More power to manage your devices
1781520902392
Turbocharged management for macOS:
Deploy PKG apps the way you prefer
You can now choose how you want to deploy PKG files using MDM or Agent-based installation.
This gives you the flexibility to align app deployment with your operational needs instead of adjusting your workflow to platform limitations.
When you select Agent-based installation, you unlock advanced configuration controls.
What’s new
Keep apps always installed on devices.
Show pre-install alerts and installation progress notifications.
Configure deferral options and override DND restrictions when needed.
Define custom installation detection using app bundle paths, files, folders, or custom scripts.
Run pre-install, post-install, and uninstall scripts to control the full app lifecycle.
Use a guided publish flow that walks you through installation mode and configuration selection.
View detailed status information, including the installation or execution mode used during publishing.
Offer Self-Service for ES Apps and Scripts
You can now extend Self-Service beyond the App Catalog. Add Enterprise Store (ES) apps and scripts directly to Self-Service and give users controlled flexibility.
With this feature, you can:
Publish ES apps and scripts to Self-Service.
Silently install apps while still listing them in Self-Service.
Allow users to uninstall apps when required.
Display script descriptions in Self-Service so users understand what they’re running.
Improve Script reliability automatically
You no longer need to chase failed executions manually. Reduce remediation effort and improve execution success rates across your macOS fleet.
If a script fails, the agent automatically retries execution up to three times before marking it unsuccessful.
Identify failed devices directly from the View Status option on the dashboard
Re-execute the script instantly.
Updates to OneIdP
OneIdP now supports Passkeys for SSO authentication
Your users can authenticate using built-in biometric authentication, external hardware security keys, or mobile devices using QR code-based authentication.
You can now:
Enable or disable Passkeys at the Directory level.
Once enabled, users will be prompted to register a Passkey.
After setup, future sign-ins will use Passkeys across supported platforms.
If users don't have access to their Passkey device or authentication fails, they can continue signing in using their password.
Additional improvements include:
IT teams can reset configured MFA methods and Passkeys from the Dashboard
Users can manage their MFA methods and Passkeys from the User Portal
Note:
Compliance checks continue to be enforced regardless of the authentication method used.
Passkeys do not replace MFA policies. Users will still be prompted for MFA wherever configured.
Note: Passkeys work across supported sign-in flows. For certain native desktop and mobile applications, authentication behavior may vary based on platform support. We are continuing to optimize the experience for these scenarios.
Enhanced security for service accounts
Service accounts created by the Scalefusion MDM Agent now have additional security controls!
If a local administrator changes the service account password, the agent automatically detects the change and rotates the password.
Service account passwords are automatically rotated every 30 days.
Interactive RDP logins using the service account are blocked.
What’s new with Linux
App Inventory for Linux devices
You can now view installed applications on Linux devices directly from Device Details and App Version Reports.
Applications are automatically categorized into:
Desktop Apps
All Executables
This makes it easier to understand exactly what's running on managed Linux devices and improve software visibility across your fleet.
Note: The Last Updated Time shown for applications is currently being improved and may not always be accurate.
Branding support for Linux
Create a more consistent user experience across managed Linux devices. You can now configure wallpapers and login screen messages for Linux devices using Branding policies.
Note:
Raspberry Pi OS (Raspbian) does not support the complete Branding feature set.
On Nobara and MX Linux, wallpaper configuration is supported, but login screen messages are not.
Public IP Address visibility
Linux device information now includes the device's public IP address.
You can view this information from:
Device Details
Device Inventory Reports
This makes it easier to identify device connectivity and troubleshoot remote devices.
Update device hostname while renaming
When renaming a Linux device from the dashboard, you can now choose to update the device hostname at the same time. No additional steps required!
Support for Manjaro Linux
Scalefusion now supports basic management capabilities for Manjaro-based Linux devices.
This expands Linux device coverage and gives administrators more flexibility when managing mixed Linux environments.
Note: Remote Terminal with Consent is currently not supported on Manjaro devices.
Stay ahead with Zebra Lifeguard OTA enhancements
Don’t wait for full version jumps to keep devices updated. You can now detect and publish incremental (dot) releases in addition to major version upgrades when using Zebra Lifeguard OTA.
If re-authentication is required for the Lifeguard OTA integration, you’re alerted directly within the Scalefusion dashboard so you can quickly restore synchronization.
Additional enhancements to your Scalefusion experience
Script Execution Reports
Script Execution Reports can now be downloaded for the last 5 days or for a specific date, making it easier to review script execution history and track execution status over time.
This enhancement is particularly useful for environments where report scheduling is configured.
For reports that are not scheduled, or for scheduled reports that have not yet run, the Last 5 Days option provides the most recent script execution status available for each device.
Better visibility into APK signature mismatches
Managing multiple versions of the same Android app just got easier. You can now upload different versions of the same application even if they use different signing certificates.
To help prevent deployment issues, Scalefusion now alerts you when signature mismatches are detected during app upload. A note is also displayed in App Details whenever uploaded versions of an app use different signatures.
You'll also get visibility during app publishing.
If devices in a profile or group already have a version installed with a different signature, a certificate indicator is shown to highlight that the update cannot be installed directly.
In such cases, the existing app must be uninstalled before the new version can be installed.
Prevent Broadcast Message from deletion
Enable retention of high-priority communications on-device until they're no longer needed. On Android, iOS, macOS, and Windows devices, now configure the number of days until which the user cannot delete the received message.
Note: If not enabled, users can delete all messages by default.
Updates to the Android MDM Agent
The agent now supports a 16KB page size, aligning with Google’s latest Android guidelines and improving compatibility with Android 15 devices for better performance on modern hardware.
Note: This is a critical update affecting core agent flows, so we recommend validating the build on a few devices before mass rollout.
Windows MDM Agent
We noticed OS update reporting wasn’t fully accurate on domain-joined devices. That’s now fixed. What’s installed and what’s reported are back in sync.
Simplified day-to-day management.
What’s new
Use special characters like ! @ # $ % & * _ - in file names within Content Management (subject to OS-level support).
Use the new “Clear Files” role, now separated from “Clear App Data,” to gain more granular administrative control.
Ensure core macOS policies continue to apply even if Active Directory connectivity fails, thanks to improved payload handling.
Improved MDM Agent-based OS update reporting to ensure more consistent visibility of updates on domain-joined devices.
Did you like this update?
![]()
![]()
![]()
Leave your name and email so that we can reply to you (both fields are optional):
