Uninstall Sophos Endpoint on macOS
Sophos Endpoint cannot be removed from a Mac by moving the app to the Trash. Services, System Extensions, Network Extensions, and protected components would remain. For a supported removal, use the installed Remove Sophos Endpoint tool or, for a managed deployment, the official InstallationDeployer.
First, clarify the objective: this article applies when Sophos Endpoint must be removed completely from the Mac. If only individual Endpoint features or components should no longer be used, review the product and policy assignments instead. The overview of Sophos Endpoint features helps distinguish between these cases. A complete uninstall interrupts protection; it is not the appropriate way to change the licensing or configuration of a single feature.
The sequence matters: first stop MDM from reinstalling the software automatically and preserve any required data, then uninstall the agent locally and verify the result. Only then delete the computer from Sophos Fusion (formerly Sophos Central). Deleting the Fusion device record offboards its management data; it does not uninstall the software from the Mac.
Preparations
Clarify and document the following before uninstalling:
- a local macOS administrator account is available,
- installed Sophos products and assigned policies, groups, licenses, MDM profiles, and installation jobs have been recorded; for larger estates, the Sophos Fusion device inventory can help,
- if Tamper Protection is active, the individual device password is available or its deactivation for this device has been confirmed,
- for a managed Mac, access to MDM or software distribution is available,
- a decision has been made on how protection will be maintained or interrupted in a controlled manner while the device is retired, repaired, or migrated to another tenant,
- the installer for the correct Fusion tenant and the required MDM profiles are available for any subsequent redeployment.
The device password is available for the affected device under Devices > Computers and Servers, under Tamper Protection. Alternatively, disable Tamper Protection there for this device only. For an online Mac, wait until it has applied the change. Disabling it globally is unnecessary for a single device. An offline device cannot receive the change; in that case, the device password must have been retrieved securely beforehand.
Preserve any required alerts, forensic information, and recovery data beforehand. For MDM-managed devices, also remove the installation policy from scope. Otherwise, the Mac may automatically reinstall the agent you just removed.
Recommended method: integrated Removal Tool
- Open Spotlight with
Command + Space. - Search for Remove Sophos.
- Open Remove Sophos Endpoint.
- Enter the local macOS administrator password and, if requested, the Tamper Protection password.
- Complete all the instructions and restart the Mac when prompted by the tool.
Do not drag the Sophos app to the Trash or manually delete directories in /Library. If the integrated uninstaller is missing or does not work, use the official standalone Removal Tool.
Supported uninstallation in Terminal
For remote management or a controlled MDM job, Sophos confirms the following commands. Run them in macOS Terminal or in the management system’s execution context with root privileges:
cd /Library/Application\ Support/Sophos/saas/Installer.app/Contents/MacOS/tools/
sudo ./InstallationDeployer --remove --tamper_password '<TAMPER_PROTECTION_PASSWORD>'
Replace <TAMPER_PROTECTION_PASSWORD> with the individual Tamper Protection password for this Mac. If Tamper Protection has already been disabled in Fusion and the Mac has applied the change, the parameter is optional:
sudo ./InstallationDeployer --remove
Sophos requires sudo for a Terminal-based uninstall; without sudo, the tool opens a graphical credentials dialog instead. A password supplied as a command-line argument may be visible in management logs or process data. For managed devices, it is therefore safer to disable Tamper Protection specifically for that device in Fusion, wait for synchronization, and then uninstall without the password parameter.
If the normal process does not trigger the required macOS consent dialog, Sophos documents this variant:
sudo ./InstallationDeployer --remove --ui --tamper_password '<TAMPER_PROTECTION_PASSWORD>'
Pilot this variant first on the major macOS version actually in use. Sophos notes that consent dialogs may differ between macOS versions due to changes in Apple’s security controls.
Standalone Removal Tool as a repair option
If the installed uninstaller is missing or has already failed, open the public Sophos download for the Removal Tool for Sophos Endpoint for Mac. After completing the export or download steps shown there, extract the package and open Remove Sophos Endpoint. The standalone tool is a targeted repair option, not the standard method for every uninstall.
If this tool also fails, collect SDU data before making any further changes. Sophos Endpoint: diagnostics with SDU describes the appropriate process. Do not use old cleanup scripts, third-party tools, or copied commands to delete protected files manually. With the diagnostic information, you can then open a case with Sophos Support.
Handle MDM profiles and extensions separately
The Sophos uninstaller removes the installed Endpoint components. An MDM configuration profile, by contrast, is part of device management and is not treated like an app. Do not assume that a local uninstall automatically removes Sophos profiles from MDM. After uninstalling, make a separate decision:
- The Mac remains in the organization or will be reimaged: Remove Sophos profiles from scope or delete them only if no other assigned Sophos configuration still requires them.
- The Mac leaves device management: Remove the Sophos profiles through MDM and verify there that they will not be assigned again.
- Migration to a new tenant: Remove the old installation assignment and any profiles that are no longer required, then deploy the current profiles and installer for the new tenant.
Do not delete System Extensions or Network Extensions manually. If macOS continues to show an extension after a successful uninstall, first restart the Mac and check the MDM assignments. If it remains, preserve the logs and contact Sophos Support. The separate installation process, including profiles, Full Disk Access, and rollout verification, is explained in Deploy Sophos Endpoint on macOS with MDM.
Verify success and clean up Fusion
Local removal, prevention of software redeployment, and Fusion offboarding are separate verification steps. After any restart requested by the tool, first check the local state:
- Sophos Endpoint and its menu bar icon no longer appear,
- filter for
Sophosin Activity Monitor; this is an additional plausibility check, not sufficient proof of successful removal on its own.
Then verify that MDM or software distribution does not start a new installation and that any Sophos MDM profiles no longer required have been removed or taken out of scope. The old tenant’s device record must not show any further communication.
Only after these checks pass should you remove the old device record from Fusion. Deleting that record alone does not uninstall the software from the Mac. For a tenant migration, install and validate the device in the new tenant: verify the correct device identity and group, assigned policy, green health status, update, and last communication.
If uninstallation fails
Symptom: The agent reappears after uninstallation
First check the MDM status, installation policy, and existing Sophos profiles. An installation job that remains assigned can reinstall the agent and make it appear that the uninstall failed. Remove the old assignment from scope, then check the local and Fusion states again.
Symptom: The Removal Tool is missing or stops with an error
- Do not repeatedly delete files and directories manually.
- Record the macOS and Sophos agent versions, local administrator rights, Tamper Protection status, method used, time, and the displayed error message or exit code.
- Use the official standalone Removal Tool as a repair option.
- Collect current SDU diagnostic data before the next intervention.
- Open a Sophos Support case with these details and logs.
Symptom: The device has already been deleted from Fusion
In Sophos Fusion, open Reports > Recover Tamper Protection passwords. For up to 30 days after deletion, you can use Restore to restore the device there. The report retains deleted devices and their Tamper Protection passwords for 120 days; use Export to save the displayed entries. After 30 days, Restore is no longer available, even if the password record still appears in the report during the 120-day retention period.
Last resort: bypass Tamper Protection in Recovery Mode
This procedure applies only to macOS and only when device restoration, password recovery, and both regular Removal Tools are unavailable or unsuccessful. It modifies product-info.plist on the APFS Data volume. Selecting the wrong volume or using a different path can damage the system. Stop and contact Sophos Support if the volume assignment is unclear.
Start the Mac in macOS Recovery using the Apple procedure for that model. Select Options and Continue if that choice appears, then sign in with an administrator account.
From the top menu bar, open Utilities > Terminal and list the APFS volumes:
diskutil apfs listUse only the entry labeled APFS Volume Disk (Role): … (Data). Note the Disk Identifier, Mount Point, and FileVault status of that Data volume. Do not select the System, Preboot, or Recovery volume.
If FileVault shows No, continue with step 6. If it shows Yes (Locked), unlock the Data volume. Replace
<DISK_IDENTIFIER>with the identifier you noted and enter the administrator password when prompted:diskutil apfs unlockVolume <DISK_IDENTIFIER>Check the volume list again. If the Data volume is still shown as locked, repeat the unlock and check; do not continue while it is locked:
diskutil apfs listMount the Data volume, again replacing the placeholder:
diskutil mount <DISK_IDENTIFIER>Change to its Library directory. Replace
<MOUNT_POINT>with the mount point noted earlier. The quotation marks are required because the path may contain spaces, for examplecd "/Volumes/Data/Library":cd "<MOUNT_POINT>/Library"Only after confirming that the current path is the Library directory of the correct Data volume, run the following case-sensitive command:
plutil -insert "HomeVersion" -string "10.7.3" Sophos\ Anti-Virus/product-info.plistIf
plutilreports an error or you are uncertain about the result, stop here. There is no documented way to reverse this plist change in this procedure. Do not attempt further plist modifications or manual deletion commands; instead, document the steps taken, preserve the diagnostic information, and contact Sophos Support.Restart from the Apple menu and boot normally. Then run Remove Sophos Anti-Virus or the current official standalone Removal Tool. Use the macOS administrator password when prompted.
Verify the result as described above. Reinstall Sophos only if required; otherwise, complete the Fusion and MDM cleanup.
Related articles
For manual installation instructions, see Install Sophos Endpoint on macOS. The time-limited local override and password recovery are described in Safely disable Sophos Fusion Tamper Protection.