Manage Sophos Central Endpoint devices and groups
Computer groups give Endpoint policies a stable target. They do not answer every inventory or identity question: tags and general device actions belong to the shared Central platform, while user groups use a separate identity model.
Quick workflow: define the group model, create a group under My Products > Endpoint > Computers > Computer Groups, assign computers, and then verify the policies actually applied on both the group and computer objects. Clarify the lifecycle separately before deleting, cleaning up, or migrating anything.
Important: A computer can belong to only one computer group. Tags add multiple flexible attributes, while Agent mode describes software scope. These levels are not interchangeable.
Separate Endpoint groups from platform features
The shared My Environment > Computers & Servers view is the right foundation for filters, columns, tags, Tamper Protection, software scope, health reset, and general deletion. Manage the Sophos Central device inventory covers that platform workflow, so it is not duplicated here.
Sophos is replacing the older My Products > Endpoint > Computers page with this unified view. During the transition, the older page can still appear in a tenant and remains the route to Computer Groups; the group procedures below therefore use that path.
Users, logins, and user groups are separate objects too. Assign Sophos Central Endpoint users and groups correctly explains whether a policy should follow a person or a device and how order works when several policies match. This article focuses on computer groups and their Endpoint lifecycle.
Define the group model before rollout
Computer groups suit stable organisational boundaries. A practical model follows genuinely different protection requirements, for example:
- pilot devices
- standard workstations
- highly critical workstations
- kiosk or production systems
- non-persistent virtual desktops
Departments make good groups only when they truly need different policies. Reproducing a deep organisation chart often obscures assignments without improving security.
Create a group as follows:
- Open My Products > Endpoint > Computers and select Computer Groups.
- Click Add Computer Group.
- Enter an unambiguous name and a short description.
- Assign only the intended computers from the available list and save.
Assigning an already grouped computer to a new group removes it from its previous group. For an existing group, open its name, select Edit in the left pane, amend Assigned Computers, and save. Delete removes only the group, not its computers. Document old and new membership and move a few pilot devices first before making a bulk change.
Use tags for flexible attributes
Tags complement the fixed group with several freely combinable attributes, such as owner=finance, site=zurich, criticality=high, or lifecycle=pilot. A device can have at most 15 tags, and up to five tags can be pinned in the shared device list.
Tags help with filters and worklists but do not control group membership. Storing the same fact in device names, groups, and several tags creates conflicting data. The linked Central device inventory explains how to create, verify, and remove tags.
Check policy assignment
A group is not operationally complete until its policy effect has been checked:
- Open the group name under My Products > Endpoint > Computers > Computer Groups.
- Select Policies and review the enabled policies applied to the group.
- Open a policy name if required. Editing it affects every user and group to which it is assigned, so verify target scope and policy order before saving.
- Open a pilot device under My Environment > Computers & Servers and compare the effective policy of each type on Policies.
- Correct target assignment or order, then check again after the next Central contact.
The target type has no automatic priority: if user and computer policies of the same type match, their order decides. Build Sophos Central Endpoint policies correctly explains the full priority model.
Interpret Agent mode and device status
Endpoint, XDR, and XDR Sensor represent different software scopes; XDR Sensor does not include Sophos malware protection. On the computer object, Summary shows assigned scope and group, Status shows individual health assessments, and Policies shows effective policies. The Central device inventory covers available columns, filters, and software actions in the shared device view.
Investigate inactive devices
An inactive record is a signal, not an immediate deletion instruction. Determine why contact is missing:
- the device has been retired or replaced
- the user is absent for an extended period
- the agent, proxy or network connection is disrupted
- the computer was cloned from an old image
- the device belongs to a lab, VDI environment or Update Cache
The new unified view includes devices inactive for more than 30 days. In older Endpoint lists, the Not online recently filter may be required.
Last Active is updated only about once an hour on average. An Event can therefore have a newer timestamp than the displayed Last Active value. This is not automatically a data error.
The same delayed update model applies to Online and Last Activity. After a new user signs in, Central may already associate the device with that user while timestamps still show the previous state for roughly an hour. If the device then goes offline, correction takes correspondingly longer.
In the Computer Report, Online and Last User do not mean the same thing: Online is based on the latest processed status message. Last User changes only when another unique user account signs in to the device for the first time. A very old Last User value therefore does not prove that the endpoint has been offline since that date.
Automatic cleanup
Under Global Settings > Products and Services > Endpoint and Server > Removal of Inactive Devices, rules can be created separately for endpoints and servers.
Sophos distinguishes Targeted rules for selected groups and one Global rule for the remaining devices. The global period must be longer than the targeted-rule periods. Infrastructure such as Update Caches, Message Relays and rarely started specialist computers belongs in explicitly excluded groups.
Two targeted rules can be created. No more than four groups can be excluded from the global rule; subgroups count separately and are not automatically excluded with their parent. Sophos evaluates the rules daily at midnight in the tenant’s data region.
MSP and Marketplace customers must select at least 31 inactive days for a rule. For VDI clones created with --nonpersistent, Permanently remove VDI desktops can be enabled; these devices cannot subsequently be restored. The Gold Image master itself is not removed by such rules.
Removed devices remain in the Recovery Report for 120 days. They can be restored during the first 30 days. Update Cache and Message Relay are not restored.
Removal is not local uninstallation: Automatic cleanup removes the record from Central. The treatment of the Sophos software on the device must be decided first.
Distinguish automatic removal from general deletion
An automatic removal rule removes inactive devices from management but does not uninstall Sophos software left locally. On supported current Windows systems with Core Agent 2023.2 or later, Delete and licence expiry instead trigger the documented back-off: Tamper Protection and protection components are removed, but Sophos Endpoint Agent still requires local uninstallation for complete removal. Do not conflate these workflows.
The Recovery Report and Tamper Protection password remain available for 120 days; a removed device can be restored during the first 30 days. Update Cache and Message Relay are not restored. Uninstall Sophos Central Endpoint on Windows covers controlled Windows removal. General Delete and health-reset steps are in the Central device inventory.
Do not confuse migration with changing groups
Change group moves a computer object within the same tenant. Moving it to another Central tenant is instead an API-based Device Migration with separate receiving and sending jobs. Devices can remain queued for up to 14 days; persistently offline devices must then be queued again. Follow Migrate Sophos Endpoint devices between Central tenants for the complete piloted workflow.
Handle duplicate devices correctly
Every Sophos installation receives a unique device ID during registration. If an already registered system is cloned without preparation, several endpoints can use the same ID. Central initially shows only one device object that they overwrite in turn. Automatic Duplicate Detection identifies this pattern on Windows, macOS, and Linux, registers the affected devices again, and thereby creates additional objects.
The newly registered device inherits the group, policies, and product assignment of the original object. Check these values after deduplication because the inherited assignment may not be appropriate for every clone.
An alert such as Device has been detected as a duplicate device is not an instruction to delete the marked record immediately. Other clones using the same ID may still depend on the original object. If it is removed too early, those devices can no longer communicate with Central and must be reinstalled. Sophos recommends retaining the marked original object for at least two weeks unless every affected system has been identified with certainty.
Use this safe sequence:
- Review the affected device’s alert and events.
- Search for the device name and compare active and older records using Last Active.
- Check group, policies, and product assignment on the newly registered object.
- Correct the cause in deployment, the Gold Image, or the snapshot.
- Delete only when all systems using the old ID are known and none still communicates through it.
In non-persistent VDI environments, every new clone or return to a snapshot can trigger another registration. Additional objects are therefore not necessarily a new deduplication error. Prepare the Gold Image with the supported process described in Deploy Sophos Central Endpoint for VDI and Gold Images.
AWS instances and Azure VMs also undergo this detection. Windows Servers with active Server Lockdown and devices sharing an ID but using different operating systems are not automatically deduplicated. Resolve recurring alerts at the image and registration cause instead of concealing them through repeated deletion.
Important: Central cannot repair an accidental deletion of the shared original object for clones that no longer communicate. The Sophos Agent must then be reinstalled.
Interpret restarts correctly
An initial installation or removal of a competing product can require a restart. Product updates often do not require one immediately. If a device has not restarted for months, however, two update states can each require a restart in succession. Sophos recommends waiting about 20 minutes between the two restart cycles so that the first update can complete fully.
Old Windows and macOS Alerts are removed from the detail view after 90 days. A red Health State can nevertheless remain until the cause is resolved and the state is reset. The absence of the old Alert alone does not prove that the issue was repaired.
Monthly operational check
A short monthly check prevents blind spots from accumulating:
- Filter devices without recent activity and identify their owners.
- Resolve health problems by cause, not just colour.
- Check
Product unassigned,Upgrade availableand unsupported devices. - Justify and correct Tamper Protection with status
Off. - Clean up computers without groups or with incorrect tags.
- Exclude Update Caches, Message Relays and VDI gold images from removal rules.
- Uninstall devices no longer needed and delete them afterwards.
Sources
The following official Sophos pages were used for the UI paths, group rules, status details, restart guidance, and lifecycle boundaries described here (retrieved 11 September 2026):
- Computers and servers
- Computers (current Endpoint view)
- Computers (legacy Endpoint path)
- Computer Groups
- Computer Group Summary
- Computer Group Policies
- Computer Summary
- Computer Status
- Computer Policies
- Computer restarts
- Removal of inactive devices
- Deleted and expired devices
- Device migration
- Duplicate device frequently asked questions (KBA-000006069)