Skip to content
Avanet

Sophos Mobile Threat Defense: Create and assign policies safely

MTD policies for Sophos Intercept X for Mobile must be distinguished from installed Android/iOS device policies in the MDM edition and the separate Chrome Security policy type. Device and group selection, the Assign sequence, status checks, and support downloads are covered in the shared policy workflow. This article adds only MTD-specific preparation, synchronization, and reversal. When Sophos Mobile manages Sophos Intercept X for Mobile on Android, the organization configures the app’s settings centrally. Neither a license nor a menu item establishes MDM capabilities or an actual effect on a device.

The centrally configured settings of the managed Intercept X app are separate from the organization’s app-management actions: if the organization manages the Android device or its work area with Sophos Mobile Control, it can initiate app installation or uninstallation there. These are administrative actions by the organization, not local user settings in Intercept X. Uninstalling an app is not the same as Uninstall policy, MDM unenrollment, or removing the work profile. This capability establishes neither permission for every app on every device nor a successfully completed remote uninstallation.

Before the pilot: Edition, platform, and policy contents

  1. Check MTD entitlement, admin role, platform, and policy type in the target tenant. If you need to manage different device types, create multiple appropriate policies. This does not imply a separate policy for every device or a precedence rule for overlapping assignments. For a pilot device, record the registered Intercept X app, device ID, existing and proposed policies, and individual and group assignments. Do not assume which assignment takes precedence when they overlap, or what effect a group change will have. Check Android options in the tenant; for iPhone and iPad, consult the iOS MTD policy and, for Web Filtering, the iOS filtering limits and exceptions. This is not a cross-platform filtering guide.
  2. Under Policies > [Platform] > Create > [Policy type], enter a name and description. Inspect the Network configuration that the Threat Defense help says is added automatically and adjust it if needed. Use Add configuration to add any other required configurations; enter the required settings on each added configuration’s settings page. Once all required configurations have been added, recheck their values and select Save to create the policy. Assignment is a separate step. Network is not an established MDM Wi-Fi/network profile; MDM update and uninstall procedures do not apply here. Check the effect on the target platform separately.
  3. Placeholders used in a policy are replaced at assignment: %_EMAILADDRESS_% is the assigned user’s email address; %_USERNAME_% is that user’s Exchange Login (not necessarily their general sign-in name). %_DEVPROP()_% represents a device property; insert its name in the parentheses. You can use all properties listed on the Device properties and Custom properties tabs of the device’s Show device page. For example, %_DEVPROP(IMEI)_% is replaced by the device’s IMEI value, if available. Verify field suitability, user/device mapping, the actual value, and confidentiality in the pilot; do not guess missing values.

Stop before assigning iOS Web Filtering: The full Sophos Mobile help explicitly restricts this configuration to supervised devices. The omission of that restriction from the Threat Defense help is not authorization for device-wide filtering on unsupervised iPhones or iPads. Establish supervision, profile, filtering scope, classification-service availability, a pilot, and an independent reversal path using the iOS MTD policy and iOS filtering limits and exceptions. Do not expand deployment if the scope or reversal path is unclear; check Android prerequisites separately.

Assignment, effect, and reversal

After the specific MTD policy has been approved, use the linked shared workflow to assign it to individual pilot devices first. Add groups only after checking membership and overlapping assignments. For direct Assign, the Threat Defense help lists the platform, Select devices or Select device groups, and Finish, but no Schedule task page. Do not transfer scheduling or uninstall steps for certain installed MDM device policies to this MTD procedure. The help also mentions device and task-bundle assignments. To assign a policy as part of a task bundle, add an Assign policy task to the bundle and transfer the bundle to the intended devices or device groups. Check the edition, platform, available task types, and target set first; the same pilot and reversal limits apply here. Creation, ordering, scheduling, and troubleshooting are covered in the separate task-bundle lifecycle. This documented assignment method establishes neither a bundle transfer tested here nor the policy’s effect on the target devices.

Sophos describes MTD policies as taking effect when assigned and synchronizing every time a device connects to Sophos Mobile; policy changes do not require a manual Update devices action. “Immediately” does not establish delivery to an offline device or an effective protection state. On each pilot device, after it connects, check the assignment, app/profile state, affected function, and normal app/network use with approved, low-risk tests. Expand deployment only after the effect is demonstrated and the reversal path has been checked.

If the MTD effect is missing or fails, stop further assignments and narrow down the cause in order:

  1. Target and assignment: In Policies > [Platform], compare the policy type and saved values with the pilot plan. Under My Environment > Mobile Devices > [Device] > Policies, check the assignment and its status; if this view does not show the policy type, use Open in Sophos Mobile in the device details. Compare the device ID, individual or group assignment path, and current group membership. If the intended assignment is absent, do not assume the function itself has failed.
  2. Connectivity: In the device details, check Last Intercept X for Mobile sync and the observed app synchronization; Last active alone does not establish an Intercept X connection. Do not claim delivery while a connection is pending; after the next connection, recheck status and effect. If synchronization does not occur, keep expansion on hold and escalate.
  3. Prerequisites and conflicts: Compare the edition, license, role, platform, registered Intercept X app, and required profile state on the pilot device. For iOS filtering failures, consult the linked iOS owners rather than making a blanket filter change. Check for overlapping individual and group assignments; do not guess their precedence. Only after assignment, connectivity, and prerequisites are understood should an approved, low-risk functional test establish whether the function actually fails.

Reversal if a discrepancy is confirmed: Identify affected devices and compare them with their previous state. For MTD, Sophos specifies changing the policy or assigning another policy, not Uninstall policy for MDM device profiles. Do not change a shared policy or group wholesale while scope and precedence remain unclear. For pilot devices unambiguously assigned individually, assign the previously checked alternative specifically to them or correct their pilot policy. After they reconnect, check both the policy and the function on every affected device. If synchronization does not occur or business-critical connectivity is disrupted, do not report the reversal as successful; escalate instead.

Treat new API policies and support exports separately

The Sophos Mobile service release 2026.38 of September 21, 2026 automatically adds configurations with recommended settings when new MTD policies are created through the Mobile API. Existing policies are not changed by this. The release statement specifies neither the actual values nor any change to manual Create defaults, the client version, permissions, or automatic assignment. Before piloting an API-created policy, inspect its actual platform, every generated configuration, and their values in the target tenant. Do not equate the Network configuration automatically added in the older UI instructions, or other UI defaults, with the new API defaults.

An MTD policy download can provide settings to Sophos Support. Selection, file inspection, and protected transfer are described in the support download section of the shared policy workflow. In the target tenant, check the edition, type, platform, permissions, and recipient; inspect the file for confidential values and securely remove copies after authorization. The same UI steps do not establish identical MDM and MTD export contents. A download is neither proof of assignment or synchronization nor an established backup, import, or rollback path.

Not operationally tested: No tenant, device, API, or support-transfer tests were performed for this article; it demonstrates neither a successful pilot nor an effective assignment or reversal. Before actual execution, obtain explicit approval and check the edition, permissions, admin role, policy type, platform, registered Intercept X app, and required profile state in the target tenant. Establish which devices are targeted, their individual and group assignments, and how overlapping assignments behave; for iOS Web Filtering, also establish supervision, filtering scope, and classification-service availability. For API-created policies, check the configurations and values actually generated. Initially, limit assignment to individual approved pilot devices; expand deployment only after observing the effect and testing an independently reachable reversal path. Before a support transfer, check the export contents and confidential values, confirm the authorized recipient, and establish how to protect the transfer and securely remove copies.