Skip to content

Update default Apple automatic enrollment profile #40905

Description

@melpike

Related to: #40832

Goal

User story
As an IT admin,
I want to make sure all Apple automatic enrollment profile defaults are set correctly
so that end users have the best experience possible.

Changes

Product

UPDATE:

  • Per previous discussion, the default automatic enrollment profile should:
    • not be removable
    • be as minimal as possible (e.g. no screens skipped by default)
Image
  • UI changes: Figma
  • CLI (fleetctl) usage changes: No changes
  • YAML changes: No changes
  • REST API changes: [API/YAML] API docs for v4.86.0 automatic enrollment profile update #43782
  • Fleet's agent (fleetd) changes: No changes
  • Fleet server configuration changes: No changes
  • Exposed, public API endpoint changes: No changes
  • fleetdm.com changes: No changes
  • GitOps mode UI changes: No changes
  • GitOps generation changes: No changes
  • Activity changes: No changes
  • Permissions changes: No changes
  • Changes to paid features or tiers: No changes
  • My device and fleetdm.com/better changes: No changes
  • Usage statistics: No changes
  • Other reference documentation changes: Route for Learn more: [Route] Update routes.js #41867
  • First draft of test plan added
  • Once shipped, requester has been notified
  • Once shipped, dogfooding issue has been filed

Engineering

  • Test plan is finalized
  • Contributor API changes: No changes
  • Feature guide changes: Update articles/apple-mdm-setup.md . Call out that existing fleet instances are unaffected by new enrollment profiles being added and how to check which profile your instance is using.
  • This is a premium only feature: Yes

ℹ️  Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".

Risk assessment

  • Requires load testing: No
  • Risk level: Low

Test plan

Make sure to go through the list and consider all events that might be related to this story, so we catch edge cases earlier.

  • Confirm "Learn more" goes to /learn-more-about/enrollment-profiles (goes here: https://developer.apple.com/documentation/devicemanagement/profile?changes=l_11_5)
  • On a brand-new Fleet instance (no existing mdm_apple_enrollment_profiles row), upload an ABM token, then confirm the UI shows the updated default profile with the new skip items and
    removed keys.
  • On the same fresh instance, DEP-enroll a Mac and confirm at Setup Assistant:
    • Accessibility pane is shown (removed from skip list)
    • Region/Language chooser is shown (Region default removed)
    • Apple Intelligence, Software Update, Update Completed, OS Showcase, and Welcome panes are skipped
    • Device is supervised (automatic for ADE, IsSupervised key removed)
  • DEP-enroll an iPhone and an iPad against the fresh instance and confirm the setup flow matches expectations (new skip items do not cause DefineProfile rejections from Apple).
  • On an upgraded Fleet instance (ABM setup on prior fleet version, thus stored default profile row already existed before upgrade), confirm the stored JSON is unchanged after upgrade and the UI reflects the pre-existing defaults.
    Flag clearly in the feature guide that existing instances are not auto-updated.
  • On an upgraded instance, delete the ABM token and re-add it; confirm this does not refresh the default profile row. Downloading the profile still gets the old one
  • Upload a custom enrollment profile and confirm the Fleet default is hidden; only the uploaded file name shows (not the full path); custom profile contents still apply on enrollment.
  • Delete the custom profile and confirm the default re-appears with download (but not delete) available.
  • Test ADE enrollments of macs on macOS 14, 15, and 26 on a fleet instance with the new profile to confirm Apple accepts the new skip keys across supported OS versions and there are no issues with the new profile. Also test with latest iOS/iPadOS. Test with earlier(17+) iOS/iPadOS if possible(skip and document if not)
  • Run as global admin, global maintainer, global observer, team admin, team maintainer, team observer, team observer+, and GitOps — confirm permissions match the existing Setup Assistant section.
  • Verify that the Setup Assistant page in Setup Experience shows the proper(Existing) empty state when MDM is disabled or Apple MDM is enabled but ABM is not configured and does not break
  • Verify that Controls->Setup Experience shows the proper empty state(calling out need for fleet premium) on Fleet Free and does not break

Testing notes

Confirmation

  1. Engineer: Added comment to user story confirming successful completion of test plan.
  2. QA: Added comment to user story confirming successful completion of test plan.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

#g-apple-at-workProduct group focused on Apple devices:productProduct Design department (shows up on 🦢📨🎉 Product design intake & outtake board)storyA user story defining an entire feature~macos-workstationProduct maturity category~product-maturityContributes to Fleet's product maturity goals for the current year

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions