- @noahtalerman: For Windows, I think we want to squeeze turning off MDM and uninstalling fleetd into one script. - Why? Because Fleet automatically turns on Windows MDM, two scripts means Fleet could beat the IT admin and turn MDM back on before they uninstall fleetd. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Windows fleetd uninstall now proactively detects and disables MDM enrollment before removal to help ensure a cleaner device unenrollment. * **Bug Fixes** * Improved uninstall error reporting by surfacing the underlying failure message and exiting with a clear non-zero code. * **Chores** * Updated fleet testing and workstation configurations: removed the Windows uninstall/MDM-related steps from QA and workstation controls, and added new Windows security/setup scripts plus additional cross-platform post-install and extension installation tasks. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Steven Palmesano <3100993+spalmesano0@users.noreply.github.com>
Solutions
Best Practices
General
- Name the file what the profile does.
- For example, instead of
googlePlayProtectVerifyApps.json(the name of the Android policy for this control), describe what it does:enforce-google-play-protect.json.
- For example, instead of
- Use kebab case in file names, with all letters in lowercase.
- Instead of
passwordPolicy.json, usepassword-policy.json.
- Instead of
- Be sure to end files with an empty newline.
symlinks
If a solution is applicable to multiple platforms, keep the original in the main platform directory and symlink it to the other platforms. For example, if an Apple configuration profile can be used on both macOS and iOS, use macOS as the source, and create a symlink in the iOS directory.
cd docs/solutions/ios-ipados/configuration-profiles/- Note that this is the destination that we want the symlink to be in.
ln -s ../../macos/configuration-profiles/my-profile.mobileconfig .- The
.here at the end means the current directory, and will use the same file name as the original (which is what we want).
- The
git add profile.mobileconfiggit commit