# The macOS WARP client is finally GA!

Hey everyone, it's Shiichan! Today I want to share an update to the app that keeps your work Macs safe.

## What was announced?

From the Cloudflare Changelog: the macOS Cloudflare One Client (the WARP client), version 2026.6.822.0, has reached GA. You can grab it from the [downloads page](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/download/) now.

## The story so far

This client is the app that connects your company Macs to Cloudflare's Zero Trust network. It gets updated regularly, but this one is a milestone GA release that rolls up a big batch of new features and bug fixes.

## What changes

Security and manageability both take a nice step up. IT admins in particular get safer device registration and new ways to push settings. Even for everyday users, small wins like fixing the broken captive-portal screen on airline Wi-Fi make this a handy update.

## Dive Deep

Here are the main changes I could pull from the post.

- [Hardware-backed device registration](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/hardware-backed-registration/) using the Secure Enclave keeps registration keys better protected.
- [DNS search suffixes](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/configure/settings/#dns-search-suffixes) from device profiles and network policies now apply to single-label queries.
- The local DNS proxy now supports DNSSEC passthrough.
- New `warp-cli` debug commands make it easier to diagnose connections and grab [extra debug logging](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/troubleshooting/diagnostic-logs/#extra-debug-logging).
- A [new MDM format](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/parameters/#organization_configs) for org-wide settings, plus [client version assignments](https://developers.cloudflare.com/cloudflare-one/team-and-resources/devices/cloudflare-one-client/deployment/mdm-deployment/client-version-assignments/) managed from the dashboard.
- All API requests are unified under the api.devices.cloudflare.com SNI, and Path MTU Discovery is now on by default.
- The captive-portal rendering bug on airline Wi-Fi is fixed.

There is one known issue: registration can hang at "Checking your organization configuration". A reboot resolves it.

## Wrap-up

- macOS Cloudflare One Client 2026.6.822.0 is now GA
- Stronger security with Secure Enclave hardware-backed registration and DNSSEC passthrough
- Easier management via a new MDM format and dashboard-driven deployments
- Lots of smaller fixes, including the airline Wi-Fi rendering bug

If you manage Macs with Zero Trust, this is the update to check first!
