Noah Talerman
Noah Talerman
Teams are available in Fleet Premium.
In Fleet, you can organize hosts into 'teams' to apply queries, policies, scripts, and other configurations tailored to their specific risk and compliance requirements.
To manage teams:
Note:
- A host can only belong to one team.
- You can give users access to only some teams.
Fleet's best practice teams:
💻 Workstations
: End users' production work computers (macOS, Windows, and Linux)💻🐣 Workstations (canary)
: IT team's test work computers. Sometimes, for demos or testing, includes end user's work computers. Used for dogfooding a new workflow or feature that may or may not be rolled out to the "Workstations" team.☁️ Servers
: Security team's production servers.☁️🐣 Servers (canary)
: Security team's test servers.Compliance exclusions
: All contributors' test work computers or virtual machines (VMs). Used for validating workflows for Fleet customers or reproducing bugs in the Fleet product.📱🏢 Company-owned iPhones
: iPhones purchased by the organization that enroll to Fleet automatically via Apple Business Manager. For example, iPhones used by iOS Engineers.🔳🏢 Company-owned iPads
: iPads purchased by the organization that enroll to Fleet automatically via Apple Business Manager. For example, conference-room iPads.📱🔐 Personally-owned iPhones
: End users' personal iPhones, like those enrolled through a BYOD program, that have access to company resources.If some of your hosts don't fit into the teams listed above, consider their purpose. This will help determine their risk and compliance requirements, which in turn define their security baseline and appropriate team in Fleet. If these hosts have distinct compliance needs and security baselines, it's advisable to create a new team in Fleet.
You can add hosts to a team in Fleet by either enrolling the host with a team's enroll secret or by transferring the host via Fleet UI after the host has been enrolled to Fleet.
Quick tip: When viewing a specific team (from the Teams dropdown), Selecting Add hosts will display instructions to add new hosts directly to that team.
Quick tip: You can hit the checkbox next to the host you wish to transfer to access its quick menu. From there, select Transfer and follow the on-screen instructions.
You can automatically enroll hosts to a specific team in Fleet by installing a fleetd with a team enroll secret. Learn more here.
Changing the host's enroll secret after enrollment will not cause the host to be transferred to a different team.