Skip to content
Avanet

Deploy Sophos Central Endpoint systematically

Sophos Central Endpoint is not a single installer, but an operating model comprising a cloud tenant, administrator access, user and device identities, licences, policies, agent software, monitoring and Response. Merely deploying the agent adds devices to Central, but does not yet establish a reliable protection baseline.

1. Clarify the account and region

After creating the account, activate the tenant through the invitation email. Check the company details, data region and responsible partner. The data region affects API hosts and certain services, among other things, and must be chosen deliberately.

At least two responsible administrators should be available so access does not depend on one person during leave, after departure or when an MFA device is lost.

2. Secure administrator access

Set up MFA immediately. Sophos supports passkeys and authenticator apps with time-based one-time passwords. Every administrator registers at least two independent MFA methods.

Use Super Admin only for roles, APIs and other far-reaching settings. Daily work uses an appropriate Admin, Help Desk, Read-only or Custom Role. Plan Sophos Central Endpoint roles and permissions explains the Endpoint-specific permissions.

For Identity Providers, passkeys, recovery and Sign-in Rules, see Secure Sophos Central sign-in with MFA and an IdP.

3. Determine the licence and Agent Mode

Before rollout, determine which Endpoint licence is active and which Agent Mode is intended:

  • Endpoint for full Endpoint protection,
  • XDR for full protection plus XDR functions,
  • XDR Sensor for telemetry alongside a separate protection product.

XDR Sensor does not itself protect against malware. Check licence expiry and product assignment before a mass rollout. The implications are explained in Understand Sophos Central Endpoint licences.

4. Define the identity source

User policies follow a person, while computer policies follow the device. Decide early how users and groups are created in Central:

  • automatically through Endpoint sign-ins,
  • manually or by CSV,
  • from an on-premises Active Directory,
  • from Microsoft Entra ID.

Multiple sources for the same domain can create duplicates and unexpected policy assignments. Test the identity model before rollout.

5. Design the group and policy model

A small number of understandable groups is easier to maintain than a group for every department and exception. A typical model includes:

  • pilot devices,
  • production workstations,
  • critical special-purpose devices,
  • a time-limited exception group,
  • test devices for new software stages.

For each policy type, the first matching active policy applies. Full planning is covered in Build Sophos Central Endpoint policies correctly.

6. Define the protection baseline

Define at least the following areas before the first production device:

  • Threat Protection and HTTPS Decryption,
  • Application, Peripheral and Web Control,
  • DLP and DNS Protection where licensed and required,
  • Update Management and Software Packages,
  • Tamper Protection and exclusions,
  • Data Collection, Isolation and Live Response,
  • Alert email rules and ownership.

Introduce new control functions in Monitor or pilot mode. An exclusion without an owner, reason and expiry date does not belong in the baseline.

7. Prepare the network and platforms

Allow the current Sophos domains and ports on the proxy and network firewalls actually in use. TLS Inspection must not break agent communication with an untrusted certificate chain.

Pilot Windows and macOS separately. MDM profiles and Apple security permissions must be ready before broad Mac rollout.

8. Deploy the installer in a controlled manner

Download the appropriate tenant-bound installer under My Environment > Installers. Old installers can be invalidated irreversibly with Expire previous installers.

The first rollout covers a few representative devices. For Windows, follow Install Sophos Central Endpoint; for macOS, see Install Sophos Central Endpoint.

For API-based inventory or bulk changes, use a dedicated service principal with the minimum role. Authentication, regional API hosts and secure bulk processing are covered in Securely automate Sophos Central Endpoint API.

Automated rollouts use documented CLI parameters, secure Secret transfer and unambiguous logs.

9. Validate the pilot technically

A device is successfully deployed only when all of the following are correct:

  1. Local Endpoint status is healthy.
  2. The device appears in the correct tenant and group.
  3. Agent Mode and installed components match the licence.
  4. The intended policies are effective.
  5. Last Active and Events update.
  6. A test Detection, Web, Application or Peripheral Event appears as expected.
  7. Update, restart and uninstallation have been tested in the pilot.
  8. Alert email and Response ownership work.

Safely test Sophos Endpoint protection features explains the safe EICAR, reputation, MTD and web tests.

10. Establish operations and ownership

Before broad rollout, define fixed responsibilities:

  • Who handles High Alerts and outbreaks?
  • Who approves exclusions and when do they expire?
  • Who reviews Account Health, inactive devices and licences?
  • Who maintains update stages and maintenance windows?
  • Who may use Live Response or AI functions?
  • Which data may be processed in Sophos Central and support packages?

The current Central interface groups devices under My Environment, products under My Products, and global settings under the cog icon. Sophos Help offers search, contextual resources and interactive guides.

Sophos changes navigation and function names regularly. Runbooks therefore document function names and search terms as well as screenshots.

Frequently asked questions

Can Sophos Endpoint be rolled out before policies are planned?

Technically yes, but this is operationally risky. Without a prepared baseline, groups and Alert process, devices may receive incorrect settings or generate Events for which nobody is responsible.

When is the pilot phase complete?

When installation, Agent Mode, policies, protection tests, updates, Alerts, Response and rollback work reliably on representative Windows and macOS devices.