You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Feature guide changes: Update articles/apple-mdm-setup.md . Call out that existing fleet instances are unaffected by new enrollment profiles being added and how to check which profile your instance is using.
This is a premium only feature: Yes
ℹ️ Please read this issue carefully and understand it. Pay special attention to UI wireframes, especially "dev notes".
Risk assessment
Requires load testing: No
Risk level: Low
Test plan
Make sure to go through the list and consider all events that might be related to this story, so we catch edge cases earlier.
On a brand-new Fleet instance (no existing mdm_apple_enrollment_profiles row), upload an ABM token, then confirm the UI shows the updated default profile with the new skip items and
removed keys.
On the same fresh instance, DEP-enroll a Mac and confirm at Setup Assistant:
Accessibility pane is shown (removed from skip list)
Region/Language chooser is shown (Region default removed)
Apple Intelligence, Software Update, Update Completed, OS Showcase, and Welcome panes are skipped
Device is supervised (automatic for ADE, IsSupervised key removed)
DEP-enroll an iPhone and an iPad against the fresh instance and confirm the setup flow matches expectations (new skip items do not cause DefineProfile rejections from Apple).
On an upgraded Fleet instance (ABM setup on prior fleet version, thus stored default profile row already existed before upgrade), confirm the stored JSON is unchanged after upgrade and the UI reflects the pre-existing defaults.
Flag clearly in the feature guide that existing instances are not auto-updated.
On an upgraded instance, delete the ABM token and re-add it; confirm this does not refresh the default profile row. Downloading the profile still gets the old one
Upload a custom enrollment profile and confirm the Fleet default is hidden; only the uploaded file name shows (not the full path); custom profile contents still apply on enrollment.
Delete the custom profile and confirm the default re-appears with download (but not delete) available.
Test ADE enrollments of macs on macOS 14, 15, and 26 on a fleet instance with the new profile to confirm Apple accepts the new skip keys across supported OS versions and there are no issues with the new profile. Also test with latest iOS/iPadOS. Test with earlier(17+) iOS/iPadOS if possible(skip and document if not)
Run as global admin, global maintainer, global observer, team admin, team maintainer, team observer, team observer+, and GitOps — confirm permissions match the existing Setup Assistant section.
Verify that the Setup Assistant page in Setup Experience shows the proper(Existing) empty state when MDM is disabled or Apple MDM is enabled but ABM is not configured and does not break
Verify that Controls->Setup Experience shows the proper empty state(calling out need for fleet premium) on Fleet Free and does not break
Testing notes
Confirmation
Engineer: Added comment to user story confirming successful completion of test plan.
QA: Added comment to user story confirming successful completion of test plan.
Related to: #40832
Goal
Changes
Product
UPDATE:
Engineering
Risk assessment
Test plan
mdm_apple_enrollment_profilesrow), upload an ABM token, then confirm the UI shows the updated default profile with the new skip items andremoved keys.
IsSupervisedkey removed)Flag clearly in the feature guide that existing instances are not auto-updated.
Testing notes
Confirmation