Skip to main content

Enforce Device Security

Enforcement adds device security to authentication by checking whether a device passes your XFA policy before access continues. Depending on your configuration, XFA can warn users, block access, or allow exceptions without managing or taking control of the device, so rollout can match your risk tolerance.

XFA supports integration with the following identity providers:

By linking your IDP to XFA, you can enforce device compliance during authentication.

Configuring Enforcement Integrations

Configure on an application

You can also configure enforcement for specific applications. XFA supports the following integrations:

Custom SAML Integrations

For applications not listed above, XFA supports custom SAML integrations. This allows you to enforce device security on any SAML-enabled application.

Google Workspace Google

Google Workspace can also be linked to XFA via a SAML integration to enforce device compliance.

🔐 Multi-Factor Authentication

XFA offers multiple MFA methods to add an extra layer of security to your integrations:

Silent MFA

Silent MFA provides multi-factor authentication without interrupting the user experience. Users approve authentication requests directly in the XFA App, ensuring secure access without unnecessary friction.

TOTP Authentication

TOTP (Time-based One-Time Password) allows users to authenticate using temporary codes from authenticator apps like Google Authenticator or Microsoft Authenticator. This industry-standard method works offline and is compatible with any TOTP-compliant app.

Both MFA methods can be enabled on a per-integration basis.


With the Enforce Device Security feature, XFA empowers your organization to secure its critical applications and systems by ensuring only trusted and compliant devices can access them. Explore the individual application guides linked above to configure enforcement for your specific use cases.