Skip to content
Avanet

Install Sophos Central Endpoint (macOS)

Sophos Central Endpoint only fully protects a Mac once the agent is installed and the extensions and privacy permissions required by macOS have been granted. This guide covers a manual installation, explains how to select the right installer, and shows how to verify protection afterwards.

Important: A full Sophos Endpoint installation should not run alongside another antivirus product. The separate XDR Sensor is the exception: It is designed to run with an existing third-party antivirus product, but does not provide malware protection itself.

Before installation

The following requirements should be confirmed before downloading the installer:

When migrating from another endpoint solution, its removal should first be tested on a small number of Macs. This confirms whether old system or network extensions remain and interfere with the new agent.

Sophos does not support beta versions of macOS. For macOS 26 Tahoe, Sophos names Endpoint 2025.1 or later as the supported baseline for new installations and upgrades. Before every major macOS upgrade, nevertheless check the current system requirements, known issues and agent version actually installed; a generally “current” agent display does not replace this version check.

For supported Intel and Apple silicon Macs, Sophos specifies at least 2 GB free disk space and 2 GB RAM. This is a technical minimum, not a practical capacity target. Leave additional space for macOS and Endpoint Updates, logs and SDU archives, especially on small SSDs.

Download the appropriate macOS installer

  1. Sign in to Sophos Central Admin at central.sophos.com.
  2. Open My Environment > Installers.
  3. Under Endpoint, select the appropriate macOS installer.
  4. Download SophosInstall.zip.

Sophos Central provides several options:

  • Download Complete macOS Installer: Installs the endpoint products covered by the licenses in the Central account.
  • Choose Components: Creates an installer containing only the selected components. This is useful when, for example, Device Encryption or ZTNA should not be installed on the Mac.
  • XDR Sensor Installers: Installs only the XDR Sensor for detection and investigation alongside an existing third-party antivirus product. An XDR-capable license and at least macOS 13 Ventura are required. This sensor does not replace antivirus protection.

The complete installer is normally appropriate for a standard workstation that will be fully protected by Sophos. Choose Components should be used when the intended product combination deliberately differs from the licensed set.

Install Sophos Endpoint manually

Starting with macOS Monterey 12.4, SophosInstall.zip must be moved from Downloads, Documents, or the desktop to the user’s home directory before extracting it. Otherwise, the installer cannot create its working files correctly and the installation fails.

One possible destination is:

~/SophosInstall

Then:

  1. Extract the ZIP file in the destination folder.
  2. Start Sophos Installer.app.
  3. Confirm the administrator credentials.
  4. Complete the installation.
  5. Grant the Sophos extensions and permissions requested by macOS.

The installer downloads additional components from Sophos Central. A successfully started installation wizard therefore does not by itself prove that the Mac is fully protected.

Verify the installer before making an exception

Before removing a quarantine attribute or adding an installer to software deployment, verify its Apple notarisation and signature:

spctl -a -t exec -vv 'Sophos Installer.app'
codesign -vv 'Sophos Installer.app'

spctl must report the installer as an accepted Notarized Developer ID. codesign must confirm that the bundle is valid on disk and satisfies its Designated Requirement. In verbose output, the signature chain belongs to Developer ID Application: Sophos (2H5GFH3774), the Apple Developer ID Certification Authority and the Apple Root CA. Do not bypass a differing or rejected result through Gatekeeper; download a fresh installer directly from the organisation’s Central tenant instead.

Install from Terminal

For an unattended installation of Sophos Anti-Virus and Intercept X, run the extracted installer in Terminal:

cd ~/SophosInstall
sudo ./Sophos\ Installer.app/Contents/MacOS/Sophos\ Installer \
  --products antivirus intercept \
  --quiet

--products antivirus intercept defines the protection components to install. --quiet hides the installation dialog, but does not replace the required macOS permissions. Before a wider deployment, product names and options should be tested with a current installer on a test device.

To assign the Mac directly to a Central device group during installation, specify the group as follows:

sudo ./Sophos\ Installer.app/Contents/MacOS/Sophos\ Installer \
  --products antivirus intercept \
  --devicegroup Firma\\Macs \
  --quiet

In this example, Firma\Macs is an existing Central subgroup. The double backslash ensures that the shell passes the group path to the installer correctly.

If macOS blocks the installer

First check whether macOS has added a quarantine attribute to the installer:

xattr ~/SophosInstall/Sophos\ Installer.app

If com.apple.quarantine is shown and the file was downloaded directly from the organization’s own Sophos Central account, remove the attribute only from the Sophos installer:

sudo xattr -r -d com.apple.quarantine \
  ~/SophosInstall/Sophos\ Installer.app

This does not disable Gatekeeper globally. The attribute must not simply be removed from an installer obtained from an unknown source.

If the installer reports a differing system umask, do not blindly set an arbitrary permission value. A system-wide umask affects every file created by system accounts and can damage security and applications. Back up the responsible LaunchDaemon configuration, compare it with the applicable macOS baseline, and have only an administrator who understands the device-wide impact remove or correct it.

A Folder Insecurity error means a parent system path no longer matches the secure macOS default, allowing an installer to adopt foreign files with elevated privileges. Affected paths can include /, /Library, /Library/Caches, or /Library/Application Support. Compare ownership and write permissions with an equivalent healthy Mac. Do not disable SIP for a blanket chmod workaround. Correct the imaging or management software that changed protected paths and involve Apple or Sophos Support where necessary.

Grant macOS permissions

Depending on the licensed products, Sophos requires a security extension, a network extension, proxy approval, and Full Disk Access. If one of these permissions is missing, the agent can be installed and visible in Central while individual protection functions still do not operate.

The exact interface varies by macOS version:

  • macOS 14 and earlier: Allow the Sophos system extensions under Privacy & Security.
  • macOS 15: Open System Settings > General > Login Items & Extensions. Under Endpoint Security Extensions, enable Sophos Detection.app; under Network Extensions, enable Sophos Network Extension.app.
  • macOS 26: In the same location, under By App, enable the security extension for Sophos Detection and the network extension for Sophos Network Extension.

After enabling the network extension, macOS asks whether Sophos Network Extension may be allowed as a network proxy. Confirm this dialog with Allow so that scanning and web protection can operate fully.

The most reliable way to check and grant Full Disk Access is through Sophos Endpoint:

Sophos Endpoint > About > Open Endpoint Self Help Tool > Prerequisites

Under Prerequisites, Sophos shows which permission is missing and opens the corresponding macOS setting. Required entries can change with the agent version and licensed products, so this check is more reliable than a static list.

Sophos Service Manager checks these permissions automatically about every 30 minutes. After granting a permission manually, restart Sophos Service Manager to trigger an earlier check; the new state appears after approximately 30 seconds.

Verify installation and protection

After installation, verify three levels:

  1. Locally: No permissions are missing under Endpoint Self Help > Prerequisites.
  2. Sophos Central: The Mac appears under My Environment > Computers & Servers, communicates with Central, and does not have a red health status.
  3. Protection scope: The expected products and policies are active on the device details page.

A device should not be deleted from Sophos Central prematurely. Removing the Central object does not uninstall the agent, but can make normal access to the device-specific tamper protection password more difficult. First disable tamper protection in a controlled manner, then uninstall the agent.

If a Mac was already deleted from Central, rerunning the installer does not simply register the existing installation. The installer treats it as an upgrade and retains the old device identity. For Endpoint 2024.1 and later, Sophos recommends a complete uninstall followed by a reinstall. Older instructions that delete the read-only Sophos keychain entry and use internal commands to re-register do not apply to these versions.

The complete supported removal process is documented in Uninstall Sophos Central Endpoint on macOS.

Sophos Central normally detects signed-in users automatically. Manual user or license assignment is mainly required when different local sign-in names have created duplicate user objects.

Features installed later can be managed separately. The article Install or uninstall Sophos Endpoint features explains the process.

Deploy multiple Macs through MDM

For multiple Macs, permissions should not be confirmed manually on every device. Under My Environment > Installers, the SophosMacDeploymentTools.zip package is available under Deployment Tools. It contains MDM profiles and installation scripts for Sophos Endpoint and Sophos Endpoint with ZTNA.

The order is important:

  1. Select the appropriate profile for the product combination and macOS version.
  2. Deploy the MDM profile to the test devices first.
  3. Confirm that the profile was installed.
  4. Then run the installer or the included installation script.
  5. Check the MDM policy and Endpoint Self Help > Prerequisites.

Sophos documents this process for Jamf Pro. The profiles and scripts can generally be used with other MDM solutions as well, but must be validated through the organization’s own testing and approval process.

Common installation issues

The Mac does not appear in Sophos Central

Check the internet connection, DNS, system time, and proxy. With restrictive egress rules, the current Sophos domains must be reachable. Also confirm that the installer was downloaded from the correct Central account.

The installation dialog distinguishes Software Installed, Registration Status to Sophos Central, and Configuration Status. Assign a failure to the correct stage. For Network or Registration Errors, record the displayed server and exact message. If registration succeeds but configuration fails, examine Central communication and policy processing instead of immediately reinstalling.

The agent is installed, but the status remains red

Check Endpoint Self Help > Prerequisites for missing system, network, or privacy permissions. On macOS 14 and 15, missing Full Disk Access for SophosUpdater in particular can cause update failures.

Since Endpoint 2024.4, Sophos treats missing Full Disk Access for the updater as a poor service state even when updates still work. For MDM deployments, use the current Sophos profile. Without MDM, start the approval through Endpoint Self Help > Prerequisites > Allow Full Disk Access. SophosUpdater may be absent from the normal macOS picker until macOS has blocked it once. In that case, follow the drag-and-drop workflow offered by Self Help.

Search the relevant log as follows:

sudo log show \
  --predicate "subsystem == 'com.sophos.macendpoint'" \
  --last 1d |
grep -i 'Error renaming Installer directory'

A match indicates that SophosUpdater could not rename its installer directory. In this case, deploy the current MDM profile or grant /Library/Sophos Anti-Virus/SophosUpdater.app Full Disk Access.

If Central reports error 6001 while downloading MacEndpoint and SophosUpdater.log shows 403 Forbidden or EXPIRED_TOKEN, the package is not the primary cause. The Mac lost Central communication and could not renew its JWT. Restore DNS, proxy and MCS communication, restart the endpoint and check the update again before considering re-registration.

Endpoint Self Help shows the server, resolved address, proxy and last successful contact for Update and Management Communication. Invalid Server URL indicates failed name resolution, while HTTP 503 tells the client to retry later. For services, distinguish missing from unexpected. Recheck a missing service after restart and, if it remains absent, escalate with the component name and an SDU instead of manually removing more agent files.

The Policy page shows when a Central policy was last received and refreshes automatically on the Mac. For a controlled test, minimally change a setting that is actually assigned, save it and check again after about 30 seconds. If the timestamp remains unchanged, investigate Management Communication first. An unknown three-letter policy abbreviation means Self Help does not recognise the received policy type; it is not a reason to modify policies at random.

The System page is inventory information only and does not affect Health State. By default, Central takes the macOS computer name from Sharing. Without directory binding, the local computer name may appear as the user domain. If different names are required, use Sophos-documented installer overrides and then check for new or duplicate device objects.

For process diagnosis, consider roles rather than names alone: SophosServiceManager monitors agent components, SophosMcsAgentD communicates with Central, SophosUpdater updates, the Sophos Network Extension handles network interception, SophosCryptoGuard protects against ransomware, SophosOSQuery and SophosLiveQuery supply query data, and SophosLiveResponse provides the privileged session. Encryption uses separate processes under the signed-in user and _sophosencryption. A missing process is an error only when its licensed function should be installed and enabled.

Captive portal on public Wi-Fi

If a hotel, aircraft or guest Wi-Fi sign-in page does not appear, Endpoint Self Help > Captive Portal Mode can suspend network interception for no more than five minutes. It ends sooner when disabled manually and does not require the Tamper Protection password. Use it only to sign in to the portal, then recheck protection and connectivity. Sophos has reported no further instances of the historical Apple issue since early 2024, but retains the mode as a narrowly scoped aid.

Files on SMB shares remain locked

If files opened from a Mac remain temporarily locked on an SMB share, first record the agent version, reproducible path, application and duration. An On-Access exclusion alone does not necessarily change the behaviour. Sophos documents a narrowly scoped workaround that adds the same network path to both On-Access and CryptoGuard or ransomware exclusions. This removes two protection layers from that path, so assess the share, write permissions and server-side protection. Globally disabling Real-time Scanning - Network is broader and not preferred.

Use Reset summary to reset the local detection counter. This removes neither malware nor Central events or incident history. Use it only after technical remediation so an empty local display is not mistaken for a resolved incident.

Another antivirus product is already installed

For full Sophos protection, the existing antivirus product should be migrated and removed in a controlled manner. If the existing protection is deliberately retained, only the separate XDR Sensor is intended for this coexistence. Because it does not provide malware protection of its own, the third-party antivirus product must remain active and healthy.

The local _Sophos account appears

The installer creates the restricted service account _Sophos on macOS. It has no interactive login shell, is not part of the normal user group and runs Sophos processes with fewer privileges than root. It is therefore not an unknown user and must not be deleted. The agent neither stores nor uses its automatically generated password for signing in.

Frequently asked questions

Why is the Mac visible in Central while its protection status is red?

Installation and Apple security approvals are separate. Check Endpoint Self Help for missing system extensions, network extensions and Full Disk Access permissions.

Can Sophos Endpoint remain installed alongside another antivirus product?

The XDR Sensor is designed for this coexistence. It does not provide malware protection itself, so the third-party product must remain active and healthy.