Organizations that already use Microsoft Intune, Configuration Manager or Jamf can now pre-install XFA and connect devices with their organization's enrollment token. Instead of waiting for each person to install the app, add XFA to your existing deployment so its checks are in place when people start using their devices.
The dashboard provides the setup steps, packages and commands for the rollout. MDM pre-installation is available on Enterprise. Deploy XFA through your MDM
The redesigned dashboard overview brings the status of Discovery, Awareness and Enforcement together with device posture, known risks and recent activity. See where your rollout stands, which risks need attention and what to do next, without piecing the picture together from several pages.
Recommendations point to the next useful setup or security action. The posture and risk cards keep the numbers alongside their explanation, so you can move from an overview to the devices that need a closer look. Open your dashboard
MFA requests now reach you through a system notification on Windows, macOS and Linux. Approve or deny the request from the notification itself, instead of having to open the XFA tray menu to find it.
Dashboard: rolling-release Linux devices show the basis for their OS assessment, including the last full update and local package vulnerability information, instead of treating “rolling” as a version number.
The new Getting Started page helps you get more out of XFA. It lays out four tracked steps, from discovering every device to staying secure and compliant, so you always know what to set up next.
The Devices page now opens with a card for Discovery, Awareness and Enforcement, so you can see at a glance where your organization stands. Each card says whether that pillar is running or waiting on you, with the number behind it: devices discovered, alerts sent, successful sign ins. See the Devices overview
Trends are now a single card: four tiles act as tabs above one chart, with the period, the operating system filter and the chart type on the card instead of in a fullscreen modal. Custom date ranges are supported, and the BETA labels are gone.
The device detail view now reports whether a device allows unattended remote access, and explains what the check looks for. You can act on it in your policy; XFA does not change the setting on the device. See your device policy
Dashboard: a Discovery integration that was never connected now shows a red alert and a Reconnect button, and counts towards the Discovery badge.
Dashboard: smaller interface fixes throughout, including larger tooltip and dismiss targets, steadier invoice rows, and long organization names that truncate instead of pushing controls off screen.
Dashboard: the Discovery page no longer shows a next run in the past. It is now anchored to the coming hour.
Dashboard: confirming a delete no longer leaves the button spinning. The dialog closes once the delete succeeds, and shows an error if it fails.
Desktop: the screen lock timeout row now shows a warning icon when the check fails on the timeout, instead of staying green while the check warns.
Desktop: the OS updates check now follows your policy grace in the app, the systray and the web flow alike.
Desktop: eighteen strings in the check details and fix actions are now translated in German, Spanish, French and Dutch, instead of falling back to English.
Mobile: approving MFA on another device no longer leaves the mobile app waiting.
The checks that flag a jailbroken, rooted or developer-mode device, or one that was just rebooted, already ran in the XFA app and showed in your dashboard. They now also reach the access decision at sign-in for mobile devices, so a risky mobile device is warned or blocked at login per your policy, the same way it already is on desktop. Nothing new is installed: the mobile app simply reports these signals when it verifies the device at sign-in. See your device policy
Dashboard: a lighter, more responsive feel, with smoother transitions, clearer hover and loading states, skeleton placeholders while data loads, and success confirmations that appear only once an action has actually saved. Motion respects your reduced-motion setting.
Dashboard: notifications are rebuilt to be calmer and more legible, and no longer duplicate, flicker or jump when several arrive at once.
Dashboard: Discovery and Enforcement now have a Watch demo action that opens a short guided tour without leaving the dashboard.
Desktop: the device-lock check now applies your organization's maximum screen-lock timeout, so it no longer shows OK in the app while sign-in is actually being blocked.
Desktop: the OS updates check on Fedora Linux is much faster, and no longer reports a device as out of date right after a reboot before its update data is ready.
Dashboard: setting up Google Workspace discovery no longer skips the domain-wide delegation step. You now confirm delegation is configured before continuing.
Web app: MFA and TOTP sign-in are more reliable. Trusted devices register after approval, malformed device tokens are refreshed instead of failing, and TOTP email confirmation links open the right step.
Dashboard: fixed a rare case where the dashboard could get stuck reloading right after a new version was deployed.
Dashboard: fixed a redirect loop that could bounce you back and forth during MFA sign-in.
Dashboard: blocked-account access handling is more consistent, and you now review your billing details before checkout.
Dashboard: an invited user's signup now always uses the invited email address, even if an earlier unfinished signup was left in the browser.
Setting up an Enforcement policy no longer means guessing what will happen. The policy settings now show a threshold timeline and a live timing summary as you edit, plus suggestion chips for common warn and block windows. You can see precisely when a device would be warned, and when it would be blocked, before you save. Enforcement stays configurable: a policy can warn or block, with or without an Awareness notification. Set up a policy
Discovery has a redesigned two-column overview and a clearer way to add a connection. Selecting Add connection now opens a provider picker for Microsoft, Google or Okta and takes you straight to a step-by-step setup page for the one you chose. Discovery reads the devices in your organization from a connected identity provider, so adding one is the first step to seeing every device in use. Connect Discovery
Dashboard: the Devices table now shows whether a device's Last Seen came from the XFA agent or from Discovery.
Dashboard: billing details and the change-address flow moved into a redesigned Subscription section, and adding a payment method now asks you to pick a plan first when none is active.
Dashboard: an account blocked for billing can still open Settings to download its invoices.
Dashboard: the Overview shows its shell and skeletons immediately for a faster first load, removing the blank white first paint.
Dashboard: the onboarding language switcher now uses the shared dropdown for a consistent look.
Integrations: you can now disconnect a Microsoft Teams connection from the Integrations page, the same as Slack.
Web app: the install and MFA screens have a refreshed layout and clearer copy.
Dashboard: the app now reloads itself once after a deploy instead of erroring on a stale page chunk.
Dashboard: the device-notify popup hides right away after you choose Don't show again.
Integrations: reconnecting Vanta no longer fails with a 500 error.
Administrators now get a clearer signal when a device with the XFA agent stops reporting a verified status. The Devices overview highlights these devices as Lost connection, making it easier to spot endpoints that need to reconnect and complete verification again.
You can filter by the new status in both the Devices and People views, then request verification from the Dashboard to help the user reconnect the XFA app and resume sharing device security status.
Administrators can now snooze individual devices from the dashboard when a device needs a temporary exception.
Snooze is available from the device action menu in the Devices overview and from the device detail page. Choose a preset or custom date and time for each device, optionally add a reason, and remove or update the snooze later from the same menu.
Snoozed devices are hidden from overviews and analytics by default, but remain available through the Show snoozed devices filter. During the snooze period, device checks and awareness notifications are paused for that device.
MFA remains active by default. Admins can explicitly include MFA in the snooze when they need to pause MFA for Enforcement sign-ins as well.
Add your own message to the bottom of XFA's onboarding and sign-in cards. Configure two separate messages — one shown during device onboarding, one during sign-in — from the Applications page in your Dashboard to reinforce your policies, link to an internal runbook, or add a bit of your own voice where end users will actually see it.
Policies now support compliance goals, giving you granular control over how and when devices are warned or blocked.
For each security check, you can now configure three separate actions:
Set your compliance goal — Define the time period in which devices should become compliant (e.g., 30, 60, or 90 days). This goal is only visible to administrators.
Warn users — Choose when users are informed about a risk: before the compliance goal or on the due date.
Block a device — Determine when non-compliant devices are blocked from access: before the compliance goal or on the due date.
For version-based checks (OS, browser, reboot), the device detail page now shows timeline badges with the configured goal, warning, and blocking thresholds in days, so you can see at a glance how close a device is to each deadline.
User status visibility - See at a glance what stage a user is in: installing the XFA app, affiliating their device with the organization, or undergoing device checks
Grant access to pending users - Users stuck in a pending state can now be manually granted access via the Allow access button
Failed checks details - Click on the badge to see which specific device checks failed (e.g., firewall, encryption, OS update)
Policy information - Each sign-in attempt now shows which policy the device was checked against
You can now add notes and tags to devices directly from the dashboard to better organize and track your device inventory.
Notes allow you to add custom descriptions or important information about specific devices. Whether it's tracking device assignments, maintenance schedules, or special configurations, notes help you keep all relevant device information in one place.
Tags provide a quick way to categorize and filter devices based on your organizational needs. Create custom tags for departments, locations, device types, or any other classification system that works for your team.
Both features are accessible from the device details view and can help streamline your device management workflow.
Visibility is everything when it comes to security. Our latest XFA Dashboard update makes it even easier to have an overview of devices connected to the business apps and a confirmation that your organization is secure.
This update brings a more detailed view of each device’s security health, a centralized overview of device checks that have been performed, and improved visibility across your team, designed to make device security simpler and your team’s productivity higher.
XFA now includes Trends in the dashboard, so administrators can track how device security changes over time. See how your fleet's compliance has evolved, spot patterns, and act on them before they turn into risk.
Trends plots your OS out-of-date rate — the share of devices running an outdated operating system — over time, giving you a clear read on whether your fleet is getting more secure or less.
We’ve introduced an easy way to see which high and critical vulnerabilities your devices might be exposed to. Right at the top of your dashboard, you’ll find three components that organize potential threats into clear categories:
Data Breach
Ransomware
Phishing
By clicking on any of these categories, you can see exactly which devices are affected. This makes it easier to prioritize and address security risks before they escalate.
In the Awareness tab, you can configure which devices and groups receive awareness emails.
Before you can configure which emails to send and the frequency, you need to define the scope for the devices and groups that will receive these emails.
When setting up the scope, you can choose between:
All Devices: Emails will be sent to all discovered or enforeced devices within your organization.
Limited Scope: Fine-tune which devices and users receive emails by configuring the following options:
Ignore Managed Devices: Exclude devices managed by your IT team from receiving emails.
Ignore Desktop Devices: Exclude desktop devices from receiving emails.
Ignore Mobile Devices: Exclude mobile devices from receiving emails.
If your organization has completed a discovery integration (e.g., with Google Workspace, Microsoft, or Okta), you can also configure group-based scoping:
Groups: Select specific groups to receive emails. These groups are managed within the integration application (e.g., Google Workspace Admin Console).
note
Scoping must be configured before selecting the email types and frequency.
You can now choose which notifications you want to receive.
We may still send you important information about your account outside of your notification settings.
You can now accept beta versions or major versions on your policy. This will allow you to have more flexibility when enforcing security rules for your organization’s devices.
This is only possible on the OS version or the browser version for now.
It's now possible to see the managed devices in your dashboard. This will give you a better overview of which devices are managed by an MDM and which are not.
You can see that managed devices have an extra tag in the overview. This tag is dependent on the MDM you are using to manage your devices.
We've added the statistics based on the device checks you have selected in your policy on your dashboard and in your weekly email. This will give you a better overview of the devices that are compliant with your policy.