Skip to content
Avanet

Install Sophos Fusion Endpoint (macOS)

Sophos Fusion Endpoint only fully protects a Mac once the agent is installed and the extensions and privacy permissions required by macOS have been granted. This guide covers a manual installation, explains how to select the right installer, and shows how to verify protection afterwards.

For the complete cross-platform sequence, including planning, prerequisites, and rollout order, follow the Sophos Endpoint onboarding path.

Important: A full Sophos Endpoint installation should not run alongside another antivirus product. The separate XDR Sensor is the exception: It is designed to run with an existing third-party antivirus product, but does not provide malware protection itself.

Before installation

The following requirements should be confirmed before downloading the installer:

When migrating from another endpoint solution, its removal should first be tested on a small number of Macs. This confirms whether old system or network extensions remain and interfere with the new agent.

Before installation, check the currently approved macOS and agent versions in the maintained Sophos support matrix. The linked lifecycle article explains how to interpret these dynamic requirements; this guide deliberately does not copy a fixed matrix because it changes independently of the installation workflow.

Download the appropriate macOS installer

  1. Sign in to Sophos Fusion Admin at fusion.sophos.com.
  2. Open My Environment > Installers.
  3. Under Endpoint, select the appropriate macOS installer.
  4. Download SophosInstall.zip.

Sophos Fusion provides several options:

  • Download Complete macOS Installer: Installs the endpoint products covered by the licenses in the Central account.
  • Choose Components: Creates an installer containing only the selected components. This is useful when, for example, Device Encryption or ZTNA should not be installed on the Mac.
  • XDR Sensor Installers: Installs only the XDR Sensor for detection and investigation alongside an existing third-party antivirus product. It requires an XDR-capable license; consult the system requirements for the currently supported macOS version. This sensor does not replace antivirus protection.

The complete installer is normally appropriate for a standard workstation that will be fully protected by Sophos. Choose Components should be used when the intended product combination deliberately differs from the licensed set.

Install Sophos Endpoint manually

Starting with macOS Monterey 12.4, SophosInstall.zip must be moved from Downloads, Documents, or the desktop to the user’s home directory before extracting it. Otherwise, the installer cannot create its working files correctly and the installation fails.

One possible destination is:

~/SophosInstall

Then:

  1. Extract the ZIP file in the destination folder.
  2. Start Sophos Installer.app.
  3. Confirm the administrator credentials.
  4. Complete the installation.
  5. Grant the Sophos extensions and permissions requested by macOS.

The installer downloads additional components from Sophos Fusion. A successfully started installation wizard therefore does not by itself prove that the Mac is fully protected.

Verify the installer before making an exception

Before removing a quarantine attribute or adding an installer to software deployment, verify its Apple notarisation and signature:

spctl -a -t exec -vv ~/SophosInstall/Sophos\ Installer.app
codesign -vvvd ~/SophosInstall/Sophos\ Installer.app

spctl must report the installer as an accepted Notarized Developer ID. codesign must confirm that the bundle is valid on disk and satisfies its Designated Requirement. In verbose output, the signature chain belongs to Developer ID Application: Sophos (2H5GFH3774), the Apple Developer ID Certification Authority and the Apple Root CA. Do not bypass a differing or rejected result through Gatekeeper; download a fresh installer directly from the organisation’s Central tenant instead.

Install from Terminal

For an unattended installation of Sophos Anti-Virus and Intercept X, run the extracted installer in Terminal:

cd ~/SophosInstall
sudo ./Sophos\ Installer.app/Contents/MacOS/Sophos\ Installer \
  --products antivirus intercept \
  --quiet

--products antivirus intercept defines the protection components to install. --quiet hides the installation dialog, but does not replace the required macOS permissions. Before a wider deployment, product names and options should be tested with a current installer on a test device.

To assign the Mac directly to a Central device group during installation, specify the group as follows:

sudo ./Sophos\ Installer.app/Contents/MacOS/Sophos\ Installer \
  --products antivirus intercept \
  --devicegroup Firma\\Macs \
  --quiet

In this example, Firma\Macs is an existing Central subgroup. The double backslash ensures that the shell passes the group path to the installer correctly.

If macOS blocks the installer

Quarantine, App Translocation, and Folder Insecurity require clear safety boundaries. The macOS troubleshooting runbook guides diagnosis and explains when to pause and escalate without blanket permission changes.

If the installer reports a differing system-wide umask, do not blindly set an arbitrary value. A system-wide umask affects every file created by system accounts and can damage security and applications. After taking a backup, compare the responsible LaunchDaemon configuration with the applicable macOS baseline; only an administrator who has assessed the device-wide impact should remove or correct it.

Grant macOS permissions

Depending on the licensed products, Sophos requires a security extension, a network extension, proxy or Web Content Filter approval, Full Disk Access, and notifications. If one approval is missing, the agent can be installed and visible in Central while individual protection functions do not operate or warnings go unnoticed.

Sophos displays a notification whenever a permission is missing. Open System Settings takes you to the relevant macOS setting; only dismiss the message after granting the permission and checking it in Self Help.

The exact interface varies by macOS version:

  • macOS 14 and earlier: Allow the Sophos system extensions under Privacy & Security.
  • macOS 15: Open System Settings > General > Login Items & Extensions. Under Endpoint Security Extensions, enable Sophos Detection.app; under Network Extensions, enable Sophos Network Extension.app.
  • macOS 26: In the same location, under By App, enable the security extension for Sophos Detection and the network extension for Sophos Network Extension.

After enabling the network extension, macOS asks whether Sophos Network Extension may be allowed as a network proxy. Confirm this dialog with Allow so that scanning and web protection can operate fully.

Also approve the Web Content Filter request and allow Sophos notifications. The filter is part of web protection; notifications ensure that users see protection and permission warnings. If a prompt does not appear, do not create a blanket macOS exception. Use Self Help to identify the missing entry.

The most reliable way to check and grant Full Disk Access is through Sophos Endpoint:

Sophos Endpoint > About > Open Endpoint Self Help Tool > Prerequisites

Under Prerequisites, Sophos shows which permission is missing and opens the corresponding macOS setting. Required entries can change with the agent version and licensed products, so this check is more reliable than a static list.

Sophos Service Manager checks these permissions automatically about every 30 minutes. After granting a permission manually, restart Sophos Service Manager to trigger an earlier check; the new state appears after approximately 30 seconds.

Verify installation and protection

After installation, verify three levels:

  1. Locally: No permissions are missing under Endpoint Self Help > Prerequisites.
  2. Sophos Fusion: The Mac appears under My Environment > Computers & Servers, communicates with Central, and does not have a red health status.
  3. Protection scope: The expected products and policies are active on the device details page.

Acceptance is complete only when all three levels pass. A green Central status alone does not prove that macOS granted every local approval, while a clean local Self Help result does not prove current Central communication. On a pilot device, record the installer variant, agent version, and time of the successful checks before using the same workflow more widely.

A device should not be deleted from Sophos Fusion prematurely. Removing the Central object does not uninstall the agent, but can make normal access to the device-specific tamper protection password more difficult. First disable tamper protection in a controlled manner, then uninstall the agent.

If a Mac was already deleted from Central, rerunning the installer does not simply register the existing installation. The installer treats it as an upgrade and retains the old device identity. For Endpoint 2024.1 and later, Sophos recommends a complete uninstall followed by a reinstall. Older instructions that delete the read-only Sophos keychain entry and use internal commands to re-register do not apply to these versions.

The complete supported removal process is documented in Uninstall Sophos Fusion Endpoint on macOS.

Sophos Fusion normally detects signed-in users automatically. Manual user or license assignment is mainly required when different local sign-in names have created duplicate user objects.

Features installed later can be managed separately. The article Install or uninstall Sophos Endpoint features explains the process.

Deploy multiple Macs through MDM

For multiple Macs, permissions, the Web Content Filter, and notifications should not be approved one device at a time. The dedicated MDM guide covers the current Sophos profiles, the order in which to deploy the profile and installer, and pilot acceptance checks.

Common installation issues

If installation, Central registration, configuration, permissions, or updates do not complete, move to the symptom-first Sophos Endpoint macOS troubleshooting runbook. It covers blocked installers, network and proxy failures, incomplete permissions, reinstall decisions, and escalation. This keeps repair procedures separate from the normal installation and acceptance path.

Interpret policy timestamps, the System page and process roles

The Policy page shows the last receipt of a Central policy and updates automatically. For a controlled test, minimally change an assigned setting, save it and check again after about 30 seconds. If the timestamp does not change, investigate Management Communication first. An unknown three-letter policy abbreviation means Self Help does not recognise the received policy type; it is not a reason to change other policies at random.

The System page is inventory information only and does not affect Health State. By default, Central takes the macOS computer name from Sharing; without directory binding, the local computer name can appear as the user domain. Set other names only through documented installer overrides, then check for new or duplicate device objects.

For process diagnosis, assess roles rather than names alone: SophosServiceManager monitors agent components, SophosMcsAgentD communicates with Central, SophosUpdater updates, Sophos Network Extension handles network interception, SophosCryptoGuard protects against ransomware, SophosOSQuery and SophosLiveQuery provide query data, and SophosLiveResponse provides the privileged session. Encryption uses separate processes under the signed-in user and _sophosencryption. A missing process is an error only when its licensed function should be installed and enabled.

Captive portal on public Wi-Fi

If a hotel, aircraft or guest Wi-Fi sign-in page does not appear, Endpoint Self Help > Captive Portal Mode can suspend network interception for no more than five minutes. It ends sooner when disabled manually and does not require the Tamper Protection password. Use it only to sign in to the portal, then recheck protection and connectivity. Sophos has reported no further instances of the historical Apple issue since early 2024, but retains the mode as a narrowly scoped aid.

Files on SMB shares remain locked

If files opened from a Mac remain temporarily locked on an SMB share, first record the agent version, reproducible path, application and duration. An On-Access exclusion alone does not necessarily change the behaviour. Sophos documents a narrowly scoped workaround that adds the same network path to both On-Access and CryptoGuard or ransomware exclusions. This removes two protection layers from that path, so assess the share, write permissions and server-side protection. Globally disabling Real-time Scanning - Network is broader and not preferred.

Use Reset summary to reset the local detection counter. This removes neither malware nor Central events or incident history. Use it only after technical remediation so an empty local display is not mistaken for a resolved incident.

Another antivirus product is already installed

For full Sophos protection, the existing antivirus product should be migrated and removed in a controlled manner. If the existing protection is deliberately retained, only the separate XDR Sensor is intended for this coexistence. Because it does not provide malware protection of its own, the third-party antivirus product must remain active and healthy.

The local _Sophos account appears

The installer creates the restricted service account _Sophos on macOS. It has no interactive login shell, is not part of the normal user group and runs Sophos processes with fewer privileges than root. It is therefore not an unknown user and must not be deleted. The agent neither stores nor uses its automatically generated password for signing in.

Frequently asked questions

Why is the Mac visible in Central while its protection status is red?

Installation and Apple security approvals are separate. Check Endpoint Self Help for missing system extensions, network extensions and Full Disk Access permissions.

Can Sophos Endpoint remain installed alongside another antivirus product?

The XDR Sensor is designed for this coexistence. It does not provide malware protection itself, so the third-party product must remain active and healthy.