Manage a Mac with Sophos Mobile: Enrollment and Verification
Quick path for manual enrollment: First sign in as the intended local Mac user, open your organization’s enrollment instructions from the email or Self Service Portal, and install the provided Enrollment Policy using an administrator password. Then check the enrollment status in the Sophos Mobile device record and the applied management profiles on the Mac. The exact installation prompts depend on the instructions provided and the macOS version; there is no universal sequence of clicks here.
This process sets up a Mac for Sophos Mobile MDM. Sophos Mobile uses the native macOS MDM client to manage policies and profiles. It is not the installation of Sophos Endpoint for malware protection. Nor is a Sophos Endpoint configuration profile deployed by another MDM solution the same thing as the Sophos Mobile Enrollment Policy. For Endpoint installation and protection checks, see the separate macOS Endpoint guide; for Endpoint profiles delivered by MDM, see the Jamf and Sophos Mobile context.
Decide before enrollment
- User: With this manual method, Sophos Mobile manages the local user signed in to the Mac during enrollment. Sophos documents that this enrolled user cannot be changed afterward. Do not simply sign in with an arbitrary administrator account: have the intended user sign in, and provide an administrator password separately when installing the policy. This user is not necessarily the owner assigned separately in the Sophos device record. There is no documented way here to switch users within an existing enrollment, nor a universally safe reset procedure.
- Ownership and policies: For a personally owned Mac, clarify consent and the expected scope of management first. Sophos Mobile does not offer Macs the Apple User Enrollment BYOD mode described for iPhones and iPads. Mac Device policies apply to all signed-in users; User policies apply to the enrolled local user and to network users known to Sophos through the configured external LDAP directory. This does not amount to a blanket assurance that private data is isolated, or mean that every User policy can affect only one person.
- Prerequisites: Check licensing and permissions in your tenant, the permitted macOS version, service connectivity, a valid organization-specific invitation, and the necessary administrator credentials. As of September 25, 2026, Sophos Mobile’s requirements list macOS 12, 13, 14, 15, 26, and 27 for the native MDM client; macOS 11 is no longer listed. Before a rollout, the Sophos Mobile version deployed in your tenant must be approved for the specific macOS version. Also test the Device policies and User policies actually used, along with the rollback process, on an approved test Mac; if support has not been confirmed, stop the rollout and clarify approval with the responsible administrator. A supported OS version does not establish support for every individual policy feature or suitability for Sophos Endpoint.
- Rollback: Before enrollment, record which MDM profiles and certificates provide Wi-Fi, VPN, or email access, who can initiate unenrollment, and how the Mac will remain reachable afterward. Test first on an approved test Mac with the intended user and actual policies, not across an entire fleet.
Enroll and verify the result
- Sign in to the Mac as the local user to be managed. This determines the user’s identity for the manual process described here; do not switch to another account during enrollment.
- Open your organization’s invitation or follow the steps shown in the enabled Sophos Fusion Self Service Portal. For a device already created, an administrator can initiate the task under Devices > [device] > Actions > Enroll; Sophos then sends an email with the specific steps. The available option depends on the tenant setup.
- Install exactly the Enrollment Policy provided for this device, following those instructions, and enter an administrator password when prompted. An arbitrary
.mobileconfigprofile from another environment is not a substitute. Do not proceed blindly if the Mac, organization, or user in the invitation is incorrect. - In Sophos Mobile, check that the device record and enrollment task have the expected status. On the Mac, confirm that the organization’s management profile and expected settings have arrived; find the applicable location in System Settings for the macOS version in use. Sophos’ older instructions still refer to System Preferences > Profiles; that is not verified menu navigation for macOS 26/27. After a synchronization, compare an innocuous expected policy setting with the plan. A successfully initiated task alone does not prove that all profiles and certificates are in effect.
If verification fails: If the local user is wrong, stop before making further policy changes and plan a coordinated unenrollment and reenrollment; simply changing the owner’s name in the device record does not establish a change to the enrolled local user. If the profile is missing, check the invitation, administrator approval, network connection, and task status. If a User policy does not arrive, also check the next sign-in and, where applicable, the LDAP mapping; changes to Device policies take effect at the next sync, and changes to User policies at the next sign-in. Do not blindly or repeatedly install unverified profiles; first verify the invitation, user, Mac, policy, and task status. A backup is prudent but does not make repeated installation safe.
Unenrollment and other enrollment methods
When a Mac is unenrolled, Sophos Mobile removes the policies and certificates received via MDM. This can disrupt managed access: first ensure independent network and administrative access and a plan for data and certificates, then test the process on the test Mac. The documented admin action is Devices > [select device] > Actions > Unenroll and requires confirmation. Removing the Enrollment Policy locally also unenrolls the Mac and requires administrator privileges; removing a User policy alone does not—it may be reassigned at the next sign-in. Deleting a device record while the device is still enrolled unenrolls it only at the next synchronization; for an offline Mac, this is not immediate remote unenrollment. Verify the state on the Mac and in the tenant after the sync. This process does not imply that a factory reset is required or guarantee preservation of data and identity on reenrollment.
Apple Business / automated Mac enrollment is a different method that uses Setup Assistant. It may allow user assignment in the device record; do not assume that the warning about the signed-in local user in the manual process above applies to this method. APNs continuity, Activation Lock, and any device handover require their own tested rollback plan. Likewise, individual User Restrictions cases on macOS 26+ and older software update deferrals on macOS 27 need version-specific checks. Until the policies deployed in the tenant and the rollback process have been verified on a suitable test Mac, this is not an approved fleet rollout.