Sophos Mobile: Handoff to users in the Self Service Portal
This handoff is for users of a device designated by their organization for Sophos Mobile. The Sophos Fusion Self Service Portal (SSP) is called the Sophos Central Self Service Portal in older Sophos user instructions; these names refer to the same portal route, not two separate sign-ins. The SSP and the Sophos Mobile Control app are separate interfaces: enrollment and some device-related actions start in the SSP; support contact details and messages, among other things, appear in Mobile Control. Available features depend on the device and the organization’s setup. An action being available in the portal does not authorize you to manage someone else’s device or account.
Before the handoff
Administrative preparation, not user self-service: Personal settings and setting up the technical support contact are two separate IT tasks, not settings for the user’s SSP account. The getting-started guide dated September 9, 2026 lists both in addition to SSP configuration. The procedure is in Set basic settings without changing devices:
- Configure personal settings: The responsible administrator configures the display settings for their signed-in administrator account under Setup > General > Personal and saves them with Save. The linked section explains each setting and how to check it. This does not establish a mandatory value for users or a general enrollment prerequisite.
- Configure the technical support contact: The responsible IT team enters the approved contact information under Setup > General > IT contact and saves it with Save. The linked section describes setup, limiting personal information to what is necessary, checking the details on a separately approved test device, and making corrections. Opening Support in Mobile Control later displays information already entered; it neither sets up the contact nor proves that the details have been checked on the device.
IT must tell the user which account and specific device to use, the approved enrollment route, the device model or platform, and how to reach support. Users should sign in only with their own designated account and check that the displayed device entry matches their device before taking any action. If the account, device assignment, ownership/BYOD approval, or management mode is unclear, stop here and ask IT. IT-side access prerequisite: Configure Sophos Fusion Self Service Portal access covers SSP access, invitations, and permissions. This user guide does not assign roles or portal permissions; the existing access article does not establish that this particular tenant and user have already been enabled.
Check what is approved for this account: Before enrollment, IT must confirm which SSP configuration applies to this account’s user group (the highest-priority matching configuration, or the Default configuration if none matches), the approved enrollment/ownership type (corporate or personal device), the device limit, and the platform-specific enrollment package or policy approved for this device. The Actions enabled there and the platform’s eligibility also limit later self-service options. If the approved enrollment type or a required action is missing, or the device limit has been reached, stop and ask IT; do not switch types or accounts or try a substitute action. Seeing an action in the portal is not, by itself, IT approval for this device and management mode.
Before approving a step, IT must clarify which apps, profiles, accounts, and work data are affected in the applicable management mode. In particular, Wipe, Unenroll, Remove work profile, and Delete are not part of normal initial enrollment. If a device is lost or stolen, use the internal reporting process first; locating a device can reveal personal location data and, according to Sophos, is logged by the organization. Resetting a device irreversibly deletes all data; unenrolling a fully managed Android Enterprise device resets it to factory settings. Do not trigger any of these actions as a test.
Enrollment and everyday use
- Enroll only with IT approval: If IT approved SSP-initiated enrollment, sign in with the assigned account, select Mobile > Enroll Device, and use only the enrollment type approved for your own device. Account-driven Apple User Enrollment starts in device Settings instead; follow IT’s approved platform instructions rather than trying the SSP button as a substitute. Before proceeding: If the organization’s terms of use are displayed for that enrollment type, read them and agree only if you understand and accept them for your device and its approved ownership and management mode. If anything is unclear, disputed, or unacceptable, do not click Agree; contact IT instead. Terms may not be displayed at all; this article does not replace their actual text. Then follow the instructions for your own device and any post-enrollment instructions, if shown. The specific OS and profile procedure depends on the device platform; do not apply Android, Apple, Mac, or Windows steps to a different platform. An entry for the designated device in the Mobile device view helps identify it but does not prove enrollment is complete. During the pilot, IT must define a verifiable enrollment/management status for the exact assigned device, platform, and management mode, check it after completion, and record the result. Do not assume the device is successfully managed without confirmed status. If enrollment does not complete or the status is unclear, contact support rather than trying to “fix” it by deleting or repeatedly adding a device.
- Read organization messages: A new message triggers a device notification; tapping it opens Sophos Mobile Control. On its dashboard, open Messages: received messages appear in a list and can be deleted individually. A message does not automatically constitute consent to deletion or a profile change.
- Distinguish Android app protection from device locking: Only if the organization has configured App Protection for specific apps, tap App Protection on the Sophos Mobile Control dashboard. Password-protected apps lists the apps protected by the organization. Create an App Protection password the first time you open a protected app. The user guide describes authenticating again when opening a protected app later or after the device has been locked. When authentication is required again depends on the effective policy, any grace period, and the permitted method; if approved, a fingerprint can replace the password. These instructions do not establish whether locking the device ends the grace period. Do not assume you will be prompted for a password every time you open an app. App Protection does not replace the device lock or the work profile lock. To lock the protected apps, tap Lock protected apps: this locks all such protected apps at once, not the entire device. If the organization has specified apps that must not be started, tap App Control on the Sophos Mobile Control dashboard. A list of those apps appears. According to Sophos, both features are Android-only. If a section is absent, do not assume the feature is available on another platform.
- Work email: After enrollment, access may work immediately or the organization may provide separate instructions, depending on the device and its configuration. Do not set up personal accounts or email profiles speculatively; if access is missing, ask IT for the approved email setup route.
For apps approved by the organization, use the app catalog and the appropriate installation route; for Android devices where only the work profile is managed, the separate Google Play route described there applies. Visible apps and installation options still depend on the device and the organization’s configuration; if approval is missing or the route is unclear, ask IT.
View policy violations and resolve them on the device
A notification may indicate a violation, such as an installed app prohibited by the organization. In Sophos Mobile Control, tap the top dashboard tile showing the compliance status to open the list of all violations. Beside a violation, Fix it shows the steps needed to resolve it. If the instructions are unclear or affect data, apps, or profiles, ask IT first.
Separately, you can view violations in the SSP: sign in with your own designated account, open Mobile, and select your own affected device. Beside Compliance Status, click Noncompliant. This link is available only when the device is noncompliant, and the feature is not offered for all device types. A missing link therefore does not prove compliance.
Viewing the list alone does not resolve a violation. The necessary measures, agreed with IT, must be carried out on the device. They do not authorize you to bypass protection requirements or wipe the device. IT must then check the actual compliance status; do not infer successful remediation from opening the list.
General iPhone/iPad setup with Mobile Control
The general Sophos instructions dated March 14, 2023 describe the following setup route. It applies here only if IT has approved it for the specific iPhone or iPad; it does not replace instructions for account-driven or profile-based Apple User Enrollment. The iOS version mentioned is not a promise of current OS or tenant support.
First install the Sophos Mobile Control app, then configure it on the device. The specific setup steps are in the organization’s email. If the device is enrolled through the SSP, the instructions are displayed there. An invitation to access the portal is not automatically these device setup instructions.
Install the downloaded profile in time: If this approved general setup route downloads a configuration profile, these instructions state that from iOS 12.2 onward, it must be installed in the Settings app. If it is not installed within eight minutes, the downloaded profile that has not yet been installed is deleted, and the approved setup process must be started again. This is not an instruction to wipe or unenroll the device or run Reconfigure. These general instructions do not establish an eight-minute deadline for account-driven or profile-based Apple User Enrollment. If the current management state or the route for repeating setup is unclear, ask IT before trying again.
If access or management stops working
- Forgot only the App Protection password (Android): This is not the device unlock password. Only if App Protection was previously configured and IT has approved Reset App Protection password for this account, your verified Android device, and its platform, and the exact action is available, select Mobile > your own device > Actions > Reset App Protection password > Reset in the SSP. The next time you open a protected app, you must create a new App Protection password. If the device assignment is unclear or approval or the exact action is missing, stop and contact IT; do not reset the device password instead.
- Only the Mobile Control app was accidentally removed (iPhone/iPad): This applies only while the Sophos Mobile MDM account remains on the device. Historical description, not current authorization to act: The Sophos user instructions dated October 1, 2024 describe reinstalling the app, signing in to the Sophos Central Self Service Portal, and using Mobile > your own device > Actions > Reconfigure SMC app. According to those instructions, a page with detailed instructions then appears. They give two alternatives: scan the displayed QR code with Sophos Mobile Control, or enter the displayed configuration details manually in the app. They describe the outcome as reconnecting the Mobile Control app to the Sophos Mobile server. This proves neither a current app connection nor restored device management. The September 2026 administrator list instead names Reconfigure the SMC app for an already installed app and also describes Reconfigure device as an app action. The mapping and effect of the current portal actions are therefore unresolved. Before reinstalling or selecting any action, ask IT to verify your own device, the retained MDM account, and the approved route; do not substitute Reconfigure, Reconfigure device, or a similarly named action. Do not share QR codes or configuration details. IT must verify the app connection and management status afterward. If the MDM account is gone or the route is unclear, remain with IT.
- Device management disabled or MDM account removed: Do not use Reconfigure as a self-service recovery action. The October 2024 Sophos user instructions describe Actions > Reconfigure as re-enrollment and warn that an already managed device will be unenrolled. Historical workflow description, not self-service instructions: For this workflow dated October 1, 2024, Sophos gives the next step as triggering contact from the device to the Sophos Mobile server. The instructions say it may take some time before reconfiguration starts; they do not specify a fixed waiting period. They then refer to the enrollment procedure in “Set up Sophos Mobile on your device”. Only after that enrollment process is complete do they describe the device as enrolled in Sophos Mobile again. This is a historical description of the outcome, not evidence of current management status or authorization to use Reconfigure or a similarly named action. Current IT approval and verification of the appropriate platform and management mode are still required. The September 2026 administrator list instead describes Reconfigure device as reconfiguring the Mobile Control app; it does not establish an equivalent device-management recovery. Neither a similar label nor action visibility proves its effect. IT must verify the account, your own device, platform, actual management state and mode, current action and warning, and approved enrollment route, and arrange backup and tested recovery of affected data. Unenrolling a fully managed Android Enterprise device factory-resets it and deletes data according to Sophos; other modes can also lose managed data. Do not try another action as a substitute. A device entry or a short wait is not proof of recovery; IT must confirm management status on the correct device.
Help and privacy: On the Sophos Mobile Control dashboard, tap Support to see the organization’s contact details and any additional support information it has provided. Email opens a message to the support contact; on Android, tap Phone or Mobile to call the support contact. When reporting a problem, share only the necessary account details, device model, and error message. Do not send passwords, QR codes, private content, or location data unless explicitly requested through an approved process. If the device is lost, you suspect someone else has accessed your account, or device ownership is unclear, use the IT security reporting process rather than attempting a self-service fix.