Skip to content
Avanet

Deploy and remove apps with Sophos Mobile

Sophos Mobile lets you add apps to a catalog for supported devices, make them available to device groups, or install them on selected devices. A catalog entry, an app group, and an app actually installed on a device are different things. Before creating a task, check the device platform, management mode, app source, and permissions. This workflow covers the shared steps; approval in managed Google Play, Apple Business content tokens, licenses, and license assignment are separate platform-specific tasks.

Operational limit: Vendor documentation explains how to use the controls, not whether a task will succeed in your tenant. Before a production task, check licenses and roles, platform and OS versions, management mode, effects on data, and the outcome of removal on an authorized pilot device. Do not distribute or uninstall broadly without a verified package source, a backup of business data, and a documented recovery path.

Before deployment: decide on the source, targets, and recovery path

  • Source: An app-store link, an approved enterprise package, or a platform entry already configured. Use a trusted source and verify the package version and identifier. For an in-house iOS/iPadOS app distributed as an IPA, create an app-specific provisioning profile before deployment and make sure it is already installed on the target devices or included in the IPA. For Windows MSI links, the correct ProductCode GUID and matching SHA-256 file hash are essential: an incorrect GUID prevents uninstallation through Sophos Mobile, while an incorrect hash prevents installation. Keep the approved package and its verification details for redeployment.
  • Targets: Individual devices or device groups whose membership and management modes you have checked in advance. A change to a device group can affect more devices than the pilot. For personally used devices, establish beforehand what remains private and which managed data could be lost when the app is removed.
  • Version and recovery path: Before installing or updating, record both the intended version and the version actually installed on the pilot device, along with the configuration, assignment, and affected work data. Determine who initiates updates for the platform and assignment mode, and agree on how to restore the package, settings, and data before making a wider change. Neither a catalog version nor a successful task proves which version is installed or that an update succeeded; do not assume automatic version pinning or rollback. Removing a catalog entry, withdrawing an assignment, and uninstalling an app are different actions. Reinstallation does not automatically restore configuration or data.

Management-mode boundaries: The general Add app, Install, and Uninstall procedures below do not replace the separate procedures for managed Google Play apps on Android Enterprise. Install and Uninstall are also available under Apps > Android for those apps, but the Play-specific workflow differs: installation sends a request to Google and does not have the Now/Date step described here; a Play uninstall task, by contrast, may offer Now or Date. For Android devices managed under the older Device Administrator mode, the app view has Android (Legacy). With Apple User Enrollment, this installation route can install only Apple Business apps. App-store approvals and license allocation are outside this workflow.

Who handles what before you begin: Approval, Play installation, updates, and removal on Android Enterprise belong to the separate managed Google Play workflow; Sophos Mobile does not initiate updates for these apps, and users update them through Google Play. Apple Business content tokens, license inventory, and user/device assignment belong to the Apple Business app workflow, not general installation. Do not confuse the content token with the ADE service token. Use the separate workflow for policy assignment and the task bundle lifecycle for task bundles. For devices with only a managed Android work profile, use the user procedure for work apps below. An app task does not replace platform-specific prerequisites or their verification in your own tenant.

Add an app and make it available to users

  1. In Sophos Mobile, open Apps and select the appropriate platform. Use Add app to choose a supported store link or the intended package, enter the app settings, and save: an Android link for the older Device Administrator management mode, an iOS link or enterprise IPA, a macOS PKG, or a Windows MSI or Microsoft Store link. For Android Enterprise, use managed Google Play approval instead of this Add app route. Import Apple Business apps through Import VPP apps rather than treating an ordinary store link as a substitute for licensing.
  2. Check the name, version, and internal identifier against the intended app. For imported Apple Business apps for iOS/iPadOS and macOS, Name, Version, App ID and Link are read-only. You can check the details, but cannot edit them in these fields. On Android, the package identifier appears after id= in the Google Play link; on iPhone and iPad, use the bundle ID (the App ID field in the Sophos Mobile App Store search dialog); on ChromeOS, use the identifier at the end of the Chrome Web Store URL. For a Windows MSI, use the ProductCode GUID without surrounding braces; for Microsoft Store apps, use the Package Family Name (PFN). You can check the PFN with Get-AppxPackage on a Windows test device and the MSI hash with Get-FileHash. For a macOS PKG containing multiple apps, Sophos Mobile may show details for only one of them. The catalog version does not prove which version is running on a given device.
  3. If users should install the app themselves, set Available to device groups only for the intended groups. The app then appears in the Enterprise App Store in the Sophos Mobile Control app. After enrollment, users open Apps on the Dashboard of the Sophos Mobile Control app, tap the app they want, and follow the installation steps; depending on the device, the organization can also install apps without confirmation. For Android devices with only a managed work profile, use the user procedure for work apps instead.
  4. Test the app on a pilot device first: check that it is the right app and that configuration, network access, and any required user interaction work. For an in-house IPA, also check the signature, the appropriate provisioning profile, and actual installation on an authorized target device. Only then expand the group scope.

Install work apps yourself in an Android work profile

This user procedure applies to Android devices on which Sophos Mobile manages only the work profile. If the organization has approved apps for the device, users install them through the Google Play Store in the work profile, not through Apps in Sophos Mobile Control or the personal Play Store:

  1. On the device, open the Google Play Store with the briefcase icon in the work profile.
  2. Find the work app you want in the Store and open its app page.
  3. Tap Install on the app page and follow the installation steps.

The organization can also install or uninstall apps within the work profile without user confirmation. This does not affect personal apps or override the uninstall policy restrictions described below. Tapping Install alone does not prove installation is complete; the existing pilot-device checks are still required.

Catalog fields for Android (Legacy) and iPhone/iPad

The following details belong to the app catalog, not App groups > Custom. On Android, they apply to the older Device Administrator management mode; Android Enterprise uses its own settings for managed Google Play apps.

  • Android link: Link contains the app’s URL in Google Play. Go to Google Play opens a new browser tab. Open the intended app’s page there, copy the URL from the address bar, and paste it into Link. Then use Get data to retrieve the internal App ID from Google Play.
  • iPhone/iPad link: Link contains the App Store URL. The Search in App Store procedure described below fills in App ID, App category, and Link. Alternatively, select Obtain link, search for the app on the App Store Marketing Tools website, and copy the value under Content Link into Link. Sophos Mobile retrieves App ID from the App Store or, for a package, from the IPA file; management status is covered separately below.
  • Version: On both platforms, this field is the version displayed in the Enterprise App Store. Android takes it from Google Play; iPhone/iPad app links use the version from the App Store. This still does not prove which version is installed on a device.
  • App category names the section in which the offered app appears in the Enterprise App Store. For example, Productivity is a category name you can choose, not a required value. Description is the description text displayed there. You can place the %_appstoretext_% placeholder anywhere in this text; in the Enterprise App Store, it is replaced with the current app description from Google Play or, for iPhone/iPad, from the App Store.

For Android (Legacy) and iPhone/iPad, click Show beside Available to device groups and select one or more intended groups. This makes the app visible in the Enterprise App Store for user-initiated installation; it is not an installation task. The read-only fields of imported Apple Business apps remain unchanged.

Upload an IPA: For an iPhone/iPad app package, select Upload a file, choose the approved IPA file, and upload it with Open. Alternatively, drag the file from File Explorer into the Upload a file area. Signature and provisioning-profile checks are still required before deployment.

Samsung Knox exception: On Samsung Knox devices, Install in Knox container installs the app inside the Knox container. This setting is available only if a Samsung Knox license has been configured. Do not equate this documented legacy option with an Android Enterprise work profile or infer that it is approved for any current Samsung device. Check suitability and the actual installation location on a pilot device before creating a task.

macOS catalog fields and PKG upload

For a PKG package, Sophos Mobile reads Name, Version, and App ID from the PKG file. To upload it, select Upload a file, choose the approved PKG, and click Open. If the package contains multiple apps, only the name, version, and identifier of one app are displayed; this does not mean that only that app is installed.

The macOS settings also describe Version as the App Store version and Link as the App Store URL. However, this does not establish an ordinary macOS Store link as an installation route currently selectable through Add app: the routes described here remain PKG and the separate Apple Business import. For imported Apple Business apps, the fields listed above are read-only; license assignment through VPP licenses > Show belongs to the Apple Business app workflow and is device-based on macOS.

App category is a category name, such as Productivity, and Description is an app description. Neither value is currently used on macOS. Do not extend the Enterprise App Store sections or description substitution for Android and iPhone/iPad to macOS.

Find app identifiers and Windows package values

On Edit Windows app, Name is the app name and Version is the app version; for app links, Sophos Mobile takes the version from the Microsoft Store. App category contains a category name, such as Productivity, and Description contains a description of the app. This does not imply a Store-section or assignment effect like the one documented here for Android and iPhone/iPad. For an MSI link, Link is the URL of the approved MSI file; ProductCode GUID and SHA-256 file hash must match that exact package.

Windows MSI installation options: When adding an MSI link, Installation options contains the command-line options for the msiexec.exe installer. The default option /quiet installs the app without user interaction. Check this execution option separately from the ProductCode GUID, package link and file hash; it is not a substitute for correct values in those fields.

Add a Microsoft Store entry: In the catalog settings for a Microsoft Store link, use Go to Microsoft Store to open the Store in a new browser tab and navigate to the intended app’s page. Copy its URL from the address bar and paste it into Link, then use Get Store ID to populate Store ID automatically. Store ID identifies the Microsoft Store entry, while Package Family Name (PFN) identifies the app’s package family; ProductCode GUID, by contrast, belongs to an MSI file. These identifiers are not interchangeable. To check the PFN, use the procedure described below.

Select a Store offer using SKU ID: SKU ID identifies the offer variant (stock-keeping unit) in the Microsoft Store catalog. Full versions, trial versions and offers for different market regions may have different SKU IDs. Check the appropriate variant of the intended app; use the default value 0010 specified by Sophos only if its SKU ID is unknown. This value does not confer a licence entitlement or override the restrictions described below concerning free apps, trial periods and system requirements.

Look up an Android identifier in a browser: To find the identifier for the intended Android app, open Google Play in a web browser, search for the app, and click the matching app result. Only after opening its app page should you check the URL in the address bar: the package identifier appears after id=. Searching alone does not give you the URL of the specific app entry. Before copying the identifier, check that the selected entry and its identifier match the intended app; if you selected the wrong result, return to the results and open the correct app. This finds the identifier but does not approve the app in managed Google Play or install it in the work profile. Link requires the full app-page URL; a manual identifier lookup needs only the package name. The catalog fields described above and the edition-specific Identifier input explained below remain separate.

Look up an iPhone/iPad identifier: Under Apps > iOS & iPadOS > Add app > iOS link, click Search in App Store. Enter the app name, select Search, and choose the matching result. Sophos Mobile fills the fields with the app details from the App Store; App ID contains the bundle ID. This is an identifier lookup, not a substitute for Apple Business licenses or their assignment.

Look up a ChromeOS identifier: Open the Chrome Web Store in a browser, search for the app or extension you want, and open its details page from the results. The identifier is the last part of the URL in the address bar; copy only this identifier into the group entry.

Look up a Windows PFN: For the identifier lookup described by Sophos, first install the intended app from the Microsoft Store on a Windows 10 or Windows 11 test device. This defines the scope of the lookup, not the operating system’s current support status. Then open Windows PowerShell and run the read-only command Get-AppxPackage <app_name>. Replace <app_name> with the package name, not the PFN. If you do not know the package name, use a known part of the name with the wildcard *, for example:

Get-AppxPackage *onenote

*onenote is only a search example; replace it with part of your own app’s name. If there are multiple results, identify the correct app entry first. From its output, copy the value beside PackageFamilyName, not PackageFullName. The query returns details of the locally installed app, not the inventory of all managed devices.

Find the SHA-256 hash of an MSI file: On the Windows test device, run Get-FileHash <Path-to-MSI-file> in PowerShell; replace <Path-to-MSI-file> with the path to the approved MSI package. A path containing spaces must be enclosed in quotation marks, for example:

Get-FileHash "C:\Freigegebene Pakete\Unternehmensapp.msi"

Replace the example path with your own package path. The query reads the file without changing it. In the output, check that Algorithm is SHA256 and copy the Hash value for this exact file; do not confuse the hash with an app identifier or the ProductCode GUID.

Find the ProductCode of an MSI file: On a Windows test device, open the approved MSI package with Microsoft Orca from the Windows SDK components for Windows Installer developers. In the Property table, find the ProductCode row and copy the entry from Value; omit the surrounding braces for Sophos Mobile. Do not modify or save the package. By contrast, Get-FileHash returns the file hash, not the ProductCode GUID.

Create an app group or populate it from CSV

App groups are policy lists, not installation tasks. Under App groups, select the appropriate platform and click Create app group. On the Edit app group page, enter the new group’s name in Name. Only then choose between Add app and Import apps:

  • Add individual apps: Through Add app > App list, select apps currently installed on managed devices. This list is device inventory, not an app catalog or store offering. Alternatively, enter your own app details through Custom and add them with Add. ChromeOS app groups can also include extensions. After adding the entries, save the group with Save.
  • Import CSV: Under Import apps, use Example CSV from your own console as a template. Select the prepared file with Upload a file. The imported rows are displayed before Finish; compare these entries with the intended CSV list. Incorrect or conflicting rows cause the entire file to be rejected. Correct the displayed errors and upload it again, then select Finish and Save on the app group. Verify imported identifiers before assigning a policy broadly.

CSV import accepts at most 10,000 apps and requires .csv, UTF-8, a header row that is not imported, and semicolons as separators. Empty optional columns still need the right number of semicolons.

Under Custom, App name is a unique name used to identify the entry for Android, iOS, macOS, Windows, and ChromeOS apps and extensions. For store apps, you can use Link: Obtain link opens Google Play for Android, the App Store for iOS and macOS, or the Microsoft Store for Windows. Open the page for the app you want, copy its URL, and paste it into Link. Get data fills in App name and Identifier automatically. For iOS and macOS, Identifier is the app’s bundle ID; Windows and ChromeOS identifiers are described above. The App Store link for a macOS group entry is not a new installation route for the app catalog.

In the full edition of Sophos Mobile, when manually entering a managed Google Play app for Android Enterprise devices under Custom, prefix the package name with app: in the Identifier field. This is an app-group identifier, not Play approval or installation. The Sophos Mobile Threat Defense documentation does not include this prefix instruction: check the edition and input field before applying it.

Start installation and verify the result

Windows Store selection before creating the task: Through Sophos Mobile, you can install only free apps or apps with a free trial from the Microsoft Store. This restriction does not apply to MSI files. According to Sophos, installing a paid Store app with a trial automatically starts that trial; account for this when planning the pilot. Installation of a paid Store app without a free trial fails even if Sophos Mobile shows the task as successful. Installation also fails if the computer does not meet the Store app’s system requirements; Sophos identifies error code 82 for this case. The code alone does not prove that this is the cause of every Windows error.

For the general installation route, excluding Android Enterprise, open the platform under Apps, click the blue triangle beside the intended app and select Install from the menu. Then choose individual devices or Select device groups. Now starts the task immediately; Date schedules it for later. Complete it with Finish. Alternatively, install an app through Show device > Installed apps > Install app, through Devices > Actions > Install app, or as a task in a task bundle. Check the scheduled time and target scope again before confirming.

Check the installation task in Task view. On macOS, the Successful status means only that the device has started downloading the app, not that installation is complete. Synchronize the Mac after the task, then check the app actually shown under Show device > Installed apps; on other platforms, check the app inventory after reviewing the task. For an update, compare the version installed on the pilot device with the approved target version. If inventory does not show a version, or shows an ambiguous one, verify it on the device or in the app itself. Then launch the app and test sign-in, connectivity, and required data. Proceed to the next target group only after confirming the intended state. On iPhone and iPad, also check the Managed column. A successful task alone does not prove the app is usable or at the intended version.

In the Windows inventory, Sophos Mobile distinguishes Microsoft Store (Store UWP), Nonstore (UWP outside the Store), System (Windows built-in UWP), and Win32 (MSI). The Microsoft Store category also includes UWP apps previously installed from the now-retired Microsoft Store for Business and Education. This describes the historical source of apps already installed, not a way to obtain new apps; the public Microsoft Store is separate. Do not mistake this inventory classification for the catalog entry or proof of successful installation.

Unattended installation depends on the management mode: Android Enterprise apps, managed apps on supervised iPhones and iPads (including device-assigned Apple Business apps), Mac apps, and Windows MSI packages using /quiet can be installed without user interaction. Unmanaged iPhone/iPad apps require user confirmation even on supervised devices. This does not provide a Sophos uninstall route for unmanaged apps. For other combinations, plan for a prompt or confirmation rather than promising silent installation.

Check managed configuration and app behavior

For iPhone/iPad apps, you can enter developer-supported Managed configuration for a managed app under Apps > iOS & iPadOS > App > Settings and VPN. Select Show beside Settings and VPN to open the settings. Under Managed configuration, use Add parameter to add a parameter and enter the required settings. The app developer’s documentation determines which parameters and values the app supports; do not copy keys from another app. After entering the settings, select Apply on Edit settings and VPN, then Save on the app.

Assign per-app VPN: At least one device policy with a Per app VPN configuration must already exist. Sophos distinguishes the configuration references for iOS device policy and iOS user policy; this does not mean that both policy types must be configured. In the app settings, select Show beside Settings and VPN, then select the appropriate existing connection in VPN connection used by the app. The list contains the per-app VPN configurations from all device policies, not just a policy previously viewed; this does not assign the connection to all devices. According to Sophos, the app uses the assigned connection for all its network communication. Select Apply on Edit settings and VPN and then Save on the app. Test connectivity and the recovery path on the pilot device before making a change. The documented mapping alone does not prove actual routing or fail-closed blocking if the VPN fails.

A web content filter for individual managed apps on non-supervised iPhones/iPads requires iOS 16 or iPadOS 16.1 or later, respectively. For the generic filter, the policy owner must first have prepared a suitable device policy with a Web content filter configuration for this mode and approved its full assignment scope. For this route, use the Web content filter configuration of an iOS device policy, not the MTD Web Filtering configuration. Check that Use web content filter for managed apps on non-supervised devices is enabled in it. On the Web content filter configuration page, select Apply, then save the policy with Save on Edit policy; selecting Apply later in the app settings does not replace these two steps. Creating, distributing, and changing shared policies belong to the policy assignment workflow; an app pilot does not limit the effect of a policy change on devices already assigned to that policy. Then under Apps > iOS & iPadOS, click the arrow beside the app name and select Edit from the menu. Click Show beside Settings and VPN, then select this policy in Web content filter used by the app, select Apply on Edit settings and VPN, and select Save on Edit iOS app. After policy assignment is confirmed, install the app as managed. Test filtering and network access on the pilot device. Filtering on supervised devices is a different policy task.

Evaluate Sophos Intercept X separately as a per-app alternative: The Sophos instructions for assigning filters to individual managed apps on non-supervised devices list Sophos Intercept X as an alternative to the generic Web content filter device policy. Neither this nor selecting it for the app alone confirms that filtering works or constitutes blanket approval for device-wide Web Filtering. The iOS Mobile Threat Defense configuration for device-wide filtering on supervised devices remains a different task. Before using the per-app alternative, work with the owners of iOS web filter safety and the iOS MTD policy to separately check and obtain approval for suitability, licensing, the installed and managed Intercept X app, profile status, and the actual app scope. Do not roll out without confirmed filtering and network access on the authorized pilot device.

Outlook account profiles are not a general app installation. Android and iOS/iPadOS use different managed configurations and email placeholders; Exchange Online and an on-premises Exchange Server need separate checks of endpoints and authentication. Before deployment, check account mapping, approved identity, and the current authentication mode in the relevant tenant. The complete fields, placeholders, and example values, along with delivery questions still to be resolved, belong to the separate Outlook configuration workflow. In particular, do not infer a blanket BasicAuth recommendation from a server example.

iOS management status: An iPhone/iPad app installed through Sophos Mobile Admin is managed. For an installation from the Enterprise App Store, the status depends on Sophos Mobile managed installation. If this option is turned off for an app link, the Enterprise App Store redirects the user to the Apple App Store to install the app; the app is installed as unmanaged. That setting is unavailable for uploaded IPA packages. Sophos Mobile cannot uninstall unmanaged apps. In other suitable management modes, an unmanaged app installed by the user from the Apple App Store can be converted to a managed app by reinstalling it through Sophos Mobile. This conversion is not possible under Apple User Enrollment. Before reinstalling, discuss effects on data and any required consent with the user; afterwards, check the status under Show device > Installed apps > Managed. Managed apps are removed when the device is unenrolled from Sophos Mobile; unmanaged apps remain. Back up business app data before unenrolling.

Remove apps and troubleshoot failures

  1. First check the target and the consequences: do you only want to hide the app in the Enterprise App Store, change a policy list, withdraw an assignment, or uninstall it from the device? If a rollout has gone wrong, stop adding new target groups and record the previous intended state.
  2. Check how the Windows app was installed before uninstalling it: On Windows, Sophos Mobile can uninstall only apps it installed itself. An entry in the inventory or task selection is not sufficient proof; an uninstall task fails if the app was installed by the user. /quiet controls only execution without user interaction and does not override this installation-source restriction. For the general route, excluding Android Enterprise and macOS, open the platform under Apps, then select Uninstall. For Android under Device Administrator management, first select Android (Legacy) on Apps - Android Enterprise. Choose individual devices or use Select device groups to select one or more groups, then choose the specific app on Select app. On Schedule task, use Now to request immediate uninstallation or Date to enter the day and time. Check the target scope and timing again, then confirm with Finish. For an individual device, you can use the trash icon beside the app under Show device > Installed apps. Verify that the app was actually removed from the device. Managed apps on supervised iPhones/iPads and appropriately configured /quiet apps installed by Sophos Mobile on Windows can be removed without user interaction.
  3. macOS exception: Sophos Mobile cannot uninstall ordinary Mac apps. Only Apple Business apps (a checkmark in the VPP column) offer Unassign in the arrow menu beside the app under Apps > macOS. Choose individual Macs or use Select device groups to select one or more groups. On Schedule task, use Now to request immediate unassignment or Date to enter the day and time; after checking the details, confirm with Finish. Withdrawing the assignment revokes the license; the app initially remains installed, receives no updates unless reassigned, and, according to Sophos, is removed by Apple after a 30-day period. Even Now may take days to result in removal. Check assignment and actual device status separately; do not treat the task or a deleted catalog entry as proof of uninstallation. License recovery and user/device assignment belong to the Apple Business app workflow. If immediate removal or containment is necessary, agree on a separate authorized approach with device and security owners. License revocation is not an immediate containment measure.
  4. Android Enterprise exception: Coordinate removal with the team responsible for managed Google Play using the Play-specific route; in particular, check the applicable Allow app uninstall policy setting and any remaining deployments. For targeted removal under Apps > Android, select Uninstall on Apps - Android Enterprise. Choose individual devices or use Select device groups to select one or more groups, then choose the app on Select app. On Schedule task, select Now or Date, entering the day and time for Date; after checking the details, select Finish. This also applies to apps users installed themselves from the managed Play Store. Sophos Mobile sends the task to a Google API; uninstallation may take minutes to begin. Alternatively, for an individual device, use the trash icon beside the app under Show device > Installed apps. The same policy and management-mode boundaries apply there. Deleting a Play catalog entry does not uninstall apps already installed. After a user uninstalls an app that Sophos Mobile installed, it may be reinstalled immediately unless the relevant policy permits the uninstall. Check device status and policy behavior on a pilot device rather than treating catalog deletion or a Play task as completed removal.
  5. If an app remains or is missing, compare the platform and management mode, app identifier, target group, timing, Task view, and Installed apps first. On Windows, distinguish MSI GUID or hash problems from Store eligibility and system requirements; on iOS, check Managed status and whether user confirmation is needed. Do not reflexively repeat the same installation task or unenroll devices to fix an app problem.
  6. Only after confirming removal or correction on the pilot device should you proceed with the remaining devices. To restore an app, redeploy the previously documented version and settings, and verify app functionality and required data with users.

Disable preinstalled iPhone/iPad apps

Disabling preinstalled iPhone/iPad apps is not uninstallation: it requires supervised devices and a restrictions policy with an app group. In particular, blocking the App Store can prevent acceptance of Apple Business app terms; Phone and Settings cannot be disabled this way. Treat such restrictions as a separate, tested policy change.

Before editing, check the devices assigned to the policy and its recovery path. The following steps do not turn an existing, broadly assigned policy into a pilot policy. For iPadOS, first resolve the uncertainty about the update and rollback path described in the policy assignment workflow on an authorized pilot device; do not treat the iOS procedure as a verified iPadOS route.

  1. Prepare an app group containing exactly the preinstalled apps you want to disable. Use the Apple list of bundle IDs for native iPhone/iPad apps for their identifiers; an ordinary store lookup does not replace this list.
  2. Under Policies > iOS & iPadOS, open the device policy already assigned to the intended devices. Open the Restrictions configuration; if it is missing, add it through Add > Restrictions.
  3. Under Restrictions > Applications, set Filter type to Forbidden apps. In App group, select the prepared group containing the apps to disable.
  4. Select Apply to apply the configuration, then Save to save the policy. Sophos then describes selecting Yes in the dialog for updating assigned devices. This confirmation can affect all devices already assigned to the policy: initiate it only within the previously approved change scope, not as an isolated app test.
  5. After the device has processed the policy, verify that the intended apps are no longer available and that the other required functions still work. If unexpected side effects occur, do not make further assignments; restore the documented, previously approved restriction through the confirmed policy recovery path and check the effect on devices again.