A full-coverage alternative to Iru

XFA verifies every device at login without enrolling it in an MDM or taking control of it. Built for teams that also need to secure personal and contractor devices, on any operating system.

See XFA next to Iru for your team

We can help you compare based on your team's needs.

Securing devices for leading organizations like

What is XFA?

XFA is the device security solution that identifies every device used by people in your organization, informs users about risks, and verifies compliance with your security policy at login, without needing to manage the device. It runs standalone: no identity provider migration, no manual device enrollment.

What is Iru?

Iru, formerly Kandji, is a platform that combines device management, endpoint security, identity and compliance. Its main product is Iru Endpoint, an MDM that lets IT enroll, configure and control company-owned devices through an installed agent. Iru then uses that managed-device status to decide who can sign in to company apps. We will compare this specific feature with XFA.

XFA vs Iru, feature by feature

IncludedNot included
XFA
Iru

Device trust

OS version, disk encryption and screen lock checks

Included
Included

Jailbreak and root detection

Included
Included

Browser kept up to date

Included
Included

Active antimalware verified

Included
Included

Covers the most common operating systems

Included
Not includedLinux is not supported.

BYOD

Works for company-owned devices

Included
Included

Made for self-install

Included
Not included

Discovers every device through SSO, no install required

Included
Not includedIru only sees the company-owned devices it manages. Unmanaged devices stay unknown to the organization.

Setup & admin

Centralized admin dashboard

Included
Included

Self-serve setup, no IT rollout

Included
Not included

Per-device CVE insight from OS and browser versions

Included
Included

Warns users before they are blocked at login

Included
Not included

Ecosystem

Works with any identity provider

Included
Okta, Entra, Iru Identity

No device management migration needed

Included
Not included

Why teams choose XFA over Iru

Three differences that decide it for most teams.

Secure unmanaged devices too

XFA verifies the security of unmanaged devices at login, without enrolling them. It can run alongside your MDM or replace it. Iru only secures the company-owned devices it manages.

Privacy-first by design

XFA needs no admin rights and only reads security signals at login. With no invasive management, personal devices can be secured too.

Every operating system, Linux included

Windows, macOS, Linux, Android and iOS get the same checks, so one tool covers every device your team uses for work.

See the difference in your own environment.

Start free.

Simple per-user pricing with unlimited devices, and no migration from your current setup required.

See the difference in your own environment.

What our customers say

"I think it's a good balance between being lightweight, non-intrusive, and transparent. Transparent in the sense of what you are looking at. The only way for me to get adoption was actually giving people access to the dashboard and showing what I'm looking at. Other solutions we tested didn't make it that transparent."
Read the full testimonial →
Gus Fune
Gus FuneChief Technology Officer
G24.9/5 on G2