Sophos Mobile EAS proxy: Plan installation only after compatibility checks
Preliminary documentation review, not approval for installation. The source material documents product guidance and download listings; it does not verify a downloaded installer or approve a particular build, tenant, or production installation. The standalone Sophos Mobile EAS proxy can sit in the EAS mail path in proxy mode or manage access through Exchange in PowerShell mode, while devices communicate directly with Exchange. These modes, their server targets, and their authentication paths are not interchangeable. Before installation or any change to production mail access, confirm the specific Sophos version, target, mail client, and procedure with Sophos and the Exchange team. The EAS architecture decision covers the mail path and quarantine; Exchange migration and EAS troubleshooting are separate tasks.
Pre-installation review without making changes
- Record the target and mode: The Sophos architecture guide and PowerShell setup guide distinguish proxy mode for Exchange Server only from PowerShell mode for Exchange Server or Exchange Online: in the latter mode, devices communicate directly with Exchange, while the service controls access through its administrative connection. The general mail-server list in the release notes is not approval to use Exchange Online in proxy mode. IBM Traveler is listed as a mail server; for non-iOS Traveler clients, Sophos cannot check every request for authorization because the device ID is missing. Record the tenant/cloud, affected EAS devices, and mail apps. According to Sophos, Mac mail traffic cannot be filtered through the EAS proxy or controlled in PowerShell mode because Macs do not use ActiveSync. A working administrative connection alone proves neither the mail path nor enforcement of a device block.
- Have the host and mail server checked: The Sophos Mobile release notes, Requirements > Sophos Mobile EAS proxy list Windows 10 or later and Windows Server 2016 or later as installation hosts; the general mail-server list includes Exchange Server 2016 and 2019, Microsoft 365 (Exchange Online), and IBM Traveler 9.0. That product list establishes neither current Microsoft lifecycle support for the named Windows/Exchange versions nor compatibility of a specific installer build and tenant; check both separately. The Sophos installation description requires administrator rights on the installation computer, the Sophos Mobile server URL, and access to the required mail servers. The installer does not configure unreachable mail servers as connections. According to Sophos, the displayed URL is in the Sophos Mobile interface under Setup > Sophos setup > EAS proxy > External; it is not a tenant URL to guess. Obtain operations-team approval for the host, network paths, and mail target before any changes.
- Do not confuse a download listing with approval: The Sophos download description points to the installer link under External. The official download listings for en-us and the URL without a language code are dynamic lists, not verification of a downloaded binary. On September 29, 2026, the en-us listing displayed Standalone EAS Proxy Installer 9.8.2; the URL without a language code redirected to en-gb and displayed 9.8.1. An earlier retrieval of the same URL redirected to de-de and displayed 9.8.2; intervening timeouts do not establish permanent unavailability. The list also includes older on-premises downloads; the discontinued status of that product branch says nothing about the status of Central-managed Sophos Mobile. The redirect and displayed version vary by locale; neither establishes a universally latest version or support for a build on the specific host or with Exchange Online. The downloaded file, its signature/provenance, version, supported host environment, and Sophos approval were not checked here. Do not launch an installer on the basis of this page.
- Track certificates as separate trust paths: In proxy mode, assess separately the client-facing HTTPS certificate on the proxy, the TLS connection to the Exchange target, and the per-instance certificate generated for the connection to Sophos Mobile. At the Exchange target, the configured ActiveSync server name must match the CN or a SAN on the Exchange certificate; also check the chain and trust. Upload the instance certificate to Sophos Mobile. The separate Sophos configuration description warns that if the service starts before the upload, Sophos Mobile rejects the connection and the service does not start. Nevertheless, the Sophos installation procedure describes starting before upload and then restarting; do not adopt that sequence unquestioningly as safe operating instructions. Before commissioning, clarify the mapping of each instance, backup of certificate files, and approved startup window. Separate warning from the SSL Certificate Wizard: The Sophos description of the SSL Certificate Wizard warns that a self-signed certificate or one issued by a private CA requires manually distributing trust to devices before enrollment (otherwise the Sophos Mobile Control app will not trust the server) and precludes Android zero-touch and Knox Mobile Enrollment. That source does not identify a specific mail TLS endpoint as the cause of the enrollment trust failure it describes; do not assign it to the client-facing proxy certificate, Exchange backend certificate, or instance certificate without evidence. Do not disable certificate validation as a fix.
- Assess installation side effects by mode: Proxy mode: The wizard checks proxy-instance ports and creates inbound Windows Firewall rules; the mail user-agent allowlist can exclude clients. PowerShell mode: Devices communicate directly with Exchange; Sophos says the EAS proxy needs no inbound mail port for this mode. Approve and verify the outbound administrative path to Exchange separately from the direct device mail path; do not present proxy-instance ports or user-agent filters as the PowerShell mail path. According to Sophos, log entries are moved daily to a new file named
EASProxy.log.yyyy-mm-dd. These daily log files are not deleted automatically and can cause disk-space problems over time. Sophos therefore recommends a process that moves the log files to a backup location. The backup destination, access protection, privacy requirements, and retention period must be agreed with the operations team; this recommendation does not authorize an archiving or deletion process to be run on the basis of this page. Changes, log protection, and a storage/retention plan require their own change approval; no default setting here should be treated as approved. - Scope an Outlook pilot in proxy mode separately: Sophos documents possible erroneous blocks of Outlook on Android/iOS: on initial proxy contact or after reinstallation, matching the username and ActiveSync ID can fail with multiple devices or a changed ID. Before a pilot, record affected users/devices and existing mail functionality; after initial contact, check the association and mail flow for each test device. If a device cannot be matched unambiguously or mail is blocked, stop the pilot and return to the previously approved mail path; do not grant blanket access or invent an ID correction.
- Consider the service account only for PowerShell mode: Sophos describes a dedicated account for this mode that reads ActiveSync device information, allows or blocks device access, and manages ActiveSync device access rules. For these tasks, Sophos specifies the Exchange RBAC roles Mail Recipients and Organization Client Access; according to Sophos, no Microsoft 365 mailbox, Microsoft 365 license, or Azure/Microsoft Entra role is required. These are documented role names, not authorization or authentication approval verified in this tenant. Review identity, role assignments, password/secret management, MFA, Conditional Access, and revocation with the Exchange team; do not create an account or assign roles based on this article. Reviewing tenant sign-in requirements is separate from assigning permissions and is not a reason to assign additional directory roles.
Proxy mode: wizards and configuration scope
The following sections describe the screens and decisions documented by Sophos for EAS proxy, not the PowerShell instance. They are intended to support complete preparation of a later change. Do not install, add, import, upload, save, or restart anything on the basis of this page. These actions require a separately approved change, confirmed build/host/mail-server compatibility, planned certificate trust, and a documented starting state, maintenance window, stop criteria, and verified recovery path. The source conflict over the first service start remains unresolved; the description below does not resolve it.
From setup to the configuration wizard
Sophos describes Sophos Mobile EAS Proxy Setup.exe as the entry point to the Sophos Mobile EAS Proxy - Setup Wizard. Choose Install Location is where the destination folder is selected; Install starts installation. Once installation is complete, the Sophos Mobile EAS Proxy - Configuration Wizard starts automatically. The destination folder and automatic handoff therefore belong in installation planning, but are not an instruction to launch the unverified installer.
The Sophos Mobile server configuration dialog takes the Sophos Mobile server URL identified earlier. Use proxy server is an optional setting when the EAS proxy needs a network proxy for its connection to Sophos Mobile. This is the HTTPS control path, not the device mail path or the separate, system-wide WinHTTP configuration for the connection to Exchange. Changing one of these paths replaces neither the checks nor the approval required for the other.
Incoming TLS, certificate import, and client authentication
Sophos recommends Use SSL for incoming connections (Clients to EAS Proxy) to protect the connection from mail clients to the proxy. Selecting this option displays Configure server certificate for this endpoint’s HTTPS certificate. The wizard distinguishes between:
- Create self-signed certificate: The documented option when no trusted certificate is available yet. The next page requires a server that client devices can reach. Reachability alone does not establish certificate trust; this option is not a blanket recommendation for the production mail path.
- Import a certificate from a trusted issuer: For an existing trusted certificate, the choices are PKCS12 with certificate, private key and certificate chain (intermediate and CA) or Separate files for certificate, private key, intermediate and CA certificate. The certificate details appropriate to the selected type follow. The import therefore includes the private key and chain; files and keys must be protected and mapped to the correct endpoint.
The optional Use client certificates for authentication adds a client certificate to the EAS proxy credentials; it does not replace those credentials. Selecting this option displays SMC client authentication configuration. This page selects the certificate of a certification authority (CA) from which the client certificates must be derived. The EAS proxy checks this derivation when a connection is attempted. Keep this CA selection separate from the HTTPS server certificate, the Exchange backend certificate, and the instance certificates to be uploaded later. Before approval, the intended mail clients and their certificate provisioning must support this authentication path; the screen alone does not establish that support.
Separate SSL Certificate Wizard: request and historical Apple requirements
This is a documentary inventory, not approval to create a certificate. The installer places the separate wizard in C:\Program Files (x86)\Sophos\Sophos Mobile EAS Proxy\tools\Wizard; its executable is Sophos Mobile SSL Certificate Wizard.exe. On Upload CSR, Open CSR opens the certificate signing request (CSR) if the CA accepts pasted request text. On Import Certificate Files, the CA certificate downloaded during Upload CSR belongs in Select CA certificate file. Certificate created shows the completed certificate folder for later setup. Record that location and securely back up the entire folder, including private keys. Do not launch the wizard or create or import files here; the existing change, trust, and recovery boundaries still apply.
For a self-signed certificate created outside the Sophos Mobile Configuration Wizard and SSL Certificate Wizard, Sophos refers to historical Apple requirements for iOS 13 and macOS 10.15: RSA keys in TLS server certificates and issuing CAs must be at least 2048 bits, their signatures must use SHA-2, and the server DNS name must appear in Subject Alternative Name (SAN); a DNS name only in Common Name is insufficient. For TLS server certificates issued after July 1, 2019 (as indicated by NotBefore), those historical requirements additionally specify Extended Key Usage id-kp-serverAuth and validity of no more than 825 days between NotBefore and NotAfter. Violations can prevent TLS connections on those platforms. This historical limit is neither sufficient approval for current platforms or certificate lifetimes nor proof of trust. Check current requirements and trust distribution separately; enrollment exclusions and the prohibition on bypassing TLS remain.
Fields for each EAS proxy instance
On EAS Proxy instance setup, Sophos describes one or more instances. Record the values and their mapping separately for each planned instance:
- Instance type:
EAS proxy, notPowerShell Exchange/Office 365. - Instance name: A freely chosen name to identify the instance.
- Server port: The incoming mail port on the EAS proxy. If there are multiple proxy instances, each must use a different port. Do not infer a default port from this description; port allocation, network approval, and the client route must match the approved design.
- Require client certificate authentication: The instance-specific requirement for mail clients to authenticate with a client certificate when connecting. Check this selection against the client CA described above and the actual certificate provisioning.
- ActiveSync server: The name or IP address of the Exchange ActiveSync server instance to which this proxy instance connects. The entered value must match the CN or SAN of that server’s TLS certificate; an arbitrary reachable IP address is not sufficient.
- SSL: Protection of the connection from the proxy instance to the Exchange ActiveSync server using SSL or TLS as supported by that server. This is a different connection from Use SSL for incoming connections (Clients to EAS Proxy); the field label is not approval to use obsolete protocols or bypass TLS.
- Enable Traveler client access: According to Sophos, only for required access by Traveler clients on non-iOS devices. The limitation caused by the missing device ID described above remains; this selection neither extends approval for Exchange Online in proxy mode nor guarantees an authorization check for every request.
Add and export the instance certificate
After the instance details have been entered, Add adds the new instance to the Instances list. For each proxy instance, the installer generates a separate certificate for its later connection to Sophos Mobile. After Add, an upload message appears; OK opens a dialog showing the folder containing the generated certificate.
Alternatively, the same dialog can be opened on EAS Proxy instance setup by selecting the relevant instance and Export config and upload to Sophos Mobile server. Document the certificate folder together with its instance mapping and back up the file securely: the folder is needed for the later upload. According to Sophos, additional instances are configured by repeating Add. This is not the unchanged Save of an existing PowerShell instance or the saving of a certificate upload in Sophos Mobile.
After all required instances, the installation description specifies Next, with port checks and creation of inbound Windows Firewall rules. Allowed mail user agents offers Allow all mail user agents without restrictions or Only allow the specified mail user agents, with selection and repeated Add for each permitted mail client. Clients not listed are rejected in the restricted option. Neither blanket access nor an unchecked restriction is approved here.
Upload all instance certificates — startup order remains unresolved
The documented first start is contradictory. The installation description returns to setup from Sophos Mobile EAS Proxy - Configuration Wizard finished through Finish. It then requires Start Sophos Mobile EAS Proxy server now and Finish, meaning the first service start occurs before the certificate upload. The separate configuration description instead warns that Sophos Mobile rejects the connection without a prior upload and the service does not start. Neither a vendor resolution nor a tested safe sequence is established here. Do not infer a checkbox change or another workaround; before the first start, clarify the sequence for the specific build with Sophos and the operations team.
The upload documented afterward expressly covers every proxy instance, not just PowerShell connections:
- In Sophos Fusion, open My Products > Mobile, then Setup > Sophos setup and the EAS proxy tab.
- Under External > Upload a file, select the certificate generated during configuration and mapped to the relevant instance. For multiple instances, repeat the upload for all instance certificates.
- Save with Save. This saves in Sophos Mobile; it is not Add in the Windows wizard.
- In Windows, Sophos specifies the Services dialog and a restart of the EASProxy service.
This list is a configuration inventory, not approval to execute the procedure despite the startup conflict. Upload, Save, and especially the disruptive service restart belong exclusively in the separately authorized change. First back up the complete instance/certificate mapping and service state; the agreed stop and recovery criteria apply to partial uploads, rejected connections, or failure of the service to start. A successful upload or restart guarantees neither device sign-in nor mail flow. Actual verification and restoration remain limited to the approved pilot and its test mailboxes.
Service account: documented options and change boundaries
The following outlines the options in the Sophos service-account description; it is not an approved setup procedure. Account creation, changes to password requirements, license removal, and role and group changes each require separate approval, with a documented starting state and an agreed recovery path. The commands are examples from the source; none were executed here.
Prepare the account: Exchange Online or Exchange Server
| Target | Documented location for account creation | Boundary |
|---|---|---|
| Exchange Online | Microsoft 365 admin center, admin.microsoft.com | Create the identity here; assign roles in Exchange afterward. |
| On-premises Exchange Server | Exchange admin center, https://<ServerFQDN>/ecp | <ServerFQDN> is the fully qualified domain name of this Exchange server. |
For both options, Sophos describes a username that indicates the account’s purpose, such as smc_powershell, and disabling the setting that forces a password change at the next sign-in. The example name is not mandatory. For Exchange Online, Sophos also describes removing an automatically assigned Microsoft 365 license because this service account requires neither a license nor a mailbox. This is not an instruction to change existing accounts, password requirements, or licenses during the pre-installation review.
Assign roles: two cloud alternatives and one on-premises group option
For Exchange Online, Sophos documents two alternative assignment methods:
- Role group in the Exchange admin center: At
admin.exchange.microsoft.com, the path Roles > Admin roles leads to the role group. The new group described in the guide receives a purpose-specific name, such assmc_powershell_role, the roles Mail Recipients and Organization Client Access, and the service account as a member. This group name is also only an example. - Direct assignment with Exchange Online PowerShell: Sophos lists this alternative for automated or scripted deployments, or when the command line is preferred. An Exchange Online PowerShell session is required; the administrative identity performing the role assignment needs separately approved assignment permissions. It must not be confused with the service account whose access will be checked later. Sophos shows the following session connection command and two state-changing assignment commands; these are not approval to execute them:
Connect-ExchangeOnline
New-ManagementRoleAssignment -Role "Mail Recipients" -User "smc_powershell@<tenant>.onmicrosoft.com"
New-ManagementRoleAssignment -Role "Organization Client Access" -User "smc_powershell@<tenant>.onmicrosoft.com"
smc_powershell@<tenant>.onmicrosoft.com is the unchanged example address from the source: the account name and <tenant> must match the actual service-account identity in a separately approved change. Do not execute the placeholders literally. Sophos then shows this read-only check of the assignments, displaying the Role and RoleAssigneeName columns:
Get-ManagementRoleAssignment -RoleAssignee smc_powershell@<tenant>.onmicrosoft.com | Select-Object Role, RoleAssigneeName
According to Sophos, direct assignments are a valid Exchange Online RBAC mechanism and behave at runtime in the same way as assignments through a role group. This does not establish approval for sign-in or for the Sophos service in the specific tenant.
For on-premises Exchange Server, Sophos describes a new, purpose-named role group with Mail Recipients and Organization Client Access, with the previously created account as a member. The cloud command-line alternative is not part of this on-premises guidance.
Check Exchange Online account access separately
For a separately authorized check of service-account access, Sophos describes an Exchange Online PowerShell session using Connect-ExchangeOnline, followed by these read-only cmdlets. The session must test access by the service account being checked, not merely by another administrative identity:
Get-MobileDevice
Get-ActiveSyncDeviceAccessRule
If either cmdlet fails, Sophos identifies checking the assignment of both roles to the service account as the next step. The queries themselves do not fix an error; no test results or expected device or rule lists are available here. Successful queries establish only this Exchange administrative access, not the runtime compatibility or authentication path of the Sophos service, nor a mail app’s ability to send, receive, or synchronize mail.
Broader privileges are not a production solution: Sophos warns that Exchange Administrator works but grants substantially more permissions than required. The source limits the exception to temporary troubleshooting and explicitly and strongly advises against using the role in production; permanent assignment is therefore also ruled out. This is a vendor description, not a recommended repair or permission to elevate privileges. Even temporary privilege changes require their own approval and revocation plan. The source provides neither a fixed duration nor specific revocation or restoration commands; no tested recovery path is claimed here.
EAS PowerShell authentication: Modern Auth attempt and Basic fallback boundary
The Sophos Modern Auth description applies expressly only to PowerShell mode. It describes a Modern Auth attempt for Exchange Online when the ExchangeOnlineManagement module is available and a Basic fallback if that fails; for an on-premises Exchange Server, it describes Basic for the administrative connection, not for every client sign-in. Microsoft states that Basic Authentication for Exchange Online EAS and Remote PowerShell has been disabled and cannot be re-enabled. The fallback described by Sophos is therefore not a usable recovery path for Exchange Online. The module alone proves neither the actual transport used by the installed Sophos service nor a supported sign-in for the cloud, tenant, and service account. Do not take PowerShell commands, instructions to enable Basic, TLS bypasses, or blanket role assignments from these source texts.
Specific conflict between sources: The Sophos PowerShell configuration description names outlook.office365.com for the global cloud and says the wizard appends /powershell-liveid; the Microsoft connection guide presents this Remote PowerShell connection only as a historical, unsupported method and describes current REST-based module connections. Sophos’s description of its Modern Auth attempt does not establish whether a particular proxy build still uses the old path or instead uses supported REST cmdlets. Neither the module’s availability nor a separate successful Connect-ExchangeOnline session confirms the Sophos service’s authentication path.
HOLD for Exchange Online: Before approving a pilot, Sophos and the Exchange team must confirm the specific proxy build; host, module, and runtime compatibility; the cloud and protocol endpoint; OAuth/REST behavior of the service; service-account permissions; and tenant MFA/Conditional Access requirements. Separately, the actual mail app must be able to sign in to the intended mailbox and send, receive, and synchronize mail; a successful PowerShell connection or “Last active” does not prove this. If any of these points remains unresolved, do not recommend installation, a DefaultAccessLevel/quarantine change, or a broad client migration.
Documented sequence for new and existing installations — not approval to execute
The Sophos Modern Auth guide distinguishes two cases for Exchange Online in PowerShell mode. For a new installation, it describes opening Windows PowerShell as an administrator on the intended EAS host, installing the ExchangeOnlineManagement module, and only then installing the EAS proxy or configuring it for PowerShell mode. For an already installed proxy, it also describes opening Windows PowerShell as an administrator on that proxy’s host: first comparing the installed proxy version with the vendor’s offering under Standalone EAS Proxy Installer, then installing the module, and then reopening the configuration wizard. Comparing versions establishes neither a universally latest version nor approval to upgrade; support for the specific build and host, module, and runtime compatibility still require separate confirmation. This sequence documents the source, not an installation or update approved here. The HOLD above and a separately approved change with a documented starting state and an agreed recovery path remain prerequisites.
For an existing installation, the source inventories this read-only registry command on the Windows host: Get-Item -Path "Registry::HKLM\SOFTWARE\Wow6432Node\Sophos\Sophos Mobile Control EAS Proxy\". It depends on the specified registry path; a missing key or its contents establish neither the version of every build nor runtime compatibility. No output or registry property was observed here or is invented. For both new and existing installations, the source also specifies Install-Module -Name ExchangeOnlineManagement as a modifying module installation in administrative Windows PowerShell. This is not an automatic repair recommendation: separate change approval, support and host/module/runtime compatibility review, and recovery planning are required. Neither command was executed here. Neither registry inventory nor module presence proves service OAuth/REST behavior; the HOLD and unchanged Save for every existing PowerShell instance remain.
For an existing installation, Sophos describes reopening the Windows app Sophos Mobile EAS Proxy - Configuration Wizard after preparing the module. In the wizard, it describes selecting an instance with Instance type PowerShell Exchange/Office 365, then selecting Save without changing any values. The source describes repeating this selection and unchanged save for each additional instance of this type, then completing the remaining wizard steps. This is a separate configuration operation, not Add for a new connection or Save after a certificate upload in Sophos Mobile. Even saving unchanged values is not a read-only diagnostic and requires a separately approved change. This sequence establishes neither a particular internal update mechanism nor a required restart or repeat certificate upload; it proves neither successful Modern Auth sign-in nor a tested fix.
Quarantine: separate source example, not installation completion
Organization-wide quarantine is a separate access change, not the final step of installation. The EAS architecture decision covers prerequisites, ABQ/protocol limits, impact, and the rollback path. The documented source example is explicitly one line and is not approved for execution here:
Set-ActiveSyncOrganizationSettings -DefaultAccessLevel quarantine -UserMailInsert "Bitte registrieren Sie Ihr Gerät bei Sophos Mobile."
-DefaultAccessLevel quarantine sets the organization-wide default; the quoted text after -UserMailInsert is a customizable enrollment notice for the quarantine email. The HOLD above and separate change and rollback approval remain in force.
Acceptance and rollback boundary
Before any later, separately approved pilot, document the starting state by mode: existing EAS endpoints/DNS and mail profiles on affected devices, current Exchange access rules including individual decisions, proxy instance/port/firewall/user-agent filters, certificate mapping, service account/roles, email-account policies and SSP tasks, and mail flow using test mailboxes. Exchange and Mobile operations must approve a rollback for the specific mail path in advance, including restoration of the previous client route, access decisions, and assignments; merely stopping the proxy service is not enough after clients have been migrated. Set a change window and stop criteria also covering a failed certificate upload or partial migration. In an authorized, limited pilot, observe the service connection to Sophos Mobile, the Exchange administrative sign-in, and device mail flow separately; after stopping, verify restoration of sending, receiving, and synchronization for each affected test app. Neither the appearance of an instance in Sophos Mobile nor a successful service login proves client access. Without a verified installer, authentication path, trust setup, and tested rollback, installation and production cutover are not approved. These prerequisites concern operational approval, not publication of this preliminary documentation review.