Policies
You can create and manage device security policies to enforce specific security rules for your organization’s devices.
You have the flexibility to customize these rules and add Enforcement integrations to ensure that devices comply with your organization’s security standards.
✅ Available Security Checks
A policy can include the following checks:
-
Add devices to organization
- When enabled, devices will be added and reported to the organization.
-
Allow users to skip the device verification
- Users will be able to skip the device verification process and gain access to the application.
-
Allow unsupported devices to access the application
- Devices that aren’t supported by XFA can still access the application.
-
Validate Operating System version
- XFA will verify the OS version of each device. You can:
- Warn users after a specified period.
- Block users after a set period if the OS version doesn’t comply.
- Warn or block users with specific beta versions to access the application.
- Warn or block users with specific versions that are still supported (even when it's not the latest version) to access the application.
- XFA will verify the OS version of each device. You can:
-
Validate Operating System autoupdate setting
- XFA checks if devices have auto-updates enabled. You can:
- Warn users if autoupdates are disabled.
- Block users without autoupdates enabled.
- XFA checks if devices have auto-updates enabled. You can:
-
Validate browser version
- XFA verifies the browser version of each device and allows you to:
- Warn users after a period of time.
- Block users for outdated browsers after a certain time.
- Warn or block users with specific beta versions to access the application.
- Warn or block users with specific versions that are still supported (even when it's not the latest version) to access the application.
- XFA verifies the browser version of each device and allows you to:
-
Validate disk encryption
- Devices without disk encryption will trigger warnings or can be blocked based on your settings.
-
Validate screen lock
- XFA checks whether devices have screen lock enabled and allows for warnings or blocking users without it.
-
Validate antivirus
- The system verifies whether antivirus software is active on the device, with options to warn or block users without it.
-
Validate password manager
- Ensures users have a password manager enabled. You can decide whether to warn or block users who don’t comply.
Enforcement Integrations
You can integrate this policy with various enforcement tools (e.g., Microsoft, Google, Okta) to ensure that only compliant devices have access to your business platforms. This helps automate device security across your organization and guarantees that users meet the required security standards.
To modify or enforce these rules, visit your dashboard and configure the enforcement settings to fit your organization's needs.
For more details on enforcement, refer to our enforcement documentation.