Skip to content
Avanet

Understanding Sophos Fusion Endpoint licences

Sophos Fusion Endpoint is licensed per user for most customers. A user can have multiple devices without consuming a separate Endpoint licence for each one. For a quick check, open Licensing from the profile menu and compare its usage figure with Reports > Users.

The figure in Fusion is a technical calculation, not the contractual definition. If they differ, the Sophos End User License Agreement (EULA) takes precedence. A figure that is too low therefore does not reduce the actual licensing requirement.

How Fusion calculates usage

A device can be assigned to only one user at a time, while a user can have multiple devices. If an administrator installs the agent, the device is initially associated with that login. After the administrator signs out, the assignment moves to the next user who signs in.

Each licence type is calculated independently. A user can, for example, consume one Sophos Endpoint licence and one Sophos XDR licence. Device Encryption counts only after an Encryption Policy with encryption turned on has been assigned to the device.

Some agreements permit device-based licensing. Fusion still applies its user-based calculation in this case; reported usage cannot exceed the number of devices and can understate the actual requirement in some situations. The contractual entitlement remains decisive.

Identify duplicate users

If the same person signs in to two devices with the same domain login, Fusion shows one user with two devices. Different local accounts such as PC1\Jane and PC2\Jane, however, create two users and therefore two counted licences. Under People > Users, assign both logins to the same user and optionally delete the empty duplicate afterwards.

What changes Endpoint usage

  • Offline for more than 30 days: The device does not count while inactive. When it reconnects, Fusion automatically includes it again, and Endpoint downloads the latest Core Agent and related components.
  • Deleted in Fusion: Sophos documents that a deleted device stops contributing to usage 30 days after deletion. Do not assume an immediate correction. Deletion is also not a licensing strategy because it ends protection on current Windows devices.
  • Real-time Scanning turned off: The device does not count towards Endpoint Protection usage. This is not a sensible optimisation because an essential protection mechanism is then missing.
  • RDS session: Server Protection covers the session; an Endpoint Protection licence per session is not required.

A sudden fall in usage is therefore not automatically good news. It can also indicate devices that have been offline for too long or no longer have real-time protection.

Trace the displayed licence usage

The authoritative usage display is under Licensing. Under Reports > Users, sort active users or users seen on a device during the last 30 days to narrow down what is contributing to usage. Sophos states that this report helps with analysis but is not an exact licence report.

Do not equate Devices and users: summary or Hero Reports with licence usage either. For Sophos XDR and Sophos MDR, also check which devices have these features assigned under Manage Endpoint Software. This lets you assess licence type, user assignment and installed scope together.

Sophos does not enforce an overage reported by Fusion because the calculation can be inaccurate. Licensed products initially remain available for use and management. This does not grant an additional entitlement: duplicate users, obsolete device records and the requirement under the EULA still need to be resolved.

Distinguish Workspace Protection correctly

The standalone Sophos Workspace Protection licence includes Sophos Protected Browser, Sophos ZTNA, Sophos DNS Protection for endpoints and Sophos Email Monitoring System, but does not include a Sophos Endpoint licence. Endpoint is included only in the combined Sophos Endpoint Plus Workspace Protection bundle or with a separately purchased Endpoint licence.

For a Workspace Protection bundle, the required count is the highest usage of any included product. With 75 ZTNA users, 80 Protected Browser users and 100 devices using DNS Protection, for example, the licence count is 100. For the combined bundle, Endpoint usage is also included in this comparison.

A Sophos Firewall Xstream Protection subscription includes only the standalone DNS Protection capabilities. DNS Protection for endpoints requires Workspace Protection. These similarly named entitlements should be checked separately when ordering and renewing.

What happens at expiry

The outcome depends on the licence status:

StatusEffects in Sophos Fusion (formerly Sophos Central) and on endpoints
Trial expiredAll licences are removed; existing endpoints do not receive updates, new endpoints cannot be protected and policies cannot be changed; Devices, Dashboard and products under My Products are unavailable, and options under Global Settings are limited.
Full licence expiredLicences remain visible as expired; existing endpoints do not receive updates, new endpoints cannot be protected and policies cannot be changed; unlicensed products are uninstalled.
Full licence revoked or terminatedAll licences are removed; existing endpoints do not receive updates and new endpoints cannot be protected; Devices and products under My Products are unavailable, options under Global Settings are limited and Tamper Protection remains on.

Expiry is therefore not merely a billing issue. It can remove protection components and stops new protection updates. Complete renewal or a planned migration before the end date, then verify the result under Licensing.

The 90-day window on current Windows devices

Since Core Agent 2023.2, the deleted-and-expired-device process also applies to supported Windows devices after licence expiry: Sophos removes installed protection components, disables protection, and Endpoint Agent displays Your device isn’t managed by your IT team any longer. The remaining agent must be uninstalled separately for complete removal.

After a new licence is activated, the device can be recovered if no more than 90 days have passed since the licence expired. After 90 days, Sophos Endpoint Agent must be reinstalled. Sophos refers to the installer option --registeronly for this; the related article below explains the recovery workflow.

According to Sophos, Windows 10 and later and Windows Server 2016 and later do not require a recovered Tamper Protection password to uninstall the software in this state. Do not assume the same behaviour on older or otherwise unsupported systems.

Monthly review workflow

  1. Under Licensing, check the limit, usage, licence type and expiry date.
  2. Under Reports > Users, look for unexpected users and different logins belonging to the same person.
  3. Investigate devices offline for more than 30 days instead of accepting the lower usage without checking.
  4. Under Manage Endpoint Software, compare XDR and MDR assignments with the intended Agent Mode.
  5. Complete renewal, piloting or migration before expiry and verify the new status under Licensing afterwards.

Manage Sophos Endpoint Agent Mode and software explains Agent Mode and software assignment. For expired or deleted devices, see Uninstall Sophos Endpoint after deletion from Fusion.

Frequently asked questions

Does a user with two computers consume two Endpoint licences?

Usually not, provided Fusion assigns the same login on both devices to the same user. Different local logins can create two users and two counted licences.

Is a deleted device removed from licence usage immediately?

Do not rely on that. Sophos documents that a device deleted in Fusion stops contributing to usage 30 days after deletion. Verify the figure under Licensing.