Skip to main content

Skip managed devices

Skip managed devices lets an application accept the devices your organization already manages, without running the XFA device check at sign-in. Use it when an MDM or your identity provider already covers part of your fleet, so that Enforcement focuses on the devices you know least about: personal laptops, phones and contractor machines.

Beta

Skip managed devices is in Beta. The setting carries a Beta label in the XFA Dashboard, and its behavior can still change.

Before you start

  • You need to be an admin of your organization in the XFA Dashboard.
  • XFA has to know that a device is managed. That knowledge comes from a connected identity provider through Discovery, or from rolling XFA out with your MDM. Without one of the two, no device counts as managed and the setting changes nothing.

Enable the setting

  1. Go to the XFA Dashboard and open Enforcement.
  2. Click New to create an application, or open an existing application.
  3. Under Filter options, check Skip managed devices.
  4. Save the application.

The setting belongs to that one application, so you can skip the check on an internal tool and keep it everywhere else.

Verify it worked

  1. On the Devices tab, find the device you want to test and check its Managed by column. XFA only skips the check for a device that is managed by the organization.
  2. Sign in to the application from that device. The sign-in completes without the device check.
  3. Sign in from a device that is not managed. The usual device check still runs, which confirms the setting did not widen beyond what you intended.

What counts as a managed device

XFA treats a device as managed when either of the following is true.

  • Discovery reported it as managed. When you connect Microsoft Entra ID or Google Workspace, XFA reads the management state of the devices it discovers. See Discover your devices.
  • You rolled XFA out with your MDM. A device that affiliates using your MDM enrollment token is recorded as managed at that moment.
A device cannot claim to be managed itself

XFA does not take the device's word for this. The management state is read from your identity provider or recorded during the MDM rollout, and it is held against that one device. A user cannot make a personal device skip the check by changing a setting locally.

How long it lasts

The two sources age differently, which matters when a device leaves your management.

SourceCounts as managed
MDM rolloutUntil Discovery reports the device as unmanaged, or the device is removed from XFA
Discovery (Microsoft Entra ID, Google Workspace)For 30 days after the last Discovery observation

The 30-day limit applies to Discovery-sourced management only. A device that Discovery stops seeing returns to the full device check 30 days after its last Discovery observation, and continued use of XFA does not keep that exemption alive, because it follows your identity provider and not the XFA agent.

Management recorded during an MDM rollout does not expire that way. A device that simply disappears from Discovery keeps it, however long it stays away. To end it, either let Discovery report the device as unmanaged, which replaces the MDM record, or remove the device from XFA. Take this into account when you offboard a device: unenrolling it from your MDM only ends the exemption once your identity provider reports the change to XFA.

Notes and troubleshooting

  • Multi-factor authentication still applies. Skipping the device check does not skip authentication. If the application is configured for Silent MFA or TOTP, the user is still asked for it.
  • Managed devices are also accepted without the XFA agent. An application that does not allow agentless sign in still accepts a managed device without the agent. This is intended, because your MDM already covers the device, but it is worth knowing if you enabled the setting expecting the agent to stay mandatory.
  • Email and operating system filters are applied first. If the application also filters on email addresses or operating systems, those decide first, whether or not the device is managed.
  • Discovery matches some devices on their properties. Where Discovery has no device identifier to match on, it matches on properties such as the user, operating system and model. In uncommon cases that can treat a second device of the same user, with the same operating system and model, as the managed one. Rolling XFA out with your MDM does not rule this out. The setting accepts management from either source, so for as long as an identity provider reports management state to XFA, Discovery-sourced exemptions stay possible alongside your MDM rollout. There is no setting that narrows the filter to MDM-sourced management only.
  • A device is managed for the whole organization. The setting is per application, but the management state behind it is not. You cannot treat one device as managed for one application and unmanaged for another.