Application safety
What it checks
Most apps are signed by the company that made them, a bit like a seal on an envelope. XFA looks at the apps installed on your device and checks whether each one carries a valid signature from a developer your operating system trusts.
The XFA app shows these checks under Application safety, for example Apps with no signature found or Tampered apps found.
Why it matters
A signature tells your computer who made an app. An app with no signature could come from anyone. A tampered app changed after its developer signed it, which can mean someone slipped something in. Those are the apps worth a second look.
What XFA sees
XFA reads the signature of each app on your device. Your organization only gets the number of apps in each group, for example "three apps with no signature". It does not get the names.
XFA sometimes cannot finish checking an app, for example a very large one. The XFA app then shows it to you as Couldn't verify its signature and tries again later. Nothing about that app goes to your organization.
What happens if it does not pass
The XFA app shows you which apps are involved and what you can do:
- Remove the app. XFA first lists exactly what it will remove and asks you to confirm. When part of it needs administrator rights, your Mac asks for your administrator password, and Windows asks for your permission. A removal cannot be undone.
- Install the app again from the maker's own website or store.
XFA never removes anything unless you confirm it.