Install protection
Install protection checks that the operating system checks apps before they run. On macOS that is Gatekeeper. On Windows it is SmartScreen for apps and files. The API name of the policy is install_protection.
Use this policy when you want the operating system itself to warn about or stop untrusted apps before they run, not only report on them afterwards.
Application checks are turned on per organization. If you do not see them under Policies, contact XFA to turn on application checks for your organization.
macOS and Windows are supported. Linux reports this check as not supported, because it has no equivalent of Gatekeeper or SmartScreen across distributions.
Why this matters
Application safety tells you which untrusted apps are already on a device. Install protection comes before that: it decides whether the operating system warns about or stops such apps before they run. With Gatekeeper or SmartScreen off, an unsigned or known bad app runs without a warning.
Both are on by default. Users turn them off to get past a dialog they did not understand, and malware turns them off on purpose. Either way, you want to know.
How the check works
The XFA app reads the current state of the setting. It collects nothing about specific apps or install attempts.
macOS
spctl --statusreports whether Gatekeeper is on. The check fails when Gatekeeper is off.
Windows
- The
SmartScreenEnabledvalue underHKLM\Software\Microsoft\Windows\CurrentVersion\Explorerholds the SmartScreen setting for apps and files. - The
EnableSmartScreenvalue underHKLM\Software\Policies\Microsoft\Windows\Systemholds a Group Policy or MDM setting. When it is set, it wins over the setting above. - The check fails when SmartScreen is off, in the setting or through Group Policy or MDM.
Get-MpPreferencereports whether Microsoft Defender's protection against potentially unwanted apps (PUA) is on. XFA reports this state, but it does not decide the result, because Defender scans apps after they are installed rather than before they run.
Linux
Linux reports this check as not supported.
What leaves the device
Only the state of the setting is sent: whether Gatekeeper is on on macOS, and the SmartScreen setting and the Defender PUA state on Windows.
Nothing about specific apps, install attempts, blocked programs, or user actions is collected or sent.
What you can configure
You configure this policy under Policies in the XFA dashboard, the same way as other on or off checks:
- Warn. Devices with install protection off get a warning in the XFA app and, if you configured it, an Awareness notification. Sign-in is not blocked.
- Block. Devices with install protection off are blocked from signing in to applications protected by XFA.
For how warning and blocking work across XFA, see Compliance goals.
What the user sees
The XFA app shows this check under Install protection. It reads Install protection is disabled when it fails and Install protection is active when it passes.
When it fails, the user can click Turn on install protection. XFA runs the command that turns Gatekeeper or SmartScreen back on. First macOS asks for an administrator password, and Windows asks for permission through User Account Control. Nothing changes unless the user starts it and allows it.
On Windows, when Group Policy or MDM turned SmartScreen off, XFA cannot turn it on. The XFA app tells the user to ask their IT administrator instead.
Frequently asked
Why is Linux not supported?
Linux has no equivalent of Gatekeeper or SmartScreen across distributions. Some package managers check package signatures, but there is no single setting to read.
What if a user turns off Gatekeeper to install one app?
The check reads the current state on every run, so the device is flagged for as long as Gatekeeper is off. Turning it back on clears the warning on the next run.
Why does Defender PUA protection not decide the result?
Defender PUA protection scans apps after they are installed. Install protection is about the check before an app runs, which is SmartScreen on Windows. XFA still sends the Defender PUA state so you can see it.
Does this check report on individual apps?
No. It only reads the operating system setting. Checks on individual apps are in Application safety and Risky app categories.
Related
- Application safety, which finds untrusted apps that are already installed.
- Risky app categories, for apps in categories that do not belong on a work device.
- Policies