Skip to content
Avanet

Deploy Sophos Central Device Encryption securely

Sophos Central Device Encryption manages the drive encryption built into Windows and macOS: BitLocker on Windows and FileVault on macOS. Sophos does not provide a separate encryption engine; it applies policies, collects status information and manages recovery keys.

Boot and fixed data volumes are managed, but removable media are not. BitLocker To Go can encrypt such drives, but Sophos Central does not manage their status or recovery keys.

Requirements and licence

Before rollout, check the licence, supported operating system, hardware and existing encryption. A device may already be managed through BitLocker, FileVault, Group Policy, MDM or a previous product.

A successful Endpoint installation does not prove that Device Encryption is licensed, assigned or technically ready. Under Manage device software, verify whether the component should and can be installed. The standard Windows installer automatically installs the Device Encryption component when a licence is available; on macOS it is installed separately as specified by Sophos.

On supported 64-bit Windows platforms, Central Device Encryption has been delivered through the Core Agent warehouse since product version 2025.1.3. The displayed CDE version therefore matches the installed Core Agent version on these systems. This does not indicate an incorrect package.

What happens when a licence expires

After the Encryption licence expires, the Device Encryption page disappears from the Self Service Portal. Users can then no longer retrieve recovery keys themselves. Sophos also removes most Encryption components from the device but leaves the parts required for a future reconnection.

This does not disable BitLocker or FileVault and does not decrypt the drives. That is precisely why an unplanned expiry is critical: protection remains active while central management and recovery are restricted. If a BitLocker recovery key changes during this unmanaged period, Central initially still knows the old key after the licence is reactivated. Licence renewal and an independent emergency recovery process must therefore be part of operational planning.

Define ownership and recovery first

Before activating the first policy, answer the following questions:

  • Who may retrieve recovery keys?
  • How is the requesting user’s identity verified?
  • Will Self Service be used?
  • Where are recovery operations logged?
  • What happens when a user leaves, a device is lost or a mainboard is replaced?
  • How is a device decrypted or cryptographically erased before disposal?

Treat a recovery key as a highly sensitive secret. Do not store it unencrypted in email, chat or tickets.

Policy assignment

Device Encryption policies are assigned to users or groups. User identity and device association must therefore be correct. Test the behaviour on shared devices and with local accounts during the pilot.

A Windows device remains encrypted if a user without the relevant policy signs in later. With FileVault, however, every user of the Mac must be covered by the encryption policy for the intended user and recovery management to work fully.

With Encrypt boot volume only, fixed data volumes remain outside the Sophos policy. Compare this decision with where data is actually stored. The Windows option Encrypt used space only accelerates initial encryption, but can leave previously deleted data areas unencrypted and is therefore intended only for newly provisioned computers.

Do not enable the Base Policy across the tenant without testing. A pilot group covers at least several hardware generations, laptop models, operating-system versions and existing encryption states.

Plan Windows and macOS separately

Windows requires an appropriate TPM and BitLocker design. Authentication modes, Group Policy and the recovery partition affect activation.

macOS requires FileVault, reliable user association and, depending on the platform, an MDM bootstrap token or the appropriate Apple permissions. Check the personal recovery key and authorised FileVault users.

Platform details are covered in Manage BitLocker with Sophos Central and Manage FileVault with Sophos Central.

Specific status, service, TPM, WMI and recovery-key errors are covered in Systematically troubleshoot Sophos Device Encryption.

Monitor status

Sophos Central shows encryption status, errors and recovery information. After activation, verify:

  1. The policy is effective for the correct user and device.
  2. Encryption starts and reaches 100 per cent.
  3. The recovery key is stored in Central.
  4. Restart and sign-in work.
  5. The recovery procedure has been tested in a controlled manner.
  6. Alert emails and ownership work as intended.

A pending user prompt or restart does not constitute a completed rollout.

Do not close the Medium alerts Device is not encrypted, Recovery key is missing and Device Encryption is suspended without investigation. A missing key requires immediate recovery planning, while a suspended drive can be an intentional short-term state during an update. The cause, affected volume and valid recovery method must be known before the alert is closed.

Central distinguishes several status values:

StatusMeaning
Encryptedencryption is complete
Pendingpolicy assigned; encryption is running or waiting
SuspendedBitLocker is temporarily suspended on at least one volume
Plainat least one volume is unencrypted or has not started
Unmanagedagent present, but no Device Encryption policy is effective
Not supportedplatform or operating mode is unsupported
Not availableCentral does not know the state, for example because the component is missing

Under My Products > Encryption > Computers, the Computers without Device Encryption installed filter shows managed computers without the component. After AD Sync, the Unmanaged computers tab additionally contains devices known from AD that do not have Sophos protection. Do not confuse these two lists.

Self Service Recovery

Authorised users can retrieve their own recovery key through the Sophos Central Self Service Portal. They must first receive a setup invitation. The portal shows only computers on which the person was the most recent user to sign in. If someone else has since signed in, that device is no longer available to the original user for Self Service Recovery.

Under Global Settings > Access Control > Sign-in and Identity > Sophos Sign-in, Self Service access can be enabled automatically for new and existing users. If this automation is later disabled, users who already have access do not lose it automatically. Offboarding and permission reviews therefore remain necessary.

Self Service reduces Helpdesk effort, but does not replace identity verification during administrative recovery or investigation of the event that triggered recovery.

Administrators can also search for a key using at least five characters of the recovery-key ID or Volume ID. BitLocker has a separate key for each protected volume. As soon as an administrator displays a Windows recovery key, Sophos marks it as used and replaces it at the next synchronisation. Do not retrieve a key merely for testing on production devices.

When Sophos Central Device Encryption is installed, existing BitLocker recovery keys are replaced automatically. Before a management migration, ensure that the new key is available in Central.

Password-protected files on Windows

Device Encryption 2.0 or later can package files of up to 50 MB on Windows in an AES-256-protected HTML file. This is done through the Explorer context menu or an add-in for classic Outlook for Windows; the new Outlook is not supported for this purpose.

This function provides secure file transfer, not drive encryption, and is not a substitute for DLP. Send the password through a separate channel. Test browser support and the recipient process before production use.

Adopt existing encryption

An already encrypted device is not automatically decrypted and re-encrypted. Sophos can adopt supported BitLocker or FileVault states, but requires a valid recovery-key and management state.

During migrations, back up existing recovery keys and then rotate them in a controlled manner where the official workflow requires it. Two management systems must not enforce conflicting encryption policies at the same time.

Deactivation and offboarding

Removing the Sophos component does not automatically decrypt a drive in every scenario. Conversely, removing a policy must not inadvertently trigger decryption.

Before offboarding, define the target state, recovery-key retention, transfer of ownership and local uninstallation. Check the status directly in the operating system after the final action.

Frequently asked questions

Does Sophos encrypt the drive using its own technology?

No. Sophos Central manages BitLocker on Windows and FileVault on macOS, including policy, status and recovery-key management.

Can the policy be enabled immediately for all users?

This is not advisable. First test hardware, TPM, existing Group Policy, FileVault users and the recovery process in a representative pilot group.