Install Sophos Central Intercept X (Windows)
Sophos Central no longer installs an isolated component called “Intercept X” on Windows using the old component model. The selected Agent Mode is decisive: Endpoint, XDR, or XDR Sensor. This choice determines whether the computer receives full Sophos protection or only XDR telemetry.
For most production Windows clients using Sophos as the primary protection, Endpoint or XDR is appropriate. XDR Sensor is a special case for devices where a third-party product provides the actual protection.
⚠️ XDR Sensor is not antivirus protection: Sophos explicitly documents that
xdrsensordetects threats and provides data, but does not protect against threats itself. A suitable third-party protection product must be active on the device. This mode must not accidentally be deployed as full Endpoint Protection.
Quick path for a secure pilot installation
- Check the licence, required features, and target group in Sophos Central.
- Decide whether to install
Endpoint,XDR, orXDR Sensor. - Select a fully patched, supported Windows pilot with local administrative access.
- Clarify the migration or coexistence plan for existing security software.
- Download the appropriate Windows installer under My Environment > Installers.
- Run the installer internally and in a controlled manner on the pilot device.
- Check local protection status, installed components, and update state.
- Verify the device, agent mode, group, policy, and health in Sophos Central.
Proceed with the wider rollout only after the positive test, policy assignment, and agent mode are correct.
Distinguish Endpoint, XDR, and XDR Sensor
The current Sophos installer logic uses these product values:
endpoint: installs anti-malware protection without XDR features.xdr: installs XDR features and the full protection provided byendpoint.xdrsensor: installs XDR detection without anti-malware protection. A third-party product must protect the device.
For xdr, there is no need to select endpoint separately. The XDR option already includes endpoint protection. The options visible in Central depend on the licence and tenant.
Download Complete Windows Installer includes all endpoint products covered by the current licence. With the relevant licence, this can also include Device Encryption. Use Choose Components when the scope must be restricted and verify the product selection shown before downloading.
The current Sophos documentation for endpoint installers is authoritative for the options shown in the tenant. Installed features are not maintained by repeatedly running an arbitrary old component installer. The controlled process for adding or removing features is covered in Manage Sophos Central Endpoint features.
Prerequisites before downloading
Before installation, confirm the following:
- Windows is currently supported and fully patched.
- A local or managed administrator account is available for installation.
- The required Endpoint, XDR, or MDR licence exists in the tenant.
- The device can reach Sophos Central through DNS and HTTPS or through a documented proxy.
- The migration or coexistence path for existing third-party antivirus software is defined.
- The pilot target group, policies, and responsible owner are defined.
- A restart and brief disruption fit within the agreed maintenance window.
A fixed list of Windows versions in an installation runbook becomes outdated quickly. Check the currently supported platform in Sophos requirements before every new rollout. A historical statement such as Windows 7+ is no longer a valid approval criterion.
Handle existing antivirus software correctly
Sophos only explicitly confirms operation alongside third-party protection for XDR Sensor. There is no blanket coexistence assurance for arbitrary security products when installing full endpoint or xdr protection.
The Windows installer can remove recognised competing products. The --nocompetitorremoval option disables this attempt, but does not make an unknown product combination compatible. It should therefore not be used as a general workaround. Document the product, version, self-protection, restart requirement, and fallback path of the previous antivirus before rollout.
Prepare the network and proxy
The network firewall, proxies, and restrictive egress rules must permit DNS, HTTPS, and the current Sophos domains. The complete and changeable list is in Domains and ports to allow.
Broad country or regional blocks can unexpectedly affect cloud endpoints. A successful download of the small setup file also does not prove that registration, component download, and subsequent updates work.
Download the installer in Sophos Central
After signing in to Sophos Central Admin, the current entry point is:
My Environment > Installers
The Endpoint section provides two typical paths:
- Download Complete Windows Installer downloads the complete licence-dependent installer.
- Choose Components creates an installer for a deliberately restricted product selection.
For XDR Sensor, use the designated installer or the documented xdrsensor product value. Do not derive the mode solely from the marketing name of the licence; verify the selection offered in the tenant.
Treat the installer as confidential because it is tenant-bound. Anyone who receives it cannot access Sophos Central, but can register new devices in the tenant. Remove copies from generally accessible shares, tickets, and download folders after rollout.
If an installer was distributed without control, Expire Previously Downloaded Installers under My Environment > Installers can invalidate old installers. This action cannot be undone and therefore belongs in a documented change.
Install manually on the pilot device
- Copy the installer from the correct Sophos Central tenant to the pilot.
- Run the file with administrative privileges.
- Read precheck warnings and do not bypass them blindly.
- Compare the displayed products with the planned agent mode.
- Complete the installation and perform a required restart.
- After the restart, allow registration, component download, and initial updates to finish.
The complete installer downloads current components from Sophos Central. An old locally stored setup file is therefore not a substitute for working cloud communication.
Install the pilot from the command line
For a managed pilot group, the current Windows installer can be run unattended. This example installs endpoint protection plus XDR and assigns the device to a pilot group:
SophosSetup.exe --products=xdr --devicegroup="Windows Clients\Pilot" --quiet
The values depend on the environment:
- Replace
xdrwithendpointwhen only Endpoint Protection is required. - Use
xdrsensoronly when a third-party product provides protection. - Replace
Windows Clients\Pilotwith the actual device group and subgroup. --quiethides the interface, but is not proof of success.
The official Windows installer options additionally document proxy, message relay, tags, and other deployment values. Commands containing tenant tokens, proxy passwords, or internal server names do not belong in tickets or generally readable script repositories.
--registeronly is not a normal installation switch. It is used for the controlled re-registration of an already protected device, for example during a tenant migration, and requires Tamper Protection to be disabled. Do not use this special case as the standard installation method.
Validate the installation correctly
A completed setup interface is not sufficient. Check local and Central success criteria separately.
On the Windows device
- Open Sophos Endpoint from the shield icon.
- On the status page, verify the green Your device is protected state.
- Under About, check which components are installed and whether they are current.
- If components are missing or faulty, use Open Endpoint Self-Help Tool for the first diagnosis.
- Confirm that the planned third-party protection remains active only for
XDR Sensormode.
In Sophos Central
- Under My Environment > Computers & Servers, verify that the device appears.
- Under My Environment > Computers & Servers, check agent mode, status, and last activity.
- Verify the expected group and policy assignment.
- Confirm that
Endpoint,XDR, orXDR Sensormatches the plan. - Check alerts and pending restart requirements.
A green local status does not prove the correct group or policy. Conversely, a device record in Central does not prove that all components are installed, current, and healthy.
Troubleshoot systematically
Device does not appear in Sophos Central
First verify that the installer comes from the correct tenant. Then check DNS, HTTPS, proxy, system time, and the required Sophos domains.
The main installer log is:
C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller.log
Lines containing Opening connection to show the registration and management destinations actually used by the installer. Compare these destinations with the egress rule and proxy. One reachable host does not prove the complete installation path.
Incorrect agent mode or missing features
Under My Environment > Computers & Servers, filter by Agent mode status. If Central shows Product unassigned or Upgrade available, move the affected devices to the intended mode in a controlled manner through Manage Software.
Do not immediately delete and reinstall the device to force a change. Sophos Central deploys the new software to an online device during the next update, usually within about an hour. Then check the local component status and Central again.
Installation stops because of existing security software
Do not broadly disable the self-protection of both products. First determine whether full Sophos protection or only XDR Sensor is required. For the full mode, check the supported migration, required restarts, and remaining drivers from the previous product.
Installation is green locally but Central remains red
The policy assignment, pending updates, restart, health data, or agent mode may still be incorrect. Evaluate local status, last activity, alert text, and the agent mode column together. Restarting the installer without this analysis can create additional symptoms.
Operate securely after rollout
- Provide the installer only for the required period and recipient group.
- Fully validate the pilot group before wider distribution.
- Recheck the agent mode and licence after product changes.
- Do not rely only on the default policy when device groups have different requirements.
- Document Tamper Protection and uninstall as separate lifecycle steps.
- Invalidate old or lost installers selectively when required.
- Remove devices from Central only after a controlled uninstall and inventory check.
For a standard Windows endpoint installation without the XDR-specific decision, also see Install Sophos Central Endpoint on Windows. Manage Sophos Central Endpoint features explains how to add or remove licensed components. For a planned removal, see Uninstall Endpoint on Windows and the special case Uninstall with Tamper Protection.
Checklist
- Deliberately selected
Endpoint,XDR, orXDR Sensoragent mode. - Defined third-party protection and the migration or coexistence path.
- Confirmed supported, patched Windows and administrative access.
- Documented tenant, licence, pilot group, and policies.
- Checked network, proxy, DNS, and HTTPS path.
- Distributed the tenant-bound installer confidentially.
- Checked local protection status, components, and updates.
- Checked device, group, policy, agent mode, and health in Central.
- Completed restart requirements and alerts.
- Removed installer copies or invalidated them after loss.
Frequently asked questions
Is Intercept X still a separate installer on Windows?
Endpoint, XDR, and XDR Sensor. Available products depend on the licence and tenant. XDR uses the xdr product value and already includes endpoint protection.Can Sophos Intercept X run alongside another antivirus?
XDR Sensor is explicitly intended to run alongside third-party protection, and it does not protect against threats itself. A full endpoint or xdr installation requires a tested migration or compatibility path.What is the difference between xdr and xdrsensor?
xdr installs XDR features plus full endpoint protection. xdrsensor provides XDR detection without anti-malware protection and therefore requires a separate protection product.Why does the computer not appear in Central after installation?
SophosCloudInstaller.log shows the connection destinations and installation progress.