Understanding Sophos Central Endpoint licences
Sophos Central Endpoint is licensed per user for most customers. A user can own multiple devices without consuming a separate Endpoint licence for each device. What matters is the assignment of login, user and protected device that Central recognises.
The displayed figure is a technical calculation. If there is a discrepancy, the definition in the Sophos End User License Agreement takes precedence. A figure that appears too low does not override the contractually correct licensing requirement.
Users, devices and licence types
A device is assigned to only one user at a time. If another user signs in after installation, this assignment can change. A user, however, can own multiple devices.
Each licence type is calculated separately. A user can, for example, consume both an Endpoint and an XDR licence. Device Encryption only counts when the feature is configured accordingly.
Local accounts with different names are recognised as different users. PC1\Jane and PC2\Jane can therefore show two licences even though the same person uses them. The logins can be assigned to one common user in Central. An empty duplicate user can then be removed.
Workspace Protection is not automatically Endpoint Protection
The standalone Sophos Workspace Protection licence includes Protected Browser, ZTNA, DNS Protection for endpoints and Email Monitoring System, but no Sophos Endpoint licence. Full Endpoint protection is included only in the combined Sophos Endpoint Plus Workspace Protection bundle or through a separately purchased Endpoint licence.
For the Workspace bundle, Sophos counts the highest usage of any included product. For example, if 80 users and 100 DNS Protection devices are active, a 100-seat bundle is required. This calculation does not replace the product-specific Endpoint licence logic. In particular, a Firewall Xstream Protection subscription does not entitle a customer to DNS Protection for endpoints.
What does not count
A device that has been offline for more than 30 days is no longer included in usage while it remains inactive. When it reconnects, it automatically counts again and updates the Core Agent and components.
A recently deleted device can continue to consume a licence during its 30-day recovery period. This applies when the assigned user has no other device and the deleted device had not already been offline for at least 30 days before deletion. The licence is released only after the recovery period ends. Immediately deleting and recreating objects is therefore not a reliable licence clean-up method.
If Real-time Scanning is turned off, the device does not count towards Endpoint Protection usage. This is not a sensible way to optimise licences because real-time protection is missing at the same time, and Account Health Check or alerts highlight the risk.
RDS sessions are covered by Server Protection. An additional Endpoint licence per session is not the intended model.
Check the displayed usage
Open the licence page from the profile menu and Licensing. The user report under Reports > Users shows which users generate the usage. Device and user summaries or Hero Reports provide operational overviews but are not always an exact licence record.
For XDR and MDR, also check under Manage Endpoint Software which devices have the feature assigned. This allows the licence display, Agent Mode and the software actually installed to be assessed together.
Activate a licence and plan changes
Activate a new licence from Licensing in the profile menu by entering the Activation Code or License Key, unless the Sophos Partner handles this step. A trial does not require activation yet; use the key when moving to a paid licence.
A product cannot be started again as a trial while a full licence for it is active. After a trial expires, the same trial can be restarted only after 30 days and cannot be extended repeatedly. Treat a trial as a fixed test window with explicit exit criteria.
A licence change can immediately add or change Endpoint software and therefore bypass a planned update window. For example, assigning XDR or Device Encryption can install the associated components straight away. Licence activation and software assignment therefore belong in the same change and pilot process.
Renewal and expiry warnings
Sophos displays a warning at every sign-in from 30 days before expiry. It can be dismissed temporarily but returns until the licence is renewed. Access becomes increasingly restricted after expiry; when the final warning can no longer be dismissed, only the Licensing page remains accessible, and a tenant without a valid licence for an extended period may be at risk.
Plan renewal with the partner, owner and new key before the warning period. A successful order is not sufficient until Central displays the new term.
Over-usage
Sophos does not immediately enforce over-usage calculated in Central because automatic assignment can be inaccurate. Management and protection initially remain available. This is not a permanent grace licence. Duplicate users, old devices and the contractual requirement should be clarified promptly.
What happens at expiry
The effect depends on the licence status:
| Status | Main consequences |
|---|---|
| Trial expired | Licences removed, no updates or new protected devices, heavily restricted interface |
| Full licence expired | Licence remains visible but expired, no updates, new devices or policy changes, unlicensed products are removed |
| Full licence revoked or terminated | Licences removed, heavily restricted interface, Tamper Protection remains active |
An existing agent does not simply disappear completely when the licence expires. The most critical point is that devices no longer receive current protection updates. Renewal, software packages and an uninstall or migration plan should therefore be clarified before the end date.
On current Windows devices with Core Agent 2023.2 or later, the agent removes the protection components after licence expiry and indicates locally that IT no longer manages the device. If a new licence is activated within 90 days, the device can be taken under management again. After that window, registration or installation is required again. --registeronly is suitable only when a technically healthy agent base already exists and does not replace repairing a damaged installation.
If Tamper Protection remains active after a licence has ended, use the documented methods for deleted or expired devices. On current Windows versions, the supported uninstall does not always require the recovery of an old password.
Monthly licence maintenance
A useful operational check compares the licence limit, displayed usage, users without a consistent identity, devices offline for more than 30 days and XDR assignments. A sudden reduction can indicate inactive or unprotected devices and is not automatically an improvement.
Related articles
Manage Sophos Endpoint Agent Mode and software explains Agent Mode and software assignment. For expired or deleted devices, see Uninstall Sophos Endpoint after deletion from Central.