Sophos Mobile: Plan macOS security and privacy policies
Scope: This article covers Sophos Mobile for managed Macs, not Sophos Endpoint protection policies or a local macOS installation. A macOS device policy applies to all users of the Mac; a macOS user policy applies to the local user who enrolled the Mac with Sophos Mobile and to network users known to Sophos Mobile through the external LDAP directory for the Self Service Portal—not automatically to every local user. The same configuration name in both policy types does not establish that their assignment and effects are identical. Keep the security and privacy decisions here separate from Wi-Fi/VPN/certificates, directory integration, and the dedicated update rollout. The Sophos Endpoint MDM profile for Full Disk Access and System/Network Extensions is not a substitute for these Mobile policies; its rollout is covered in Deploy Sophos Endpoint on macOS via MDM.
Before making changes: establish scope and a recovery path
Sophos Mobile distinguishes four macOS policy families: device, user, and declarative policies configured in Sophos Mobile, and imported policies based on Apple configuration profiles. An imported .mobileconfig profile may come from Sophos Fusion for Endpoint, Apple Configurator, or a trusted third party. It is not equivalent to a native Sophos Mobile configuration: check its device or user channel and potential overlaps against its actual payloads; do not assume that the conflict rule below applies to every imported profile.
Before importing, establish the profile’s origin, approved file version, included certificates and secrets, suitability for macOS, and the required import and assignment permissions in your tenant. Encrypted configuration profiles cannot be imported. Start at Policies > macOS > Create > Import policy: enter a name and description, select the reviewed .mobileconfig under Upload a file, and select Save. This creates only the policy entry; it does not install the profile on the Mac. Separate assignment, conflict checks, and pilot verification are covered in Import Apple configuration profiles into Sophos Mobile; for Endpoint, use the Endpoint MDM guide linked above.
Before editing or assigning native macOS policies, confirm an active Sophos Mobile Device Management license or Sophos Mobile with MDM included in your tenant. Sophos Mobile Threat Defense alone does not cover this Mac management. Check the actual permissions for policy editing and assignment: Helpdesk cannot edit policies, and Read-only has only read access; do not infer editing rights from available support actions. If the license or required permissions are missing or unclear, do not proceed; involve the responsible tenant administrator. Only then identify the device or user policy actually assigned under Policies > macOS. The enrollment policy is itself a device policy. In addition, a Mac can be assigned one device policy, one declarative policy, and one user policy. Record these separately. A declarative macOS policy is a type of device policy that uses Apple’s Declarative Device Management (DDM). Document the device, enrollment user, known network users, macOS version, management mode, and current policy assignments. Check option names and availability against the labels in your own console: some restrictions depend on device type and operating system version.
What DDM changes in operation: With classic MDM, Sophos Mobile controls individual settings and periodically polls the device’s status. With DDM, you specify a desired state; the Mac itself is responsible for reaching and maintaining that state and reports changes asynchronously, without waiting for the next periodic status poll. These ongoing status reports do not mean that a newly assigned or changed policy is installed immediately or that an update has already completed. For policy changes, the distinction between device sync and user sign-in described below still applies.
For each change, record whether it should affect all users or only the enrollment user and known network users. Before editing any already-assigned policy, inventory every assignment of that exact policy: capture all target Macs, groups, affected managed users, and indirect assignments; document the actual scope and approver. A pilot Mac does not isolate a change to a policy shared with other devices: change only a separate policy assigned exclusively to the pilot, or obtain explicit approval for the impact on all existing assignments. Until the full assignment inventory is known, do not select Apply or Save. According to Sophos, the more restrictive setting generally wins in a conflict; exception: software update and app settings in a declarative policy take precedence over the corresponding settings in device or user policies. Preserve a baseline of the affected settings without obsolete keys and identify the responsible approver. Choose a pilot Mac with one test user and, where relevant, a second user. Do not assign a policy indiscriminately to the entire fleet.
Assess the impact in advance: remote access and file sharing, camera/FaceTime, printers, app installation, iCloud data flows, credentials, and required browsers and third-party filters. Before enforcing passwords, arrange user communications, support, and an independent recovery path for lockouts. Do not use “Number of failed attempts until device wipe” as a test value: once the threshold is exceeded, data and settings are removed. According to Sophos, after the sixth failed password attempt, a delay begins before another password can be entered; it increases with each further failed attempt. At values of six or fewer, this delay does not apply. Withdrawing a policy does not undo a wipe or lockout that has already occurred; plan data recovery only through previously tested backups and approved device-recovery procedures.
Obtain privacy approval for filter and account payloads: who processes browser/socket traffic, URL and connection metadata, or contact and calendar data? Which third-party app and data flows have been approved? Keep passwords, tokens, principal/server URLs, and personal test URLs out of screenshots, tickets, and logs, or securely redact them before sharing; do not store secrets in repositories. Servers, ports, and placeholders are tenant- and provider-specific, not reusable sample configurations. Sophos Mobile policy payloads alone establish neither consent for a Data Lake nor particular macOS system permissions for a third-party app.
Device security configuration
Configure the following payloads under macOS device policy only with confirmed device-wide scope and in the approved pilot:
- Firewall: Turn on application firewall enables the macOS application firewall. Block all incoming connections blocks incoming connections to sharing services such as File Sharing or Screen Sharing; the documented system services
configd,mDNSResponder, andracoonare exempt. Use stealth mode ignores unsolicited requests such as ping. Select app groups under Allowed connections and Denied connections; for other apps, the user may allow or deny connections. The two settings that automatically allow built-in apps or downloaded apps signed by a valid certificate authority (CA) cannot be turned off in this configuration. Test the required remote administrative access before blocking it. This is inbound network protection, not FileVault disk encryption. - Gatekeeper: Allow apps downloaded from offers Anywhere, Mac App Store, or Mac App Store and identified developers. Check the choice against required signed internal apps and installation methods. Do not broadly relax Gatekeeper to Anywhere to work around a broken installer.
- Password policies: Set Allow simple value, Require alphanumeric value, minimum length, minimum number of complex characters, Maximum password age in days (
0= no change required; up to730), maximum Auto-Lock time, password history, and maximum grace period for the device lock. None for the lock grace period leaves the available intervals to the user; Immediately requires a password on every unlock. The documentation specifies a 60-minute window when assigning the policy to a noncompliant device, after which apps may no longer launch. Verify the exact macOS behavior in the pilot before production enforcement. - Restrictions: Change only explicitly approved switches, such as camera, Spotlight web results, iCloud Backup/Photos/Keychain/Documents, Touch ID, fingerprint configuration, Apple Watch Auto Unlock, password AutoFill, and AirDrop password sharing. Allow iBeacon discovery of AirPrint printers carries an explicit phishing warning; AirPrint over TLS may require Force trusted certificates. Change sharing and remote-management switches only if administration and recovery remain possible. Allow Erase All Content and Settings applies only to Macs with Apple Silicon or a T2 chip. Allow Time Machine configuration at device level lets users configure external backups; it does not guarantee that a backup exists.
- Managed domains: Email domains marks messages in Mail from addresses outside the listed organization domains as outside the domain; this is a label, not a DLP block or authorization for data transfer.
Gatekeeper: what the selection allows. According to Sophos, Anywhere allows users to open all apps regardless of where they were installed from, within this Gatekeeper source selection. It guarantees neither that every app will launch nor that other macOS safeguards will be bypassed. With Mac App Store and identified developers, users may open only apps from the Mac App Store or from developers approved by Apple. A signature or internal approval alone does not establish membership in this developer category. Check availability and actual app-opening behavior on the intended pilot Mac; the warning against broadly relaxing Gatekeeper to Anywhere still applies.
Restrictions in detail: Sophos describes the following permissions and effects for the device policy. They allow features or their configuration; they do not prove that those features are already configured or in use. Availability and effect still need to be checked on the intended Mac.
Allow Startup Disk configuration lets users change the startup volume to start the Mac from another drive or a network volume. Align this decision with the approved boot and recovery procedure before restricting this option. Allow adding users lets users add accounts in System Settings. This permits account creation; it does not assign a Sophos Mobile user policy to new local accounts.
Assess three separate sharing mechanisms: Allow Bluetooth Sharing configuration lets users configure file sharing between the Mac and other Bluetooth devices. Allow Internet Sharing configuration permits configuring the sharing of the Mac’s internet connection with other computers on the same local network, for example over Wi-Fi. Allow Printer Sharing configuration permits configuring printer sharing with other Macs or UNIX computers on the same local network. These decisions concern Bluetooth file transfer, sharing a network connection, and making a printer available, not merely joining Wi-Fi or sending an AirPrint job. Allow only the mechanisms needed and approved for operations.
Allow iCloud Drive for Desktop and Documents permits storing the Mac desktop and Documents folder in iCloud Drive and accessing them on other devices. Data approval must therefore account for the contents of these working folders, not just individually selected documents. Allow Find My Mac permits using the iCloud service to locate, lock, or erase the Mac remotely. Establish who is responsible and authorized for these actions in advance. This is separate from Sophos Mobile unenrollment or the password-dependent wipe threshold; do not trigger a remote erase as a pilot check.
Allow password auto-fill lets users enable AutoFill Passwords to use saved passwords or credit-card information in Safari or other apps. According to Sophos, clearing the checkbox also disables automatic strong-password suggestions. Account for this side effect when deciding against AutoFill; it is not a password-composition requirement.
Approve Freeform and Wi-Fi credentials separately: The following two switches are documented under Restrictions for both device and user policies. In a device policy, they affect all users of the Mac; in a user policy, only the local enrollment user and network users known to Sophos Mobile, not every local user. Some settings are available only for particular device types or operating system versions: before changing them, check the labels beside each switch in Sophos Mobile for the target Mac; do not infer a default value or universal availability from the documentation.
- Allow iCloud for Freeform lets users store their Apple Freeform boards in iCloud and use them on other devices. Before allowing it, establish whether the contents of these boards may be stored in iCloud and accessed across devices. Approval concerns this data flow, not blanket use of all iCloud features; an enabled switch does not establish actual synchronization.
- Request Wi-Fi passwords from nearby devices concerns requesting passwords from nearby devices when the Mac sets up a Wi-Fi connection. Allow it only if obtaining Wi-Fi credentials this way is approved for the affected users and networks. This is a separate decision about credential flow, not Wi-Fi profile configuration or the separate Allow AirDrop password sharing permission to share passwords from Password Manager.
For both changes, check the intended permission or restriction in the approved pilot after device sync or the managed user’s next sign-in: use only empty or synthetic test boards for Freeform, and only an approved test network and test devices for Wi-Fi password requests. Do not record production board contents or Wi-Fi passwords in verification evidence. If behavior differs, first check availability, policy scope, and parallel Restrictions; the documented option alone does not confirm effective implementation on the Mac.
Additional Restrictions and explicitly excluded legacy procedures
The following decisions also apply to the documented device and user Restrictions, within their respective scopes defined above. Change only options actually offered and tested on the target Mac; neither identical labels nor a saved legacy value proves current support.
- Allow use of camera: Without permission, Sophos describes the camera as unavailable and the Camera icon as removed; photos, videos, and FaceTime are then not possible. Establish the required camera/FaceTime use before restricting it; do not assume that the icon description represents universal current macOS UI behavior.
- Allow internet search result for Spotlight, Allow Apple Music, Allow definition lookup: The first switch controls internet search results in Spotlight; according to Sophos, Spotlight provides no such results when it is disabled. The other two allow access to the Apple Music library and looking up selected words, respectively. These are separate feature decisions, not general web-filter or app-installation approval.
- Allow backup, Allow iCloud Photo Library, Allow document sync: These permissions concern iCloud backups, iCloud Photo Library, and storing documents and app configuration data in iCloud, respectively. Approve data types and permitted accounts separately; permission confirms neither successful backup nor synchronization.
- Allow iCloud Keychain sync: Allows password synchronization between iPhone, iPad, and Mac through iCloud Keychain. According to Sophos, without permission these keychain data are stored only locally. Decide on this credential flow separately; a block proves neither deletion of data already transferred nor blocking of other password routes.
- Allow iCloud Bookmarks, Allow iCloud Mail: Allow synchronization of browser bookmarks across browsers and platforms, and setting up an iCloud mail account on the Mac, respectively. Approve bookmark transfer and account creation separately from the EWS/IMAP/POP account.
- Allow iCloud Calendar, Allow iCloud Reminders, Allow iCloud Address Book, Allow iCloud Notes: Allow sharing calendars, reminder lists, contacts, and notes, respectively, across devices and with other iCloud users; Notes also includes taking notes. Approval must therefore consider both cross-device access and potential sharing with other users. It does not replace CalDAV/CardDAV approval.
- Allow Touch ID and Face ID to unlock device, Allow fingerprint configuration, Allow Auto Unlock: According to Sophos, biometric unlocking is not possible without the first switch; its label does not establish Face ID hardware on the Mac. The second allows adding and removing Touch ID fingerprints, and the third allows automatic unlocking through Apple Watch. Approve the unlock method and changes to stored fingerprints separately; retain password and recovery access.
- Allow AirPrint, Force trusted certificates for AirPrint over TLS: AirPrint allows sending files to AirPrint-capable printers. The certificate option rejects AirPrint over TLS if the printer certificate is untrusted; it does not itself configure TLS or a chain of trust. The iBeacon phishing warning above remains a separate decision.
- Allow AirDrop password sharing: Lets users share passwords from Password Manager with other users through AirDrop. Define recipients and permitted credentials in advance; do not equate this with general AirDrop file transfer or requesting Wi-Fi passwords. Use only synthetic credentials in the pilot.
- Allow File Sharing configuration: Lets users specify which files and folders they share with other users on the same local network. Limit approved contents and recipients. This is neither Bluetooth Sharing nor the Mac–iPhone/iPad transfer distinguished below; permission to configure does not confirm an actually reachable share.
- Allow Remote Application Scripting configuration, Allow Remote Management configuration: The first option allows configuring users who may send Apple Events to the Mac from other computers, for example to open or print a file stored there. The second allows configuring remote access to the Mac. Define authorized senders, data access, and an independent administrative recovery path; these switches do not grant blanket privacy permissions to a remote app.
Allow Back to My Mac — not a rollout procedure in this article: The retained Sophos list describes iCloud-based file and screen sharing between a remote and a local Mac. This specific remote-access decision is not covered by general iCloud, firewall, or local file sharing. The historical label explicitly provides no basis here for current availability or instructions to restore the service. Back to My Mac is excluded from the pilot and rollout approved here: do not import legacy keys, reactivate an obsolete service, or claim successful remote access. If this work is needed, the responsible Mac/remote-access administrator takes over selection and separate approval of a currently supported method, including identities, network path, file/screen permissions, and recovery. This switch does not automatically approve a replacement.
Allow iTunes File Sharing — check the data path, exclude legacy instructions: Sophos describes copying files between a Mac and an iPhone or iPad through File Sharing in iTunes. This is a distinct transfer route, not sharing Mac folders on the local network. For macOS Catalina and later, Apple describes using Finder for this file transfer, with an iOS/iPadOS app that supports File Sharing. This does not mean that the historical Sophos switch allows or blocks Finder transfers on every current Mac. The iTunes procedure is therefore excluded from this current Mac rollout; do not install iTunes or legacy profiles to restore it. If this transfer is needed, before approval ask the Mac/app administrator, with the target version, devices, participating app, permitted files, and recipients specified, to check the supported route and actual Restriction effect separately. Use only synthetic files and test both copying directions; until there is evidence, do not treat blocking, data-transfer approval, or migration as completed.
Additional locking and erasure effects: According to Sophos, during the documented 60-minute password window, the device prompts for a password change each time the Home screen is opened; afterward, the launch block also affects internal apps. This UI description does not promise identical current Mac dialogs: test with a test account, without deliberate lockout or wipe. Allow Erase All Content and Settings permits erasing settings, data, and apps through macOS System Settings on the Apple Silicon/T2 Macs mentioned above. This is a destructive user feature, not a backup, Mobile unenrollment, or a control test to execute in the pilot.
Password composition: Allow simple value allows sequential or repeated characters in the password. According to Sophos, Require alphanumeric value requires at least one letter or one digit. Minimum number of complex characters sets the minimum number of non-alphanumeric characters. These are characters that are neither letters nor digits.
Password history: According to Sophos, Password history sets how many previously used passwords Sophos Mobile stores. A new password must not match any password in this configured history; the setting therefore prevents reuse within the stored history.
Two separate lock intervals: Maximum Auto-Lock (in minutes) limits the idle duration, in minutes, that the user can set before the device locks. Maximum grace period for device lock, by contrast, limits the interval the user can set after a lock during which the device can be unlocked without a password prompt. Both values are ceilings on the user’s settings, not necessarily the actual times selected.
Updates are separate: The macOS software update delay restriction is 0 (offer immediately) or 1–90 days after release. For macOS 27 and later, Sophos also documents Software update settings in a declarative policy. The choice between a target version with a deadline, a specific Background Security Improvement, and general update settings, together with their interaction with classic policies, is covered in Manage macOS updates with Sophos Mobile. Plan update timing, mode, and deployment there with a dedicated pilot, not alongside firewall and privacy changes.
FileVault is separate: Neither the application firewall nor the 19 source payloads covered here configure or confirm FileVault encryption, encryption status, or recovery-key escrow. That is a separate task for the owner of Manage FileVault with Sophos Fusion; do not infer successful encryption or key escrow from firewall or password policy status.
Device-level privacy preferences and web content filtering
Privacy preferences policy control (device policy): Sophos Mobile documents the specific option Allow Sophos Endpoint to scan all files, giving Sophos Endpoint access to data such as Mail, Messages, Safari, Home, Time Machine backups, and certain administrative settings for all Mac users. Users must accept the policy; according to Sophos, this acceptance requirement does not apply to devices managed with Apple Business. In the pilot, check management mode, assignment, user acceptance where required, and actual Endpoint access separately. This single option is not a general PPPC/TCC grant for third-party apps and does not replace app-specific Full Disk Access, System Extension, or Network Extension profiles. The profiles and permissions required for each third-party app belong to the responsible profile/app owner for approval, not to a permissions matrix inferred from these 19 sources.
Web content filter (device policy): Requires a third-party app whose Filter ID is its bundle ID. Configurable fields include Filter name, Server (name, IP address, or URL), optional Organization, User name, Password, Certificate, and provider-specific Third-party settings. According to Sophos, Certificate authenticates to the filtering service; it does not validate the service’s TLS server certificate. Clarify the requirements for this authentication certificate with the provider. Under Filter range, choose between Browser traffic (Safari and other browsers) and Socket traffic (app network traffic). Verify the app license, required system permissions, data recipients, filtering behavior, and failure behavior with the provider and in your tenant beforehand. For filter servers using credentials, use only a tested TLS-protected transport with certificate validation; otherwise, do not deploy credentials until a documented provider/tenant exception with an equivalently secure path has been approved and tested. The Mobile payload is not a built-in Sophos web-filtering engine, nor does it automatically grant macOS Network Extension or privacy permissions.
User policy, data access, and system permissions
Under macOS user policy, select payloads only for the local enrollment user and known network users. According to the respective Sophos pages, Managed domains and Password policies contain the same described fields as their device-policy counterparts, but have a different policy scope. Restrictions are also largely parallel; the user policy specifically no longer includes Allow Time Machine configuration. When policies are assigned in parallel, test the general “more restrictive wins” rule and the documented precedence of declarative software update/app settings with the test user; do not assume any other precedence rule.
- App Store: Restrict to updates permits updates but not new installations. Forbid app adoption prevents apps not installed through the Store from being adopted into the Apple Account; those apps then cannot be updated through that route. Turn off update notifications suppresses update notices and is not a substitute for an update policy.
- Restrictions / privacy: iCloud switches affect the potential transfer of mail, calendars, contacts, photos, notes, passwords, and files. Switches for camera, Touch ID, Auto Unlock, AirPrint, and remote scripting affect functionality, not automatically the PPPC/TCC permissions of arbitrary apps. Assess operational consequences in advance for Apple Events permitted by Remote Application Scripting, and for Remote Management and file sharing. Do not infer a blanket “Full Disk Access granted” from this list.
- CalDAV / CardDAV (user policy): Account display name, server, port, optional Principal URL, username, and password concern calendars or contacts, respectively. For CardDAV, enter the CardDAV server’s hostname or IP address under Server. Require SSL/TLS and trusted certificate validation for accounts with credentials; if the service does not support this, do not deploy credentials until a documented exception approved by the provider and tenant owner, with an equivalently secure transport, has been tested. Check the synchronization scope in the pilot.
- Email account (user policy): Configures an Exchange Web Services (EWS) account for mail, contacts, reminders, and calendars. Set Account name as the account name. Do not enter the Sophos Mobile EAS Proxy as the server: Macs do not support its ActiveSync protocol.
- Exchange Online: For the global Microsoft 365 cloud, use
outlook.office365.comas Server name when automatic OAuth host discovery is not used; check the appropriate provider address for other clouds instead of reusing this host. Leave Domain blank. User is usually the email address;%_EMAILADDRESS_%inserts the assigned user’s address. - Exchange Server: Enter your own server URL as Server name when automatic OAuth host discovery is not used. Enter the user account’s domain under Domain;
%_USERNAME_%in User inserts the assigned user’s Exchange login. Email address can be populated with%_EMAILADDRESS_%from the actual address. Use both placeholders only if Exchange Login and Email Address are maintained for the correct user in Sophos Fusion. - Sign-in and transport: If Password is left blank, users enter their password on the device. Enable Turn on OAuth 2.0 for the appropriate Microsoft sign-in. Leave Server name blank when using automatic OAuth host discovery. Enter an OAuth authorization endpoint only if the authentication provider requires it: doing so disables host discovery, and Server name must contain the server URL. Enable SSL/TLS and transmit credentials/tokens only over a tested TLS path with valid certificate verification; test this in the pilot before rollout.
- Exchange Online: For the global Microsoft 365 cloud, use
- IMAP/POP: Set account type, display/email address, and separate incoming and outgoing Server, Port, User name, Authentication type, Password, and SSL/TLS fields. Enter the outgoing Password only if the outgoing server requires a password; select Use same password as for incoming email only if supported by the server arrangement. Placeholders likewise require maintained user data. Confirm the secured TLS path and certificate validation in both incoming and outgoing directions before signing in with a test account, rather than assuming sample ports.
- LDAP: This payload supplies directory data to the macOS Address Book app and is not a domain join. Configurable fields include host, username, password, Use SSL/TLS, and Search settings with a base DN and scope (base only, base and direct children, or all descendants). Base specifies the path to the starting node in the LDAP directory where the search begins; Scope determines which descendant nodes are included from that base. For binds using credentials, require Use SSL/TLS and certificate validation; if the provider does not support TLS, do not silently enable a plaintext bind. Proceed only after documented provider/tenant approval and testing of an equivalently secure transport. Limit search scope and access rights to the required records.
- Web Clip: Configure Description, URL, Can be removed, Full screen, and Icon. According to Sophos, enabling Full screen opens the clip in full screen and launches its URL as a web app; the option therefore controls the launch mode, not just the display. If you choose this mode, verify on the pilot Mac that the approved URL opens as a web app in full screen. Use an HTTPS link you have verified yourself; the payload also accepts custom URL schemes, which may launch other apps unless checked. According to the documentation, a nonremovable clip can only be deleted after its policy is removed. Icons must be PNG/GIF/JPEG and no larger than 1 MB.
Additional account and display fields: For CalDAV and CardDAV, Account name is the account name displayed on the device, Server is the hostname or IP address, Port is the service port, and Principal URL, if required by the server, is the specific calendar or contact resource. Username and password are this account’s sign-in credentials. An incorrect resource can result in an incorrect synchronization scope even when sign-in succeeds. The Google example URLs and calendar/account identifiers in the vendor help are not an approved tenant configuration; Google-specific setup and identifying these values remain with the calendar/contact administrator, who must check the current service agreement.
For IMAP/POP, Account name is the displayed account name, Account type selects the incoming protocol IMAP or POP, and User display name is the display name for outgoing messages. %_USERNAME_% inserts the assigned user’s name there; Email address can use %_EMAILADDRESS_% for their actual address. The separate server fields expect the hostname or IP address of the incoming and outgoing server, respectively. Fill either Password field only if the corresponding server agreement requires it; the incoming field is not universally mandatory. Check display name, address, and authentication identity separately with the test account.
For LDAP, Account description describes the connection and Description the individual search entry; distinguish both from host, bind identity, Base, and Scope. Actual Active Directory domain joining belongs to the separate Directory service device configuration and is neither configured here nor inferred as successful from a working address-book search.
Web Clip display: According to Sophos, the clip is placed on the macOS desktop. For a bare domain, the URL field may omit https://; other URLs require the complete value. Nevertheless, the explicit, verified HTTPS link required above remains the rule for this rollout. Telephone/support and custom app schemes are a separate app/helpdesk task to check in advance, not an exception approved here. The icon is cropped to a square and adapted to the screen resolution; Sophos recommends 180 × 180 pixels. Depending on the HTML favicon, the device may display the website favicon instead. Check the visible icon in the pilot, and do not infer an incorrect URL or a failed policy rollout solely from it.
Network reachability, certificate chain, proxy, VPN, and managed root/client certificates are approved separately in a connectivity runbook. System permissions: The Sophos Endpoint option above is a specifically documented Mobile device payload outside the 19 original child-page indices. Additional TCC/PPPC, Full Disk Access, System Extension, and Network Extension permissions are checked separately for each app and its current vendor profile; the 19 sources do not establish a universal PPPC allowlist.
Test in a pilot before expanding
On the test Mac, verify the device policy and, where applicable, declarative policy assignment and a recent Sync: according to Sophos, changes to these policies take effect at the next sync. For the user policy, verify assignment and a new sign-in by the enrollment user or known network user: changes to it take effect only at the next sign-in; a check-in alone is insufficient. Document policy status in Sophos Mobile and the locally effective macOS settings separately for each user; assigned does not mean effective.
On macOS 26, view profiles under Apple menu > System Settings > General > Device Management; scroll down if needed. Compare the expected profiles with the assignments in the appropriate user context. For other macOS versions, including macOS 27, check the applicable menu path instead of assuming the macOS 26 path is correct. The older System Preferences > Profiles is not a universal current path. A visible profile does not replace the functional tests below.
Run checks matched to the change: inbound remote access/file sharing after a firewall change, launching an approved and an unapproved app under Gatekeeper, idle time before locking, the password-free unlock interval, and password changes with a test account without triggering the wipe threshold, out-of-domain labeling in Mail, App Store behavior, iCloud access, and account synchronization. For the Sophos Endpoint privacy payload, verify required user acceptance or the Apple Business exception and effective access after sync; verify third-party permissions separately. Test filters only with approved test destinations and browser as well as app traffic as appropriate for the selected Filter range; do not copy real personal URLs into test logs. Before using production credentials, test TLS and certificate validation with synthetic test data for CalDAV/CardDAV, EWS, incoming and outgoing IMAP/POP servers, LDAP, and any third-party filter server that uses credentials; if a documented provider/tenant exception is used, test its equivalently secure transport in the pilot as well. Document only redacted results without secrets or URLs.
Test user and device payloads on the same Mac with the enrollment user, a known network user if applicable, and an unmanaged user; sign in again as each affected user. Fleet-wide rollout remains blocked until assignment, effective local behavior including privacy consent, secure account transport, and an independent recovery path have been demonstrated on the pilot Mac in your own tenant. Roll out only confirmed values and platform versions in waves; compare policy status, functionality, and support reports after each wave.
Diagnose failures and roll back safely
Removing a policy locally is not a policy rollback: Users cannot remove native device or declarative policies from the Mac. They can remove a user policy, but it is automatically reassigned at the next sign-in; this does not unenroll the Mac. Removing the enrollment policy has a different outcome: when removed with the required administrator privileges, the Mac is unenrolled from Sophos Mobile. This does not undo an individual security setting and must not be used to troubleshoot firewall or privacy issues. Preparation for intentional unenrollment and its consequences for policies, MDM certificates, and managed access are covered in Mac enrollment and unenrollment. Before unenrolling, secure independent network and administrative access and a plan for data and certificates; do not treat the profile view as blanket permission to remove profiles.
- Policy not applied: First compare the device/user, macOS version, management mode, assignment, and exact Restrictions labels. Do not change certificates or networking on speculation. If filtering has no effect, check the third-party app, bundle ID, filter range, and required macOS permissions separately. If account synchronization fails, identify the credentials/placeholders, TLS, server, and protocol involved.
- Special case: macOS 26: If the Policies view for a macOS 26 Mac shows only “Failed to apply the policy” for a User policy, the cause may be an obsolete Allow Time Machine key saved in an older user-Restrictions configuration that is no longer offered. The product update removes the visible switch, not the key from existing policies automatically. Before editing, inventory every direct and indirect assignment of this user policy and all affected Macs/managed users (step 2); changes to a shared policy affect more than the selected pilot Mac. Isolate the pilot with a separately assigned policy, or obtain approval for the entire inventoried scope before Apply/Save; do not proceed if the inventory is incomplete. After approval, open the assigned user policy under Policies > macOS, open Restrictions, then select Apply followed by Save. Beforehand, preserve only the other, still-supported values; afterward, verify policy application and the intended restrictions at the next sign-in of every affected managed user. If Time Machine configuration is required, move it to a device policy only as an explicit decision: this will affect all users. Never write the obsolete key back into a user policy; do not substitute an uncontrolled change of policy type or a network/certificate repair. If the error persists, preserve status and assignment details and escalate to Sophos Support.
- Rollback: If functionality is lost, stop the rollout. For native macOS policies, correct the affected policy under Policies > macOS or assign a reviewed replacement of the same policy type; do not assume a Mac rollback path through Uninstall or Unassign. Sophos documents uninstallation only for Android device, Knox container, and iOS device policies, and directs administrators to update or assign a replacement for other policies. For a separately isolated pilot policy, limit the correction or replacement assignment to its confirmed pilot scope. For changes to a shared policy, account for all inventoried assignments in the rollback and restore only the documented, still-supported Restrictions values in the same policy type. To stop a new payload from taking effect, use the corrected policy or reviewed replacement, not an assumed removal of the Mac assignment. Before assigning a replacement, review and approve its complete settings, target devices, user scope, and possible conflicts; preserve required security and access payloads. If editing or replacement assignment is not clearly possible in the tenant, or the permissions checked in step 1 are missing, stop and involve the tenant administrator or Sophos Support. Never restore a complete old policy backup or old policy bytes if that would bring back the obsolete User Restrictions key “Allow Time Machine”; do not recreate it manually either. Check device changes at the next sync and user changes at the next sign-in of every affected managed user. For firewall lockouts, use a previously tested alternative local administrative access method. Do not blindly remove the entire device policy, required Endpoint MDM permissions, or the last administrative access method. After each correction, recheck the policy status and restored functionality on the Mac. A password lockout or device wipe that has already occurred is not reversible through policy rollback: use support/recovery procedures and tested backups where appropriate; never trigger a wipe threshold as a “rollback test.”