Enroll and verify Windows computers with Sophos Mobile
Quick path: Enroll only after approval for the specific Windows computer and the correct Sophos Mobile tenant. In Sophos Mobile, an administrator can use Devices > Add > Add device wizard to create the device, choose Enroll device without a policy for Windows or Enroll device with task bundle using a Windows bundle containing Enroll, and pass on the organization-specific instructions from the wizard or the email sent to the designated address. Alternatively, an authorized person can use the organization’s configured Sophos Fusion Self Service Portal path and follow the instructions shown there. Only a verified MDM connection on the Windows device and the corresponding device status in Sophos Mobile count as a result—not an email or a created device record.
Scope: This is Sophos Mobile MDM for Windows computers, not Sophos Endpoint Protection, Sophos Intercept X for Mobile, or the former Windows Mobile for phones. Sophos ended support for Windows Mobile on December 31, 2019, and announced the removal of remaining enrollment functions in November 2024. Your organization provides the actual enrollment steps by email or in the Self Service Portal. This is not a universal download, generally applicable installer, or single Windows click path. Windows computers use the operating system’s native MDM client. The term “device management agent” therefore does not mean that a separate Sophos Mobile EXE must be installed.
Before the invitation: clarify support and consequences
- License and platform: Verify entitlement to Sophos Mobile Device Management or Sophos Mobile with MDM in the tenant actually in use; a Mobile Threat Defense-only entitlement is not Windows MDM. Sophos lists Windows 11 Pro, Education, and Enterprise and Windows 10 Pro, Education, and Enterprise from 20H2 onward for the native Windows MDM client in its release notes; Home is not listed. For a new pilot, first choose a currently serviced Windows 11 version in one of those editions. This Sophos list is not a promise that every Windows version still receives Microsoft updates, every policy takes effect, or a device already managed elsewhere can be enrolled. Identify the pilot device’s edition and version with
winverand compare them with the Sophos platform list above. Immediately before approval, open the row for that exact version and edition in Microsoft’s Windows release information and compare the end-of-servicing date with the planned period of use. If servicing has ended, no matching entry is found, or the update path is unclear, stop and have IT clarify support; for Windows 10, also perform the ESU/LTSC checks below. - Special case: Windows 10: Regular Microsoft support for Windows 10 version 22H2 ended on October 14, 2025. For an existing Windows 10 device, first check its exact edition and version and evidence of an active update path: Microsoft’s ESU program requires 22H2 for regular Windows 10 and eligible, activated participation; LTSC/LTSB have separate edition- and version-specific lifecycles and are not thereby approved by Sophos. Neither Sophos’s minimum “20H2” nor ESU eligibility alone proves current security updates or compatibility with every Sophos policy. Do not enroll a new device without a viable update path. Windows 11 support also depends on the specific version and edition.
- Management scope and responsibility: Sophos Mobile lists only Device mode for Windows—neither an Android work profile nor Apple User Enrollment. Owner: Personal in the wizard or portal is an ownership designation, not a technically isolated BYOD profile. Before enrolling a personal computer, clarify the management scope, consent, privacy, and an authorized offboarding path with the responsible IT team; do not enroll if ownership is unclear. On the pilot device, inspect existing work/school accounts and MDM connections under Windows Settings > Accounts > Access work or school; also identify domain/Entra management, reachability, device group, user assignment, and the intended Windows policy. Do not disconnect an existing connection on a hunch or assume a second MDM management system is compatible. Do not use a Windows standard account or the built-in Administrator account for enrollment: standard accounts and the built-in Administrator account are excluded from MDM enrollment. Agree with IT on an authorized administrator account for the approved process.
- Exit path: Before enrollment, ensure access to an authorized local administrator account and an independent network, a backup, and, if BitLocker is active, the recovery process valid for this device. If Windows restrictions are planned, check Forbid manual MDM unenrollment and Forbid resetting the computer against the approved offboarding procedure beforehand. The Restrictions configuration does not apply to Windows Pro; do not assume these restrictions work on Pro. Do not deploy an untested lockout, kiosk, network, or password policy in an initial trial. For entitlements and editions, see Sophos Mobile licensing; for a later Wi-Fi/certificate pilot, see the separate Windows guide.
Enroll exactly one approved computer
- Administrator path: In Sophos Mobile, open Devices > Add > Add device wizard. Select the intended user, or choose Skip user assignment for a deliberately userless pilot. On Device details, check the Windows platform, a unique device name (for example,
WIN-PILOT-01, a locally selectable name), Email address for the instructions, Owner, and Device group against the authorization. For an assigned user, Sophos says the email address comes from user management in Sophos Fusion; if it is missing or wrong, resolve the assignment before sending. For an enrollment-only test, choose Enroll device without a policy. Choose Enroll device with task bundle only after reviewing the Windows bundle: it must contain an Enroll task; additional policy or app tasks may take effect immediately after enrollment. Follow the steps displayed on Enrollment and give the intended recipient the device-specific email. An enrollment task running in the background is not completed enrollment. - Alternative portal path: The administrator checks the prioritized configuration for the user group under Setup > Self Service Portal, Maximum number of devices, and, for the Windows platform, the displayed type, Owner, Device group, and Windows Enrollment package (a policy here, not the administrator’s task bundle). Only if this path is approved should the authorized person sign in to the Sophos Fusion Self Service Portal with their own designated account, open Mobile > Enroll Device, select the offered Windows type, and follow the organization-specific instructions shown there. The Self Service Portal user handoff explains the prior account and device assignment and the limits of self-service. If Windows is missing or the displayed owner or organization is wrong, stop; do not choose another platform type. Have a separate test user check the SSP configuration before inviting users broadly.
- Compare device and tenant: After completing the steps, open Windows Settings > Accounts > Access work or school, select the correct organization connection, and check the MDM connection details under Info. According to Microsoft, Info is available for MDM connections; merely having a connected work account does not prove MDM enrollment. If necessary, initiate Sync there and then check the result in the tenant—Connect is not a substitute for the Sophos invitation, especially if Entra auto-enrollment could lead to another MDM instance. In Sophos Mobile under Devices, hover over the computer’s Managed icon, then open the computer: on Status, management status must be Managed, not Not managed or Enrolling; compare the user, owner, device group, and last synchronization. Check Tasks for failed or pending tasks and Policies for the intended assignment. If a policy was planned, separately verify its actual effect on the pilot device. If the bundle includes apps, check their installation on the device too; Sophos may report a task as successful even when certain paid Windows Store apps cannot be installed. A device entry, delivered email, completed wizard, or Sophos endpoint agent alone does not prove successful MDM enrollment.
If results differ: Do not initiate a second enrollment, a different policy, or a factory reset on a hunch. First check the recipient/invitation, tenant, license, SSP group priority and device limit, Windows edition/version, permissions of the Windows account used, existing MDM management, and network. In Sophos Mobile, inspect the details and error code of a failed task under Tasks; if needed, export MDM diagnostic logs for IT via Windows Settings > Accounts > Access work or school > Export your management logs. Coordinate any retry with the Mobile administrator only after the current state has been clarified. Do not approve a rollout without confirmed device MDM status.
Do not confuse unenrollment with deletion
Deleting a still-enrolled Windows computer from Sophos Mobile does not automatically unenroll it at the next sync. Subsequent offboarding must be verified as a separate, approved operation on the device and in the tenant. For non-Android devices, Devices > select device > Actions > Unenroll is available as an administrator action. On Windows, manual unenrollment after deletion is a separate operation; if Forbid manual MDM unenrollment is effective, a factory reset may be required. Do not infer that the administrator action reliably bypasses an active Windows restriction; verify the actual available exit path with IT before the pilot. A factory reset is not a recommendation: it deletes data and may be blocked in Settings and Windows RE by Forbid resetting the computer. Before any removal, check backups, policies, certificates, network, BitLocker recovery, and physical access with the responsible device owner. Windows policy and kiosk limitations are a separate task. No tenant or device test of this enrollment procedure was performed for this draft; it is not approval for fleet enrollment or offboarding.