Skip to content
Avanet

Password Safe in Intercept X for Mobile: Back Up Your Data in Time

As of September 26, 2026. Sophos has announced that it will remove Password Safe from the Intercept X for Mobile app. On Android, Sophos began a phased retirement with app version 9.8.4125: if no Password Safe file exists, the menu item is no longer shown; if a file exists, the app warns of its eventual removal. Version 9.8.4125 is an app version, not a version number for the Sophos Mobile management service. The Android and iOS help pages still recommend exporting the KDBX file and opening it in another password manager. This does not establish that the feature has already been removed entirely; those pages do not give a firm removal date.

Sophos’s announcement of September 29, 2026 describes a future read-only phase before complete removal. During this phase, the safe can still be opened; entries can be viewed and data copied or exported. New entries cannot be created, and existing entries cannot be edited or deleted. No automatic deletion takes place during this phase. This article does not assume that phase has begun on any particular device or specify when it will. Do not count on a later update or another opportunity to export. Make a backup while you can still open your own safe.

According to Sophos, the existing password store remains encrypted and protected until you choose to export or delete it. This statement concerns the existing store, not the protection of an export destination or any guarantee of access or recovery. It does not replace a protected backup or verification of the migration.

Hand over your personal KDBX file before the feature is retired

  1. Check access: The person concerned opens their existing Password Safe file in Intercept X for Mobile and checks which credentials are required for that file: a master password, a key file, or both. On iOS, a safe file may also be protected only by a key file; in that case, no master password is required. Without the required credentials, an existing file may be unreadable. Before migrating, check whether the chosen destination manager supports the specific file and its required credentials.
  2. Make a backup copy: On Android, with Password Safe open and unlocked, tap More in the three-dot menu in the upper-right corner, then select Export. Next, select the app to which you want to share a copy of the Password Safe file, and choose a protected storage location there. This documented procedure applies while the safe remains accessible in the app. On iOS, Sophos’s announcement describes the following procedure: open Intercept X for Mobile, tap Password Safe, and tap the Info button in the upper-left corner of the authentication screen. Then select Back Up Password Safe File and choose one of the available storage destinations. As a documented alternative, the iOS help describes a route through the app dashboard: tap Info in the Password Safe tile, then select Back Up Password Safe File and choose a storage location for the backup file. These documented procedures apply while the feature remains accessible in the app version you are using; the exact steps on screen may change with app versions. This does not establish that the two screens are identical or that both routes are available on every device. What matters is that a copy of the correct existing file is actually present in a protected location. Record its location securely, and do not share the file to a public or uncontrolled destination.
  3. Move it manually to the destination manager: Choose a password manager suitable for the existing file and capable of handling KDBX files. Follow that manager’s current instructions for importing or opening the file, and open your copy using the required credentials. Sophos does not automatically transfer entries to another manager. Support for KDBX does not, by itself, guarantee compatibility with every individual file or the transfer of all its contents.
  4. Check the result with the person concerned: In the destination manager, check that the expected groups and a selection of entries, including the fields they need, are readable. Keep the backup copy and a separately stored recovery method until use of the destination manager is reliably working. Only then plan a device change or the retirement of the previous access method; do not preemptively delete the app or file. After confirming the migration, review any additional copies at export and sharing destinations, along with any exposed recovery information. Remove only unneeded copies in line with applicable retention rules—never the only usable backup.

Having a backup is not the same as completing a migration. If the destination manager cannot open the file, leave the original and the backup unchanged; check the file version, the credentials required, and the chosen manager’s import requirements. No destination manager has been tested here, and there is no guarantee of successful recovery or of a particular export-format version. According to Sophos’s announcement, the built-in Password Safe feature on Android and iOS supports only the older KDBX 3 format, not KDBX 4. The iOS help limits importing and opening files in the Sophos app to KDBX 3 or earlier; it does not establish which file version an export produces in any particular case. The built-in feature’s format limitation does not guarantee compatibility with the chosen destination manager either.

Protect the backup and recovery information separately

Back up the Password Safe file regularly while you still use the safe on Android or iOS and can open it. After making changes, create a new protected copy so that the backup reflects the version still in use. Sophos does not prescribe a fixed backup interval or describe an automatic backup mechanism on the backup page.

An up-to-date copy is needed if the device is lost or the safe file is accidentally deleted. The iOS help also calls attention to the master password and/or key file in use, as well as a sheet containing recovery information: without the required credentials, the safe may become inaccessible. To print the sheet on iOS, tap Info in the Password Safe tile on the app dashboard and select Print recovery details sheet. Select the printer and number of copies, then tap Print. If this sheet is used as a recovery method, the person concerned adds by hand to the printout the master password, if one is used, the storage location of the Password Safe file in use (original), and the storage location of the backup copy. The completed sheet therefore contains sensitive access information and is kept in a secure location with restricted access; the information is not sent to administrators. For a safe protected only by a key file, this does not imply that a master password is required; these instructions do not establish how the password field on such a printout is handled. The sheet on its own is not a backup if the safe file is lost. Someone who obtains both the sheet and the safe file may be able to read the stored data. Keep the copy, any password, the key file, and recovery information separate and access-restricted in accordance with your security requirements. For a safe that uses a key file, the iOS sheet may contain a QR code with its fingerprint: Sophos describes this as an alternative to the key file when opening the Password Safe file. That does not establish that another password manager will accept the QR code or that the key file can be recovered from it for migration. Therefore keep the actual key file protected for the migration; the QR code also does not belong in a ticket, screenshot, or unprotected message.

The migration concerns personal credentials. Administrators should inform affected users in good time and have them confirm completion of the handover without inspecting passwords, KDBX files, or recovery sheets. A managed Sophos Mobile tenant does not migrate the personal safe on the user’s behalf. If the safe is no longer accessible in the app, first check the original storage location of the previously linked local KDBX file on the device and any existing protected backup copies. According to Sophos, that file remains in its original location even after the feature is removed, although the app will then neither display nor open it. This is not a guarantee that the file or its credentials are still available in any given case, or that a destination manager can read it. If no usable file or backup with the credentials it requires is available, the affected accounts must be handled through their respective recovery procedures. Do not delete any app, file, or backup as part of a supposed cleanup.