June 2026 Summaries
9 posts from Fleet
Filter
Month:
Year:
Post Summaries
Back to Blog
EDR Freeze is a stealthy technique that allows attackers with root access to suspend security tools, making them appear operational while disabling their functionality, posing a threat to macOS systems. Santa, an open-source binary authorization agent for macOS maintained by North Pole Security, has introduced version 2026.3 to counteract this by adding the AntiSuspendSigningIDs configuration, which prevents the suspension of specified processes. The protection can be deployed and monitored using Fleet, which integrates Santa's configuration into existing GitOps workflows, allowing for version-controlled changes without the need for additional infrastructure. Santa's telemetry can detect attempts to suspend processes, and Fleet provides a centralized platform for monitoring the health and status of macOS hosts. This solution leverages existing tools and workflows to enhance security without the overhead of traditional sync servers, using Santa's built-in capabilities to protect against EDR Freeze attacks effectively.
Jun 29, 2026
2,210 words in the original blog post.
macOS 26.4 introduces the Managed Migration Assistant, transforming Mac-to-Mac migrations from user-controlled processes into IT-governed policies to enhance security, compliance, and operational efficiency. This tool allows IT departments to define which data, folders, and user accounts are transferred during a migration, while also providing an audit trail and status reports that detail what was moved and when. The Managed Migration Assistant integrates with Apple's deployment stack, supporting automated device enrollment and enabling seamless, zero-touch migrations. It uses version-controlled YAML configurations within a GitOps workflow, ensuring that migration policies are peer-reviewed, auditable, and reversible. This approach not only facilitates faster hardware refreshes by selecting optimal data transfer methods but also addresses security concerns by preventing the migration of unwanted data like personal accounts and outdated credentials. The system's success hinges on deploying it with devices enrolled through Apple Business Manager or Apple School Manager and requires the source Mac to be authenticated by users with local administrator credentials, which can be managed through tools that allow temporary privilege elevation.
Jun 26, 2026
1,581 words in the original blog post.
AI is transforming the IT landscape not by eliminating jobs but by redefining the skills required to perform them, with experience rather than job function determining who benefits most. The shift is creating a clear divide between employees who adapt to AI-enhanced, code-first workflows and those who rely on traditional, GUI-based systems, with the former gaining a measurable productivity advantage. While AI tools can significantly boost efficiency when integrated with structured configurations like GitOps repositories, the rapid evolution of skills demanded by AI is outpacing many workers, resulting in a wage premium for AI-specific roles. This shift has led to employment declines among younger workers in AI-exposed roles, while more experienced workers see employment growth, highlighting that judgment and deep systems knowledge are crucial assets. The labor disruption primarily affects individuals rather than organizations, as evidenced by companies like General Motors, which have reported strong earnings despite workforce reductions. Trust in AI accuracy is declining among developers, suggesting a need for careful engagement with AI without excessive optimism or panic. The World Economic Forum's projections indicate a net gain in jobs by 2030 but with uneven distribution, emphasizing the importance of developing judgment and system design skills that AI cannot easily replace.
Jun 26, 2026
1,114 words in the original blog post.
Config-as-code has become the standard approach for device management, allowing platforms like Jamf, Zentral, Workspace ONE, and Fleet to describe endpoints in a repository and manage changes through version control. The key debate now centers on the costs associated with this approach, including the time commitment, required skill level, and potential reliance on individual expertise. Platforms like Fleet use a simpler, built-in config-as-code method that allows teams to gradually adopt GitOps, reducing the barrier to entry and allowing more team members to participate without deep technical expertise. In contrast, using tools like Terraform offers robust capabilities but also demands handling complex infrastructure concerns such as provider management, state files, and lifecycle operations, which may be challenging for teams without dedicated platform engineering resources. The effectiveness of config-as-code is ultimately measured by its ability to retain institutional knowledge in documented schemas and readable repositories, ensuring continuity and resilience even when team members depart. The choice between different config-as-code approaches should consider factors like team participation, ongoing maintenance costs, phased adoption capabilities, and the potential impact of personnel changes to ensure the workflow remains operable by the entire team.
Jun 18, 2026
2,426 words in the original blog post.
Adopting CIS benchmarks is a common practice for organizations aiming to enhance security, but verifying compliance in real-time is challenging due to traditional MDM tools' limitations, which often only confirm the delivery of configurations rather than their current effectiveness. Fleet addresses this gap by continuously monitoring each device's live state, providing real-time compliance metrics instead of periodic snapshots, thus ensuring immediate detection and remediation of any drift from compliance. This approach transforms compliance verification from an intermittent task into an ongoing operational process, reducing the burden of audit preparation and ensuring a unified compliance view across macOS, Windows, and Linux platforms. By utilizing Fleet, organizations can demonstrate continuous control and provide stronger evidence of compliance, as the system allows for automated remediation and maintains a current evidence trail, simplifying the process of meeting CIS benchmarks.
Jun 11, 2026
1,557 words in the original blog post.
In technology organizations, the common friction between IT and security teams often arises from their reliance on disparate data sources, leading to disagreements over device inventories and vulnerability management. This divide is exacerbated by the use of different tools that produce conflicting data, creating inefficiencies and risks, especially as the time from vulnerability disclosure to exploitation has dramatically shortened. Fleet addresses this issue by providing a unified, real-time inventory across all device platforms, enabling both IT and security to work from the same data, thus eliminating the need for reconciliation and reducing disruptive requests. This shared platform also transforms audit and compliance processes by maintaining continuous compliance data, allowing organizations to produce evidence on demand without the usual pre-audit scramble. By aligning IT and security through a single foundation, Fleet fosters a collaborative rather than adversarial relationship, streamlining incident response, patch management, and compliance, ultimately leading to a more secure organizational environment.
Jun 11, 2026
1,446 words in the original blog post.
Shadow AI, which refers to unauthorized AI tools running on devices, poses a challenge for endpoint management as traditional tools often miss these unsanctioned applications. AI tools leave detectable footprints on endpoints across macOS, Windows, and Linux, but they often bypass identity providers and SaaS catalogs since they're not sanctioned apps. Fleet provides a solution by turning devices into live databases that can be queried in real time, offering insights into the AI tools running across an organization's network. This approach allows for effective governance by storing reports and policies as code in Git, enabling auditability and reversibility. Standardizing on a single AI vendor doesn't mitigate the risk as transformative work often occurs outside official boundaries, in native desktop apps and command-line interfaces. Fleet's open-source, API-first design ensures transparency and allows organizations to manage AI governance efficiently, transforming detection into actionable insights by matching discovered tools against CVE data and enabling software updates and policy enforcement. This proactive approach to endpoint management ensures organizations can adopt agentic development responsibly, establishing necessary guardrails while maintaining visibility and control over their AI ecosystem.
Jun 10, 2026
1,933 words in the original blog post.
Annual compliance audits often cause significant disruptions for IT teams due to the need for extensive evidence gathering, which diverts focus from strategic tasks to manual data reconciliation and reporting. This challenge stems not from the compliance frameworks themselves, but from the inadequacy of traditional management tools that are not designed for continuous compliance evidence, such as MDM platforms. Fleet's approach introduces an architecture focused on continuous audit readiness, utilizing live device state assessments and continuous policy evaluations across all platforms to provide a reliable, unified evidence package. By integrating configuration as code and leveraging a GitOps workflow, Fleet ensures seamless change management and separation of duties, enhancing audit trail accuracy and integrity. This model not only addresses the gap between control requirements and evidence but also adapts to evolving audit demands for speed and AI integration, positioning continuous evidence as an operational norm rather than an exceptional burden.
Jun 02, 2026
2,344 words in the original blog post.
Fleet's continuous evidence architecture streamlines audit preparation by integrating compliance monitoring into everyday device management, reducing the traditional pre-audit scramble to a simple verification step. The architecture operates on principles such as live device state monitoring, continuous policy evaluation, and unified multi-platform coverage, which align with various compliance frameworks like SOC 2, ISO 27001, HIPAA, PCI-DSS, FedRAMP, NIST, and CIS. Fleet continuously monitors endpoint controls, such as device encryption, software inventory, and policy compliance, generating real-time and historical compliance data that auditors require. This approach ensures audit readiness by maintaining a comprehensive and ongoing record of compliance, as opposed to relying on point-in-time reports. Fleet also integrates with existing Mobile Device Management (MDM) systems, offering a detailed observation layer without requiring organizations to change their device management vendors immediately. By embedding compliance into regular operations, Fleet transforms audits into routine checkpoints of continuous compliance, enhancing both security and efficiency across organizational teams.
Jun 02, 2026
3,192 words in the original blog post.