Disable Sophos Fusion Tamper Protection safely
Tamper Protection safeguards Sophos services, settings and uninstallation against local changes. It is not a convenience switch. It is an important barrier against attackers who try to disable endpoint protection first.
For maintenance and troubleshooting, disable it for the shortest time and smallest scope possible. The local override for up to four hours is usually sufficient. Global disablement affects every managed device and is only appropriate for controlled bulk maintenance.
The current agent also uses Enhanced Tamper Protection from Sophos Endpoint Defense. It blocks configuration changes, stopping protected processes, manipulating registry permissions and replacing protected files. Local administrators and software deployment tools are affected as well.
⚠️ Do not confuse it with a policy: Tamper Protection protects the agent itself. Threat Protection, Web Control and other Endpoint features are controlled through separate policies.
Which method fits?
| Situation | Recommended method | Effect |
|---|---|---|
| short work on an accessible device | local override with device password | up to four hours |
| longer maintenance on one device | disable for that device in Sophos Fusion | until manually enabled |
| planned bulk maintenance | disable globally | all managed endpoints and servers |
| device already deleted from Sophos Fusion | use deleted-device password or restoration | depends on platform and deletion time |
Changes in Sophos Fusion (formerly Sophos Central) require a role with the necessary administrative permissions. The function is available for Windows and macOS, not Linux.
Disable Tamper Protection for one device
Sign in at fusion.sophos.com. The current entry point is My Environment > Computers & Servers.
- Open the affected device.
- Scroll to Tamper Protection in the device details.
- Click Turn off tamper protection and confirm the change.
- Wait for the device to retrieve the change.
- Check locally that the intended maintenance action is possible.
The setting remains disabled until it is enabled again for the device. An offline device applies the change only after its next successful connection to Sophos Fusion.
View a device password
The local override requires the individual device password:
- Open the device under My Environment > Computers & Servers.
- Scroll to Tamper Protection and select View password details.
- Display the password and provide it only to the person performing the work.
- Do not retain the password in tickets, chats or unprotected notes afterwards.
Every device has its own password. A password from another Endpoint record will not work.
Use Generate New Password to create a password for exactly this device. Sophos Fusion deliberately provides no shared permanent master password for all endpoints.
Windows: override protection locally for four hours
- Open Sophos Endpoint from the shield icon.
- Select Admin sign-in or Admin-Login.
- Enter the device’s Tamper Protection password.
- Open Settings.
- Enable Override Sophos Central Policy for up to 4 hours for troubleshooting.
- Turn off Tamper Protection under local user control.
The override ends automatically after no more than four hours. This is usually the safest method for diagnosis, repair and controlled uninstallation.
During the override, the device does not apply new or changed Central policies. End it immediately after the work instead of waiting for four hours.
Windows: control Tamper Protection with SEDcli
If the local Sophos interface cannot be opened, SEDcli.exe is available on current Sophos Fusion Windows endpoints and servers. It does not apply to macOS or Linux. Open Command Prompt as administrator and change to C:\Program Files\Sophos\Endpoint Defense. SEDcli.exe -h shows the options supported by the installed agent; -v shows the application version.
SEDcli.exe -h
SEDcli.exe -status
SEDcli.exe -OverrideTPoff DEVICE_PASSWORD
SEDcli.exe -ResumeTP
SEDcli.exe -ResumeTP DEVICE_PASSWORD
Replace DEVICE_PASSWORD with the Tamper Protection password shown in Sophos Fusion. -status reports whether SED Tamper Protection is enabled or disabled. -OverrideTPoff overrides the Central policy for up to four hours and disables protection; the device event is Central management has been suspended. No new or updated policy can be applied while management is suspended.
-ResumeTP ends the maintenance window early, turns on Tamper Protection and resumes the Central policy. Normally run it without a password. Use the device-password form only if the Sophos MCS Agent service is not running; Central management still resumes in that case, but the Central management has been resumed event is not generated. Run -status again afterwards to verify the state.
Do not store the password in scripts: The device password appears as a command-line argument and may enter history, logs or process data.
SEDcliis for controlled local repair, not persistent mass disabling.
macOS: override protection locally for four hours
- Open Sophos Endpoint on the Mac.
- Select Admin Login.
- First enter the local Mac administrator password and click OK.
- Click the padlock and Sophos icon, then enter the device password from Sophos Fusion.
- Open Settings and enable Override Sophos Central Policy for up to 4 hours.
- Turn off Tamper Protection for the maintenance window and save.
End the override immediately after the work and verify that protection is active again.
Disable Tamper Protection globally
The exact path is Global Settings (gear icon) > Products and Services > Endpoint and Server > Tamper Protection. Move the slider left to turn it off. To enable it later, turn the switch on and select Save in the upper-right corner.
Global disablement is acceptable only when the scope, time window and rollback are documented. During this period, local administrators or malware can change Sophos components more easily.
Before disabling it, define at least:
- affected devices and maintenance reason
- start and planned end
- responsible person
- validation after the work
- confirmation that the global switch is enabled again
The global method is disproportionate for individual devices.
When the global switch is off, no device is protected by Tamper Protection. A locally enabled state cannot compensate for global disablement. Account Health Check flags both a disabled global switch and individual unprotected devices; bulk changes appear in Audit Log.
If the device was already deleted
Sophos Fusion currently retains Tamper Protection passwords for deleted devices for 120 days. Deleted devices can be restored for 30 days. On current Windows versions from Windows 10 or Windows Server 2016, the modern Core Agent normally disables protection after deletion so password recovery is not required.
The current recovery path is Reports > Reports > Endpoint Protection (or Server Protection) > Restore deleted devices and recover Tamper Protection passwords. Within 30 days, select the device record and click Restore. Up to day 120, Password details in the Tamper Protection password column shows the current and previous passwords. Recovery through Sophos Fusion is no longer available after that.
The exact process depends on the operating system, agent version and deletion time. Uninstall Sophos Endpoint after deletion from Sophos Fusion describes the current recovery path without registry changes.
Do not use old registry hacks: Manually disabling Sophos services and Tamper Protection keys in Safe Mode is no longer a standard uninstall route. It can leave the Core Agent inconsistent and make later installation or registration more difficult.
On current Windows devices with Core Agent 2023.2 or later, old recovery steps after deletion from Sophos Fusion or licence expiry are no longer required. Windows Recovery Environment and registry recovery are a last, version-dependent support path only when Sophos Fusion, the local password, SEDcli, and restoring the deleted object all fail.
Recovery through macOS Recovery is likewise not standard. It changes protected product information so the Sophos uninstaller can run again. Because volume name, APFS data volume, FileVault state and agent version affect the procedure, use only the current Sophos instructions or work with Sophos Support.
When Enhanced Tamper Protection must be disabled temporarily
Besides uninstallation and local troubleshooting, a few legitimate operations are blocked by Sophos Endpoint Defense. These include an operating-system upgrade, restoring a Windows restore point and custom scripts that modify Sophos services, protected files or registry permissions.
A disabled switch is not a general solution for permanently blocked operations. Older agents could leave protection partly active after imaging or a Windows volume-name change because of a since-fixed defect. On current agents, update the installed Core Agent first instead of adopting old driver and registry workarounds.
After maintenance
The shortest safe return path depends on the method used:
- Local Windows override:
SEDcli.exe -ResumeTPends the window immediately. If you used the interface, end the local override there instead of waiting for the four-hour timeout. - One device in Sophos Fusion: My Environment > Computers & Servers > [device] > Tamper Protection > Turn on tamper protection.
- Global: first enable Global Settings > Products and Services > Endpoint and Server > Tamper Protection and select Save. Then fix any individual devices that remain unprotected.
Wait for the next successful device contact, then verify locally that Tamper Protection is active. In Sophos Fusion, check Last activity, health state and open alerts. Under My Environment > Account Health Check, both the global check and the endpoint or server check must be healthy again. Securely remove any temporary password records.
Sophos Fusion administrator changes and automatic Health Check fixes can be reviewed under Reports > General logs > Audit Logs. The report includes the time, administrator account, modified item, description and source IP; it shows seven days by default and can cover up to 90 days. A purely local override is not a complete Sophos Fusion maintenance record, so also record the device, reason, start, end and validation result in the change or ticket system.
If the agent is to be removed completely, continue with Uninstall Sophos Endpoint on Windows.
For Macs, use the separate process in Uninstall Sophos Endpoint on macOS.
Common problems
The password is rejected
The computer name and Sophos Fusion record must match exactly. Also check the keyboard layout, copied whitespace and the last synchronisation. For a deleted device, retrieve the password from the deleted devices area.
The switch is unavailable in Sophos Fusion
Check the administrator role, product licence, operating system and current device status. Linux does not support Tamper Protection.
The device does not react to the change
An offline device cannot receive the Sophos Fusion setting. Check network, proxy, system time and last activity. On an accessible local device, use the four-hour override with the previously retrieved password.
When to escalate
If the password, Sophos Fusion switch and SEDcli cannot change the state cleanly, or the agent remains unprotected or unhealthy after re-enabling, do not try registry, driver or service workarounds. Collect the device ID, operating system, Core Agent version, last Sophos Fusion connection time, exact error and relevant Audit Log entry, then open a Sophos Support case. For a deleted device, include its deletion date and restore status.