Skip to main content

Application safety

Application safety checks the code signature of the apps installed on a device and flags apps whose signature is missing, broken, or not trusted. It is six policies, one for each kind of signature problem, so you decide for each one whether to warn or block.

Use these policies when you want to know how much untrusted software is on your devices without collecting a list of everyone's apps.

Before you start

Application checks are turned on per organization. If you do not see them under Policies, contact XFA to turn on application checks for your organization.

macOS and Windows are supported. Linux reports these checks as not supported. See Why is Linux not supported? below.

Why this matters

A code signature tells the operating system who made an app and whether it changed since. An app with no signature could come from anyone. An app whose files no longer match its signature was changed after its developer signed it, which can mean someone slipped something in.

The number of installed apps with a missing or untrusted signature is an early warning sign. XFA tells you that number without sending per-app data off the device.

Application safety policies

Each policy covers one kind of signature problem. The name in the first column is the name the user sees in the XFA app.

PolicyWhat it flagsPlatformsAPI name
Apps with no signatureThe app carries no code signature at all.macOS, Windowsno_unsigned_apps
Tampered appsThe app's files no longer match its signature, so it changed after its developer signed it.macOS, Windowsno_tampered_apps
Apps with a revoked certificateThe certificate that signed the app was revoked.macOS, Windowsno_revoked_signature_apps
Apps from an unknown developerThe app is signed, but not by a developer the operating system trusts. On macOS the signature does not lead back to Apple, so it is not a Developer ID, Mac App Store, or Apple signature. On Windows the certificate does not lead to a trusted root, or it is in the device's list of untrusted certificates.macOS, Windowsno_untrusted_signer_apps
Apps whose developer skipped Apple's malware checkThe app is signed with an Apple Developer ID but Apple did not notarize it.macOSno_unnotarized_apps
Self-signed appsThe app has only an ad-hoc signature, with no developer identity behind it. This is common for apps someone built on their own machine.macOSno_adhoc_signed_apps

Apps that pass include notarized apps, Mac App Store apps and Apple's own apps on macOS, and apps with a valid Authenticode signature that leads to a trusted root on Windows. On macOS, the shortcuts Chrome, Edge, Brave, or Vivaldi create for an installed web app are not flagged.

How the check works

The XFA app lists the apps installed on the device and checks the signature of each one. Each app gets exactly one result. One scan feeds all six policies.

macOS

  • Spotlight finds the installed .app bundles.
  • codesign reads the signature, the developer, and the certificate chain.
  • spctl asks Gatekeeper whether it accepts the app.

The XFA app never reads the user's private folders: Desktop, Documents, Downloads, iCloud Drive, cloud storage folders, the Trash, and removable drives. Apps stored there are not checked.

Windows

  • The Uninstall registry keys (HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall and its Wow6432Node mirror) list classic installed apps.
  • Get-AppxPackage lists AppX and MSIX packages.
  • UserAssist finds apps the user started that the registry keys miss.
  • Get-AuthenticodeSignature reads the Authenticode signature, the signer, and its trust status.

Linux

Linux reports these checks as not supported.

Apps XFA could not verify

On macOS and Windows, the signature check now and then does not finish for an app, for example a very large app on a busy device. The XFA app then shows that app to the user as Couldn't verify its signature and tries again in the background every 6 hours. On Windows, this happens once the check has not finished on two scans in a row.

Nothing about such an app goes to your organization, and it does not count toward any of the six policies.

What leaves the device

Per-app data never leaves the device. The names, paths, hashes, versions, and signature details of individual apps stay on the device.

Only the number of apps per signature category is sent, for example three with no signature, one self-signed, and forty-two notarized. The XFA app also sends whether the scan is still running and whether the check is supported on the device. Apps XFA could not verify are not counted.

You can therefore see that a device has four tampered apps without learning which apps those are. Only the user sees the list, on their own device.

What you can configure

You configure each of the six policies under Policies in the XFA dashboard, the same way as other on or off checks:

  • Warn. Devices with at least one such app get a warning in the XFA app and, if you configured it, an Awareness notification. Sign-in is not blocked.
  • Block. Devices with at least one such app are blocked from signing in to applications protected by XFA.

Leave a policy off to ignore that kind of app. Start with warn until you know how many devices a policy affects.

For how warning and blocking work across XFA, see Compliance goals.

What the user sees

The XFA app shows these checks under Application safety, one row per policy. A row that fails reads, for example, Apps with no signature found or Tampered apps found. A row that passes reads, for example, No apps without a signature.

Each failing row lists the apps involved, on the user's own device only. The user can:

  • Remove the app from the XFA app. XFA first lists exactly what it will remove and asks the user to confirm. When part of it needs administrator rights, macOS asks for an administrator password and Windows asks for permission through User Account Control. A removal cannot be undone.
  • Reinstall the app from its developer's own website or store.

XFA removes nothing unless the user confirms. When your policy covers a check, the user cannot ignore an app for that check. They can only remove it or replace it.

Frequently asked

Why is Linux not supported?

Linux signs software packages in the package manager, not individual programs. There is no equivalent of Authenticode or Apple code signing for each program, so treating every Linux program as unsigned would produce noise instead of signal. Risky app categories does support Linux, because it does not depend on signatures.

What about command line tools and helper programs?

The check covers .app bundles on macOS, and entries from the Uninstall registry keys, AppX, or UserAssist on Windows. Other programs, such as command line tools on macOS, are not checked. Apps that ship with the operating system carry the vendor's signature, so they pass.

Can one app match two policies?

No. Each app gets exactly one result, from the most specific signal available.

Does the dashboard see which apps are installed?

No. It sees the number of apps per category and the result of each policy.