Skip to content
Avanet

Install Sophos Fusion Intercept X (Windows)

Sophos Fusion (formerly Sophos Central) no longer installs an isolated component called “Intercept X” on Windows using the old component model. The selected Agent Mode is decisive: Endpoint, XDR, or XDR Sensor. This choice determines whether the computer receives full Sophos protection or only XDR telemetry.

For the complete cross-platform sequence, including planning, prerequisites, and rollout order, follow the Sophos Endpoint onboarding path.

For most production Windows clients using Sophos as the primary protection, Endpoint or XDR is appropriate. XDR Sensor is a special case for devices where a third-party product provides the actual protection.

⚠️ XDR Sensor is not antivirus protection: Sophos explicitly documents that xdrsensor detects threats and provides data, but does not protect against threats itself. A suitable third-party protection product must be active on the device. This mode must not accidentally be deployed as full Endpoint Protection.

Quick path for a secure pilot installation

  1. Check the licence, required features, and target group in Sophos Fusion.
  2. Decide whether to install Endpoint, XDR, or XDR Sensor.
  3. Select a fully patched, supported Windows pilot with local administrative access.
  4. Clarify the migration or coexistence plan for existing security software.
  5. Download the appropriate Windows installer under My Environment > Installers.
  6. Run the installer internally and in a controlled manner on the pilot device.
  7. Check local protection status, installed components, and update state.
  8. Verify the device, agent mode, group, policy, and health in Sophos Fusion.

Proceed with the wider rollout only after the positive test, policy assignment, and agent mode are correct.

Distinguish Endpoint, XDR, and XDR Sensor

The current Sophos installer logic uses these product values:

  • endpoint: installs anti-malware protection without XDR features.
  • xdr: installs XDR features and the full protection provided by endpoint.
  • xdrsensor: installs XDR detection without anti-malware protection. A third-party product must protect the device.

For xdr, there is no need to select endpoint separately. The XDR option already includes endpoint protection. The options visible in Central depend on the licence and tenant.

Download Complete Windows Installer includes all endpoint products covered by the current licence. With the relevant licence, this can also include Device Encryption. Use Choose Components when the scope must be restricted and verify the product selection shown before downloading.

The current Sophos documentation for endpoint installers is authoritative for the options shown in the tenant. Installed features are not maintained by repeatedly running an arbitrary old component installer. The controlled process for adding or removing features is covered in Manage Sophos Fusion Endpoint features.

Prerequisites before downloading

Before installation, confirm the following:

  • Windows is currently supported and fully patched.
  • A local or managed administrator account is available for installation.
  • The required Endpoint, XDR, or MDR licence exists in the tenant.
  • The device can reach Sophos Fusion through DNS and HTTPS or through a documented proxy.
  • The migration or coexistence path for existing third-party antivirus software is defined.
  • The pilot target group, policies, and responsible owner are defined.
  • A restart and brief disruption fit within the agreed maintenance window.

A fixed list of Windows versions in an installation runbook becomes outdated quickly. Check the currently supported platform in Sophos requirements before every new rollout. A historical statement such as Windows 7+ is no longer a valid approval criterion.

Handle existing antivirus software correctly

Sophos only explicitly confirms operation alongside third-party protection for XDR Sensor. There is no blanket coexistence assurance for arbitrary security products when installing full endpoint or xdr protection.

The Windows installer can remove recognised competing products. The --nocompetitorremoval option disables this attempt, but does not make an unknown product combination compatible. It should therefore not be used as a general workaround. Document the product, version, self-protection, restart requirement, and fallback path of the previous antivirus before rollout.

Prepare the network and proxy

The network firewall, proxies, and restrictive egress rules must meet the Sophos Endpoint network and proxy requirements, including outbound TCP 443 and DNS 53. Recheck the requirements before every rollout; a fixed domain shortlist copied from an old firewall object is not sufficient.

Broad country or regional blocks can unexpectedly affect cloud endpoints. A successful download of the small setup file also does not prove that registration, component download, and subsequent updates work.

Download the installer in Sophos Fusion

After signing in to Sophos Fusion Admin, the current entry point is:

My Environment > Installers

The Endpoint section provides two typical paths:

  1. Download Complete Windows Installer downloads the complete licence-dependent installer.
  2. Choose Components creates an installer for a deliberately restricted product selection.

For XDR Sensor, use the designated installer or the documented xdrsensor product value. Do not derive the mode solely from the marketing name of the licence; verify the selection offered in the tenant.

Treat the installer as confidential because it is tenant-bound. Anyone who receives it cannot access Sophos Fusion, but can register new devices in the tenant. Remove copies from generally accessible shares, tickets, and download folders after rollout.

If an installer was distributed without control, Expire Previously Downloaded Installers under My Environment > Installers can invalidate old installers. This action cannot be undone and therefore belongs in a documented change.

Install manually on the pilot device

This guide is the authoritative workflow for a manual, interactive Windows installation. If an older guide brought you here using the names Endpoint Standard or Endpoint Advanced, review the mapping of the former product names separately, then return to this current installation workflow.

Sophos explicitly instructs you to turn off User Account Control (UAC) temporarily in its current manual workflow. Record the organization’s setting before changing it. Disable UAC only for the maintenance window on the pilot device; do not lower it through a broad Group Policy. If security policy prohibits this change, stop and agree an approved deployment method with the security team.

  1. Copy the installer from the correct Sophos Fusion tenant to the pilot.
  2. Run the file with administrative privileges.
  3. Read precheck warnings and do not bypass them blindly.
  4. Compare the displayed products with the planned agent mode.
  5. Complete the installation and perform a required restart.
  6. Immediately restore User Account Control (UAC) to the recorded organizational setting.
  7. After the restart, allow registration, component download, and initial updates to finish.

The complete installer downloads current components from Sophos Fusion. An old locally stored setup file is therefore not a substitute for working cloud communication.

Do not delete the local Windows groups created by Sophos

The Windows agent creates the local groups SophosUser, SophosPowerUser, and Sophos Administrator. Sophos Anti-Virus uses these groups for local permission assignment. Hardening, cleanup scripts, and Group Policy must not delete them.

If a group is missing, do not recreate it prematurely with arbitrary memberships. First review installer and endpoint logs, agent health, and when the group was removed. Then perform a controlled repair or reinstallation through the documented Sophos workflow. This prevents an attempted cleanup from further changing local Sophos permissions.

Install the pilot from the command line

For a managed pilot group, the current Windows installer can be run unattended. This example installs endpoint protection plus XDR and assigns the device to a pilot group:

SophosSetup.exe --products=xdr --devicegroup="Windows Clients\Pilot" --quiet

The values depend on the environment:

  • Replace xdr with endpoint when only Endpoint Protection is required.
  • Use xdrsensor only when a third-party product provides protection.
  • Replace Windows Clients\Pilot with the actual device group and subgroup.
  • --quiet hides the interface, but is not proof of success.

The official Windows installer options additionally document proxy, message relay, tags, and other deployment values. Commands containing tenant tokens, proxy passwords, or internal server names do not belong in tickets or generally readable script repositories.

The example above is sufficient for choosing the mode on a pilot. For software distribution, combinations of parameters, process status, proxies, message relays, and rollout waves, use Deploy Sophos Endpoint automatically on Windows.

--registeronly is not a normal installation switch. It is used for the controlled re-registration of an already protected device, for example during a tenant migration, and requires Tamper Protection to be disabled. Do not use this special case as the standard installation method.

Validate the installation correctly

A completed setup interface is not sufficient. Check local and Central success criteria separately.

On the Windows device

  1. Open Sophos Endpoint from the shield icon.
  2. On the status page, verify the green Your device is protected state.
  3. Under About, check which components are installed and whether they are current.
  4. If components are missing or faulty, use Open Endpoint Self-Help Tool for the first diagnosis.
  5. Confirm that the planned third-party protection remains active only for XDR Sensor mode.

In Sophos Fusion

  1. Under My Environment > Computers & Servers, verify that the device appears.
  2. Check agent mode, status, Tamper Protection, and last activity.
  3. Verify the expected group and policy assignment.
  4. Confirm that Endpoint, XDR, or XDR Sensor matches the plan.
  5. Check alerts and pending restart requirements.

A green local status does not prove the correct group or policy. Conversely, a device record in Central does not prove that all components are installed, current, and healthy.

Troubleshoot systematically

The checks below provide initial triage. For log phases, error messages, a safe retry, and support data, continue with Troubleshoot a failed Sophos Endpoint installation systematically rather than using parallel repair recipes here.

Device does not appear in Sophos Fusion

First verify that the installer comes from the correct tenant. Then check DNS, HTTPS, proxy, system time, and the required Sophos domains.

The main installer log is:

C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller.log

Lines containing Opening connection to show the registration and management destinations actually used by the installer. Compare these destinations with the egress rule and proxy. One reachable host does not prove the complete installation path.

Incorrect agent mode or missing features

Under My Environment > Computers & Servers, filter by Agent mode status. If Central shows Product unassigned or Upgrade available, move the affected devices to the intended mode in a controlled manner through Manage Software.

Do not immediately delete and reinstall the device to force a change. After Sophos Fusion applies the change to the online device, check the local component status and Central again.

Installation stops because of existing security software

Do not broadly disable the self-protection of both products. First determine whether full Sophos protection or only XDR Sensor is required. For the full mode, check the supported migration, required restarts, and remaining drivers from the previous product.

Installation is green locally but Central remains red

The policy assignment, pending updates, restart, health data, or agent mode may still be incorrect. Evaluate local status, last activity, alert text, and the agent mode column together. Restarting the installer without this analysis can create additional symptoms.

Operate securely after rollout

  • Provide the installer only for the required period and recipient group.
  • Fully validate the pilot group before wider distribution.
  • Recheck the agent mode and licence after product changes.
  • Do not rely only on the default policy when device groups have different requirements.
  • Document Tamper Protection and uninstall as separate lifecycle steps.
  • Invalidate old or lost installers selectively when required.
  • Remove devices from Central only after a controlled uninstall and inventory check.

For a standard Windows endpoint installation without the XDR-specific decision, also see Install Sophos Fusion Endpoint on Windows. Manage Sophos Fusion Endpoint features explains how to add or remove licensed components. For a planned removal, see Uninstall Endpoint on Windows and the special case Uninstall with Tamper Protection.

Checklist

  • Deliberately selected Endpoint, XDR, or XDR Sensor agent mode.
  • Defined third-party protection and the migration or coexistence path.
  • Confirmed supported, patched Windows and administrative access.
  • Documented tenant, licence, pilot group, and policies.
  • Checked network, proxy, DNS, and HTTPS path.
  • Distributed the tenant-bound installer confidentially.
  • Checked local protection status, components, and updates.
  • Checked device, group, policy, agent mode, and health in Central.
  • Completed restart requirements and alerts.
  • Removed installer copies or invalidated them after loss.

Frequently asked questions

Is Intercept X still a separate installer on Windows?

The current Sophos Fusion logic mainly distinguishes Endpoint, XDR, and XDR Sensor. Available products depend on the licence and tenant. XDR uses the xdr product value and already includes endpoint protection.

Can Sophos Intercept X run alongside another antivirus?

A blanket assurance is incorrect. Only XDR Sensor is explicitly intended to run alongside third-party protection, and it does not protect against threats itself. A full endpoint or xdr installation requires a tested migration or compatibility path.

What is the difference between xdr and xdrsensor?

xdr installs XDR features plus full endpoint protection. xdrsensor provides XDR detection without anti-malware protection and therefore requires a separate protection product.

Why does the computer not appear in Central after installation?

Common causes include an installer from the wrong tenant, blocked Sophos domains, proxy or DNS problems, incorrect system time, or an interrupted component download. SophosCloudInstaller.log shows the connection destinations and installation progress.