Orbit fails to run when enrolling into a team with end user authentication enabled on macOS
-
customer-shackleton: Slack thread. -
#help-customers: Slack thread.
Fleet version: 4.77.0
💥 Actual behavior
When installing the agent using a generated package on a macOS host, enrolling into a team with end user authentication required enabled, the host fails to enroll to the Fleet instance.
The following error appears in the logs:
2025-12-11T08:25:46-08:00 INF orbit enroll attempt failed error="enroll request: end user authentication required"
2025-12-11T08:25:46-08:00 ERR opening SSO window error="opening browser: opening setup experience browser page not supported on darwin"
The behaviour is inconsistent across the same macOS versions (26.1)
🛠️ To fix
On manually-enrolled Macs, open up a browser window to do end user auth the same way Windows and Linux hosts do
🧑💻 Steps to reproduce
These steps:
- [ ] Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
- [x] Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
- Unable to reliably reproduce so far
🕯️ More info (optional)
Reproduced in Dogfood. Marking this as a P1 and assigning to @sharon-fdm.
Thanks @ksatter. I agree this is a P1. We are on it.
cc @sgress454 @lucasmrod
We're on it, thanks for the report!
@sgress454 @lucasmrod I'm not sure if #37134 is another manifestation of the same issue, can you take a look to see what you think?