create an API-only user in the [API-only user guide](https://fleetdm.com/guides/fleetctl#create-api-only-user).
1. Create an API-only user with the global maintainer role. Learn how to create an API-only user in the [API-only user guide](https://fleetdm.com/guides/fleetctl#create-api-only-user).
2. In Fleet, head to **Controls > Variables** and create a Fleet variable called REQUEST_CERTIFICATE_API_TOKEN. Add the API-only user's API token as the value. You'll use this variable in your script.
3. Make a request to Fleet's [`GET /certificate_authorities` API endpoint](https://fleetdm.com/docs/rest-api/rest-api#list-certificate-authorities-cas) to get the `id` for your Hydrant CA. You'll use this `id` in your script.
4. In Fleet, head to **Controls > Scripts**, and add a script like the one below, plugging in your own filesystem locations, Fleet server URL and IdP information. For this script to work, the host it's run on has to have openssl, sed, curl and jq installed.
@@ -470,6 +381,351 @@ Enforcing IdP validation using `idp_oauth_url` and `idp_token` is optional. If e
### Step 4: Create a custom policy
1. In Fleet, head to **Policies** and select **Add policy**. Use the following query to detect the certificate's existence and if it expires in the next 30 days:
```sql
SELECT 1 FROM certificates WHERE path = '/opt/company/certificate.pem' AND not_valid_after > (CAST(strftime('%s', 'now') AS INTEGER) + 2592000);
```
2. Select **Save** and select only **Linux** as its target. Select **Save** again to create your policy.
3. On the **Policies** page, select **Manage automations > Scripts**. Select your newly-created policy and then in the dropdown to the right, select your newly created certificate issuance script.
4. Now, any host that doesn't have a certificate in `/opt/company/certificate.pem` or has a certificate that expires in the next 30 days will fail the policy. When the policy fails, Fleet will run the script to deploy a new certificate!
## Custom SCEP (Simple Certificate Enrollment Protocol)
The following steps show how to connect end users to Wi-Fi or VPN with a [custom SCEP server](https://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_Protocol).
### Step 1: Connect Fleet to a custom SCEP server
1. In Fleet, head to **Settings > **Integrations > Certificates**.
2. Select the **Add CA** button and select **Custom** in the dropdown.
3. Add a **Name** for your certificate authority. The best practice is to create a name based on your use case in all caps snake case (for example, "WIFI_AUTHENTICATION"). This name will be used later as a variable name in a configuration profile.
4. Add your **SCEP URL** and **Challenge**.
6. Select **Add CA**. Your custom SCEP certificate authority (CA) should appear in the list in Fleet.
### Step 2: Add SCEP configuration profile to Fleet
1. Create a [configuration profile](https://fleetdm.com/guides/custom-os-settings) with the SCEP payload. In the profile, for `Challenge`, use`$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_<CA_NAME>`. For `URL`, use `$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_<CA_NAME>`, and make sure to add `$FLEET_VAR_SCEP_RENEWAL_ID` to `OU`.
2. Replace the `<CA_NAME>` with the name you created in step 3. For example, if the name of the CA is "WIFI_AUTHENTICATION", the variables will look like this: `$FLEET_VAR_CUSTOM_SCEP_PASSWORD_WIFI_AUTHENTICATION` and `FLEET_VAR_CUSTOM_SCEP_DIGICERT_DATA_WIFI_AUTHENTICATION`.
3. If your Wi-Fi or VPN requires certificates that are unique to each host, update the `Subject`. You can use `$FLEET_VAR_HOST_END_USER_EMAIL_IDP` if your hosts automatically enrolled (via ADE) to Fleet with [end user authentication](https://fleetdm.com/docs/rest-api/rest-api#get-human-device-mapping) enabled. You can also use any of [Apple's built-in variables](https://support.apple.com/en-my/guide/deployment/dep04666af94/1/web/1.0).
4. In Fleet, head to **Controls > OS settings > Custom settings** and add the configuration profile to deploy certificates to your hosts.
When the profile is delivered to your hosts, Fleet will replace the variables. If something goes wrong, errors will appear on each host's **Host details > OS settings**.
#### Example configuration profiles
<details>
<summary>Apple configuration profile</summary>
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
<key>PayloadContent</key>
<array>
<dict>
<key>PayloadContent</key>
<dict>
<key>Challenge</key>
<string>$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_CA_NAME</string>
<key>Key Type</key>
<string>RSA</string>
<key>Key Usage</key>
<integer>5</integer>
<key>Keysize</key>
<integer>2048</integer>
<key>Subject</key>
<array>
<array>
<array>
<string>CN</string>
<string>%SerialNumber% WIFI $FLEET_VAR_SCEP_RENEWAL_ID</string>
</array>
</array>
<array>
<array>
<string>OU</string>
<string>FLEET DEVICE MANAGEMENT</string>
</array>
</array>
</array>
<key>URL</key>
<string>$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_CA_NAME</string>
</dict>
<key>PayloadDisplayName</key>
<string>WIFI SCEP</string>
<key>PayloadIdentifier</key>
<string>com.apple.security.scep.9DCC35A5-72F9-42B7-9A98-7AD9A9CCA3AC</string>
<key>PayloadType</key>
<string>com.apple.security.scep</string>
<key>PayloadUUID</key>
<string>9DCC35A5-72F9-42B7-9A98-7AD9A9CCA3AC</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</array>
<key>PayloadDisplayName</key>
<string>SCEP proxy cert</string>
<key>PayloadIdentifier</key>
<string>Fleet.WiFi</string>
<key>PayloadType</key>
<string>Configuration</string>
<key>PayloadUUID</key>
<string>4CD1BD65-1D2C-4E9E-9E18-9BCD400CDEDC</string>
<key>PayloadVersion</key>
<integer>1</integer>
</dict>
</plist>
```
</details>
<details>
<summary>Windows configuration profile</summary>
To get the CAThumbprint of your SCEP server, see the [advanced section](#how-to-get-the-cathumbprint-for-windows-scep-profiles) below.
Any options listed under [Device/SCEP](https://learn.microsoft.com/en-us/windows/client-management/mdm/clientcertificateinstall-csp), can be configured with the SCEP profile.
```xml
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">node</Format>
</Meta>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/KeyUsage</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">int</Format>
</Meta>
<Data>160</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/KeyLength</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">int</Format>
</Meta>
<Data>1024</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/HashAlgorithm</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">chr</Format>
</Meta>
<Data>SHA-1</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/SubjectName</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">chr</Format>
</Meta>
<Data>CN=$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/EKUMapping</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">chr</Format>
</Meta>
<Data>1.3.6.1.5.5.7.3.2</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/ServerURL</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">chr</Format>
</Meta>
<Data>$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_CA_NAME</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/Challenge</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">chr</Format>
</Meta>
<Data>$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_CA_NAME</Data>
</Item>
</Add>
<Add>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/CAThumbprint</LocURI>
</Target>
<Meta>
<Format xmlns="syncml:metinf">chr</Format>
</Meta>
<Data>2133EC6A3CFB8418837BB395188D1A62CA2B96A6</Data>
</Item>
</Add>
<Exec>
<Item>
<Target>
<LocURI>./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/Enroll</LocURI>
</Target>
</Item>
</Exec>
```
> Currently only device scoped SCEP profiles are supported for Windows devices.
</details>
## Custom EST (Enrollment over Secure Transport)
The following steps show how to connect end users to Wi-Fi or VPN with a [custom EST server](https://en.wikipedia.org/wiki/Enrollment_over_Secure_Transport).
The flow for EST is similar to Hydrant, and differs from the other certificate authorities. While other CAs in Fleet use a configuration profile to request a certificate, EST uses:
- A custom script that makes a request to Fleet's [`POST /request_certificate`](https://fleetdm.com/docs/rest-api/rest-api#request-certificate) API endpoint.
- A custom policy that triggers the script on hosts that don't have a certificate.
### Step 1: Obtain API credentials
This step will vary depending between providers. EST servers require a `username` and `password` for authentication. These may be obtained from your company's certificate authority administrator.
### Step 2: Connect Fleet to the custom EST server
1. In Fleet, head to **Settings > Integrations > Certificates**.
2. Select **Add CA** and then choose **Custom EST Proxy** in the dropdown.
3. Add a **Name** for your certificate authority. The best practice is to create a name based on your use case in all caps snake case (ex. "WIFI_AUTHENTICATION").
4. Add your Custom EST Proxy **URL**.
5. Add the username and password as the **Username** and **Password** in Fleet respectfully.
6. Click **Add CA**. Your Custom EST Proxy certificate authority (CA) should appear in the list in Fleet.
### Step 3: Create a custom script
To deploy certificates automatically to Linux hosts at enrollment, create a script that writes the certificate to the filesystem. Use a policy to trigger this script on any host that doesnt have a certificate.
There are two methods available for requesting a certificate from the "Request certificate" endpoint. The first is to use an API token, the second is to use HTTP Message Signing (RFC 9421).
#### API token
This custom script will create a certificate signing request (CSR) and make a request to Fleet's "Request certificate" API endpoint using an API token.
1. Create an API-only user with the global maintainer role. Learn how to create an API-only user in the [API-only user guide](https://fleetdm.com/guides/fleetctl#create-api-only-user).
2. In Fleet, head to **Controls > Variables** and create a Fleet variable called REQUEST_CERTIFICATE_API_TOKEN. Add the API-only user's API token as the value. You'll use this variable in your script.
3. Make a request to Fleet's [`GET /certificate_authorities` API endpoint](https://fleetdm.com/docs/rest-api/rest-api#list-certificate-authorities-cas) to get the `id` for your EST CA. You'll use this `id` in your script.
4. In Fleet, head to **Controls > Scripts**, and add a script like the one below, plugging in your own filesystem locations, Fleet server URL and IdP information. For this script to work, the host it's run on has to have openssl, sed, curl and jq installed.
Example script:
```shell
#!/bin/bash
set -e
# Load the end user information, IdP token and IdP client ID.
. /opt/company/userinfo
URL="<IdP-introspection-URL>"
# Generate the password-protected private key
openssl genpkey -algorithm RSA -out /opt/company/CustomerUserNetworkAccess.key -pkeyopt rsa_keygen_bits:2048 -aes256 -pass pass:${PASSWORD}
# Generate CSR signed with that private key. The CN can be changed and DNS attribute omitted if your EST configuration allows it.
openssl req -new -sha256 -key /opt/company/CustomerUserNetworkAccess.key -out CustomerUserNetworkAccess.csr -subj /CN=CustomerUserNetworkAccess:${USERNAME} -addext "subjectAltName=DNS:example.com, email:$USERNAME, otherName:msUPN;UTF8:$USERNAME" -passin pass:${PASSWORD}
# Escape CSR for request
CSR=$(sed 's/$/\\n/' CustomerUserNetworkAccess.csr | tr -d '\n')
REQUEST='{ "csr": "'"${CSR}"'", "idp_oauth_url":"'"${URL}"'", "idp_token": "'"${TOKEN}"'", "idp_client_id": "'"${CLIENT_ID}"'" }'
curl 'https://<Fleet-server-URL>/api/latest/fleet/certificate_authorities/<EST-CA-ID>/request_certificate' \
-X 'POST' \
-H 'accept: application/json, text/plain, */*' \
-H 'authorization: Bearer '"$FLEET_SECRET_REQUEST_CERTIFICATE_API_TOKEN" \
-H 'content-type: application/json' \
--data-raw "${REQUEST}" -o response.json
jq -r .certificate response.json > /opt/company/certificate.pem
```
This script assumes that your company installs a custom Company Portal app or something similar at `/opt/company`, gathers the user's IdP session information, uses username and a password to protect the private key from `/opt/company/userinfo`, and installs that the certificate in `/opt/company`. You will want to modify it to match your company's requirements.
For simplicity, the scripts use a `userinfo` file (below). However, the best practice is to load variables from the output of a command or even a separate network request:
```shell
PASSWORD="<Password-for-the-certificate-private-key>"
USERNAME="<End-user-email>"
TOKEN="<End-user-OAuth-IdP-token>"
CLIENT_ID="<OAuth-IdP-client-ID>"
```
Enforcing IdP validation using `idp_oauth_url` and `idp_token` is optional. If enforced, the CSR must include exactly 1 email which matches the IdP username and must include a UPN attribute which is either a prefix of the IdP username or the username itself (i.e. if the IdP username is "bob@example.com", the UPN may be "bob" or "bob@example.com")
#### HTTP signatures
This method will only work on Linux hosts with TPM (Trusted Platform Module) hardware.
This custom script will create a certificate signing request (CSR) and make a request to Fleet's "Request certificate" API endpoint using HTTP Signed Messages.
This method also requires a means of signing the HTTP request using the TPM key. Fleet has provided a reference implementation written in Go in the Fleet repository under [/orbit/cmd/fetch_cert/](https://github.com/fleetdm/fleet/blob/main/orbit/cmd/fetch_cert/main.go).
The script in this example assumes the reference implementation has been distributed to the machine requesting the certificate.
1. When enrolling the machine, make sure to build packages using the `--fleet-managed-host-identity-certificate` flag. When the client enrolls, this will generate the fleet trusted certificate used to sign the request.
2. Make a request to Fleet's [`GET /certificate_authorities` API endpoint](https://fleetdm.com/docs/rest-api/rest-api#list-certificate-authorities-cas) to get the `id` for your EST CA. You'll use this `id` in your script.
3. In Fleet, head to **Controls > Scripts**, and add a script like the one below, plugging in your own filesystem locations, Fleet server URL and IdP information. For this script to work, the host it's run on has to have openssl installed.
Example script:
```shell
#!/bin/bash
set -e
# Load the end user information, IdP token and IdP client ID.
. /opt/company/userinfo
URL="<IdP-introspection-URL>"
# Generate the password-protected private key
openssl genpkey -algorithm RSA -out /opt/company/CustomerUserNetworkAccess.key -pkeyopt rsa_keygen_bits:2048 -aes256 -pass pass:${PASSWORD}
# Generate CSR signed with that private key. The CN can be changed and DNS attribute omitted if your EST configuration allows it.
openssl req -new -sha256 -key /opt/company/CustomerUserNetworkAccess.key -out CustomerUserNetworkAccess.csr -subj /CN=CustomerUserNetworkAccess:${USERNAME} -addext "subjectAltName=DNS:example.com, email:$USERNAME, otherName:msUPN;UTF8:$USERNAME" -passin pass:${PASSWORD}
fetch_cert -ca <EST-CA-ID> -fleeturl "<Fleet-server-URL>" -csr CustomerUserNetworkAccess.csr -out /opt/company/certificate.pem
```
This script assumes that your company installs a custom Company Portal app or something similar at `/opt/company`, gathers the user's IdP session information, uses a username and password to protect the private key from `/opt/company/userinfo`, and installs the certificate in `/opt/company`. You will want to modify it to match your company's requirements.
For simplicity, the scripts use a `userinfo` file (below). However, the best practice is to load variables from the output of a command or even a separate network request:
```shell
PASSWORD="<Password-for-the-certificate-private-key>"
USERNAME="<End-user-email>"
TOKEN="<End-user-OAuth-IdP-token>"
CLIENT_ID="<OAuth-IdP-client-ID>"
```
### Step 4: Create a custom policy
1. In Fleet, head to **Policies** and select **Add policy**. Use the following query to detect the certificate's existence and if it expires in the next 30 days:
```sql
@@ -482,7 +738,7 @@ SELECT 1 FROM certificates WHERE path = '/opt/company/certificate.pem' AND not_v
## Renewal
Fleet will automatically renew certificates on Apple (macOS, iOS, iPadOS) hosts 30 days before expiration. If the entire validity period is less than 30 days (e.g. 20 days), Fleet will automatically renew at half the validity period (e.g 10 days).
Fleet will automatically renew certificates on Apple (macOS, iOS, iPadOS) hosts 30 days before expiration. If the entire validity period is less than 30 days (e.g. 20 days), Fleet will automatically renew at half the validity period (e.g 10 days). Currently, Fleet does not support automatic renewal for Windows and Linux hosts.
Automatic renewal is only supported if the validity period is set to 2 days or longer.
@@ -494,6 +750,8 @@ If an end user is on vacation (offline for more than 30 days), their certificate
>
> If automatic renewal fails, you can resend the configuration profile manually on the host's **Host details** page, the end user's **Fleet Desktop > My Device** page, or via [Fleet's API](https://fleetdm.com/docs/rest-api/rest-api#resend-custom-os-setting-configuration-profile).
>
## Advanced
### User scoped certificates
@@ -520,7 +778,10 @@ When you edit a certificate configuration profile for Apple hosts, via GitOps, a
* NDES SCEP proxy is currently supported for macOS devices via Apple config profiles. Support for DDM (Declarative Device Management) is coming soon, as is support for iOS, iPadOS, Windows, and Linux.
* Fleet server assumes a one-time challenge password expiration time of 60 minutes.
* On Windows, SCEP challenge strings should NOT include `base64` encoding or special characters such as `! @ # $ % ^ & * _ ()`
* On **Windows**, SCEP challenge strings should NOT include `base64` encoding or special characters such as `! @ # $ % ^ & * _`, and Common Names (CN) should NOT include `+` characters.
* The SCEP Server used for **Windows**, should accept `/pkiclient.exe` at the end, as Windows will always append this to the SCEP URL. If using a Certificate Authority and Fleet Variables, Fleet handles this and strips it away from the request sent to the backing SCEP server.
* On **Windows** hosts, Fleet will not verify the SCEP profile via osquery reports. Fleet will mark it as verified, if a successful request went through, even if the certificate is not present.
* On **Windows** hosts, Fleet will not remove certificates from profiles, when removing the profile from the host, or transferring teams.
### How the SCEP proxy works
@@ -545,6 +806,18 @@ Custom SCEP proxy:
to the host with a new passcode if the host requests a certificate after the passcode has expired.
- The static challenge configured for the custom SCEP server remains in the SCEP profile.
### How to get the CAThumbprint for Windows SCEP profiles
Steps to get CAThumbrint from your SCEP server:
1. Use GetCACert operation to download certificate. For example, open in browser: https://scep-server-url/scep?operation=GetCACert
2. Run the following command to get the SHA1 Thumbprint
1. **Terminal (MacOS)** -> `openssl x509 -inform DER -in /path/to/downloaded-cert.cer -noout -fingerprint -sha1 | sed 's/sha1 Fingerprint=//; s/://g`
2. **PowerShell (Windows)** -> `$cert = Get-PfxCertificate -FilePath "Z:\scep (1).cer";$cert.Thumbprint`
3. It will return the SHA1 Thumbprint without colons and text. Copy this.
4. Use the copied value for `./Device/Vendor/MSFT/ClientCertificateInstall/SCEP/$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID/Install/CAThumbprint` option.
<meta name="articleTitle" value="Connect end users to Wi-Fi or VPN with a certificate (DigiCert, NDES, Hydrant, Smallstep, or custom SCEP)">
<meta name="authorFullName" value="Victor Lyuboslavsky">
<meta name="authorGitHubUsername" value="getvictor">
+1 -1
View File
@@ -4,7 +4,7 @@
_Available in Fleet Premium_
In Fleet you can deploy [Fleet-maintained apps](https://fleetdm.com/guides/fleet-maintained-apps), [App Store (VPP) apps](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet), and custom packages to your hosts.
In Fleet you can deploy [Fleet-maintained apps](https://fleetdm.com/guides/fleet-maintained-apps), [App Store (VPP) apps](https://fleetdm.com/guides/install-app-store-apps), and custom packages to your hosts.
This guide will walk you through steps to manually install custom packages on your hosts.
+2 -2
View File
@@ -8,8 +8,8 @@ This guide will cover how to deploy CrowdStrike Falcon on macOS, Linux and Windo
### Install notes
- Fleet recommends using the End User Setup Experience to install CrowdStrike on hosts when they are initially enrolled and provisioned.
- [macOS Setup](https://fleetdm.com/guides/macos-setup-experience#install-software)
- The best practice is to install CrowdStrike when hosts first enroll to Fleet. Learn how:
- [macOS](https://fleetdm.com/guides/setup-experience#install-software)
- [Linux](https://fleetdm.com/guides/windows-linux-setup-experience#choose-software)
- [Windows](https://fleetdm.com/guides/windows-linux-setup-experience#choose-software)
@@ -16,7 +16,7 @@ By following these steps, you can automate the deployment of Okta Verify across
Okta Verify can be installed:
* As a Volume Purchasing Program (VPP) application, follow [these steps to install VPP apps](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet).
* As a Volume Purchasing Program (VPP) application, follow [these steps to install VPP apps](https://fleetdm.com/guides/install-app-store-apps).
* As a *.pkg *file download the [installer from Okta](https://help.okta.com/oie/en-us/content/topics/identity-engine/devices/ov-install-options-macos.htm) and [deploy the installer using Fleet](https://fleetdm.com/guides/deploy-security-agents).
After installing Okta Verify on the host, the device will be registered in Okta.
+1 -1
View File
@@ -22,7 +22,7 @@ Apple's Device Enrollment Program (DEP) was the original, separate Apple service
The first step is to enable SAML (Security Assertion Markup Language) SSO for your IdP (Identity Provider). Follow the instructions from the [Single sign-on guide](https://fleetdm.com/docs/deploy/single-sign-on-sso). Use the URL ending with `/mdm/sso/callback.` Make sure to assign users to your SAML integration.
You can [require users to authenticate with your IdP before using their Mac](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula). Note that setting up end-user authentication is done globally. However, enabling end-user authentication is done separately for each team. You may test end-user authentication in a separate team before rolling it out to the rest of your organization.
You can [require users to authenticate with your IdP before using their Mac](https://fleetdm.com/guides/setup-experience#end-user-authentication). Note that setting up end-user authentication is done globally. However, enabling end-user authentication is done separately for each team. You may test end-user authentication in a separate team before rolling it out to the rest of your organization.
With end-user authentication enabled for your team, Fleet sends the updated enrollment profile to Apple. This sync happens once a minute and can be adjusted with the [mdm.apple_dep_sync_periodicity](https://fleetdm.com/docs/configuration/fleet-server-configuration#mdm-apple-dep-sync-periodicity) server configuration setting. The relevant attribute of the [Apple enrollment profile](https://developer.apple.com/documentation/devicemanagement/profile) is `configuration_web_url`. Fleet sets it to `{server_url}/mdm/sso`.
+1 -1
View File
@@ -27,7 +27,7 @@ Fleet can now deploy and renew certificates from Microsoft Network Device Enroll
### Software installation status improvements
Fleet now marks [App Store (VPP) apps](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet) as installed once they're visible via Apple MDM inventory, rather than as soon as the installation MDM command is acknowledged by the device. Successful installs and uninstalls (for VPP, [Fleet-maintained apps](https://fleetdm.com/guides/fleet-maintained-apps), and [custom packages](https://fleetdm.com/guides/deploy-software-packages)) also now automatically trigger a host vitals refetch, ensuring that software inventory and policy statuses quickly reflect changes made as a result of adding or removing software, rather than taking up to an hour by default.
Fleet now marks [App Store (VPP) apps](https://fleetdm.com/guides/install-app-store-apps) as installed once they're visible via Apple MDM inventory, rather than as soon as the installation MDM command is acknowledged by the device. Successful installs and uninstalls (for VPP, [Fleet-maintained apps](https://fleetdm.com/guides/fleet-maintained-apps), and [custom packages](https://fleetdm.com/guides/deploy-software-packages)) also now automatically trigger a host vitals refetch, ensuring that software inventory and policy statuses quickly reflect changes made as a result of adding or removing software, rather than taking up to an hour by default.
This release also introduces a clearer differentiation between software installed on a host (Inventory) and software available for install on a host (Library) when viewing software via the Host details page. Further improvements on this page, as well as on the My device page, are [coming soon](https://github.com/fleetdm/fleet/issues/30240).
@@ -21,7 +21,7 @@ Managing security, control, and flexibility across diverse devices can be challe
### Self-service Apple App Store apps
Fleet enables organizations to assign and install Apple App Store apps purchased through the Volume Purchase Program (VPP) directly via Self-Service using Fleet Desktop. This feature lets IT administrators [make VPP-purchased apps available to end users](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet).
Fleet enables organizations to assign and install Apple App Store apps purchased through the Volume Purchase Program (VPP) directly via Self-Service using Fleet Desktop. This feature lets IT administrators [make VPP-purchased apps available to end users](https://fleetdm.com/guides/install-app-store-apps).
By integrating VPP app distribution into the Fleet Desktop Self-Service portal, organizations can streamline the deployment of essential software across their macOS devices. This ensures that users have easy access to the tools they need while maintaining control over software distribution. This update enhances the overall user experience and operational efficiency, empowering end users to install approved applications with minimal IT intervention.
@@ -8,11 +8,11 @@ Fleet can map an end user's IdP username, groups, and department to their host(s
Fleet supports [Okta](#okta), [Microsoft Active Directory (AD) / Entra ID](#microsoft-entra-id), [Google Workspace](#google-workspace), [authentik](#google-workspace), as well as [any other IdP](#other-idps) that supports the [SCIM (System for Cross-domain Identity Management) protocol](https://scim.cloud/).
Fleet gathers IdP host vitals when an end user authenticates during these enrollment scenarios:
Fleet automatically collects IdP host vitals when an [end user authenticates](https://fleetdm.com/guides/setup-experience#end-user-authentication) during these enrollment scenarios:
- Automatic enrollment (ADE) for Apple (macOS, iOS, iPadOS) hosts.
- Manual enrollment for personal (BYOD) iOS, iPadOS, and Android hosts.
Learn how to enforce authentication in the [setup experience guide](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication).
You can also manually add/update a host's IdP username on the Host details page. Fleet will then automatically map the username to other IdP vitals.
## Okta
+48
View File
@@ -0,0 +1,48 @@
# Install app store apps
_Available in Fleet Premium_
In Fleet, you can install Apple App Store apps on your macOS, iOS, and iPadOS hosts. To do this, you must first [turn on Apple MDM](https://fleetdm.com/guides/apple-mdm-setup#turn-on-apple-mdm) and Apple's [Volume Purchasing Program (VPP)](https://fleetdm.com/guides/apple-mdm-setup#volume-purchasing-program-vpp).
You can also manage which Google Play Store apps are available for self-serivce in your end user's Android work profiles.
## Add app
1. In Fleet, head to the **Software** page and select a team in the teams dropdown.
2. Select **Add software > App store** and choose a platform.
3. To add Apple App Store (VPP) apps to Fleet, you must first purchase them through Apple Business Manager (ABM), even if they are free. Learn how in [Apple's documentation](https://support.apple.com/guide/apple-business-manager/select-and-buy-content-axmc21817890/web).
4. To add Google Play Store (Android) apps, head to the [Google Play Store](https://play.google.com/store/apps), find the app, and copy the ID at the end of the URL (e.g. "com.android.chrome")
## Edit or remove app
1. In Fleet, head to the **Software** page and select a team in the teams dropdown.
2. Search for the app you want to remove and select the app to head to it's **Software detail**s** page.
3. To edit the app, on the **Software details** page, select the pencil (edit) icon.
4. To remove the app, on the **Software details** page, select the trash can (delete) icon.
## Install app
Apple App Store (VPP) apps can be installed manually on each host's Host details page. For macOS apps, apps can also be installed via self-service on the end user's **Fleet Desktop > My device** page or [automatically via policy automation](https://fleetdm.com/guides/automatic-software-install-in-fleet).
Currently, Android apps can only be installed via self-service in the end user's managed Google Play Store (work profile).
Currently, Apple App Stpre (VPP) apps can't be uninstalled via Fleet.
## API and GitOps
Fleet also provides a REST API for managing app store apps programmatically. Learn more in the API [reference docs](https://fleetdm.com/docs/rest-api/rest-api#add-app-store-app).
To manage App Store apps using Fleet's best practice GitOps, check out the `app_store_apps` key in [the GitOps reference documentation](https://fleetdm.com/docs/using-fleet/gitops#app-store-apps).
<meta name="articleTitle" value="Install app store apps">
<meta name="authorFullName" value="Jahziel Villasana-Espinoza">
<meta name="authorGitHubUsername" value="jahzielv">
<meta name="category" value="guides">
<meta name="publishedOn" value="2025-02-28">
<meta name="description" value="This guide will walk you through installing Apple App Store and Google Play Store apps on macOS, iOS, iPadOS, and Android hosts.">
@@ -1,121 +0,0 @@
# Install App Store apps (VPP)
![Install VPP apps on macOS using Fleet](../website/assets/images/articles/install-vpp-apps-on-macos-using-fleet-1600x900@2x.png)
_Available in Fleet Premium_
In Fleet, you can install Apple App Store apps using the [Volume Purchasing Program (VPP)](https://support.apple.com/guide/app-store/volume-purchasing-app-store-mac-firc1767ec54/mac) on your macOS, iOS, and iPadOS hosts. This guide will walk you through using this feature to add apps from your Apple Business Manager account to Fleet and install those apps on your hosts.
Once a VPP app has been added to a team, it can be [automatically installed on hosts via policy automations](https://fleetdm.com/guides/automatic-software-install-in-fleet) as of Fleet [v4.63.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.63.0), and policies can be automatically created when adding a VPP app to a team as of [v4.65.0](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.65.0).
## Prerequisites
* **MDM features**: to use the VPP integration, you must first enable MDM features in Fleet. See the [MDM setup guide](https://fleetdm.com/docs/using-fleet/mdm-setup) for instructions on enabling MDM features.
> As of Fleet 4.55.0, there is a [known issue](https://github.com/fleetdm/fleet/issues/20686) that uninstalled or deleted VPP apps will continue to show a status of `installed`.
## Add your VPP token
1. **Navigate to the MDM integration settings page**: Click your avatar on the far right of the main navigation menu, and then **Settings > Integrations > "Mobile device management (MDM)"**
2. **Add your VPP token**: Scroll to the "Volume Purchasing Program (VPP)" section. Click "Add VPP", and then click "Add VPP" again on the following page. Follow the directions on the modal to get your VPP token from Apple Business Manager, and then click the "Upload" button at the bottom to upload it to Fleet.
3. **Edit the team assignment for the new token**: Find the token in the table of VPP tokens. Click the "Actions" dropdown, and then click "Edit teams". Use the picker to select which team(s) this VPP token should be assigned to.
## Purchase an app
To add apps to Fleet, you must first purchase them through Apple Business Manager, even if they are free. This ensures that all apps are appropriately licensed and available for distribution via the Volume Purchasing Program (VPP). For detailed instructions on selecting and buying content, please refer to Apples documentation on [purchasing apps through Apple Business Manager](https://support.apple.com/guide/apple-business-manager/select-and-buy-content-axmc21817890/web).
## Add the app to Fleet
1. **Navigate to the Software page**: Click on the "Software" tab in the main navigation menu.
2. **Select your team**: Click on the "All teams" dropdown in the top left of the page and select your desired team.
3. **Open the "Add software" modal**: Click on the "Add software" button in the top right of the page.
4. **View your available apps**: Click on the "App Store (VPP)" tab in the "Add software" page. The page will list the apps that you have purchased through VPP but still need to add to Fleet.
5. **Configure the app**: Select an app from the list. Select the hosts that you want to target with this app, under "Target". Select "All hosts" if you want the app to be available to all your hosts. Select "Custom" to scope the app to specific groups of hosts based on label membership. You can select "Include any", which will scope the app to hosts that have any of the labels you select, or "Exclude any", which will scope the app to hosts that do _not_ have the selected labels.
> For macOS apps, you can check the "Self-service" box on the page if you wish for the app to be available for user-initiated installs. You can also check the "Automatic install" box to have Fleet create a policy that installs the app on targeted hosts on the team that don't have the app already installed.
6. **Add the app**: Click the "Add software" button in the bottom right of the page. The app should appear in the software list for the selected team.
## Remove the app from Fleet
1. **Navigate to the Software page**: Click "Software" in the main navigation menu.
2. **Find the app you want to remove**: Search for the app using the search bar in the top right corner of the table.
3. **Access the app's details page**: Click on the app's name in the table.
4. **Remove the app**: Click on the "Actions" dropdown on the right side of the page. Click "Delete", then click "Delete" on the confirmation modal. Deleting an app will not uninstall the app from the hosts on which it was previously installed.
## Edit the app
1. **Navigate to the Software page**: Click "Software" in the main navigation menu.
2. **Find the app you want to remove**: Search for the app using the search bar in the top right corner of the table.
3. **Access the app's details page**: Click on the app's name in the table.
4. **Edit the app**: Click on the "Actions" dropdown on the right side of the page. Click "Edit". In the "Edit software" modal, you can change the hosts that you want to target with the app as well as the app's [self-service](https://fleetdm.com/guides/software-self-service) status.
## Install the app
1. **Add the host to the relevant team.**
2. **Go to the host's detail page**: Click the "Hosts" tab in the main navigation menu. Filter the hosts by the team, and click the host's name to see its details page.
3. **Find the app**: Click the **Software** > **Library** tab on the host details page. Search for the software you added in the software table's search bar. Instead of searching, you can also filter software by clicking the **All software** dropdown and selecting **Available for install.**
4. **Install the app**: Click the "Actions" dropdown on the far right of the app's entry in the
table. Click "Install" to trigger an install. This action will send an MDM command to the host
instructing it to install the app. If the host is offline, the upcoming install will show up in
the **Details** > **Activity** > **Upcoming** tab of this page. Once Fleet has verified
that the app is on the host, the app will show up as **Installed** in the **Software** > **Library** tab.
After the app is installed, Fleet will automatically refetch the host's vitals, which will update the
software inventory.
> Currently, VPP apps can't be uninstalled from devices via Fleet. Please see: [Uninstall App Store apps #20729](https://github.com/fleetdm/fleet/issues/20729).
## Install an app via self-service
1. **Open Fleet from the host**: On the host that will be installing an application through self-service, click on the Fleet Desktop tray icon, then click **My Device**. This will open the browser to the device's page on Fleet.
2. **Navigate to the self-service tab**: Click on the **Self-Service** tab under the device's details.
3. **Locate the app and click install**: Scroll through the list of software to find the app you would like to install, then click the **Install** button underneath it.
## Renew your VPP token
When one of your uploaded VPP tokens has expired or is within 30 days of expiring, you will see a warning
banner at the top of page reminding you to renew your token. You can do this with the following steps:
1. **Navigate to the MDM integration settings page**: Click your avatar on the far right of the main navigation menu, and then **Settings > Integrations > "Mobile device management (MDM)"** Scroll to the "Volume Purchasing Program (VPP)" section, and click "Edit".
2. **Renew the token**: Find the VPP token that you want to renew in the table. Token status is indicated in the "Renew date" column: tokens less than 30 days from expiring will have a yellow indicator, and expired tokens will have a red indicator. Click the "Actions" dropdown for the token and then click "Renew". Follow the instructions in the modal to download a new token from Apple Business Manager and then upload the new token to Fleet.
## Delete your VPP token
To remove VPP tokens from Fleet:
1. **Navigate to the MDM integration settings page**: Click your avatar on the far right of the main navigation menu, and then **Settings > Integrations > "Mobile device management (MDM)"**. Scroll to the "Volume Purchasing Program (VPP)" section, and click "Edit".
2. **Delete the token**: Find the VPP token that you want to delete in the table. Click the "Actions" dropdown for that token, and then click "Delete". Click "Delete" in the confirmation modal to finish deleting the token.
## Manage apps with Fleet's REST API
Fleet also provides a REST API for managing apps programmatically. You can add, install, and delete apps via this API and manage your organizations VPP tokens. Learn more about Fleet's [REST API](https://fleetdm.com/docs/rest-api/rest-api).
## Manage apps with GitOps
To manage App Store apps using Fleet's best practice GitOps, check out the `software` key in [the GitOps reference documentation](https://fleetdm.com/docs/using-fleet/gitops#software).
<meta name="articleTitle" value="Install App Store (VPP) apps">
<meta name="authorFullName" value="Jahziel Villasana-Espinoza">
<meta name="authorGitHubUsername" value="jahzielv">
<meta name="category" value="guides">
<meta name="publishedOn" value="2025-02-28">
<meta name="articleImageUrl" value="../website/assets/images/articles/install-vpp-apps-on-macos-using-fleet-1600x900@2x.png">
<meta name="description" value="This guide will walk you through installing VPP apps on macOS, iOS, and iPadOS using Fleet.">
+4 -4
View File
@@ -96,7 +96,7 @@ GitOps is an API-only and write-only role that can be used on CI/CD pipelines.
| View results of MDM commands executed on macOS and Windows hosts\** | ✅ | ✅ | ✅ | ✅ | |
| Edit [OS settings](https://fleetdm.com/docs/rest-api/rest-api#os-settings) | | | ✅ | ✅ | ✅ |
| View all [OS settings](https://fleetdm.com/docs/rest-api/rest-api#os-settings) | | | ✅ | ✅ | ✅ |
| Edit [setup experience](https://fleetdm.com/guides/macos-setup-experience)\* | | | ✅ | ✅ | ✅ |
| Edit [setup experience](https://fleetdm.com/guides/setup-experience)\* | | | ✅ | ✅ | ✅ |
| Add and edit identity provider for end user authentication, end user license agreement (EULA), and end user migration workflow\* | | | | ✅ | |
| Add and edit certificate authorities (CA)\* | | | | ✅ | ✅ |
| Request certificates (CA)\* | | | | ✅ | ✅ |
@@ -173,8 +173,8 @@ Users with access to multiple teams can be assigned different roles for each tea
| Execute MDM commands on macOS and Windows hosts* | | | ✅ | ✅ | |
| View results of MDM commands executed on macOS and Windows hosts* | ✅ | ✅ | ✅ | ✅ | |
| Edit [team OS settings](https://fleetdm.com/docs/rest-api/rest-api#os-settings) | | | ✅ | ✅ | ✅ |
| Edit [setup experience](https://fleetdm.com/guides/macos-setup-experience#macos-setup-assistant)\* | | | ✅ | ✅ | ✅ |
| Schedule and run scripts on hosts | | | ✅ | ✅ | |
| Edit [setup experience](https://fleetdm.com/guides/setup-experience)\* | | | ✅ | ✅ | ✅ |
| Schedule and run scripts on hosts | | | ✅ | ✅ | |
| View saved scripts | ✅ | ✅ | ✅ | ✅ | |
| Edit/upload saved scripts | | | ✅ | ✅ | |
| View script details by host | ✅ | ✅ | ✅ | ✅ | |
@@ -191,4 +191,4 @@ Users with access to multiple teams can be assigned different roles for each tea
<meta name="authorFullName" value="Noah Talerman">
<meta name="publishedOn" value="2024-10-31">
<meta name="articleTitle" value="Role-based access">
<meta name="description" value="Learn about the different roles and permissions in Fleet.">
<meta name="description" value="Learn about the different roles and permissions in Fleet.">
@@ -1,36 +1,16 @@
# macOS setup experience
# Setup experience
_Available in Fleet Premium_
In Fleet, you can customize the out-of-the-box macOS setup.
In Fleet, you can customize the out-of-the-box macOS, Windows, Linux, iOS, iPadOS, and Android setup.
Here's what you can configure, and in what order each happen, to your macOS hosts during setup:
1. Require [end users to authenticate](#end-user-authentication-and-end-user-license-agreement-eula) with your identity provider (IdP) and agree to an end user license agreement (EULA) before they can use their new Mac.
2. By default, Fleet's agent (fleetd) is installed to enroll the host to Fleet. Optionally, you can [deploy fleetd manually](#advanced).
3. Install a [bootstrap package](#bootstrap-package) to gain full control over the setup experience by installing tools like Puppet, Munki, DEP notify, custom scripts, and more.
4. By default, Fleet installs configuration profiles to [enforce OS settings](https://fleetdm.com/guides/custom-os-settings).
5. [Install software](#install-software) (App Store apps, custom packages, and Fleet-maintained apps).
6. [Run a script](#run-script).
7. Customize the [Setup Assistant](#setup-assistant) by choosing to show or hide specific panes.
In addition to the customization above, Fleet automatically installs the fleetd agent during out-of-the-box macOS setup. This agent is responsible for reporting host vitals to Fleet and presenting Fleet Desktop to the end user.
This guide covers macOS, iOS, iPadOS, and Android. Learn more about Windows and Linux in a [separate guide](https://fleetdm.com/guides/windows-linux-setup-experience).
macOS setup features require [connecting Fleet to Apple Business Manager (ABM)](https://fleetdm.com/guides/macos-mdm-setup#apple-business-manager-abm).
## End user authentication and end user license agreement (EULA)
## End user authentication
Using Fleet, you can require end users to authenticate with your identity provider (IdP) and agree to an end user license agreement (EULA) before they can use their new Mac.
### End user authentication
You can enforce end user authentication during automatic enrollment (ADE) for Apple (macOS, iOS, iPadOS) hosts and manual enrollment for personal (BYOD) iOS, iPadOS, and Android hosts.
You can enforce end user authentication during automatic enrollment (ADE) for Apple (macOS, iOS, iPadOS) hosts and manual enrollment for personal (BYOD) iOS, iPadOS, and Android hosts. End user authentication is also supported on [Windows and Linux](https://fleetdm.com/guides/windows-linux-setup-experience).
1. Create a new SAML app in your IdP. In your new app, use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` for the SSO URL. If this URL is set incorrectly, end users won't be able to enroll. On iOS hosts, they'll see a "This screen size is not supported yet" error message.
@@ -48,13 +28,15 @@ You can enforce end user authentication during automatic enrollment (ADE) for Ap
> (SSO)](https://fleetdm.com/docs/deploy/single-sign-on-sso) in Fleet, you still want to create a
> new SAML app for end user authentication. This way, only Fleet users can log in to Fleet.
### End user license agreement (EULA)
## End user license agreement (EULA)
To require a EULA, in Fleet, head to **Settings > Integrations > Automatic enrollment > End user license agreement (EULA)** or use the [Fleet API](https://fleetdm.com/docs/rest-api/rest-api#upload-an-eula-file).
Currently, a custom EULA is only supported for macOS hosts.
## Bootstrap package
Fleet supports installing a bootstrap package on macOS hosts that automatically enroll to Fleet. Apple requires that your package is a [distribution package](https://fleetdm.com/learn-more-about/macos-distribution-packages).
Fleet supports installing a bootstrap package on macOS hosts that automatically enroll to Fleet. Apple requires that your package is a [distribution package](https://fleetdm.com/learn-more-about/macos-distribution-packages). You can install software during out-of-the-box Windows and Linux setup. Learn more in [this separate guide](https://fleetdm.com/guides/windows-linux-setup-experience).
This enables installing tools like [Puppet](https://www.puppet.com/), [Munki](https://www.munki.org/munki/), or [Chef](https://www.chef.io/products/chef-infra) for configuration management and/or running custom scripts and installing tools like [DEP notify](https://gitlab.com/Mactroll/DEPNotify) to customize the setup experience for your end users.
@@ -139,36 +121,10 @@ To sign the package we need a valid Developer ID Installer certificate:
3. Select **Upload** and choose your bootstrap package.
## Software and script
You can configure software installations and a script to be executed during Setup Assistant. This capability allows you to configure your end users' machines during the unboxing experience, speeding up their onboarding and reducing setup time.
If you configure software and/or a script for setup experience, users will see a window like this pop open after their device enrolls in MDM via ADE:
![screen shot of Fleet setup experience window](../website/assets/images/articles/install-software-preview-462x364@2x.png)
This window shows the status of the software installations as well as the script exectution. Once all steps have completed, the window can be closed and Setup Assistant will proceed as usual.
To replace the Fleet logo with your organization's logo:
1. Go to **Settings** > **Organization settings** > **Organization info**
2. Add URLs to your logos in the **Organization avatar URL (for dark backgrounds)** and **Organization avatar URL (for light backgrounds)** fields
3. Press **Save**
> See [configuration documentation](https://fleetdm.com/docs/configuration/yaml-files#org-info) for recommended logo sizes.
> The setup experience script always runs after setup experience software is installed. Currently, software that [automatically installs](https://fleetdm.com/guides/automatic-software-install-in-fleet) and scripts that [automatically run](https://fleetdm.com/guides/policy-automation-run-script) are also installed and run during Setup Assistant but won't appear in the window. Automatic software and scripts may run before or after setup the experience software/script. They aren't installed/run in any particular order.
### Install software
## Install software
You can install software during first time macOS, iOS, iPadOS and [Windows and Linux setup](https://fleetdm.com/guides/windows-linux-setup-experience). Android support is coming soon.
For macOS, Windows, and Linux hosts, software installs are automatically attempted up to 3 times (1 initial attempt + 2 retries) to handle intermittent network issues or temporary failures. When Fleet retries, IT admins can see error messages for all attempts in the **Host details > Activity** card. The end user only sees an error message if the third, and final, attempt fails.
Retries only happen for custom packages and Fleet-maintained apps. For App Store (VPP) apps, the MDM command to install the app is sent once and either succeeds or fails. If it fails, the app wont install no matter how many times Fleet resends the command.
Currently, for macOS, iOS, and iPadOS hosts, software is only installed on hosts that automatically enroll to Fleet via Apple Business Manager (ABM).
Add setup experience software:
1. Click on the **Controls** tab in the main navigation bar, then **Setup experience** > **4. Install software**.
@@ -176,7 +132,12 @@ Add setup experience software:
2. Click **Add software**, then select or search for the software you want installed during the setup experience.
3. Press **Save** to save your selection.
To see the end user experience on iOS/iPadOS, check out the [iOS video](https://www.youtube.com/shorts/_XXNGrQPqys) and [iPadOS video](https://www.youtube.com/shorts/IIzo4NyUolM).
### Retries
For macOS, Windows, and Linux hosts, software installs are automatically attempted up to 3 times (1 initial attempt + 2 retries) to handle intermittent network issues or temporary failures. When Fleet retries, IT admins can see error messages for all attempts in the **Host details > Activity** card. The end user only sees an error message if the third, and final, attempt fails.
Retries only happen for custom packages and Fleet-maintained apps. For App Store (VPP) apps, the MDM command to install the app is sent once and either succeeds or fails. If it fails, the app wont install no matter how many times Fleet resends the command.
#### Blocking setup on failed software installs
You may additionally configure the setup experience to halt immediately if any software item fails to install. To enable this feature:
@@ -189,7 +150,7 @@ When this feature is enabled, any failed software will immediately end the setup
![screen shot of Fleet setup experience failed view](../website/assets/images/articles/setup-experience-failed-470x245@2x.png)
### Run script
## Run script
To configure a script to run during setup experience:
@@ -197,7 +158,15 @@ To configure a script to run during setup experience:
2. Click **Upload** and select a script (.sh file) from the file picker modal.
> Once the script is uploaded, you can use the buttons on the script in the web UI to download or delete the script.
To replace the Fleet logo with your organization's logo:
1. Go to **Settings** > **Organization settings** > **Organization info**
2. Add URLs to your logos in the **Organization avatar URL (for dark backgrounds)** and **Organization avatar URL (for light backgrounds)** fields
3. Press **Save**
> See [configuration documentation](https://fleetdm.com/docs/configuration/yaml-files#org-info) for recommended logo sizes.
> The setup experience script always runs after setup experience software is installed. Currently, software that [automatically installs](https://fleetdm.com/guides/automatic-software-install-in-fleet) and scripts that [automatically run](https://fleetdm.com/guides/policy-automation-run-script) are also installed and run during Setup Assistant but won't appear in the window. Automatic software and scripts may run before or after the setup experience software/script. They aren't installed/run in any particular order.
### Exiting the setup experience
@@ -207,7 +176,6 @@ The Fleet setup experience for macOS will exit if any of the following occurs:
* All setup steps complete, including failed installs or script runs, with the "Cancel setup if software install fails" option _not_ enabled (see ["Blocking setup on failed software installs"](https://fleetdm.com/guides/macos-setup-experience#install-software)).
* The user presses Command (⌘) + Shift + X at any time during the setup process.
## Setup Assistant
When an end user unboxes their new Apple device, or starts up a freshly wiped device, they're presented with the Setup Assistant. Here they see panes that allow them to configure accessibility, appearance, and more.
@@ -258,11 +226,11 @@ Testing requires a test Mac that is present in your Apple Business Manager (ABM)
4. Boot up your test Mac and complete the custom out-of-the-box setup experience.
### Configuring via REST API
## Configuring via REST API
Fleet also provides a REST API for managing setup experience software and scripts programmatically. Learn more about Fleet's [REST API](https://fleetdm.com/docs/rest-api/rest-api).
### Configuring via GitOps
## Configuring via GitOps
To manage setup experience software and script using Fleet's best practice GitOps, check out the `macos_setup` key in the [GitOps reference documentation](https://fleetdm.com/docs/configuration/yaml-files#macos-setup)
@@ -289,5 +257,5 @@ If you deploy a custom fleetd, also add the software and scripts you want to ins
<meta name="authorGitHubUsername" value="noahtalerman">
<meta name="authorFullName" value="Noah Talerman">
<meta name="publishedOn" value="2024-07-03">
<meta name="articleTitle" value="macOS setup experience">
<meta name="description" value="Customize your macOS setup experience with Fleet Premium by managing user authentication, Setup Assistant panes, and installing bootstrap packages.">
<meta name="articleTitle" value="Setup experience">
<meta name="description" value="Customize the out-of-the-box macOS, Windows, Linux, iOS, iPadOS, and Android setup">
+2 -2
View File
@@ -11,7 +11,7 @@ Fleets self-service software lets end users update and install approved apps
1. Select the team to which you want to add the software from the dropdown in the upper left corner of the page.
2. Select **Software** in the main navigation menu.
3. Select the **Add software** button in the upper right corner of the page.
4. Pick a [Fleet-maintained app](https://fleetdm.com/guides/fleet-maintained-apps), [App Store (VPP) app](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet#add-the-app-to-fleet), or upload a [custom package](https://fleetdm.com/guides/deploy-software-packages).
4. Pick a [Fleet-maintained app](https://fleetdm.com/guides/fleet-maintained-apps), [app store app](https://fleetdm.com/guides/install-app-store-apps#add-the-app-to-fleet), or upload a [custom package](https://fleetdm.com/guides/deploy-software-packages).
5. Check **Self-service** to make it available for self-service as soon as it's added.
You can also add the software and later make it available in self-service:
@@ -19,7 +19,7 @@ You can also add the software and later make it available in self-service:
1. Select the team to which you added the software from the dropdown in the upper left corner of the page.
2. Select **Software** in the main navigation menu.
3. Select the **All software** dropdown and choose **Available for install.** This filters the results in the table to show only software that can be installed on hosts. If you dont see your software, page through the results or search for your software's name in the search bar. Once you find the software, select its title.
4. Select the pencil (edit) icon and check **Self-service** in the **Options** section. You can also assign categories and add a custom icon to your software to customize the end user experience on the **My device > Self-service** page. Custom icons are only available for [custom packages](https://fleetdm.com/guides/deploy-software-packages) and [App Store (VPP) apps](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet).
4. Select the pencil (edit) icon and check **Self-service** in the **Options** section. You can also assign categories and add a custom icon. Icons appear on the **My device > Self-service** page. Custom icons are only available for [custom packages](https://fleetdm.com/guides/deploy-software-packages) and [app store apps](https://fleetdm.com/guides/install-app-store-apps).
5. Select the **Save** button.
If a software item isn't made available in self-service, end users will not see it in **Fleet Desktop > Self-service**. IT admins can still install, update, and uninstall the software from Fleet.
@@ -34,9 +34,9 @@ If you would like to use Fleet's macOS MDM features, the following endpoints nee
- `/api/mdm/apple/enroll`: If you use automatic enrollment, allows hosts to get an enrollment profile.
- `/api/*/fleet/device/*`: Provides end users access to their **My device** page.
- This page is where they download their manual enrollment profile, rotate their disk encryption key, and use other features. For more information on these API endpoints see the [API documentation for device-authenticated routes](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/api-for-contributors.md#device-authenticated-routes).
- `/mdm/sso`, `/api/*/fleet/mdm/sso`, `/mdm/sso/callback`, `/api/*/fleet/mdm/sso/callback`, and `/assets/*`: If you use automatic enrollment and you require [end user authentication](https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#end-user-authentication-and-eula) during out-of-the-box macOS setup, allows end users to authenticate with your IdP.
- `/api/*/fleet/mdm/setup/eula/*`: If you use automatic enrollment and you require that the end user agrees to an [End User License Agreement (EULA)](https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#end-user-authentication-and-eula) during out-of-the-box macOS setup, allows end user to see the EULA.
- `/api/*/fleet/mdm/bootstrap`: If you use automatic enrollment and you install a [bootstrap package](https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#bootstrap-package) during out-of-the-box macOS setup, installs the bootstrap package.
- `/mdm/sso`, `/api/*/fleet/mdm/sso`, `/mdm/sso/callback`, `/api/*/fleet/mdm/sso/callback`, and `/assets/*`: If you use automatic enrollment and you require [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication) during out-of-the-box macOS setup, allows end users to authenticate with your IdP.
- `/api/*/fleet/mdm/setup/eula/*`: If you use automatic enrollment and you require that the end user agrees to an [End User License Agreement (EULA)](https://fleetdm.com/guides/setup-experience#end-user-authentication) during out-of-the-box macOS setup, allows end user to see the EULA.
- `/api/*/fleet/mdm/bootstrap`: If you use automatic enrollment and you install a [bootstrap package](https://fleetdm.com/guides/setup-experience#end-user-authentication) during out-of-the-box macOS setup, installs the bootstrap package.
> The `/mdm/apple/scep` and `/mdm/apple/mdm` endpoints are outside of the `/api` path because they
> are not RESTful and are not intended for use by API clients or browsers.
+25 -6
View File
@@ -2,7 +2,26 @@
_Available in Fleet Premium_
In Fleet, you can customize the software that's installed when a new Windows and Linux workstations enroll to Fleet.
In Fleet, you can customize the out-of-the-box Windows and Linux setup.
Here's what you can configure, and in what order each happen, to your Windows and Linux hosts during setup:
1. Require [end users to authenticate](#end-user-authentication) with your identity provider (IdP).
2. [Install software](#install-software) (App Store apps, custom packages, and Fleet-maintained apps).
## End user authentication
### End user experience
Fleet automatically opens the default web browser and directs the end user to log in before the setup process can continue.
Learn how to enforce authentication in the [setup experience guide](https://fleetdm.com/guides/setup-experience#end-user-authentication).
> If the Fleet agent (fleetd) installed on the host is older than version 1.50.0, end user authentication won't be enforced.
## Install software
### End user experience
Fleet automatically opens the default web browser to show end users software install progress:
@@ -10,7 +29,7 @@ Fleet automatically opens the default web browser to show end users software ins
The browser can be closed, and the installation will continue in the background. End users can return to the setup experience page by clicking **My Device** from Fleet Desktop. Once all steps have completed, the **My Device** page will show the host information as usual.
If software installs fail, Fleet automatically retries. Learn more in the [macOS setup experience guide](https://fleetdm.com/guides/macos-setup-experience#install-software).
If software installs fail, Fleet automatically retries. Learn more in the [setup experience guide](https://fleetdm.com/guides/setup-experience#end-user-authentication).
To replace the Fleet logo with your organization's logo:
@@ -20,14 +39,14 @@ To replace the Fleet logo with your organization's logo:
> See [configuration documentation](https://fleetdm.com/docs/configuration/yaml-files#org-info) for recommended logo sizes.
> Software installations during setup experience are automatically attempted up to 3 times (1 initial attempt + 2 retries) to handle intermittent network issues or temporary failures. This ensures a more reliable setup process for end users.
> Software installations during setup experience are automatically attempted up to 3 times (1 initial attempt + 2 retries) to handle intermittent network issues or temporary failures. This ensures a more reliable setup process for end users.
## Choose software
### Add software
To pick which software is installed during the setup experience:
Add setup experience software setup experience:
1. Click on the **Controls** tab in the main navigation bar, then **Setup experience** > **3. Install software**.
2. Click on the tab corresponding to the operating system you're configuring: either **macOS**, **Windows**, or **Linux**.
2. Click on the tab corresponding to the operating system (e.g. Linux).
3. Click **Add software**, then select or search for the software you want installed during the setup experience.
4. Press **Save** to save your selection.
+1 -1
View File
@@ -2557,7 +2557,7 @@ spec:
expectedErr error
}{
{"signed.pkg", nil},
{"unsigned.pkg", errors.New("applying fleet config: Couldnt edit bootstrap_package. The bootstrap_package must be signed. Learn how to sign the package in the Fleet documentation: https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#step-2-sign-the-package")},
{"unsigned.pkg", errors.New("applying fleet config: Couldnt edit bootstrap_package. The bootstrap_package must be signed. Learn how to sign the package in the Fleet documentation: https://fleetdm.com/learn-more-about/setup-experience/bootstrap-package")},
{"invalid.tar.gz", errors.New("applying fleet config: Couldnt edit bootstrap_package. The file must be a package (.pkg).")},
{"wrong-toc.pkg", errors.New("applying fleet config: checking package signature: decompressing TOC: unexpected EOF")},
}
+34 -19
View File
@@ -418,18 +418,19 @@ In Fleet Premium, you can use reserved variables beginning with `$FLEET_VAR_`. F
| ---- | --------- | ----------- |
| <span style="display: inline-block; min-width: 240px;">`$FLEET_VAR_NDES_SCEP_CHALLENGE`</span> | macOS, iOS, iPadOS | Fleet-managed one-time NDES challenge password used during SCEP certificate configuration profile deployment. |
| `$FLEET_VAR_NDES_SCEP_PROXY_URL` | macOS, iOS, iPadOS | Fleet-managed NDES SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment. |
| `$FLEET_VAR_HOST_END_USER_IDP_USERNAME` | macOS, iOS, iPadOS | Host's IdP username (e.g. "user@example.com"). When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_FULL_NAME` | macOS, iOS, iPadOS | Host's IdP full name. When this changes, Fleet will automatically resend the profile. |` | macOS, iOS, iPadOS | Host's IdP username. When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_USERNAME_LOCAL_PART` | macOS, iOS, iPadOS | Local part of the email (e.g. john from john@example.com). When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_GROUPS` | macOS, iOS, iPadOS | Comma separated IdP groups that host belongs to. When these change, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_DEPARTMENT` | macOS, iOS, iPadOS | Host's IdP department. When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_UUID` | Windows | Host's hardware UUID. (Equivalent of Apple's built-in `%HardwareUUID%`.) |
| `$FLEET_VAR_HOST_END_USER_IDP_USERNAME` | macOS, iOS, iPadOS, Windows | Host's IdP username (e.g. "user@example.com"). When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_FULL_NAME` | macOS, iOS, iPadOS, Windows | Host's IdP full name. When this changes, Fleet will automatically resend the profile. |` | macOS, iOS, iPadOS | Host's IdP username. When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_USERNAME_LOCAL_PART` | macOS, iOS, iPadOS, Windows | Local part of the email (e.g. john from john@example.com). When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_GROUPS` | macOS, iOS, iPadOS, Windows | Comma separated IdP groups that host belongs to. When these change, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_END_USER_IDP_DEPARTMENT` | macOS, iOS, iPadOS, Windows | Host's IdP department. When this changes, Fleet will automatically resend the profile. |
| `$FLEET_VAR_HOST_UUID` | macOS, iOS, iPadOS, Windows | Host's hardware UUID. |
| `$FLEET_VAR_HOST_HARDWARE_SERIAL` | macOS, iOS, iPadOS | Host's hardware serial number. |
| `$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed one-time challenge password used during SCEP certificate configuration profile deployment. `<CA_NAME>` should be replaced with name of the certificate authority configured in [scep_proxy](#scep-proxy). |
| `$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment. |
| `$FLEET_VAR_CUSTOM_SCEP_CHALLENGE_<CA_NAME>` | macOS, iOS, iPadOS, Windows | Fleet-managed one-time challenge password used during SCEP certificate configuration profile deployment. `<CA_NAME>` should be replaced with name of the certificate authority configured in [scep_proxy](#scep-proxy). |
| `$FLEET_VAR_CUSTOM_SCEP_PROXY_URL_<CA_NAME>` | macOS, iOS, iPadOS, Windows | Fleet-managed SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment. |
| `$FLEET_VAR_SCEP_RENEWAL_ID` | macOS, iOS, iPadOS | Fleet-managed ID that's required to automatically renew Smallstep, Microsoft NDES, and custom SCEP certificates. The ID must be specified in the Organizational Unit (OU) field in the configuration profile. |
| `$FLEET_VAR_DIGICERT_PASSWORD_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed password required to decode the base64-encoded certificate data issued by a specified DigiCert certificate authority during PKCS12 profile deployment. `<CA_NAME>` should be replaced with name of the certificate authority configured in [digicert](#digicert). |
| `$FLEET_VAR_DIGICERT_PASSWORD_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed password required to decode the base64-encoded certificate data issued by a specified DigiCert certificate authority during PKCS12 profile deployment. `<CA_NAME>` should be replaced with name of the certificate authority configured in [digicert](#digicert). |
| `$FLEET_VAR_DIGICERT_DATA_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed base64-encoded certificate data issued by a specified DigiCert certificate authority during PKCS12 profile deployment. `<CA_NAME>` should be replaced with name of the certificate authority configured in [digicert](#digicert). |
| `$FLEET_VAR_SCEP_WINDOWS_CERTIFICATE_ID` | Windows | ID used for SCEP configuration profile on Windows. It must be included in the `<LocURI>` field.|
| `$FLEET_VAR_SMALLSTEP_SCEP_CHALLENGE_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed one-time Smallstep challenge password used during SCEP certificate configuration profile deployment. `<CA_NAME>` should be replaced with name of the certificate authority configured in [scep_proxy](#scep-proxy). |
| `$FLEET_VAR_SMALLSTEP_SCEP_PROXY_URL_<CA_NAME>` | macOS, iOS, iPadOS | Fleet-managed Smallstep SCEP proxy endpoint URL used during SCEP certificate configuration profile deployment. |
@@ -439,7 +440,7 @@ If certificate authority (CA) variables (ex. `$FLEET_VAR_DIGICERT_DATA_<CA_NAME>
### macos_setup
The `macos_setup` section lets you control the out-of-the-box macOS [setup experience](https://fleetdm.com/guides/macos-setup-experience) for hosts that use Automated Device Enrollment (ADE).
The `macos_setup` section lets you control the out-of-the-box macOS [setup experience](https://fleetdm.com/guides/setup-experience) for hosts that use Automated Device Enrollment (ADE).
> **Experimental feature.** The `manual_agent_install` feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
@@ -479,10 +480,10 @@ Can only be configured for all teams (`default.yml`).
> **Experimental feature**. This feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
The `software` section allows you to configure packages, Apple App Store apps, and Fleet-maintained apps that you want to install on your hosts.
The `software` section allows you to configure packages, store apps (Apple App Store and Google Play Store), and Fleet-maintained apps that you want to install on your hosts.
- `packages` is a list of paths to custom packages (.pkg, .msi, .exe, .deb, .rpm, .tar.gz, .sh, or .ps1).
- `app_store_apps` is a list of Apple App Store apps.
- `app_store_apps` is a list of Apple App Store or Android Play Store apps.
- `fleet_maintained_apps` is a list of Fleet-maintained apps.
Currently, you can specify `install_software` in the [`policies` YAML](#policies) to automatically install a custom package or App Store app when a host fails a policy. [Automatic install support for Fleet-maintained apps](https://github.com/fleetdm/fleet/issues/29584) is coming soon.
@@ -529,15 +530,15 @@ software:
```
#### self_service, labels, categories, and setup_experience
- `self_service` specifies whether end users can install from **Fleet Desktop > Self-service** (default: `false`). Currently, for App Store apps, this setting only applies to macOS and is ignored on other platforms. For example, if the app is supported on macOS, iOS, and iPadOS, and `self_service` is set to `true`, it will be available in self_service on macOS workstations but not on iPhones or iPads.
- `self-service` specifies whether end users can install from **Fleet Desktop > Self-service** (default: `false`) on macOS or [self-service web app](https://fleetdm.com/learn-more-about/deploy-self-service-to-ios) on iOS/iPadOS.
- `labels_include_any` targets hosts that have **any** of the specified labels. `labels_exclude_any` targets hosts that have **none** of the specified labels. Only one of these fields can be set. If neither is set, all hosts are targeted.
- `categories` groups self-service software on your end users' **Fleet Desktop > My device** page. If none are set, Fleet-maintained apps get their [default categories](https://github.com/fleetdm/fleet/tree/main/ee/maintained-apps/outputs) and all other software only appears in the **All** group. Supported values:
- `Browsers`: shown as **🌎 Browsers**
- `Communication`: shown as **👬 Communication**
- `Developer tools`: shown as **🧰 Developer tools**
- `Productivity`: shown as **🖥️ Productivity**
- `setup_experience` installs the software when hosts enroll (default: `false`). Learn more in the [setup experience guide](https://fleetdm.com/guides/macos-setup-experience).
- `setup_experience` installs the software when hosts enroll (default: `false`). Learn more in the [setup experience guide](https://fleetdm.com/guides/setup-experience).
### packages
@@ -586,7 +587,7 @@ You can view the hash for existing software in the software detail page in the F
+ Make sure to include only the ID itself, and not the `id` prefix shown in the URL. The ID must be wrapped in quotes as shown in the example so that it is processed as a string.
- `icon.path` is a relative path to the PNG icon that will be displayed in Fleet and on **Fleet Desktop > Self-service** instead of the default icon the icon sourced from Apple. It must be a square PNG with dimensions between 120x120 px and 1024x1024 px. Custom icons will only override the icon for the software title and team where they are added.
Currently, one app for each of an App Store app's supported platforms are added, along with all specified settings (e.g. `self_service`). If software for one platform is deleted in the UI, it will come back when GitOps is re-run. For example, adding [Bear](https://apps.apple.com/us/app/bear-markdown-notes/id1016366447) (supported on iOS and iPadOS) adds both the iOS and iPadOS apps to your software that's available to install in Fleet. Specifying specific platforms is only supported using Fleet's UI or [API](https://fleetdm.com/docs/rest-api/rest-api) (YAML coming soon).
To add the same App Store app for multiple platforms, specify the `app_store_id` multiple times, along with the `platform` you want. If you don't specify a platform, one app for each available platform will be added (macOS, iOS, and iPadOS).
### fleet_maintained_apps
@@ -659,7 +660,7 @@ Can only be configured for all teams (`org_settings`) and custom teams (`team_se
```yaml
org_settings:
host_expiry_settings:
host_expiry_enabled: true
host_expiry_enabled: true
host_expiry_window: 10
```
@@ -833,6 +834,8 @@ _Available in Fleet Premium._
This section lets you configure your [certificate authorities (CA)](https://fleetdm.com/guides/certificate-authorities) to help your end users connect to Wi-Fi and VPN.
#### Example
`default.yml`
@@ -859,6 +862,11 @@ org_settings:
url: https://example.com/scep
challenge: $SCEP_VPN_CHALLENGE
custom_est_proxy:
- name: SECTIGO_WIFI
url: https://example.com/.well-known/est/abc123
username: $SECTIGO_USERNAME_PASSWORD
password: $SECTIGO_WIFI_PASSWORD
hydrant: # Available in Fleet Premium
- name: EST_WIFI
url: https://example.com/est
username: $EST_PROXY_USERNAME
@@ -903,6 +911,13 @@ Can only be configured for all teams (`org_settings`).
- `url` is the URL of the Simple Certificate Enrollment Protocol (SCEP) server.
- `challenge` is the static challenge password used to authenticate requests to SCEP server.
#### custom_est_proxy
- `name` is the name of the certificate authority. Only letters, numbers, and underscores are allowed.
- `url` is the EST (Enrollment Over Secure Transport) endpoint's URL.
- `username` is the username used to authenticate with the EST endpoint.
- `password` is the password used to authenticate with the EST endpoint.
#### hydrant
- `name` is the name of the certificate authority that will be used in variables in configuration profiles. Only letters, numbers, and underscores are allowed.
@@ -1062,7 +1077,7 @@ org_settings:
#### end_user_authentication
The `end_user_authentication` section lets you define the identity provider (IdP) settings used for [end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-eula) during Automated Device Enrollment (ADE).
The `end_user_authentication` section lets you define the identity provider (IdP) settings used for [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication) during Automated Device Enrollment (ADE).
Once the IdP settings are configured, you can use the [`controls.macos_setup.enable_end_user_authentication`](#macos-setup) key to control the end user experience during ADE.
@@ -1163,4 +1178,4 @@ Unlike other options, omitting `smtp_settings` or leaving it blank won't reset t
<meta name="title" value="GitOps">
<meta name="description" value="Reference documentation for Fleet's GitOps workflow. See examples and configuration options.">
<meta name="pageOrderInSection" value="1500">
<meta name="pageOrderInSection" value="1500">
@@ -427,6 +427,42 @@ After login, SimpleSAML should redirect the user to Fleet.
<meta name="pageOrderInSection" value="200">
## Testing End-User Authentication
The SimpleSAML identity provider can also be used to test end-user authentication during the device setup experience.
### Configuration
To test devices on the same network, the easiest method is:
1. Start your local Fleet instance using the server cert and key from `/tools/osquery`, e.g.
```
fleet serve --server_cert ./tools/osquery/fleet.crt --server_key ./tools/osquery/fleet.key ...etc...
```
This allows devices to connect using `host.docker.internal` as the server address.
2. Add an entry in the candidate device's `/etc/hosts` (or for Windows, `\WINDOWS\system32\drivers\etc\hosts`) pointing `host.docker.internal` to the IP address of the computer running your Fleet instance.
3. Configure End-User Authentication on the **Integration settings -> Single Sign On -> End Users** page with the following:
```
Identity Provider Name: SimpleSAML
Entity ID: mdm.host.docker.internal
Metadata URL: http://host.docker.internal:9080/simplesaml/saml2/idp/metadata.php
```
4. Configure the Fleet server address in **Settings -> Organization settings -> Fleet web address** to:
```
https://host.docker.internal:8080
```
5. Make sure the Orbit running on your host devices uses the same `fleet.crt` certificate and `https://host.docker.internal:8080` as the Fleet address, either by building a package using `--fleet-certificate` and `--fleet-url` or running Orbit from source using those same options.
## Testing Kinesis logging
Install the `aws` client: `brew install aws-cli`
@@ -1,6 +1,6 @@
## Custom configuration web URL
In Fleet, [you can require end users to authenticate with your identity provider (IdP) before they can use their new Mac](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula).
In Fleet, [you can require end users to authenticate with your identity provider (IdP) before they can use their new Mac](https://fleetdm.com/guides/setup-experience#end-user-authentication).
Some customers require end users to authenticate with a custom web application instead of an IdP.
@@ -1,6 +1,6 @@
# End user authentication
- [Fleet's guide for setting up end user authentication during macOS setup experience](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula)
- [Fleet's guide for setting up end user authentication during macOS setup experience](https://fleetdm.com/guides/setup-experience#end-user-authentication)
- On Fleet's [pricing page](https://fleetdm.com/pricing), this feature is called `User account sync` (as of 2025/03/31)
- Also known as: IdP integration
@@ -1044,7 +1044,7 @@ If no team (id or name) is provided, the profiles are applied for all hosts (for
`204`
### Initiate SSO during DEP or Account Driven MDM enrollment
### Initiate SSO for end-user authentication during macOS, Windows or Linux setup
This endpoint initiates the SSO flow, the response contains an URL that the client can use to redirect the user to initiate the SSO flow in the configured IdP.
@@ -1056,7 +1056,9 @@ A successful response contains an HTTP cookie `__Host-FLEETSSOSESSIONID` that ne
| Name | Type | In | Description |
| ---- | ---- | -- | ----------- |
| initiator | string | body | Used to differentiate between account driven enrollment and DEP or other flows for SSO callback purposes. The callback will use the Account Driven Enrollment behavior if `account_driven_enroll` is passed as the value of this parameter |
| initiator | string | body | Used to differentiate between account driven enrollment and DEP or other flows for SSO callback purposes. The callback will use the Account Driven Enrollment behavior if `account_driven_enroll` is passed as the value of this parameter. Use `setup_experience` to initiate a web-based SSO login outside of the DEP flow. |
| user_identifier | string | body | Passed by Apple for account-driven enrollment.
| host_uuid | string | body | The hardware UUID of the device to enroll when using the `setup_experience` value for `initiator`.
#### Example
@@ -3142,6 +3144,16 @@ Same as [Refetch host route](https://fleetdm.com/docs/using-fleet/rest-api#refet
| ----- | ------ | ---- | ---------------------------------- |
| token | string | path | The device's authentication token. |
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
#### Get device's Google Chrome profiles
Same as [Get host's Google Chrome profiles](https://fleetdm.com/docs/using-fleet/rest-api#get-hosts-google-chrome-profiles) for the current device.
@@ -3251,6 +3263,16 @@ Lists the software installed on the current device.
| page | integer | query | Page number of the results to fetch.|
| per_page | integer | query | Results per page.|
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
##### Example
`GET /api/v1/fleet/device/bbb7cdcc-f1d9-4b39-af9e-daa0f35728e8/software`
@@ -3363,6 +3385,16 @@ Retrieve the icon added via Fleet or icon from App Store (VPP).
| ---- | ------- | ---- | ----------------------------------------- |
| id | integer | path | ID of the software title to get icon for. |
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
This endpoint will redirect (302) to the Apple-hosted URL of an icon if an icon override isn't set and a VPP app is added for the title on the host's team.
#### Example
@@ -3471,6 +3503,16 @@ Install self-service software on macOS, Windows, or Linux (Ubuntu) host. The sof
| token | string | path | **Required**. The device's authentication token. |
| software_title_id | string | path | **Required**. The software title's ID. |
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
##### Example
`POST /api/v1/fleet/device/22aada07-dc73-41f2-8452-c0987543fd29/software/install/123`
@@ -3492,6 +3534,16 @@ Uninstalls software from a host via the My device page.
| token | string | path | **Required**. The device's authentication token. |
| software_title_id | integer | path | **Required**. The software title's ID. |
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
#### Example
`POST /api/v1/fleet/device/22aada07-dc73-41f2-8452-c0987543fd29/software/uninstall/123`
@@ -3667,6 +3719,16 @@ Returns the URL to open when clicking the "About Fleet" menu item in Fleet Deskt
| ----- | ------ | ---- | ---------------------------------- |
| token | string | path | The device's authentication token. |
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
##### Example
`GET /api/v1/fleet/device/abcdef012456789/transparency`
@@ -3679,7 +3741,9 @@ Redirects to the transparency URL.
#### Download device's MDM manual enrollment profile
Downloads the Mobile Device Management (MDM) enrollment profile to install on the device for a manual enrollment into Fleet MDM.
Returns the URL to open to provide installation instructions and allow a user to download a manual enrollment profile
for a device. A user may be required to complete SSO authenticaton if configured on the team before being presented
with the download option.
`GET /api/v1/fleet/device/{token}/mdm/apple/manual_enrollment_profile`
@@ -3697,12 +3761,10 @@ Downloads the Mobile Device Management (MDM) enrollment profile to install on th
`Status: 200`
```xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<!-- ... -->
</plist>
```json
{
"enroll_url": "https://your-fleet-server-url.com/enroll?enroll_secret=ABCzmPbtEECxZhHlFlz9uTWApZmXsCND"
}
```
---
@@ -194,6 +194,20 @@ Key that allows the Fleet server to communicate to the Microsoft compliance part
proxy_api_key: foobar
```
### mdm.enable_custom_os_updates_and_filevault
> Experimental feature. This feature will be removed when Fleet adds the ability to add custom OS update and FileVault profiles via Fleet's UI, API, and YAML.
If set to `true`, Fleet allows users to add the [SoftwareUpdateEnforcementSpecific declaration (DDM)](https://developer.apple.com/documentation/devicemanagement/softwareupdateenforcementspecific) profile, [FDEFileVault](https://developer.apple.com/documentation/devicemanagement/fdefilevault), [FDEFileVaultOptions](https://developer.apple.com/documentation/devicemanagement/fdefilevaultoptions), [FDERecoveryKeyEscrow](https://developer.apple.com/documentation/devicemanagement/fderecoverykeyescrow), and [/Vendor/MSFT/Policy/Config/Update/](https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update) configuration profiles.
- Default value: `false`
- Environment variable: `FLEET_MDM_ENABLE_CUSTOM_OS_UPDATES_AND_FILEVAULT`
- Config file format:
```yaml
mdm:
enable_custom_os_updates_and_filevault: true
```
### FLEET_ENABLE_POST_CLIENT_DEBUG_ERRORS
Use this environment variable to allow `fleetd` to report errors to the server using the [endpoint to report an agent error](./API-for-contributors.md#report-an-agent-error). `fleetd` agents will always report vital errors to Fleet.
+5 -5
View File
@@ -13,7 +13,7 @@ Create a new SAML app in Okta:
![Example Okta IdP Configuration](https://raw.githubusercontent.com/fleetdm/fleet/main/docs/images/okta-idp-setup.png)
If you're configuring [end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` for the **Single sign on URL** instead.
If you're configuring [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` for the **Single sign on URL** instead.
Once configured, you will need to retrieve the issuer URI from **View Setup Instructions** and metadata URL from the **Identity Provider metadata** link within the application **Sign on** settings. See below for where to find them:
@@ -23,7 +23,7 @@ Once configured, you will need to retrieve the issuer URI from **View Setup Inst
## Google Workspace
If you're configuring [end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` for the **Single sign on URL** instead.
If you're configuring [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` for the **Single sign on URL** instead.
Create a new SAML app in Google Workspace:
@@ -40,7 +40,7 @@ Create a new SAML app in Google Workspace:
![Download metadata](https://raw.githubusercontent.com/fleetdm/fleet/main/docs/images/google-sso-configuration-step-3.png)
4. Configure the **Service provider details**:
- For **ACS URL**, use `https://<your_fleet_url>/api/v1/fleet/sso/callback`. If you're configuring [end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` instead.
- For **ACS URL**, use `https://<your_fleet_url>/api/v1/fleet/sso/callback`. If you're configuring [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` instead.
- For Entity ID, use **the same unique identifier from step four** (e.g., "fleet.example.com").
- For **Name ID format**, choose `EMAIL`.
- For **Name ID**, choose `Basic Information > Primary email`.
@@ -76,7 +76,7 @@ Create a new SAML app in Microsoft Entra Admin Center:
4. In your newly crated Fleet app, select **Single sign-on** from the menu on the left. Then, on the Single sign-on page, select **SAML**.
5. Click the **Edit** button in the (1) Basic SAML Configuration Box.
- For **Identifier (Entity ID)**, click **Add identifier** and enter `fleet`.
- For **Reply URL (Assertion Consumer Service URL)**, enter `https://<your_fleet_url>/api/v1/fleet/sso/callback`. If you're configuring [end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` instead.
- For **Reply URL (Assertion Consumer Service URL)**, enter `https://<your_fleet_url>/api/v1/fleet/sso/callback`. If you're configuring [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication), use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback` instead.
- Click **Save**.
6. In the **(3) SAML Certificates** box, click the copy button in the **App Federation Metadata Url** field.
![The new SAML app's details page in Enta Admin Center](https://raw.githubusercontent.com/fleetdm/fleet/main/docs/images/entra-sso-configuration-step-6.png)
@@ -111,7 +111,7 @@ Fleet can be configured to use authentik as an identity provider. To continue, y
- For **Authorization flow**, choose `default-provider-authorization-implicit-consent (Authorize Application)`.
- In the **Protocol settings** section, configure the following:
- For **Assertion Consumer Service URL** use `https://<your_fleet_url>/api/v1/fleet/sso/callback`.
- If you're configuring **[end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula)**, use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback`.
- If you're configuring **[end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication)**, use `https://<your_fleet_url>/api/v1/fleet/mdm/sso/callback`.
- For **Issuer**, use `authentik`.
- For **Service Provider Binding**, choose `Post`.
- For **audience**, use `https://<your_fleet_url>`.
+1 -1
View File
@@ -40,7 +40,7 @@ A collection of guides to help you with Fleet.
[Automatically install software](https://fleetdm.com/guides/automatic-software-install-in-fleet)
[Install App Store (VPP) apps](https://fleetdm.com/guides/install-vpp-apps-on-macos-using-fleet)
[Install App store apps](https://fleetdm.com/guides/install-app-store-apps)
<!--Admin-->
[Fleetctl](https://fleetdm.com/guides/fleetctl)
+280 -62
View File
@@ -511,6 +511,10 @@ Returns a list of the activities that have been performed in Fleet. For a compre
| per_page | integer | query | Results per page. |
| order_key | string | query | What to order results by. Can be any column in the `activities` table. |
| order_direction | string | query | **Requires `order_key`**. The direction of the order given the order key. Options include `"asc"` and `"desc"`. Default is `"asc"`. |
| query | string | query | Search query keywords. Searchable fields include `actor_full_name` and `actor_email`.
| activity_type | string | query | Indicates the activity `type` to filter by. See available activity types on the [Audit logs page](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/audit-logs.md).
| start_created_at | string | query | Filters to include only activities that happened after this date. If not specified, set to the earliest possible date.
| end_created_at | string | query | Filters to include only activities that happened before this date. If not specified, set to now.
#### Example
@@ -540,7 +544,7 @@ Returns a list of the activities that have been performed in Fleet. For a compre
"self_service": false,
"software_title": "zoom.us.app",
"software_package": "ZoomInstallerIT.pkg",
}
}
},
{
"created_at": "2021-07-29T14:40:27Z",
@@ -571,7 +575,7 @@ Returns a list of the activities that have been performed in Fleet. For a compre
"self_service": false,
"software_title": "zoom.us.app",
"software_package": "ZoomInstallerIT.pkg",
}
}
}
],
"meta": {
@@ -595,7 +599,7 @@ Returns a list of the activities that have been performed in Fleet. For a compre
### Connect certificate authority (CA)
Connect Fleet to the certificate authority. Fleet currently supports [DigiCert](https://www.digicert.com/digicert-one), [Microsoft NDES](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/network-device-enrollment-service-overview), [Hydrant](https://www.hidglobal.com/), [Smallstep](https://smallstep.com/), and custom [SCEP](https://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_Protocol) server.
Connect Fleet to a certificate authority (CA). Fleet currently supports [DigiCert](https://www.digicert.com/digicert-one), [Microsoft NDES](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/network-device-enrollment-service-overview), [Hydrant](https://www.hidglobal.com/), [Smallstep](https://smallstep.com/), and any custom [SCEP](https://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_Protocol) or [EST](https://en.wikipedia.org/wiki/Enrollment_over_Secure_Transport) CA.
`POST /api/v1/fleet/certificate_authorities`
@@ -609,6 +613,7 @@ Only one of the objects is allowed in a single request.
| digicert | object | body | See [digicert](#digicert) |
| ndes_scep_proxy | object | body | See [ndes_scep_proxy](#ndes-scep-proxy) |
| custom_scep_proxy | object | body | See [custom_scep_proxy](#custom-scep-proxy) |
| custom_est_proxy | object | body | See [custom_est_proxy](#custom-est-proxy) |
| hydrant | object | body | See [hydrant](#hydrant) |
| smallstep | object | body | See [smallstep](#smallstep) |
@@ -647,6 +652,18 @@ Object with the following structure:
| url | string | **Required**. URL of the Simple Certificate Enrollment Protocol (SCEP) server |
| challenge | string | **Required**. Static challenge password used to authenticate requests to SCEP server. |
##### custom_est_proxy
Object with the following structure:
| Name | Type | Description |
| --------------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| name | string | **Required**. Name of the certificate authority that will be used in variables in configuration profiles. Only letters, numbers, and underscores are allowed. |
| url | string | **Required**. The EST (Enrollment Over Secure Transport) endpoint's URL. |
| username | string | **Required**. The username used to authenticate with the EST endpoint. |
| password | string | **Required**. The password used to authenticate with the EST endpoint. |
##### hydrant
Object with the following structure:
@@ -719,6 +736,7 @@ When editing a CA, specify one object and only its fields that you want to updat
| digicert | object | body | See [digicert](#digicert) |
| ndes_scep_proxy | object | body | See [ndes_scep_proxy](#ndes-scep-proxy) |
| custom_scep_proxy | object | body | See [custom_scep_proxy](#custom-scep-proxy) |
| custom_est_proxy | object | body | See [custom_est_proxy](#custom-est-proxy) |
| hydrant | object | body | See [hydrant](#hydrant) |
| smallstep | object | body | See [smallstep](#smallstep) |
@@ -786,6 +804,11 @@ See [Connect certificate authority](#connect-certificate-authority-ca) above for
},
{
"id": 5,
"name": "SECTIGO_WIFI",
"type": "custom_est_proxy"
}
{
"id": 6,
"name": "SMALLSTEP_WIFI",
"type": "smallstep"
}
@@ -855,7 +878,9 @@ When the CA is deleted, the issued certificates will remain on existing hosts.
### Request certificate
Requests a base64 encoded certificate (`.pem`). Currently, this endpoint is only supported for the [Hydrant](https://fleetdm.com/guides/connect-end-user-to-wifi-with-certificate#hydrant) certificate authority (CA). DigiCert, NDES, and custom SCEP coming soon.
Requests a base64 encoded certificate (`.pem`). Currently, this endpoint is only supported for [Hydrant](#hydrant) and [custom EST](#custom-est-proxy) certificate authorities (CAs). DigiCert, NDES, and custom SCEP coming soon.
As an alternative to [API token authentication](https://fleetdm.com/docs/rest-api/rest-api#retrieve-your-api-token), you can send an [HTTP signature in the request header](#example-http-signature).
`POST /api/v1/fleet/certificate_authorities/:id/request_certificate`
@@ -894,6 +919,37 @@ Requests a base64 encoded certificate (`.pem`). Currently, this endpoint is only
}
```
#### Example (HTTP signature)
##### Request header
```http
Content-Digest: sha-512=:WZDPaVn/7XgHaAy8pmojAkGWoRx2UFChF41A2svX+T\aPm+AbwAgBWnrIiYllu7BNNyealdVLvRwEmTHWXvJwew==
Signature: sig1=:e8UJ5wMiRaonlth5ERtE8GIiEH7Akcr493nQ07VPNo6y3qvjdK\t0fo8VHO8xXDjmtYoatGYBGJVlMfIp06eVMEyNW2I4vN7XDAz7m5v1108vGzaDljr\d0H8+SJ28g7bzn6h2xeL/8q+qUwahWA/JmC8aOC9iVnwbOKCc0WSrLgWQwTY6VLp4\2Qt7jjhYT5W7/wCvfK9A1VmHH1lJXsV873Z6hpxesd50PSmO+xaNeYvDLvVdZlhtw\5PCtUYzKjHqwmaQ6DEuM8udRjYsoNqp2xZKcuCO1nKc0V3RjpqMZLuuyVbHDAbCzr\ 0pg2d2VM/OC33JAU7meEjjaNz+d7LWPg==:
Signature-Input: sig1=("@method" "@authority" "@path" "@query" \"content-digest" "content-type" "content-length")\;created=1618884475;keyid="test-key-rsa-pss"
```
##### Request body
```json
{
"csr": "-----BEGIN CERTIFICATE REQUEST-----\nMIIC/jCCAeYCAQAwITEfMB0GA1UEAwwWQ2lzY29Vc2VyTmV0d29ya0FjY2VzczCC\nASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALJZtbxathh+RfK+Z613ar4E\nYSIem8yAvv2JZJtopjD3noy1yF+nGRyF/ocm+FhYvjR5u7teJXlcv24tAAHuWL4U\nuPIql0Slakjdsfl098salkj324lkjmtElWDi6XRjUIXEj1zyCnZTCxGmyHcYB/+f3fyv/\ngZ8SkPqocNOCpX6cSW8hxOlaF9aZUC+xMHRdjQgxQ79hleb5K/n2gCJjiW1sV0Es\nRg+MX0cbPCpahpzlvIAkzA7TTUTOd7ZN+V0GW0fH86uMstrqeW2QUuZmSDC9fNyj\nQhk6n5iURaHXdFjSmyrhW5AVvw1nIblHodhUtD6J+g9kjhBg1frss3ndQtnNrnMC\nAwEAAaCBlzCkldflkjc098dlkj2KoZIhvcNAQkOMYGGMIGDMIGABgNVHREEeTB3ggljaXNjby5j\nb22BEWthYW53YXJAY2lzY28uY29thjRJRDpGbGVldERNOkdVSUQ6Y2FkMTM4OTEt\nMzU3Ni00NzhmLTk1MzAtZmM1Y2VlZTEzZTkwoCEGCisGAQQBgjcUAgOgEwwRa2Fh\nbndhckBjaXNjby5jb20wDQYJKoZIhvcNAQELBQADggEBAH2U6Or14b4O22YjM22k\nXI9QDC5P+sDczcLjivv4MyXQL1ks8R6B1nXCrOmiLPPLaZ09f+UkeMnyuGAxW8Ce\n6LTKquwvlifZ+5TjyANz0I/d9ETLQF2MTphEZd4ySNLtq2RwYyDOBKaxMdW0sUsd\n6M3WyAuTBVgBkTVIqbMJBzFsgXSrr2a0LJEHszOO2BN3yT5muDQsKPJ1uXL7tNUv\n16pGaYpQZR8yGAmWyISHhAyLaJ1N1R8L77SLxdd/Sj7RunNNxqFqaEgIJMgsyu08\nGharLkQcIoW7qPHZuaLa54xMF/s/vfKH6rgGbbCAgw9kw8Klt+6H3OH1FSMeRfZ/\nDWs=\n-----END CERTIFICATE REQUEST-----",
"idp_oauth_url": "https://idp.oauth.com/introspection",
"idp_token": "88683de5858044aaacaf4046aeeef778044aaacaf4046",
"idp_client_id": "1o2czkDnUVwTqSOc747"
}
```
#### Default response
`Status: 200`
```json
{
"certificate": "-----BEGIN CERTIFICATE-----\nMIIC5DCCAcwCCQChs1cFRAzRCTANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDDClD\ndXN0b21lclVzZXJOZXR3b3JrQWNjZXNzOmJvYkBleGFtcGxlLmNvbTAeFw0yNTA5\nMDgxODM0MzNaFw0yODA2MDUxODM0MzNaMDQxMjAwBgNVBAMMKUN1c3RvbWVyVXNl\nck5ldHdvcmtBY2Nlc3M6Ym9iQGV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEF\nAAOCAQ8AMIIBCgKCAQEAuojcu8UBxTjpz5krPX4KmWNAmWvJ4U7yh8pGXOp6kngz\n1iRmGkBYdr0CQXlkrASejqglbdDfaRt3hz8S4raIlKyiU59gFK6f2Lory54ndzJw\nhVeNGqpLrnW1T763zvjcSKaASfVzdnsa66v6pZQte2fZAk7+q5o9ezyirSQmTuks\ndxXAZ5OiDafFwzXlanGZIvCsHBTJtbi881/QU701aTdFFrxLd+jsiaFhKSoQQcL5\nt0zu96cPS2dJivxpaogZ1f8dispWeRiMbt3njaxfWazm4RqvwvDouTSstqUxTzC8\n28Kbh7bnxPcSiuajnf35q53juhTLmB2CKEf0m1eqEwIDAQABMA0GCSqGSIb3DQEB\nCwUAA4IBAQCp75tK8cxR6A0Sfu3vg7TMPD3MkGrpdgh2giAVoCa4hOxOdHl/nYgu\nfPHodsRUfXi1SXo/77jLldGOLE6Ro447FMgrN94mRkaFUZbuLC5z2VciF9x1fdus\nIFfASIFnb4Zw24F2RDBbbGqXqRrA/1m1fWjHTb20+8rHeZW+FCJmxQrL27OG7n/n\nqDr8QmfNwTm8l72FBvUIz1xisuba5nXNAEc6rxTFw6WhPq5fgtBlVZCm55h87hHd\nQbzDGlkIXf+nypg9kwk3fDQ7VY9hrqc74wAefbIkvUSTk9rNaoncxI5Mod/imyan\ngCioUdMGd7M/dpEDDXKJNyI6lfscpG1D\n-----END CERTIFICATE-----\n"
}
```
---
## Conditional access
@@ -1556,7 +1612,7 @@ Modifies the Fleet's configuration with the supplied information.
"path": "path/to/profile2.json",
"labels_include_all": ["Label 3", "Label 4"]
},
{
{
"path": "path/to/profile3.json",
"labels_include_any": ["Label 5", "Label 6"]
},
@@ -2171,7 +2227,7 @@ _Available in Fleet Premium._
| Name | Type | Description |
| --------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| enable_end_user_authentication | boolean | If set to true, end user authentication will be required during automatic MDM enrollment of new macOS devices. Settings for your IdP provider must also be [configured](https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#end-user-authentication-and-eula). |
| enable_end_user_authentication | boolean | If set to true, end user authentication will be required during automatic MDM enrollment of new macOS devices. Settings for your IdP provider must also be [configured](https://fleetdm.com/guides/setup-experience#end-user-authentication). |
<br/>
@@ -3293,7 +3349,7 @@ Returns the information of the specified host.
"software": [
{
"id": 321,
"name": "SomeApp.app",
"name": "macOSApp",
"version": "1.0",
"source": "apps",
"bundle_identifier": "com.some.app",
@@ -3301,7 +3357,18 @@ Returns the information of the specified host.
"generated_cpe": "",
"vulnerabilities": null,
"installed_paths": ["/usr/lib/some-path-2"]
}
},
{
"id": 322,
"name": "Windows",
"version": "1.0",
"source": "programs",
"upgrade_code": "{XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX}",
"last_opened_at": "2021-08-18T21:14:00Z",
"generated_cpe": "",
"vulnerabilities": null,
"installed_paths": ["/usr/lib/some-path-2"]
},
],
"mdm": {
"encryption_key_available": true,
@@ -3582,7 +3649,9 @@ If `hostname` is specified when there is more than one host with the same hostna
Returns a subset of information about the host specified by `token`. To get all information about a host, use the ["Get host"](#get-host) endpoint.
This is the API route used by the **My device** page in Fleet desktop to display information about the host to the end user.
This is the API route used by the **My device** page in Fleet Desktop to display information about the host to the end user.
This endpoint doesn't require API token authentication. Authentication on macOS, Windows, and Linux is enforced by generating a [random UUID that rotates hourly](https://fleetdm.com/guides/fleet-desktop#secure-fleet-desktop). On iOS and iPadOS, authentication requires the Fleet identity SCEP certificate. This certificate is deployed to iOS/iPadOS hosts when they enroll to Fleet.
`GET /api/v1/fleet/device/:token`
@@ -3590,7 +3659,17 @@ This is the API route used by the **My device** page in Fleet desktop to display
| Name | Type | In | Description |
| ----- | ------ | ---- | ---------------------------------- |
| token | string | path | The host's [device authentication token](https://fleetdm.com/guides/fleet-desktop#secure-fleet-desktop). |
| token | string | path | The host's [device authentication token](https://fleetdm.com/guides/fleet-desktop#secure-fleet-desktop). For macOS, Windows, and Linux, this is a random UUID that rotates hourly. For iOS and iPadOS, this is the host's hardware UUID. |
#### Request headers
This endpoint accepts the `X-Client-Cert-Serial` header for authentication in addition to device token authentication.
The `Authorization` header must be formatted as follows:
```
X-Client-Cert-Serial: <fleet_identity_scep_cert_serial>
```
##### Example
@@ -4008,7 +4087,7 @@ Updates the email for the data source in the human-device mapping. This source c
```json
{
"email": "user@example.com"
"email": "user@example.com"
}
```
@@ -4018,21 +4097,21 @@ Updates the email for the data source in the human-device mapping. This source c
```json
{
"host_id": 1,
"device_mapping": [
{
"email": "user@example.com",
"source": "mdm_idp_accounts"
},
{
"email": "user@example.com",
"source": "google_chrome_profiles"
},
{
"email": "user@example.com",
"source": "custom"
}
]
"host_id": 1,
"device_mapping": [
{
"email": "user@example.com",
"source": "mdm_idp_accounts"
},
{
"email": "user@example.com",
"source": "google_chrome_profiles"
},
{
"email": "user@example.com",
"source": "custom"
}
]
}
```
@@ -4461,6 +4540,30 @@ Currently, `hash_sha256` is only supported for macOS software from the `apps` so
"installed_paths": ["/Users/username/Library/Application Support/JetBrains/GoLand2025.2/plugins/github-copilot-intellij"],
}
]
},
{
"id": 12,
"name": "MyCustomApp",
"software_package": {
"name": "MyCustomApp-1.12.ipa",
"platform": "ios",
"version": "1.12",
"self_service": false,
"automatic_install_policies": null,
"last_install": null,
"last_uninstall": null
},
"app_store_app": null,
"versions_count": 1,
"source": "ios_apps",
"hosts_count": 48,
"versions": [
{
"id": 123,
"version": "1.12",
"vulnerabilities": null
}
],
}
],
"meta": {
@@ -4558,7 +4661,7 @@ The host will only return a key if its disk encryption status is "Verified." Get
### Get host's certificates
Available for macOS, iOS, and iPadOS hosts only. Requires Fleet's MDM properly [enabled and configured](https://fleetdm.com/docs/using-fleet/mdm-setup).
Available for macOS, iOS, iPadOS, and Windows hosts only. Requires Fleet's MDM to be [enabled and configured](https://fleetdm.com/docs/using-fleet/mdm-setup).
Retrieves the certificates installed on a host.
@@ -5336,9 +5439,12 @@ Returns a list of all the labels in Fleet.
| Name | Type | In | Description |
| --------------- | ------- | ----- |------------------------------------- |
| include_host_counts | boolean | query | Whether or not to calculate host counts for each label. Default is `true`. See "additional notes" for more information.
| order_key | string | query | What to order results by. Can be any column in the labels table. |
| order_direction | string | query | **Requires `order_key`**. The direction of the order given the order key. Options include `"asc"` and `"desc"`. Default is `"asc"`. |
When `include_host_counts` is `true` (or omitted), `host_count` will only be included for `labels` that are in use by one or more hosts, but `count` will always be included, even if it is `0`. When `include_host_counts` is `false`, `host_count` will always be omitted, and `count` will be returned as `0` for each label. Setting `include_host_counts=false` will improve API performance, especially on deployments with large numbers of hosts and labels.
#### Example
`GET /api/v1/fleet/labels`
@@ -5588,7 +5694,9 @@ Deletes the label specified by ID.
### Create custom OS setting (configuration profile)
> [Add custom macOS setting](https://github.com/fleetdm/fleet/blob/fleet-v4.40.0/docs/REST%20API/rest-api.md#add-custom-macos-setting-configuration-profile) (`POST /api/v1/fleet/mdm/apple/profiles`) API endpoint is deprecated as of Fleet 4.41. It is maintained for backwards compatibility. Please use this endpoint instead.
> **Experimental feature**. Deploying Windows SCEP profile is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
> [Add custom macOS setting](https://github.com/fleetdm/fleet/blob/fleet-v4.40.0/docs/REST%20API/rest-api.md#add-custom-macos-setting-configuration-profile) (`POST /api/v1/fleet/mdm/apple/profiles`) API endpoint is deprecated as of Fleet 4.41. It is maintained for backwards compatibility. Please use the below API endpoint instead.
Add a configuration profile to enforce custom settings on macOS and Windows hosts.
@@ -6257,7 +6365,7 @@ Deletes the custom MDM setup enrollment profile assigned to a team or no team.
The returned value is a signed `.mobileconfig` OTA enrollment profile (see [Apple enrollment profile docs](https://developer.apple.com/library/archive/documentation/NetworkingInternet/Conceptual/iPhoneOTAConfiguration/OTASecurity/OTASecurity.html)). Install this profile on macOS, iOS, or iPadOS hosts to enroll them to a specific team in Fleet and turn on MDM features.
If the team in Fleet has [end user authentication](https://fleetdm.com/guides/macos-setup-experience#end-user-authentication) enabled, the OTA enrollment profile won't work. Use the [manual enrollment profile](#get-manual-enrollment-profile) instead.
If the team in Fleet has [end user authentication](https://fleetdm.com/guides/setup-experience#end-user-authentication) enabled, the OTA enrollment profile won't work. Use the [manual enrollment profile](#get-manual-enrollment-profile) instead.
To enroll macOS hosts, turn on MDM features, and add [human-device mapping](#get-human-device-mapping), use the [manual enrollment profile](#get-manual-enrollment-profile) instead.
@@ -6302,7 +6410,7 @@ To enroll macOS hosts, turn on MDM features, and add [human-device mapping](#get
<string>UDID</string>
<string>VERSION</string>
<string>PRODUCT</string>
<string>SERIAL</string>
<string>SERIAL</string>
</array>
</dict>
<key>PayloadOrganization</key>
@@ -6791,11 +6899,11 @@ Set software that will be automatically installed during setup. Software that is
{}
```
### Update setup experience script
### Create setup experience script
_Available in Fleet Premium_
Set the script that will automatically run during macOS setup. Updates the existing script for the team, or for hosts with no team, if one already exists.
Add a script that will automatically run during macOS setup.
`POST /api/v1/fleet/setup_experience/script`
@@ -6835,6 +6943,50 @@ echo "hello"
```
### Update setup experience script
_Available in Fleet Premium_
Changes the script that will automatically run during macOS setup. Updates the existing script for the team, or for hosts with no team, if one already exists.
`PUT /api/v1/fleet/setup_experience/script`
| Name | Type | In | Description |
| ----- | ------ | ----- | ---------------------------------------- |
| team_id | integer | form | _Available in Fleet Premium_. The ID of the team to add the script to. If not specified, a script will be added for hosts with no team. |
| script | file | form | The contents of the script to run during setup. |
#### Example
`PUT /api/v1/fleet/setup_experience/script`
##### Default response
`Status: 200`
##### Request headers
```http
Content-Length: 306
Content-Type: multipart/form-data; boundary=------------------------f02md47480und42y
```
##### Request body
```http
--------------------------f02md47480und42y
Content-Disposition: form-data; name="team_id"
1
--------------------------f02md47480und42y
Content-Disposition: form-data; name="script"; filename="myscript.sh"
Content-Type: application/octet-stream
echo "hello"
--------------------------f02md47480und42y--
```
### Get or download setup experience script
_Available in Fleet Premium_
@@ -9435,9 +9587,9 @@ Deletes the session specified by ID. When the user associated with the session n
- [Update software icon](#update-software-icon)
- [Download software icon](#download-software-icon)
- [Delete software icon](#delete-software-icon)
- [List App Store apps](#list-app-store-apps)
- [Create App Store app](#create-app-store-app)
- [Update App Store app](#update-app-store-app)
- [List Apple App Store apps](#list-apple-app-store-apps)
- [Add app store app](#add-app-store-app)
- [Update app store app](#update-app-store-app)
- [List Fleet-maintained apps](#list-fleet-maintained-apps)
- [Get Fleet-maintained app](#get-fleet-maintained-app)
- [Create Fleet-maintained app](#create-fleet-maintained-app)
@@ -9468,7 +9620,7 @@ Get a list of all software.
| vulnerable | boolean | query | If true or 1, only list software that has detected vulnerabilities. Default is `false`. |
| available_for_install | boolean | query | If `true` or `1`, only list software that is available for install (added by the user). Default is `false`. |
| self_service | boolean | query | If `true` or `1`, only lists self-service software. Default is `false`. |
| packages_only | boolean | query | _Available in Fleet Premium_. If `true` or `1`, only lists packages available for install (without App Store apps). |
| packages_only | boolean | query | _Available in Fleet Premium_. If `true` or `1`, only lists packages available for install (without app store apps). |
| min_cvss_score | integer | query | _Available in Fleet Premium_. Filters to include only software with vulnerabilities that have a CVSS version 3.x base score higher than the specified value. |
| max_cvss_score | integer | query | _Available in Fleet Premium_. Filters to only include software with vulnerabilities that have a CVSS version 3.x base score lower than what's specified. |
| exploit | boolean | query | _Available in Fleet Premium_. If `true`, filters to only include software with vulnerabilities that have been actively exploited in the wild (`cisa_known_exploit: true`). Default is `false`. |
@@ -9494,6 +9646,7 @@ Get a list of all software.
"name": "Firefox.app",
"display_name": "Firefox",
"icon_url":"/api/latest/fleet/software/titles/12/icon?team_id=3",
"display_name": "",
"software_package": {
"platform": "darwin",
"fleet_maintained_app_id": 42,
@@ -9534,7 +9687,8 @@ Get a list of all software.
{
"id": 22,
"name": "Google Chrome.app",
"display_name": "Chrome",
"icon_url": null,
"display_name": "",
"software_package": null,
"app_store_app": null,
"versions_count": 5,
@@ -9567,6 +9721,7 @@ Get a list of all software.
{
"id": 32,
"name": "1Password Password Manager",
"icon_url": null,
"display_name": "",
"software_package": null,
"app_store_app": null,
@@ -9586,6 +9741,8 @@ Get a list of all software.
{
"id": 77,
"name": "Prettier",
"icon_url": null,
"display_name": "",
"software_package": null,
"app_store_app": null,
"versions_count": 2,
@@ -9825,6 +9982,7 @@ Returns information about the specified software. By default, `versions` are sor
"name": "Falcon.app",
"display_name": "Crowdstrike Falcon",
"icon_url":"/api/latest/fleet/software/titles/12/icon?team_id=3",
"display_name": "",
"bundle_identifier": "crowdstrike.falcon.Agent",
"software_package": {
"name": "FalconSensor-6.44.pkg",
@@ -9892,7 +10050,7 @@ Returns information about the specified software. By default, `versions` are sor
`browser` and `extension_for` fields are included when set and when empty, at the same level as `source`. `extension_for` will show the browser or Visual Studio Code fork associated with the extension, allowing for differentiation between e.g. an extension installed on Visual Studio Code and one installed on Cursor. `browser` is deprecated, and only shows this information for browser plugins.
#### Example (App Store app)
#### Example (app store app)
`GET /api/v1/fleet/software/titles/15?team_id=3`
@@ -9907,6 +10065,7 @@ Returns information about the specified software. By default, `versions` are sor
"name": "Logic Pro",
"display_name": "",
"icon_url": "/api/latest/fleet/software/titles/15/icon?team_id=3",
"display_name": "",
"bundle_identifier": "com.apple.logic10",
"software_package": null,
"app_store_app": {
@@ -9930,7 +10089,7 @@ Returns information about the specified software. By default, `versions` are sor
"failed": 2,
}
},
"source": "apps",
"source": "ios_apps",
"hosts_count": 48,
"versions": [
{
@@ -9944,6 +10103,57 @@ Returns information about the specified software. By default, `versions` are sor
}
```
#### Example (Play Store app)
`GET /api/v1/fleet/software/titles/16`
##### Default response
`Status: 200`
```json
{
"software_title": {
"id": 16,
"name": "Zoom Workplace",
"icon_url": null,
"display_name": "",
"application_id": "us.zoom.videomeetings",
"counts_updated_at": "2025-08-29T10:23:48Z",
"software_package": null,
"app_store_app": {
"app_store_id": "us.zoom.videomeetings",
"platform": "android",
"name": "Zoom Workplace",
"icon_url": "https://lh3.googleusercontent.com/yZsmiNjmji3ZoOuLthoVvptLB9cZ0vCmitcky4OUXNcEFV3IEQkrBD2uu5kuWRF5_ERA",
"status": {
"installed": 1,
"pending": 0,
"failed": 0
},
"self_service": false,
"automatic_install_policies": null,
"labels_include_any": null,
"labels_exclude_any": null,
"created_at": "2025-08-15T00:55:03.96954Z",
"categories": null
},
"source": "android_apps",
"hosts_count": 72,
"versions_count": 1,
"versions": [
{
"id": 333,
"version": "6.5.10.32613",
"vulnerabilities": null,
"hosts_count": 24
}
]
}
}
```
#### Example (in-house iOS app)
`GET /api/v1/fleet/software/titles/24?team_id=3`
@@ -9959,7 +10169,7 @@ Returns information about the specified software. By default, `versions` are sor
"name": "MyCustomApp",
"software_package": {
"name": "MyCustomApp-1.12.ipa",
"platform": "ios"
"platform": "ios",
"fleet_maintained_id": null,
"version": "1.12",
"self_service": false,
@@ -9994,11 +10204,10 @@ Returns information about the specified software. By default, `versions` are sor
"version": "1.12",
"vulnerabilities": null
}
],
]
}
}
```
### Get software version
Returns information about the specified software version.
@@ -10241,6 +10450,8 @@ Content-Type: application/octet-stream
"software_package": {
"title_id": 123,
"name": "FalconSensor-6.44.pkg",
"icon_url": null,
"categories": null,
"display_name": "",
"version": "6.44",
"platform": "darwin",
@@ -10317,6 +10528,9 @@ Content-Disposition: form-data; name="team_id"
Content-Disposition: form-data; name="self_service"
true
--------------------------d8c247122f594ba0
Content-Disposition: form-data; display_name="CrowdStrike agent"
true
--------------------------d8c247122f594ba0
Content-Disposition: form-data; name="install_script"
sudo installer -pkg /temp/FalconSensor-6.44.pkg -target /
--------------------------d8c247122f594ba0
@@ -10338,10 +10552,11 @@ Content-Type: application/octet-stream
```json
{
"software_package": {
"software_installer": {
"name": "FalconSensor-6.44.pkg",
"display_name": "",
"categories": [],
"display_name": "CrowdStrike agent",
"icon_url": null,
"categories": null,
"version": "6.44",
"platform": "darwin",
"fleet_maintained_app_id": 42,
@@ -10419,7 +10634,7 @@ Content-Type: image/png
_Available in Fleet Premium._
Download the icon added via [Update software icon](#update-software-icon) or icon from App Store (VPP). **This endpoint requires authentication.**
Download the icon added via [Update software icon](#update-software-icon) or icon from the Apple App Store (VPP). **This endpoint requires authentication.**
`GET /api/v1/fleet/software/titles/:id/icon`
@@ -10474,11 +10689,11 @@ Delete a custom icon added via [Update software icon](#update-software-icon). Th
`Status: 204`
### List App Store apps
### List Apple App Store apps
> **Experimental feature**. This feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
Returns the list of Apple App Store (VPP) that can be added to the specified team. If an app is already added to the team, it's excluded from the list.
Returns the list of Apple App Store (VPP) apps that can be added to the specified team. If an app is already added to the team, it's excluded from the list.
`GET /api/v1/fleet/software/app_store_apps`
@@ -10527,13 +10742,13 @@ Returns the list of Apple App Store (VPP) that can be added to the specified tea
}
```
### Create App Store app
### Add app store app
> **Experimental feature**. This feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
_Available in Fleet Premium._
Add App Store (VPP) app purchased in Apple Business Manager.
Add app store apps from the Apple App Store or the Google Play store.
`POST /api/v1/fleet/software/app_store_apps`
@@ -10541,10 +10756,10 @@ Add App Store (VPP) app purchased in Apple Business Manager.
| Name | Type | In | Description |
| ---- | ---- | -- | ----------- |
| app_store_id | string | body | **Required.** The ID of App Store app. |
| team_id | integer | body | **Required**. The team ID. Adds VPP software to the specified team. |
| platform | string | body | The platform of the app (`darwin`, `ios`, or `ipados`). Default is `darwin`. |
| self_service | boolean | body | Specifies whether the app shows up on the **Fleet Desktop > My device** page and is available for install by the end user. |
| app_store_id | string | body | **Required.** The ID of the Apple App Store app or Google Play app. |
| team_id | integer | body | **Required**. The team ID. Adds app from the store to the specified team. |
| platform | string | body | The platform of the app (`darwin`, `ios`, `ipados`, or `android`). Default is `darwin`. |
| self_service | boolean | body | **Required if platform is Android**. Currently supported for macOS and Android apps. Specifies whether the app shows up in self-service and is available for install by the end user. For macOS shows up on **Fleet Desktop > My device** page, for Android in **Play Store** app in end user's work profile, and for iOS/iPadOS in [self-service web](https://fleetdm.com/learn-more-about/deploy-self-service-to-ios) app. |
| ensure | string | form | For macOS only, if set to "present" (currently the only valid value if set), create a policy that triggers a software install only on hosts missing the software. |
| labels_include_any | array | form | Target hosts that have any label, specified by label name, in the array. |
| labels_exclude_any | array | form | Target hosts that don't have any label, specified by label name, in the array. |
@@ -10578,12 +10793,13 @@ Only one of `labels_include_any` or `labels_exclude_any` can be specified. If ne
}
```
### Update App Store app
### Update app store app
> **Experimental feature**. This feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
_Available in Fleet Premium._
Modify App Store (VPP) app's options.
Modify an Apple app store (VPP) or a Google Play app's options.
`PATCH /api/v1/fleet/software/titles/:title_id/app_store_app`
@@ -10591,10 +10807,10 @@ Modify App Store (VPP) app's options.
| Name | Type | In | Description |
| ---- | ---- | -- | ----------- |
| team_id | integer | body | **Required**. The team ID. Edits App Store apps from the specified team. |
| display_name | string | form | Optional override for the default `name`. |
| team_id | integer | body | **Required**. The team ID. Edits Apple App Store or Android Play store app from the specified team. |
| display_name | string | body | Optional override for the default `name`. |
| self_service | boolean | body | **Required if platform is Android**. Currently supported for macOS and Android apps. Specifies whether the app shows up in self-service and is available for install by the end user. For macOS shows up on **Fleet Desktop > My device** page, and for Android in **Play Store** app in end user's work profile. |
| categories | string[] | body | Zero or more of the [supported categories](https://fleetdm.com/docs/configuration/yaml-files#supported-software-categories), used to group self-service software on your end users' **Fleet Desktop > My device** page. Software with no categories will be still be shown under **All**. |
| self_service | boolean | body | Self-service software is optional and can be installed by the end user. |
| labels_include_any | array | form | Target hosts that have any label, specified by label name, in the array. |
| labels_exclude_any | array | form | Target hosts that don't have any label, specified by label name, in the array. |
@@ -10627,6 +10843,7 @@ Only one of `labels_include_any` or `labels_exclude_any` can be specified. If ne
"app_store_app": {
"name": "Logic Pro",
"display_name": "",
"icon_url" null,
"app_store_id": 1091189122,
"categories": ["Browser"],
"latest_version": "2.04",
@@ -10762,6 +10979,7 @@ Returns information about the specified Fleet-maintained app.
### Create Fleet-maintained app
> **Experimental feature**. This feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
_Available in Fleet Premium._
Add Fleet-maintained app so it's available for install.
@@ -10846,7 +11064,7 @@ Body: <blob>
_Available in Fleet Premium._
Install software (package or App Store app) on a macOS, iOS, iPadOS, Windows, or Linux (Ubuntu) host. Software title must have a `software_package` or `app_store_app` to be installed.
Install software (package or app store app) on a macOS, iOS, iPadOS, Windows, or Linux (Ubuntu) host. Software title must have a `software_package` or `app_store_app` to be installed.
Package installs time out after 1 hour.
@@ -10901,7 +11119,7 @@ _Available in Fleet Premium._
Get the results of a Fleet-maintained app or custom package install. To get uninstall results, use the [List activities](#list-activities) and [Get script result](#get-script-result) API endpoints.
To get the results of an App Store app install, use the [List MDM commands](#list-mdm-commands) and [Get MDM command results](#get-mdm-command-results) API endpoints. Fleet uses an MDM command to install App Store apps.
To get the results of an Apple App Store app install, use the [List MDM commands](#list-mdm-commands) and [Get MDM command results](#get-mdm-command-results) API endpoints. Fleet uses an MDM command to install Apple App Store apps.
| Name | Type | In | Description |
| ---- | ------- | ---- | -------------------------------------------- |
@@ -11853,7 +12071,7 @@ _Available in Fleet Premium_
| Name | Type | Description |
| --------------------- | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| enable_end_user_authentication | boolean | If set to true, end user authentication will be required during automatic MDM enrollment of new macOS hosts. Settings for your IdP provider must also be [configured](https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#end-user-authentication-and-eula). |
| enable_end_user_authentication | boolean | If set to true, end user authentication will be required during automatic MDM enrollment of new macOS hosts. Settings for your IdP provider must also be [configured](https://fleetdm.com/guides/setup-experience#end-user-authentication). |
<br/>
@@ -29,7 +29,7 @@ const UploadedPackageView = ({
automatically enroll to this team. Delete the package to upload a new
one.{" "}
<CustomLink
url="https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience"
url="https://fleetdm.com/learn-more-about/setup-experience/bootstrap-package"
text="Learn more"
newTab
/>
@@ -23,7 +23,7 @@ const UploadedEulaView = ({
Require end users to agree to a EULA when they first set up their new
macOS hosts.{" "}
<CustomLink
url="https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#end-user-authentication-and-eula"
url="https://fleetdm.com/learn-more-about/setup-experience/end-user-authentication"
text="Learn more"
newTab
/>
+2 -2
View File
@@ -243,7 +243,7 @@
# ╚═╝╚═╝╩╚═╚═╝ ╩ ╚═╝╚═╝╚═╝╩ ╩ ╚═╝╚═╝ ╩ ╚═╝╩
- industryName: Zero-touch setup
description: Zero-touch setup for macOS, iOS/iPadOS, and Windows.
documentationUrl: https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience
documentationUrl: https://fleetdm.com/guides/setup-experience
tier: Premium
jamfProHasFeature: appleOnly
jamfProtectHasFeature: no
@@ -301,7 +301,7 @@
# ╚═╝╚═╝╚═╝╩╚═ ╩ ╩╚═╝╚═╝╚═╝╚═╝╝╚╝ ╩ ╚═╝ ╩ ╝╚╝╚═╝
- industryName: User account sync
description: Sync macOS local user accounts via Okta, AD, or any IdP.
documentationUrl: https://fleetdm.com/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula
documentationUrl: https://fleetdm.com/guides/setup-experience#end-user-authentication
productCategories: [Endpoint operations,Device management,Vulnerability management]
pricingTableCategories: [Devices]
usualDepartment: IT
+1 -1
View File
@@ -5537,7 +5537,7 @@
"linux"
],
"evented": false,
"examples": "Output most table information, swapping customer ID for its length to avoid leaking sensitive information.\n\n```\nSELECT agent_id, LENGTH(cid), falcon_version, reduced_functionality_mode, sensor_loaded FROM crowdstrike_falcon;\n```",
"examples": "Get the agent ID of the CrowdStrike Falcon agent on all macOS and Linux hosts.\n\n```\nSELECT agent_id FROM crowdstrike_falcon;\n```\n\nOutput most table information, swapping customer ID for its length to avoid leaking sensitive information.\n\n```\nSELECT agent_id, LENGTH(cid), falcon_version, reduced_functionality_mode, sensor_loaded FROM crowdstrike_falcon;\n```",
"columns": [
{
"name": "agent_id",
+8 -1
View File
@@ -1,11 +1,18 @@
name: crowdstrike_falcon
notes: This table is from the [Mac Admins osquery extension](https://github.com/macadmins/osquery-extension).
notes: |-
This table is from the [Mac Admins osquery extension](https://github.com/macadmins/osquery-extension).
description: Information about Crowdstrike Falcon, collected via the falconctl utility.
platforms:
- darwin
- linux
evented: false
examples: |-
Get the agent ID of the CrowdStrike Falcon agent on all macOS and Linux hosts.
```
SELECT agent_id FROM crowdstrike_falcon;
```
Output most table information, swapping customer ID for its length to avoid leaking sensitive information.
```
+1 -1
View File
@@ -228,7 +228,7 @@ func downloadRemoteMacosBootstrapPackage(pkgURL string) (*fleet.MDMAppleBootstra
case errors.Is(err, file.ErrInvalidType):
return nil, errors.New("Couldnt edit bootstrap_package. The file must be a package (.pkg).")
case errors.Is(err, file.ErrNotSigned):
return nil, errors.New("Couldnt edit bootstrap_package. The bootstrap_package must be signed. Learn how to sign the package in the Fleet documentation: https://fleetdm.com/docs/using-fleet/mdm-macos-setup-experience#step-2-sign-the-package")
return nil, errors.New("Couldnt edit bootstrap_package. The bootstrap_package must be signed. Learn how to sign the package in the Fleet documentation: https://fleetdm.com/learn-more-about/setup-experience/bootstrap-package")
default:
return nil, fmt.Errorf("checking package signature: %w", err)
}
+8 -7
View File
@@ -860,6 +860,7 @@ module.exports.routes = {
'GET /announcements/i-work-in-operations-i-deployed-fleet-in-minutes': '/articles/i-work-in-operations-i-deployed-fleet-in-minutes',
'GET /announcements/not-everything-runs-in-kubernete': '/articles/not-everything-runs-in-kubernete',
'GET /guides/macos-mdm-setup': '/guides/apple-mdm-setup',
'GET /guides/macos-setup-experience': '/guides/setup-experience',
// ╔╦╗╦╔═╗╔═╗ ╦═╗╔═╗╔╦╗╦╦═╗╔═╗╔═╗╔╦╗╔═╗ ┬ ╔╦╗╔═╗╦ ╦╔╗╔╦ ╔═╗╔═╗╔╦╗╔═╗
// ║║║║╚═╗║ ╠╦╝║╣ ║║║╠╦╝║╣ ║ ║ ╚═╗ ┌┼─ ║║║ ║║║║║║║║ ║ ║╠═╣ ║║╚═╗
@@ -939,7 +940,7 @@ module.exports.routes = {
'GET /learn-more-about/certificate-authorities': '/guides/connect-end-user-to-wifi-with-certificate',
'GET /learn-more-about/idp-email': 'https://fleetdm.com/docs/rest-api/rest-api#get-human-device-mapping',
'GET /learn-more-about/enrolling-hosts': '/docs/using-fleet/adding-hosts',
'GET /learn-more-about/setup-assistant': '/guides/macos-setup-experience#setup-assistant',
'GET /learn-more-about/setup-assistant': '/guides/setup-experience#macos-setup-assistant',
'GET /learn-more-about/policy-automations': '/docs/using-fleet/automations',
'GET /install-wine': 'https://github.com/fleetdm/fleet/blob/main/it-and-security/lib/macos/scripts/install-wine.sh',
'GET /learn-more-about/creating-service-accounts': 'https://console.cloud.google.com/projectselector2/iam-admin/serviceaccounts/create?walkthrough_id=iam--create-service-account&pli=1#step_index=1',
@@ -981,8 +982,8 @@ module.exports.routes = {
'GET /learn-more-about/mdm-disk-encryption': '/guides/enforce-disk-encryption',
'GET /learn-more-about/encrypt-linux-device': '/guides/linux-disk-encryption-end-user',
'GET /contribute-to/policies': 'https://github.com/fleetdm/fleet/edit/main/docs/01-Using-Fleet/standard-query-library/standard-query-library.yml',
'GET /learn-more-about/end-user-license-agreement': '/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula',
'GET /learn-more-about/end-user-authentication': '/guides/macos-setup-experience#end-user-authentication-and-end-user-license-agreement-eula',
'GET /learn-more-about/end-user-license-agreement': '/guides/setup-experience#end-user-license-agreement-eula',
'GET /learn-more-about/end-user-authentication': '/guides/setup-experience#end-user-authentication',
'GET /learn-more-about/yaml-setup-experience-software': '/docs/configuration/yaml-files#software',
'GET /learn-more-about/policy-templates': '/policies',
'GET /learn-more-about/windows-mdm': '/guides/windows-mdm-setup',
@@ -1013,10 +1014,10 @@ module.exports.routes = {
'GET /learn-more-about/example-android-profile': 'https://gist.github.com/marko-lisica/45ee31f6850e1f002141c1b5b43ce519',
'GET /learn-more-about/manual-enrollment-profile': '/docs/rest-api/rest-api#get-manual-enrollment-profile',
'GET /learn-more-about/deleting-android-enterprise': '/guides/android-mdm-setup#deleting-android-enterprise-in-google-admin',
'GET /learn-more-about/setup-experience/install-software': '/guides/macos-setup-experience#install-software',
'GET /learn-more-about/setup-experience/run-script': '/guides/macos-setup-experience#run-script',
'GET /learn-more-about/setup-experience/end-user-authentication': '/guides/macos-setup-experience#end-user-authentication',
'GET /learn-more-about/setup-experience/bootstrap-package': '/guides/macos-setup-experience#bootstrap-package',
'GET /learn-more-about/setup-experience/install-software': '/guides/setup-experience#install-software',
'GET /learn-more-about/setup-experience/run-script': '/guides/setup-experience#run-script',
'GET /learn-more-about/setup-experience/end-user-authentication': '/guides/setup-experience#end-user-authentication',
'GET /learn-more-about/setup-experience/bootstrap-package': '/guides/setup-experience#bootstrap-package',
'GET /learn-more-about/built-in-variables': '/docs/configuration/yaml-files#variables',
'GET /learn-more-about/disable-entra-conditional-access': '/guides/entra-conditional-access-integration#disable',
'GET /learn-more-about/macos-configuration-profiles-same-scope': '/guides/custom-os-settings#upgrading-to-4-71-0',