Commit graph

170 commits

Author SHA1 Message Date
Allen Houchins
6ccf1a00b3
Removing minimum_version to fix enrollment issues (#33258)
- Newly enrolled devices are running into issues installing macOS 26. Removing `minimum_version` requirements in favor of Nudge enforcing OS updates.
2025-09-21 23:58:04 -05:00
Allen Houchins
ba054c43e1
Revert "Update testing-and-qa.yml" (#33223)
Reverts fleetdm/fleet#33216
2025-09-19 11:51:48 -05:00
Allen Houchins
c84145948d
Update testing-and-qa.yml (#33216)
Testing: https://github.com/fleetdm/fleet/issues/32977
2025-09-19 11:43:52 -05:00
Allen Houchins
79e123004e
Scoping Nudge to all workstations (#32909)
- Prep for scoping Nudge and all related files to all workstations
- Disabling Software Update notifications to rely more on Nudge notifications
2025-09-18 21:25:00 -05:00
Allen Houchins
650680689e
Update personal-mobile-devices.yml (#33093)
- Require end user authentication for profile-based BYOD enrollment
2025-09-16 21:02:25 -05:00
Allen Houchins
37955d80bd
Delete "Compliance exclusions" team (#32968)
- https://github.com/fleetdm/fleet/issues/32633
2025-09-14 20:50:21 -05:00
Allen Houchins
fcdef439ab
Create testing-and-qa.yml (#32954)
- https://github.com/fleetdm/fleet/issues/32633
2025-09-14 20:37:59 -05:00
Victor Lyuboslavsky
071e7c75f1
Fix agent options for darwin overrides -- all options must be set in overrides. (#32945) 2025-09-12 20:28:18 -05:00
Allen Houchins
bded4a7d4d
Added script to set lock screen message (#32820)
- Added script to set lock screen message
- Scoped it to the two workstations teams
2025-09-10 16:44:21 -05:00
Allen Houchins
cc04d2a459
Updated script and policy for OpenSUSE support (#32779)
- Updated policy and script to support Fleet Desktop on OpenSUSE
2025-09-09 14:11:56 -05:00
Allen Houchins
f6c841c4ea
Update script and policy to support OpenSUSE (#32757)
- Updated the script and policy that checks to make sure the required
extension is installed for Fleet Desktop to work with OpenSUSE
2025-09-08 20:51:12 -05:00
Allen Houchins
b9278b7b31
Added configuration profile for Google Updater (#32729)
- Added configuration profile for Google Updater to run as a background
task
- Removed configuration profile for moroz testing
2025-09-08 12:10:03 -05:00
Allen Houchins
a84c262ed7
Update compliance-exclusions.yml (#32626)
- Added FMAs: https://github.com/fleetdm/fleet/issues/32111
2025-09-04 15:42:13 -07:00
Allen Houchins
dfe01e49f4
Revert "Update company-owned-mobile-devices.yml" (#32372)
Reverts fleetdm/fleet#32371
2025-08-27 13:55:53 -05:00
Allen Houchins
61fdd8c2a2
Update company-owned-mobile-devices.yml (#32371)
- Added custom app for testing
2025-08-27 13:46:07 -05:00
Allen Houchins
b591cb92dc
Adding scope to App Store updates mobileconfig (#32272)
- adding scope to App Store updates mobileconfig
2025-08-25 13:07:07 -05:00
Allen Houchins
8c57db82d3
Revert "Change Slack to pkg install" (#32207)
Reverts fleetdm/fleet#32206
- The pkg install wipes out all previous preferences.
2025-08-22 09:56:41 -05:00
Allen Houchins
1abb5c043a
Change Slack to pkg install (#32206)
- Converted the Slack install from VPP to pkg as a workaround to this
https://github.com/fleetdm/fleet/issues/31972
2025-08-22 09:46:39 -05:00
Allen Houchins
323d11143b
Nudge configuration updates (#31953)
- Updated messaging in the UI
- Combined the assets and LaunchAgent packages
- Updated configuration profile with `systemmanager` payload
2025-08-14 22:09:59 -05:00
Allen Houchins
53c7cabe46
Added Nudge install policy and LaunchAgent (#31952)
- Added a policy to handle automatic install of Nudge
- Added LaunchAgent pkg
2025-08-14 21:24:42 -05:00
Allen Houchins
02b80eeeca
Adding configuration for Nudge testing (#31928)
In preparation for Nudge testing:
- created a label
- install policy
- install script
- pkg for assets
- configuration profile
2025-08-14 20:00:39 -05:00
Mitch Francese
5adce084b5
Add Google Apps for iOS devices (#31860)
## Demo Pasteboard management for BYOD devices

Made changes to `/it-and-security/teams/personal-mobile-devices.yml` and
`/it-and-security/lib/ios/configuration-profiles` to demo DLP
restrictions.

- Added byod-restrict-pasteboard-managed-apps.mobileconfig profile to
restrict copy/paste between managed and unmanaged apps
- Updated personal-mobile-devices team to include the new profile
- Added Google Docs, Sheets, and Drive to approved app store apps

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-08-14 19:44:38 -05:00
Allen Houchins
6c3cbff500
Added managed bookmarks for Google Chrome (macOS) (#31628)
- Added managed bookmarks for Google Chrome on macOS
2025-08-05 16:10:05 -05:00
Allen Houchins
32c4f4e503
Update macOS version to 15.6 (#31583) 2025-08-04 14:56:07 -05:00
Allen Houchins
4993c092c2
Configuration for Entra conditional access demo (#31161)
- Created a demo policy and script
- Enabled conditional access
2025-07-22 20:47:02 -05:00
Allen Houchins
aeb24dbf13
Update compliance-exclusions.yml (#31067)
- Adding the FMA version of Santa to Compliance exclusions to test updates
2025-07-18 15:50:09 -05:00
Allen Houchins
a0845a601f
Setting up Entra conditional access (#30893)
Configuring Entra conditional access:
- Test group label created
- SSO extension mobileconfig
- Policy to auto-install Company Portal app
- Company Portal software title defined
2025-07-15 14:31:39 -05:00
Allen Houchins
99afabb8a9
Update company-owned-mobile-devices.yml (#30717)
Updated yaml indents
2025-07-09 23:23:11 -05:00
Allen Houchins
27ed39d0dd
Update company-owned-mobile-devices.yml (#30701)
Added macos_setup.enable_end_user_authentication so iOS devices enroll with authentication.
2025-07-09 15:00:54 -05:00
Noah Talerman
615a97f143
Dogfood: Revert custom packages => Fleet-maintained apps (#30366)
Reverts changes made in this PR:
https://github.com/fleetdm/fleet/pull/30312

- @noahtalerman: Filed a `:help-dogfooding` issue to track moving to
Fleet-maintained apps: https://github.com/fleetdm/fleet/issues/30365
2025-06-27 10:32:50 -05:00
Noah Talerman
aba1f6e9eb
Dogfood: Chrome & Firefox Fleet-maintained apps (#30312)
To help us reproduce [this
bug](https://github.com/fleetdm/fleet/issues/30239) using dogfood.

- @noahtalerman: Only added to "Workstations (canary)" for testing. Why
not use the Fleet-maintained apps in for the "Workstations" team?
2025-06-25 13:54:16 -05:00
Allen Houchins
3ffe6d8745
Expand scope of macos_compatibility extension (#30219)
- Expanded scope of deployment to more than just our test devices
- Created label for scoped query reporting
2025-06-20 21:48:41 -05:00
Allen Houchins
3b5ae7d713
Added macos_compatibility extension (#30189)
- Added custom extension for `macos_compatibility` to Workstations (canary)
2025-06-20 11:18:43 -05:00
Allen Houchins
acf8274ba9
Add Fleet's Keynote them to self-service (#30008)
- Added a package that installs Fleet's Keynote theme and related fonts
to self-service
2025-06-13 16:01:12 -05:00
Noah Talerman
a3c11c91eb
Add Microsoft Teams to self-service (#29858)
- `customer-interkosmos` uses Teams

---------

Co-authored-by: Allen Houchins <allenhouchins@mac.com>
2025-06-10 08:51:10 -05:00
Allen Houchins
2aa4a3c1b0
Santa updates (#29801)
- Edited configuration profile 
- Added new Block rule for WhatsApp
- Scoped policy to install extension
2025-06-06 14:27:41 -05:00
Allen Houchins
c24c5cf804
Santa deployment changes (#29799)
- Updated version of santa
- Added policy and script to check for existence of santa osquery
extension and install if not found
- Changed to configuration profile based rules
- Split rules into their own configuration profiles to manage easier via
GitOps
2025-06-06 13:46:44 -05:00
Allen Houchins
9d30086dfe
Updated profile names for better readability in Fleet UI (#29796)
- Updated profile names so they appear as human readable in Fleet UI
instead of by filename.
2025-06-06 11:27:33 -05:00
Allen Houchins
ceee0b7831
Renaming MacOS DDM and Windows policies so they appear cleaner in Fleet UI (#29697)
- Updated Windows policies with human readable names so they appear cleaner in Fleet UI, rather than by their file names. Ex: `Disable OneDrive` vs `disable-onedrive`
2025-06-04 09:50:11 -05:00
Allen Houchins
be0234bfcc
Self-service overhaul (#29598)
- Added FMAs via GitOps
- Added new label for scoping apps to ARM-based (Apple Silicon) Macs
2025-05-30 08:51:00 -05:00
Allen Houchins
d3392873d8
Updating Windows configuration profiles (#29590)
- Updating Windows configuration profiles to prevent race condition
2025-05-29 13:31:44 -05:00
Allen Houchins
780fc99114
Self-service overhaul (#29566)
- added categories to existing software titles

---------

Co-authored-by: Mike McNeil <mikermcneil@users.noreply.github.com>
2025-05-29 11:14:17 -05:00
Allen Houchins
130b99e377
Updated software and operating system version strings (#29273)
- Updated software and operating system version strings throughout
policies and software yml files
2025-05-19 15:50:48 -05:00
Allen Houchins
c28d162827
Update personal-mobile-devices.yml (#28633)
- Removed incompatible DDM profile for unsupervised devices
2025-04-29 10:08:34 -05:00
Allen Houchins
86c1a12471
Updated minimum OS versions (#28439)
- Updated minimum OS versions for macOS, iOS, and iPadOS.
- Removed extra line break
2025-04-22 09:17:54 -05:00
Allen Houchins
3562daa28a
Testing cleanup of No team (#28418)
- added `custom_settings` and cleaned up invalid key (`queries`)
2025-04-21 14:36:21 -05:00
Allen Houchins
9c2ce31c07
Update no-team.yml (#28416)
Testing clean up
2025-04-21 14:17:49 -05:00
Allen Houchins
416733be5b
Update team files to clean up No Team (#28258) 2025-04-21 14:12:32 -05:00
Allen Houchins
8e148d8025
Santa reconfigured for sync server (#28407) 2025-04-21 14:33:32 -04:00
Allen Houchins
2d4a733883
Updated webhook settings (#28252)
Related to this: https://github.com/fleetdm/fleet/issues/27629
2025-04-15 13:05:30 -05:00