Manage Sophos Endpoint agent mode and software
Sophos Central manages the product scope of an already registered computer through Manage device software. The agent mode is the first important decision. It determines whether Sophos provides protection or only detection and response data alongside a third-party product.
The former dialogue with separate columns for “Endpoint Protection” and “Intercept X” no longer reflects the current model. Agent mode and other licensed products are now managed directly in the unified device view.
Agent modes
| Agent mode | Sophos protection | Detection and response | Third-party antivirus required |
|---|---|---|---|
| Endpoint | yes | no | no |
| XDR | yes | yes | no |
| XDR Sensor | no | yes | yes |
⚠️ XDR Sensor does not protect against malware. It must only be used when a separate, working protection product is present. Switching from XDR Sensor to Endpoint or XDR can remove existing third-party protection.
The available modes depend on the licence, operating system and device type. XDR Sensor is only available with an MDR licence and doesn’t support Sophos Security Heartbeat with Sophos Firewall.
The Windows XDR Sensor is supported on Windows 10 x64 and later and Windows Server 2016 and later; legacy platforms do not support Sensor mode. It provides suspicious activity, Event Collection, Data Lake upload, Live Discover, Live Response and device isolation. The Sophos interface is installed but does not start automatically in this mode.
It does not include Anti-Malware file protection, behaviour-based blocking, Exploit and Ransomware Protection, Web Protection, Web Control, Application Control, Peripheral Control, DLP or Unauthorized File Protection. The presence of services such as Sophos File Scanner or Network Threat Protection does not change this: in Sensor mode they provide telemetry, script monitoring or isolation, but not complete Sophos protection. Configure blanket mutual exclusions with the third-party product only for a specifically confirmed compatibility issue.
Check the software scope
Under My Environment > Computers & Servers, the Agent mode and Agent mode status columns and filters show the current state.
The most relevant values are:
Product unassigned: licensed software has not yet been assigned to the device.Upgrade available: additional licensed features can be installed.Installed: the intended agent mode is installed.Not Supported: the product or mode is not supported on this device.
The Account Health Check reports devices that do not match the available licences. An automatic fix can distribute software to many devices, so it must first be checked against the intended operating model.
Change software on a device
- Open My Environment > Computers & Servers.
- Select one or more similar devices.
- Select Manage Software.
- Choose the intended mode under Agent mode.
- Assign other displayed products, such as Device Encryption or ZTNA, only after checking the licence and platform.
- Confirm with Save.
- Wait until the devices are online and update.
Sophos states that the normal change often takes about an hour. This is not a guaranteed deadline. Offline devices apply the change only after their next contact.
Checks before switching
A product switch is a software change and requires the same care as a rollout:
- target mode and licence are documented
- the pilot group contains representative devices
- existing third-party protection is considered
- a maintenance window and possible restart are planned
- disk encryption and recovery keys are checked
- proxy, update cache and download path work
- business applications are tested after the switch
In particular, switching from XDR Sensor to Endpoint or XDR can remove competing protection. Without a pilot, this can temporarily produce duplicate or missing protection.
Device Encryption and other products
Additional products appear only when the licence and platform are suitable. An assignment can trigger installation immediately, even when an Update Management policy specifies a different maintenance window.
Before deploying Device Encryption, check at least the TPM or FileVault requirements, user assignment, recovery-key process and any existing BitLocker or FileVault configuration. A visible plus button is not a rollout plan.
Remove software
Manage device software can remove individual products or change the agent mode. The Sophos Core Agent remains installed so that Central can continue to manage the device and assign software later.
This is not a complete uninstall. For final offboarding, follow Uninstall Sophos Central Endpoint on Windows.
Validate the change
After assignment, check Central and the device:
- Agent mode status shows
Installed. - The expected policies apply on the Policies tab.
- Locally, About shows the expected components and versions.
- Health state and last activity are plausible.
- Third-party protection is correctly present or removed for the target mode.
- No installation, update or restart alerts remain open.
A green health state alone does not confirm the correct agent mode.
Common problems
The change remains pending
Check last activity, network, proxy, update cache, free disk space and pending restarts. An offline device cannot apply a software assignment.
XDR features are missing
Check the licence, agent mode and platform together. Endpoint includes protection but not the full XDR feature set. XDR must be assigned and installed as the agent mode.
Third-party antivirus was removed
This can happen when switching to Sophos protection. Only XDR Sensor is intended for detection alongside a separate protection product. The target mode must be unambiguous before a bulk change.
Manage Software does not remove everything
This is expected. The Core Agent remains installed for management. A complete removal uses SophosUninstall.exe locally.