Skip to content
Avanet

Disable Sophos Central Tamper Protection safely

Tamper Protection safeguards Sophos services, settings and uninstallation against local changes. It is not a convenience switch. It is an important barrier against attackers who try to disable endpoint protection first.

For maintenance and troubleshooting, disable it for the shortest time and smallest scope possible. The local override for up to four hours is usually sufficient. Global disablement affects every managed device and is only appropriate for controlled bulk maintenance.

The current agent also uses Enhanced Tamper Protection from Sophos Endpoint Defense. It blocks configuration changes, stopping protected processes, manipulating registry permissions and replacing protected files. Local administrators and software deployment tools are affected as well.

⚠️ Do not confuse it with a policy: Tamper Protection protects the agent itself. Threat Protection, Web Control and other Endpoint features are controlled through separate policies.

Which method fits?

SituationRecommended methodEffect
short work on an accessible devicelocal override with device passwordup to four hours
longer maintenance on one devicedisable for that device in Centraluntil manually enabled
planned bulk maintenancedisable globallyall managed endpoints and servers
device already deleted from Centraluse deleted-device password or restorationdepends on platform and deletion time

Changes in Sophos Central require a role with the necessary administrative permissions. The function is available for Windows and macOS, not Linux.

Disable Tamper Protection for one device

The current entry point is My Environment > Computers & Servers.

  1. Open the affected device.
  2. Select Tamper Protection in the device area.
  3. Confirm Disable Tamper Protection.
  4. Wait for the device to retrieve the change.
  5. Check locally that the intended maintenance action is possible.

The setting remains disabled until it is enabled again for the device. An offline device applies the change only after its next successful connection to Central.

View a device password

The local override requires the individual device password:

  1. Open the device under My Environment > Computers & Servers.
  2. Select Tamper Protection or View details.
  3. Display the password and provide it only to the person performing the work.
  4. Do not retain the password in tickets, chats or unprotected notes afterwards.

Every device has its own password. A password from another Endpoint record will not work.

Use Generate New Password to create a password for exactly this device. Sophos Central deliberately provides no shared permanent master password for all endpoints.

Windows: override protection locally for four hours

  1. Open Sophos Endpoint from the shield icon.
  2. Select Admin sign-in or Admin-Login.
  3. Enter the device’s Tamper Protection password.
  4. Open Settings.
  5. Enable the Central policy override for troubleshooting.
  6. Turn off Tamper Protection under local user control.

The override ends automatically after no more than four hours. This is usually the safest method for diagnosis, repair and controlled uninstallation.

During the override, the device does not apply new or changed Central policies. End it immediately after the work instead of waiting for four hours.

Windows: control Tamper Protection with SEDcli

If the local Sophos interface cannot be opened, current Windows endpoints and servers provide SEDcli.exe. Open Command Prompt as administrator and change to C:\Program Files\Sophos\Endpoint Defense.

SEDcli.exe -status
SEDcli.exe -OverrideTPoff GERÄTEPASSWORT
SEDcli.exe -ResumeTP

-status shows the current state. -OverrideTPoff overrides the Central policy and disables protection for no more than four hours. -ResumeTP ends the maintenance window early and resumes the Central policy. If Sophos MCS Agent is not running, -ResumeTP may also require the device password.

Do not store the password in scripts: The device password appears as a command-line argument and may enter history, logs or process data. SEDcli is for controlled local repair, not persistent mass disabling.

macOS: override protection locally for four hours

  1. Open Sophos Endpoint on the Mac.
  2. Select Admin Login.
  3. First enter the local Mac administrator password and click OK.
  4. Click the padlock and Sophos icon, then enter the device password from Sophos Central.
  5. Open Settings and enable the Central policy override.
  6. Turn off Tamper Protection for the maintenance window and save.

End the override immediately after the work and verify that protection is active again.

Disable Tamper Protection globally

The global switch is under Global Settings > Products and Services > Endpoint and Server > Tamper Protection.

Global disablement is acceptable only when the scope, time window and rollback are documented. During this period, local administrators or malware can change Sophos components more easily.

Before disabling it, define at least:

  • affected devices and maintenance reason
  • start and planned end
  • responsible person
  • validation after the work
  • confirmation that the global switch is enabled again

The global method is disproportionate for individual devices.

When the global switch is off, no device is protected by Tamper Protection. A locally enabled state cannot compensate for global disablement. Account Health Check flags both a disabled global switch and individual unprotected devices; bulk changes appear in Audit Log.

If the device was already deleted

Sophos Central currently retains Tamper Protection passwords for deleted devices for 120 days. Deleted devices can be restored for 30 days. On current Windows versions from Windows 10 or Windows Server 2016, the modern Core Agent normally disables protection after deletion so password recovery is not required.

The exact process depends on the operating system, agent version and deletion time. Uninstall Sophos Endpoint after deletion from Central describes the current recovery path without registry changes.

Do not use old registry hacks: Manually disabling Sophos services and Tamper Protection keys in Safe Mode is no longer a standard uninstall route. It can leave the Core Agent inconsistent and make later installation or registration more difficult.

On current Windows devices with Core Agent 2023.2 or later, old recovery steps after Central deletion or licence expiry are no longer required. Windows Recovery Environment and registry recovery are a last, version-dependent support path only when Central, the local password, SEDcli, and restoring the deleted object all fail.

Recovery through macOS Recovery is likewise not standard. It changes protected product information so the Sophos uninstaller can run again. Because volume name, APFS data volume, FileVault state and agent version affect the procedure, use only the current Sophos instructions or work with Sophos Support.

When Enhanced Tamper Protection must be disabled temporarily

Besides uninstallation and local troubleshooting, a few legitimate operations are blocked by Sophos Endpoint Defense. These include an operating-system upgrade, restoring a Windows restore point and custom scripts that modify Sophos services, protected files or registry permissions.

A disabled switch is not a general solution for permanently blocked operations. Older agents could leave protection partly active after imaging or a Windows volume-name change because of a since-fixed defect. On current agents, update the installed Core Agent first instead of adopting old driver and registry workarounds.

After maintenance

  1. Enable Tamper Protection again for the device or globally.
  2. Wait until the device has applied the setting.
  3. Check the local protection status and components.
  4. Check last activity, health state and open alerts in Central.
  5. Securely remove temporary password records.

If the agent is to be removed completely, continue with Uninstall Sophos Central Endpoint on Windows.

For Macs, use the separate process in Uninstall Sophos Central Endpoint on macOS.

Common problems

The password is rejected

The computer name and Central record must match exactly. Also check the keyboard layout, copied whitespace and the last synchronisation. For a deleted device, retrieve the password from the deleted devices area.

The switch is unavailable in Central

Check the administrator role, product licence, operating system and current device status. Linux does not support Tamper Protection.

The device does not react to the change

An offline device cannot receive the Central setting. Check network, proxy, system time and last activity. On an accessible local device, use the four-hour override with the previously retrieved password.

Frequently asked questions

How long does the local override remain active?

The local policy override ends automatically after no more than four hours. Still verify immediately after maintenance that Tamper Protection is active again.

Should Tamper Protection be disabled globally for an uninstall?

No. For one device, use the local override or disablement in the device record. The global switch increases the attack surface of all managed devices.

Can Tamper Protection be disabled on Linux?

Sophos Central Tamper Protection is not available for Linux. Linux devices use a different management and uninstallation process.