Skip to content
Avanet

Sophos Mobile: Assessing Android Enterprise Connectivity and Certificates

This article helps you decide which Android Enterprise policy and certificates a connection needs. It describes the documented settings, not a change tested in the target tenant. The pilot and recovery checks are Avanet operational recommendations, not prerequisites required by Sophos for this documentation. Before assigning a changed policy in production, you need a pilot and a tested access path that does not depend on the affected Wi-Fi, VPN, or proxy. This does not establish that activation or rollback will succeed in your own tenant.

Terminology: English Sophos labels used here come from the English-language Sophos help; the German equivalents mentioned come from the German-language Sophos help. The language and clickable labels actually shown in the target tenant’s interface have not been checked.

Establish the mode and starting scenario first

Which connection is changing: EAP Wi-Fi (including a CA or server-name change), SCEP/client certificate, VPN app, or HTTP proxy? First establish the management mode, policy type, license, and Android version on the target device. Sophos documents the Android Enterprise device policy for full device and the work profile policy for work profile separately. A setting in the work profile establishes neither access by personal apps to its certificates nor a device-wide VPN or Wi-Fi effect.

Keep the three certificate roles separate

  • SCEP server CA: Trust anchor for the SCEP server; add it as a Root certificate (German Sophos help: Stammzertifikat) in the same policy before configuring SCEP.
  • Issued client certificate: Identity for the intended app or connection. An uploaded Client certificate (German Sophos help: Client-Zertifikat, .pfx) and a certificate issued through SCEP are different configuration paths.
  • EAP server CA: Trust anchor for validating the Wi-Fi server; check it together with the expected server name. It need not be the same CA as the SCEP server CA. Check the appropriate chain separately for each purpose rather than trusting an unknown CA.

Android Enterprise device policy (full device)

The Client certificate configuration (Client-Zertifikat in the German Sophos help) is documented as installing a client certificate on devices; this establishes neither installation timing nor actual installation in the target tenant. In the File area, select Upload a file, then select a PKCS #12 certificate file (.pfx). Alternatively, drag the certificate from File Explorer into the File area to upload it. Certificate name shows the certificate’s name, which Sophos Mobile retrieves from the certificate file. These English field and action labels come from the Sophos help, not from a verified target-tenant interface. Other configurations in the same policy can use it; another policy requires another upload.

Add a root certificate to the device policy

Root certificate (Stammzertifikat in the German help) accepts an X.509 root certificate in PEM or DER format and installs it when the policy is assigned. Only configurations in the same policy can select it, for example to establish EAP server trust for Wi-Fi. Common file extensions are .cer, .crt, and .pem for PEM, and .cer and .der for DER. These are examples, not an exhaustive list or a required file extension.

  1. Open the existing device policy on Edit policy and select Add configuration > Root certificate.
  2. Select Upload a file, select the appropriate X.509 file, and open it with Open. Alternatively, drop the file from File Explorer anywhere in the File area.
  3. After the upload, Certificate name shows the Distinguished Name (DN) of the certificate issuer. Do not confuse this display with a client certificate’s name or Subject.
  4. Apply saves the configuration. Then select Save on Edit policy to save the policy. Add a separate Root certificate configuration for each additional root certificate.

SCEP fields in the device policy

SCEP lets the device request a certificate from a CA through the Simple Certificate Enrollment Protocol. First add the SCEP server CA as a Root certificate in the same policy, then add the SCEP configuration through Add configuration. To edit an existing configuration, click its name. The following fields are documented for the device policy and, within the scope described below, also for the work profile policy; they are not requirements for personal apps or another platform.

  • URL is the CA server’s web address. %_SCEPPROXYURL_% refers to the server URL under Setup > Sophos setup > SCEP.
  • Alias name is the certificate’s name in selection dialogs. Choose a memorable name, for example the Subject value without CN=.
  • Subject identifies the certificate recipient. CN=%_USERNAME_% represents a user, and CN=%_DEVPROP(serial_number)_% represents an Android device. On assignment, Sophos Mobile replaces the placeholders with the corresponding properties. %_USERNAME_% supplies the Exchange Login property of the user assigned to the device; the device placeholder supplies the specified device property. Available properties are listed on Show device under Device properties and Custom properties. The substituted Subject value must be a valid X.500 name and match the intended PKI identity.
  • For a SAN, select its type under Type of Subject Alternative Name and enter its value under Value of Subject Alternative Name. RFC 822 name is a valid email address, DNS name is the CA server’s DNS name, and Uniform resource identifier is its fully qualified URL. AD user logon name is the user logon name stored in Active Directory, the User Principal Name (UPN).
  • Challenge is the web address for requesting a challenge password, not the password itself. %_CACHALLENGE_% refers to the challenge URL under Setup > Sophos setup > SCEP. Confirm challenge generation and enrollment permissions with the PKI team.
  • Root certificate selects the CA from all uploaded Root certificate configurations in the current policy.
  • Key size is the size of the public key in the issued certificate and must match the SCEP server setting. Certificate usage offers Use as digital signature for digital signatures and Use for encryption for data encryption. Agree on the usage with the PKI team and the target service’s owners.

On Edit policy, SCEP renewal interval (SCEP-Erneuerung in the German help) sets the interval after which the device requests certificate renewal. After adding the required configurations, save the policy with Save. Neither the fields nor the selected interval establish successful issuance or renewal; no interval value is prescribed here.

Android Enterprise work profile policy (work profile)

The Client certificate configuration (Client-Zertifikat in the German Sophos help) also serves to install a client certificate on devices in this mode. In the File area, select Upload a file, then select a PKCS #12 certificate file (.pfx). Certificate name shows the certificate’s name, which Sophos Mobile reads from the file. The certificate is available to Managed Google Play apps in the work profile and other configurations in the same policy, but availability to personal apps has not been established. Another policy requires another upload.

Root certificate (Stammzertifikat in the German Sophos help) installs the PEM/DER X.509 root certificate in the work profile when assigned and makes it available to configurations in the same policy.

To upload a root certificate to an existing work profile policy, follow the format guidance, including the non-exhaustive file-extension examples, and all four steps in “Add a root certificate to the device policy”. In step 1, explicitly open the work profile policy instead of the device policy on Edit policy; Add configuration > Root certificate, file selection or drag-and-drop, the issuer DN display, and Apply followed by Save remain the same. Here, too, add a separate configuration for each additional root certificate. Installation remains limited to the work profile, and selection remains limited to configurations in the same policy.

Here, too, SCEP first requires the SCEP server CA as a Root certificate in the same policy. Issued certificates are described as available to apps in the work profile; that establishes neither device-wide availability nor automatic renewal. Check the URL, challenge, subject/X.500, CA, key length, and usage separately.

After uploading this CA, add a SCEP configuration through Add configuration in the same existing work profile policy; to edit an existing configuration, click its name. All seven field descriptions in “SCEP fields in the device policy”, from URL through Key size / Certificate usage, explicitly apply to this work profile SCEP configuration: the URL and Challenge placeholders, Alias and Subject examples, placeholder substitution and property mapping, SAN type/value selection and AD UPN, root certificate selection from the same policy, and key size matching the server setting and usage options. After making the required changes, select Save on Edit policy to save the work profile policy. This reuse covers only the SCEP add/edit steps and field descriptions, not the separate renewal-interval paragraph, the device policy’s Client certificate upload, or other connectivity fields; it does not establish certificate availability to personal apps or across the entire device.

Limit applying to both modes: The Sophos Wi-Fi setting (WLAN in the German help) lists Client certificate configurations from the same policy in its Identity certificate field (Identitätszertifikat). Direct selection of an issued SCEP certificate in this field is not documented.

Setting up the SCEP server remains a separate task. The SCEP certificates and connectivity paths procedure guides PKI, network, and MDM owners through the SCEP-capable Windows CA, server and challenge endpoints and their permissions, and inbound SCEP over TCP 443 with regional source-IP allowlisting. It also explains how to identify your region and provide the URLs under Setup > Sophos setup > SCEP to which the placeholders refer. Challenge characters and length, the optional proxy, and the documented connection test on Save belong to that setup procedure, not to the Android connectivity fields.

Check each connection type separately

Wi-Fi and EAP server names

The Wi-Fi configuration (WLAN in the German help) is documented for device and work profile policies. Identical fields do not establish a device-wide effect for the work profile policy; that remains unknown without device testing. With EAP/PEAP, EAP/TLS, and EAP/TTLS, the Wi-Fi network must not be hidden: the SSID must be broadcast. With WEP, the policy cannot be assigned to devices running Android 12 or later. A documented option is neither a recommendation nor a default value.

English fieldMeaning or optionsAvailability according to the help
SSIDWi-Fi network IDWi-Fi
Security typeNone, WEP, WPA/WPA2 PSK, EAP/PEAP, EAP/TLS, EAP/TTLSWi-Fi
Phase 2 authorizationAuthentication: None, PAP, CHAP, MSCHAP, MSCHAPv2PEAP/TTLS only
IdentityUser identityEAP only
Anonymous identityPseudonym sent unencrypted in EAP phase 1EAP only
PasswordWi-Fi passwordNo further restriction stated
Identity certificateIdentity certificate for the connectionEAP only
Trusted certificateRoot CA for the EAP server certificateEAP only
Domain suffix matchDNS name checkEAP only
Subject alternative name matchSAN substring checkEAP only

Identity certificate (Identitätszertifikat in the German help) lists all certificates from Client certificate configurations in the current policy. Trusted certificate (Vertrauenswürdiges Zertifikat in the German help) lists all certificates from its Root certificate configurations. The root CA validates the EAP server certificate; it is not automatically the SCEP server CA. Uploading is described above under the certificate roles. The list does not establish direct selection of a certificate issued through SCEP.

Domain suffix match (Domänen-Prüfung in the German help) compares the entered value with dNSName in the server certificate’s subjectAltName. It compares domain components from the right, starting with the top-level domain. example.com matches server.example.com, but not server-example.com. Multiple semicolon-separated values are alternatives; one match is sufficient. Wildcards are not allowed in the input value. A suffix is not an exact hostname match. Therefore, compare the expected RADIUS/EAP server names, a suffix as narrow as possible, and the CA chain before assignment.

Subject alternative name match (SAN-Prüfung in the German help) is an expert setting that uses substring matching. Here, too, multiple semicolon-separated values are alternatives. The documented example DNS:server.example.com;EMAIL:server@example.com matches a certificate with dNSName *.server.example.com or the email element server@example.com. Distinguish the wildcard in the certificate from the wildcard input prohibited for Domain suffix match. Sophos recommends Domain suffix match wherever possible. A matching name alone establishes neither a valid trust chain nor successful EAP authentication.

Select the VPN app and configure it at app level

In both modes, VPN client (VPN-Client in the German help) expects the identifier of the Managed Google Play VPN app already selected and installed on the device. The identifier is not the visible app title. On Edit approved app, Sophos distinguishes Title, the displayed name, from Product ID, the internal app name. For Android, find the identifier by searching for the existing app in Google Play in a browser and opening its details page. The value after id= in the URL is the app identifier. Do not select a different app just because its title is similar.

VPN connection parameters belong in the app’s managed configuration at app level, not in a VPN policy connection form documented here. If the app supports this feature, Managed Google Play displays This app offers managed configuration. The documented Sophos procedure is:

  1. Under Apps > Android, open the existing app in question.
  2. On Edit approved app, select Use managed configuration and open Edit managed configuration.
  3. Configure the settings offered by the app. The app developer’s documentation determines which VPN connection fields and values are supported.
  4. Select Save in the Managed configuration window, then select Save again on Edit approved app.

Sophos Mobile sends this change through a Google API to all devices on which the app is installed. It may take a few minutes for the settings to become available. A pilot group for the VPN policy does not automatically limit this app configuration change. Before saving, therefore, check the entire affected device fleet and an independent recovery path. These English UI labels are documented, not verified in the target tenant.

User values in the managed app configuration

If the app requires a user value in a text field, you can use $USERNAME or $EMAILADDRESS there. These placeholders can be used in any text field in the managed configuration; which values the app requires remains app-dependent. Sophos Mobile replaces them with the username and email address when assigning the settings. On devices without an assigned user, both are replaced with an empty string. Check the user assignment and the app’s requirements before using them. These app placeholders are not the policy placeholders %_USERNAME_% and %_EMAILADDRESS_%; the mapping of %_USERNAME_% to Exchange Login described above cannot be applied to $USERNAME.

For $EMAILADDRESS, you can configure the source of the address. First check the existing setting and user assignment; obtain separate approval for a change rather than making it casually during VPN setup:

  1. In Sophos Fusion, under My Products > Mobile, go to Setup > Google setup and open the Android Enterprise tab.
  2. Under Email placeholder, Use the assigned user’s email address determines the source: if selected, Sophos Mobile uses the email address of the user assigned to the device. If the user changes, installed apps update the address the next time they synchronise with Sophos Mobile. If the option is not selected, Sophos Mobile uses the email address used during device enrolment.
  3. Save the approved change with Save. Then check the address used and the app’s sign-in behaviour; placeholder substitution alone does not establish successful authentication.

Transfer configurations entered before 13 August 2022

On 13 August 2022, Sophos Mobile switched to a different Google API for managed configurations because Google no longer supports the old API. Previously entered configurations remain active, including on devices that receive them only after this date. You must re-enter them if you want to edit the configuration or install an app update that includes changes to the managed configuration. Sophos Mobile cannot automatically convert the old format.

While Use managed configuration is selected and the configuration has not yet been migrated, you can expand the old Managed configuration area on Edit approved app using the Plus icon. Securely back up the existing values, take them from this area and re-enter them in the new Managed configuration window. Then, as described above, save with Save first in the window and then on Edit approved app. This change also affects all devices with the app installed; check the affected device fleet and independent access path beforehand. This format transfer is neither migration from Device Administrator mode to Android Enterprise nor an import of AnyConnect XML profiles.

Remove the managed configuration from devices

For a separately approved removal, first check all devices with this app and the independent access path. On Edit approved app, clear Use managed configuration and save with Save. Sophos Mobile sends the change through a Google API to all devices on which the app is installed. It may take a few minutes for the settings to be removed; a VPN policy pilot group does not limit this removal either.

Then check whether the settings have actually been removed and how connection and reconnection behave. This is not app uninstallation, policy reassignment or a promise of safe tunnel rollback. Successful removal or restoration in the target tenant has not been tested here.

The policy setting alone establishes no tunnel, protocol, always-on behavior, “Block without VPN,” or, for the work profile, a tunnel for all device traffic. Tunnel establishment, intended traffic routing, app access, and reconnection remain checks to perform for the app and environment actually in use.

Global HTTP proxy

Global HTTP proxy (Globaler HTTP-Proxy in the German Sophos help): Documented only for the device policy examined here: a corporate proxy with manual connection details or a PAC file. In the Proxy field, select Manually to set up the connection details manually: Server is the HTTP proxy’s name or IP address, and Port is its port number. If a Proxy Auto-Config (PAC) file is available, select Automatic; PAC URL is the URL of that file. These English field and option labels come from the Sophos help, not from a verified target-tenant interface. This establishes neither a corresponding work profile setting nor an effect on all non-HTTP traffic. An unreachable proxy or faulty PAC can disrupt management and app access.

Checks before assigning in production

After the preliminary checks, assign the saved policy under Policies > Android. Open the blue triangle next to the policy, select Assign, select the intended pilot devices on Select devices, and complete the process with Finish. Sophos describes Android Enterprise policies as taking effect on assignment; changes synchronize automatically when the device connects to Sophos Mobile. This is not a promise of tested delivery, installation, or removal times. The manual Update devices route for older Android device policies is not the documented update step here.

The following checks are Avanet operational recommendations before changing production connectivity. When changing the managed VPN app configuration, also account for all devices with that app, as described above; separate policy pilot groups do not isolate this change.

  1. Beforehand: Check the license, Android version, and actually available policies in the target tenant. Retain the existing working policy and CA chains. Test a path to management and the network without the affected Wi-Fi, VPN, or proxy in advance. Do not put private keys, secrets, or challenge values in tickets or articles.
  2. Separate pilot devices or groups for each mode: Observe the effective policy and certificate availability in the correct profile, the expected EAP server identity and trust chain, and actual SCEP issuance, expiration, and renewal. Depending on the starting scenario, check the VPN app and tunnel, proxy/PAC reachability, app access, and management check-in. When changing a CA, remove the old CA only after checking every dependent connection.
  3. Stop and recovery path: If server identity, certificate use or renewal, connectivity, app access, or check-in cannot be shown to work, pause assignment to additional devices. Only via the independent access path tested beforehand, update or reassign a working policy and check reconnection and certificate/VPN status. A device that has gone offline cannot reliably be reached by a cloud policy change; immediate remote rollback is not guaranteed. The English Sophos help describes uninstalling a policy for individual devices (Uninstall policy), but not for these Android Enterprise policy types; this is not a button label verified here in the target tenant.

Do not assign the changed policy in production while either the intended effect in the pilot or the independent recovery path remains unverified. The settings described here do not replace these checks.