Demo: https://www.youtube.com/watch?v=cWxZlu9WuwA Guide updates: https://github.com/fleetdm/fleet/pull/49603/changes IT admins can configure the fleet that hosts enrolling through user-driven Windows MDM enrollment (Windows Autopilot, Entra join) are automatically assigned to, via the Windows MDM settings page, the mdm.windows_enrollment.default_fleet config setting, or GitOps. - New windows_enrollment_config row stores the default team; the config API surfaces it by fleet name and hydrates reads from the row so team renames and deletions never serve a stale name. Deleting the fleet clears the setting. - New edited_windows_enrollment_default_fleet activity, emitted only when the value changes. - The OMA-DM session persists the device-reported SMBIOS serial on still-unlinked enrollments, and orbit enrollment reverse-links by that serial and assigns the default fleet before orbit's one-shot setup-experience init, so the default fleet's software, scripts, and profiles apply during the Autopilot ESP. The DevDetail and osquery link paths keep the same assignment as fallbacks, and the EUA-token link path now shares the same post-link bookkeeping. - Hosts are only assigned when new to Fleet in this enrollment cycle: existing hosts, including ones parked in Unassigned, keep their fleet on re-enrollment, matching macOS ABM behavior. - GitOps defers applying the setting until teams declared in the same run are created, and fleetctl generate-gitops exports it. - Windows MDM settings page redesign per Figma: programmatic enrollment toggle, User driven enrollment section with the Entra-gated Default fleet dropdown, and a Migration section. <!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #41787 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] Timeouts are implemented and retries are limited to avoid infinite loops ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually ## Database migrations - [x] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [x] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## New Fleet configuration settings - [x] Verified that the setting is exported via `fleetctl generate-gitops` - [x] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) - [x] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - [x] Verified that any relevant UI is disabled when GitOps mode is enabled <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added support for assigning a default Fleet Premium fleet to new Windows MDM enrollments, including Autopilot and Entra join. * Default-fleet settings can be configured, cleared, and managed through Windows MDM settings and GitOps. * Assigned fleet software, scripts, and profiles can apply during out-of-box setup. * Added activity-feed visibility for default-fleet changes. * Improved Windows enrollment matching using hardware serial numbers. * **Documentation** * Documented default-fleet assignment for Windows enrollment. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
231 lines
6.5 KiB
JSON
231 lines
6.5 KiB
JSON
{
|
|
"kind": "config",
|
|
"apiVersion": "v1",
|
|
"spec": {
|
|
"org_info": {
|
|
"org_name": "",
|
|
"org_logo_url": "",
|
|
"org_logo_url_light_background": "",
|
|
"org_logo_url_dark_mode": "",
|
|
"org_logo_url_light_mode": "",
|
|
"contact_url": "https://fleetdm.com/company/contact"
|
|
},
|
|
"server_settings": {
|
|
"server_url": "",
|
|
"live_query_disabled": false,
|
|
"live_reporting_disabled": false,
|
|
"query_report_cap": 0,
|
|
"query_reports_disabled": false,
|
|
"report_cap": 0,
|
|
"discard_reports_data": false,
|
|
"enable_analytics": false,
|
|
"deferred_save_host": false,
|
|
"scripts_disabled": false,
|
|
"ai_features_disabled": false
|
|
},
|
|
"smtp_settings": {
|
|
"enable_smtp": false,
|
|
"configured": false,
|
|
"sender_address": "",
|
|
"server": "",
|
|
"port": 0,
|
|
"authentication_type": "",
|
|
"user_name": "",
|
|
"password": "",
|
|
"enable_ssl_tls": false,
|
|
"authentication_method": "",
|
|
"domain": "",
|
|
"verify_ssl_certs": false,
|
|
"enable_start_tls": false
|
|
},
|
|
"host_expiry_settings": {
|
|
"host_expiry_enabled": false,
|
|
"host_expiry_window": 0
|
|
},
|
|
"activity_expiry_settings": {
|
|
"activity_expiry_enabled": false,
|
|
"activity_expiry_window": 0,
|
|
"preserve_host_activities_on_reenrollment": false
|
|
},
|
|
"conditional_access": {
|
|
"microsoft_entra_tenant_id": "",
|
|
"microsoft_entra_connection_configured": false,
|
|
"okta_idp_id": null,
|
|
"okta_assertion_consumer_service_url": null,
|
|
"okta_audience_uri": null,
|
|
"okta_certificate": null,
|
|
"bypass_disabled": null
|
|
},
|
|
"features": {
|
|
"enable_host_users": true,
|
|
"enable_software_inventory": false,
|
|
"historical_data": {
|
|
"uptime": true,
|
|
"vulnerabilities": true
|
|
}
|
|
},
|
|
"sso_settings": {
|
|
"entity_id": "",
|
|
"issuer_uri": "",
|
|
"idp_image_url": "",
|
|
"metadata": "",
|
|
"metadata_url": "",
|
|
"idp_name": "",
|
|
"enable_jit_provisioning": false,
|
|
"enable_jit_role_sync": false,
|
|
"enable_sso": false,
|
|
"enable_sso_idp_login": false,
|
|
"sso_server_url": ""
|
|
},
|
|
"fleet_desktop": {
|
|
"alternative_browser_host": "",
|
|
"transparency_url": "https://fleetdm.com/transparency"
|
|
},
|
|
"vulnerability_settings": {
|
|
"databases_path": "/some/path"
|
|
},
|
|
"webhook_settings": {
|
|
"activities_webhook": {
|
|
"enable_activities_webhook": false,
|
|
"destination_url": ""
|
|
},
|
|
"host_status_webhook": {
|
|
"enable_host_status_webhook": false,
|
|
"destination_url": "",
|
|
"host_percentage": 0,
|
|
"days_count": 0
|
|
},
|
|
"failing_policies_webhook": {
|
|
"enable_failing_policies_webhook": false,
|
|
"destination_url": "",
|
|
"policy_ids": null,
|
|
"host_batch_size": 0
|
|
},
|
|
"vulnerabilities_webhook": {
|
|
"enable_vulnerabilities_webhook": false,
|
|
"destination_url": "",
|
|
"host_batch_size": 0
|
|
},
|
|
"interval": "0s"
|
|
},
|
|
"integrations": {
|
|
"jira": null,
|
|
"zendesk": null,
|
|
"google_calendar": null,
|
|
"conditional_access_enabled": null
|
|
},
|
|
"mdm": {
|
|
"android_enabled_and_configured": false,
|
|
"apple_bm_terms_expired": false,
|
|
"apple_server_url": "",
|
|
"apple_bm_enabled_and_configured": false,
|
|
"enabled_and_configured": false,
|
|
"apple_business": null,
|
|
"apple_business_manager": null,
|
|
"apple_account_provisioning": {
|
|
"oauth_idp_token_url": null,
|
|
"oauth_idp_client_id": null,
|
|
"oauth_idp_client_secret": null
|
|
},
|
|
"volume_purchasing_program": null,
|
|
"windows_enabled_and_configured": false,
|
|
"enable_disk_encryption": false,
|
|
"name_template": null,
|
|
"enable_recovery_lock_password": false,
|
|
"macos_updates": {
|
|
"minimum_version": null,
|
|
"deadline": null,
|
|
"update_new_hosts": null
|
|
},
|
|
"ios_updates": {
|
|
"minimum_version": null,
|
|
"deadline": null,
|
|
"update_new_hosts": null
|
|
},
|
|
"ipados_updates": {
|
|
"minimum_version": null,
|
|
"deadline": null,
|
|
"update_new_hosts": null
|
|
},
|
|
"windows_updates": {
|
|
"deadline_days": 7,
|
|
"grace_period_days": 3
|
|
},
|
|
"windows_migration_enabled": false,
|
|
"enable_turn_on_windows_mdm_manually": false,
|
|
"windows_entra_tenant_ids": null,
|
|
"windows_entra_client_ids": null,
|
|
"windows_require_bitlocker_pin": null,
|
|
"apple_require_hardware_attestation": false,
|
|
"macos_migration": {
|
|
"enable": false,
|
|
"mode": "",
|
|
"webhook_url": ""
|
|
},
|
|
"apple_settings": {
|
|
"configuration_profiles": null
|
|
},
|
|
"macos_settings": {
|
|
"custom_settings": null
|
|
},
|
|
"macos_setup": {
|
|
"bootstrap_package": null,
|
|
"enable_end_user_authentication": false,
|
|
"enable_managed_local_account": false,
|
|
"enable_release_device_manually": false,
|
|
"end_user_local_account_type": "admin",
|
|
"lock_end_user_info": false,
|
|
"macos_setup_assistant": null,
|
|
"manual_agent_install": null,
|
|
"require_all_software_macos": false,
|
|
"require_all_software_windows": false,
|
|
"script": null,
|
|
"software": null
|
|
},
|
|
"setup_experience": {
|
|
"apple_enable_release_device_manually": false,
|
|
"apple_setup_assistant": null,
|
|
"enable_create_local_admin_account": false,
|
|
"enable_end_user_authentication": false,
|
|
"end_user_local_account_type": "admin",
|
|
"lock_end_user_info": false,
|
|
"macos_bootstrap_package": null,
|
|
"macos_manual_agent_install": null,
|
|
"macos_script": null,
|
|
"require_all_software_macos": false,
|
|
"require_all_software_windows": false,
|
|
"software": null
|
|
},
|
|
"windows_enrollment": null,
|
|
"windows_settings": {
|
|
"custom_settings": null,
|
|
"configuration_profiles": null,
|
|
"managed_local_account_settings": {
|
|
"enabled": false
|
|
}
|
|
},
|
|
"android_settings": {
|
|
"certificates": null,
|
|
"custom_settings": null,
|
|
"configuration_profiles": null
|
|
},
|
|
"end_user_authentication": {
|
|
"entity_id": "",
|
|
"issuer_uri": "",
|
|
"metadata": "",
|
|
"metadata_url": "",
|
|
"idp_name": ""
|
|
}
|
|
},
|
|
"scripts": null,
|
|
"gitops": {
|
|
"gitops_mode_enabled": false,
|
|
"repository_url": "",
|
|
"exceptions": {
|
|
"labels": false,
|
|
"software": false,
|
|
"secrets": false
|
|
}
|
|
}
|
|
}
|
|
} |