Sophos Mobile: Safely manage user assignment and offboarding
Changing a device’s user assignment is not the same as deleting a Sophos Fusion user or removing the device from Sophos Mobile. For a routine handover, first check the individual device and, where its enrollment mode allows it, use Reassign user to device. For deletion of an assigned user, however, the Sophos Mobile help describes the tenant-wide setting Setup > Sophos setup > User setup > Device assignment as governing the Mobile devices assigned to that user. Read this setting before deleting any user; do not assume a default value. At the same time, the general Fusion help on user deletion says that associated devices and installed Sophos software are not deleted as a result. Do not extend either documentation scope to all Fusion devices or treat the conflict as resolved for a specific tenant.
Stop before Delete: The following choices concern the Sophos Mobile setting when an assigned user is deleted, not the separate Delete button on a Fusion Mobile device. Unassign user from device removes only the assignment and does not change the device status. Unenroll device ends Sophos Mobile management. Delete device deletes the Mobile device record; the full Sophos Mobile edition’s help says a device that is still enrolled will unenroll at the next sync, except enrolled Windows computers. The Mobile Threat Defense help does not mention this Windows exception; its omission is not evidence that Windows automatically unenrolls in that mode. Before any Windows device action, check both Forbid manual MDM unenrollment and Forbid resetting the computer in the effective policy; if neither an authorized unenrollment nor an approved recovery route is available, stop and escalate. Deleting a fully managed Android Enterprise device can factory-reset it: first check backups and valid, legitimately available credentials for the Google accounts configured for Factory Reset Protection (FRP); unknown or invalid credentials can leave the device unusable. The separate Fusion Mobile Devices > Delete help describes deletion of a still-enrolled Mobile device and unenrollment at its next sync (except Windows); its numbered UI path filters to Not managed devices, so it does not establish that this path can select a managed device. The device detail page under My Environment > Mobile Devices already warns: Unenroll the device from Sophos Mobile before Delete, or it may become unusable. The described unenrollment at the next sync does not override this warning. The separate Fusion Computers and servers > Delete route also requires prior unenrollment of enrolled Mobile devices and warns of the same risk. Neither route is a safe shortcut. Do not treat any of these actions as a harmless change of owner or a guarantee that sync will complete.
Preliminary checks: Which device and identity are affected?
Authorize the actor and role before making UI changes: Have a Sophos Mobile Administrator authorized for the task change the Mobile Device assignment setting or edit a Mobile device assignment; the Fusion Super Admin and Admin roles are mapped to this Mobile role. In the predefined Mobile role mapping, Help Desk cannot define settings or edit or delete devices, and Read-only cannot make changes. Fusion custom roles can have different effective permissions: verify the actual tenant role and access before each step; this does not waive the authorized Administrator preflight or least-privilege approval. Separately, only an Admin or Super Admin may delete a Fusion user; only a Super Admin may delete administrators, and nobody may delete their own account. Before deleting an administrator, ensure an authorized successor and adequate remaining Super Admin coverage; otherwise stop and escalate. Use only the role and approval required for each step; do not substitute another deletion route for a missing button.
- In Sophos Fusion, find affected devices under My Environment > Mobile Devices. In Sophos Mobile, use Devices > Show device to record, for each device, its user assignment, only the device identifier available there, ownership type, platform, management type and status, and last contact. Management information appears under Status on the device detail page. Apple User Enrollment (BYOD): Sophos Mobile receives no UDID, IMEI, or MAC address and identifies the device using an identifier newly generated for each enrollment. Do not ask the user for the personal device’s hardware identifiers or personal app data or collect them for the ticket; do not use an old identifier as a permanent device match after re-enrollment. Include only values actually displayed and necessary for the approved purpose in the change record. An old sync timestamp is not evidence that unenrollment has already taken effect.
- Under People in Sophos Mobile, check whether the person has other devices. In the full Sophos Mobile edition, this page also shows users with Apple Business app assignments; in Mobile Threat Defense it shows device users. In the full edition, identify any Apple Business user-based app assignments and hand them off for a separate entitlement and business-data review before user deletion; the Device assignment setting does not establish their deletion outcome or release app licenses. Manage the identity and groups under My Environment > Users & Groups in Sophos Fusion, not by deleting the People entry as if it were a separate Mobile-only case.
- Define the intended end state: Will the device remain managed while only the person changes? Will it remain managed without an assigned user? Or is explicitly approved device offboarding with protected data required? For personal devices, establish in particular whether an Android work profile may be removed; for Apple User Enrollment, arrange any required backup of business data on the managed volume before unenrollment, separately from personal data. Before any destructive choice, agree on ownership, backups, retention, and required evidence; for Android Enterprise Fully Managed, also verify FRP accounts and legitimately available credentials before deletion or reset. Unknown or invalid FRP credentials mean stop and escalate, not delete on the assumption that access will work.
- Open Setup > Sophos setup > User setup and document the currently saved value under Device assignment. This setting controls what happens to assigned devices when a user is deleted; it is not the control for changing an individual device assignment. Before changing it, assess its scope for every user it might subsequently affect.
Filter by management status: On Devices in Sophos Mobile, use the advanced filter and select the required status from the Managed dropdown under Management properties, for example Unenrolled for previously managed devices that have been unenrolled. This is a non-destructive list filter, not the Unenroll device action or the separate Fusion Not managed filter in the device-deletion route. Merely highlighting a dropdown option proves neither that a filter is active nor that unenrollment has occurred; continue to verify the affected device’s actual status in its detail view and after contact.
Licensing boundary for unassigned devices: According to Sophos, each user assigned to a managed device counts as one Mobile license, even if assigned multiple devices; each device without an assigned user counts as one Mobile license itself. Only devices that have synchronized with Sophos Mobile in the past 30 days enter the usage calculation. Unassign therefore does not guarantee a license saving; after reassignment or user deletion, check the actual count in the authorized Fusion license view without assuming immediate release or a particular entitlement. License products and administration remain a separate process.
Assign, reassign, or unassign an individual device
For an eligible device, open Devices in Sophos Mobile, select the arrow next to the affected device, and open Edit. Next to User, click Edit user assignment. For a device without a user, both the full Sophos Mobile help and the Mobile Threat Defense help document Assign user to device: under Enter user search parameters, search for the target identity using Search all fields. Matches are found only when the search text starts at the beginning of a field—for example, as a prefix of a name or email address—not when it appears in the middle of a field. Choose the user on Select user, click Apply, then click Save on Edit device. Use Refresh user details only to reload the LDAP user list if needed. For a device that is already assigned, use Reassign user to device instead, then select the approved new user. Confirm the documented change or removal through Reassign user to device or Unassign user from device with Yes, and finish with Save on Edit device. Yes is not part of the initial assignment flow described above. Then reopen the device and check the displayed assignment.
Limit: With Android Enterprise and Apple User Enrollment, the assigned user is fixed for the duration of the existing enrollment; the assignment cannot be changed by this route. Do not initiate Unenroll, Wipe, or Delete on your own as a substitute. Unenrolling Android Enterprise Fully Managed requires a factory reset; unenrolling Android Enterprise Work Profile removes the work profile, including its apps and data. A handover involving re-enrollment therefore requires a separate migration decision and backup agreed with the device owner. The Mobile Threat Defense help describes individual assignment without these two full-edition restrictions; that is not permission to bypass a restriction on a device enrolled in another mode.
Assignment alone does not determine all future enrollment rights. User groups control access to the Sophos Fusion Self Service Portal and the available enrollment options. Before handover or offboarding, separately check group membership and the portal configuration effective for the new or departing user; do not confuse an existing enrollment with permission to enroll again. With Apple Business, Google Zero-touch, and Samsung KME, enrollment may also depend on user authentication against the connected directory. Changing a device assignment does not replace that identity check.
User deletion: Deliberately choose the tenant-wide consequence
Under Setup > Sophos setup > User setup > Device assignment, the Sophos Mobile help documents three choices for Sophos Mobile devices assigned to the deleted user. The effect depends on the tenant’s saved value and, for device actions, on edition, platform, enrollment mode, and contact/sync; this is not a statement about every other device associated with a user in Fusion or about installed Sophos software. In contrast, the general Fusion help says that deleting a user does not delete associated devices. These documents do not establish the exact user-deletion trigger or its Mobile effect for a particular tenant. Treat that outcome as unknown without authoritative clarification or a specifically authorized tenant observation; a test is not a prerequisite for using this documentary decision aid. Save stores the choice; choosing it does not itself delete a user:
- Unassign user from device: Removes the user assignment and leaves the device status unchanged. If the device remains managed, designate a responsible owner and separately verify the new assignment where possible. “Status unchanged” is not evidence that access, local data, or sessions have been removed.
- Unenroll device: Unenrolls the device from Sophos Mobile; its status becomes Unenrolled. Consequences depend on platform and management mode: for example, on iPhone/iPad, MDM policies, managed apps, and MDM certificates are removed. With Apple User Enrollment, the managed Apple Account and its associated data are removed from the device and the managed APFS volume is deleted: managed apps and app data, the managed keychain, the managed account’s iCloud data, and its mail, calendar, and notes data. Before unenrollment, decide on authorized export and retention of this business data and complete any required backup; do not equate personal data on the system APFS volume or personal apps with the managed data or portray them as deleted. Do not try to work around the user fixed during enrollment by reassigning the device. With Android Enterprise, unenrollment can delete data or require a factory reset. This is not a generally harmless way back.
- Delete device: For this choice on deletion of the assigned user, the Mobile help describes removing the device from Sophos Mobile. According to the full Sophos Mobile edition’s help, a still-enrolled device unenrolls only at the next sync; this does not apply to enrolled Windows computers: they must be manually unenrolled or, if Forbid manual MDM unenrollment is active, Sophos documents a factory reset as the alternative. The Mobile Threat Defense help does not mention this Windows exception; that omission does not authorize assuming automatic Windows unenrollment in another management mode. Before any action check both that restriction and Forbid resetting the computer in the effective Windows policy, plus an approved recovery route; if a permitted, approved path is unavailable, stop and escalate rather than assume a reset can be performed. Windows Pro: According to Sophos, the Windows Restrictions policy configuration containing these two restrictions does not apply there; the exception to automatic Windows unenrollment at the next sync remains. Do not infer from a configured restriction either that it is effective or that a particular device has an authorized unenrollment or reset route; verify the edition and actual policy effect. Do not treat the next sync as a guaranteed completion. Deleting a fully managed Android Enterprise device resets it to factory settings; check backups and FRP account access first, or stop. This Mobile setting is not the separate Fusion Mobile-device Delete: its help describes still-enrolled device deletion with next-sync unenrollment except Windows, while its numbered path filters to Not managed devices and does not prove managed devices are selectable. For Fusion Mobile Devices > Delete, the device detail page also warns: Unenroll from Sophos Mobile before deleting, or the device may become unusable. The described unenrollment at the next sync does not override this warning. The separate Fusion Computers and servers > Delete route likewise requires prior unenrollment of enrolled Mobile devices and warns of the same risk. Neither route guarantees safe completion, especially for offline devices; apply the Android reset/FRP and Windows restrictions above before any separately approved action. After a separately approved device action, verify its actual effect. Do not assume restoration of the deleted Mobile entry is a rollback path.
Operational recommendation: For a planned handover, first complete and verify the individual device change instead of temporarily switching the tenant-wide deletion setting for one person. If a user really must be deleted, first check the possible consequence of the saved value for all their assigned Mobile devices, along with platform, ownership, backup, and reachability. Before deleting the Fusion user, check the identity source and block or remove access at the authoritative directory source as part of separately approved Fusion offboarding: Sophos Fusion can recreate a user still present in the directory at the next Directory Sync or after sign-in on an associated device that remains managed. Deleting the Fusion entry therefore does not establish that sign-in or enrollment permission has been revoked. If an enrollment mode cannot be handed over safely, or if the unknown user-deletion trigger or consequence could materially affect a device or its data, stop before deleting the user; obtain authoritative clarification or a specifically authorized tenant observation and separately approve the device process. Do not use a deletion to find out what happens. Safely delete and offboard Sophos Fusion users covers identity deletion and other Fusion product consequences; the Mobile setting does not replace that process. Documentary boundary: Do not claim that a specific Fusion user deletion triggers any particular Mobile device action in the target tenant without authoritative clarification or a specifically authorized tenant observation. This decision aid is documentary guidance, not a tenant-specific outcome or a mandate to test every tenant.
Verification, audit, and limited rollback
After a non-destructive individual change, reread the device details under My Environment > Mobile Devices or Devices > Show device: Does User match the approved target, and are management mode and status still as expected? For a deliberately unenrolled device, check Unenrolled and its condition after contact; for deletion, also account for the pending next sync. A missing assignment or vanished record does not by itself prove local data was erased or unenrollment completed successfully. For pending or failed device tasks, check the specific status or error under Tasks in Sophos Mobile and under Tasks on the device, but do not assume a specific task or event name for a mere assignment change.
For evidence in the change ticket, record only the console-available device identifier required for the authorized business purpose, previous and new user, management mode, previous and subsequent status, time, administrator, and approval; for Apple User Enrollment, do not request private hardware identifiers or personal app data. Restrict the ticket and any audit exports to authorized people and the defined retention process. In Sophos Fusion, check available logged changes by date range under Reports > General logs > Audit Logs; where useful, search by IP address or Modified By (the acting administrator), then inspect Item modified and Description for the affected subject; do not assume a target-user search exists. Export only if needed. Fusion audit shows only monitored activities, not necessarily the actual device condition or a guaranteed specific event name for every Mobile assignment. By default, seven days are visible, and the retrievable period extends up to 90 days; preserve evidence in time under your retention process.
If only a changeable assignment was altered accidentally, use the same route via Devices > Edit > User, select the documented previous user again, then click Save and check the device details. A changed tenant-wide Device assignment option can be restored to the documented prior value and saved; this does not reverse unenrollments, device deletions, or factory resets already triggered by user deletion. In case of deletion or data loss, stop further actions and handle recovery or re-enrollment as a separately approved case. Without a tenant test, the actual effect in your own environment remains unconfirmed.