Deploy Sophos Endpoint on macOS with Jamf Pro
An unattended rollout requires two complementary parts: the current configuration profile supplied by Sophos and the tenant installer launched by Install Sophos Script.txt. Use this order: assign and verify the profile on pilot Macs, run the installer policy, then validate protection locally and in Sophos Fusion (formerly Sophos Central). The Jamf status Completed only confirms that the script ran; it does not prove that every protection component works.
This guide follows the current Sophos workflow for Jamf Pro. Sophos created that workflow using Jamf Pro 10.40 and provides the profile and script “as is” for other MDM products. Menu and field names therefore match the English product interfaces exactly.
Prerequisites and deployment choice
Before downloading anything, confirm that:
- Macs meet the current Sophos system requirements. Check them before each rollout because supported macOS releases, hardware requirements, and retirement dates change.
- Devices are enrolled in Jamf Pro and can receive configuration profiles and computer policies.
- Required Sophos domains and ports are reachable directly or through the intended proxy or Message Relay. Because regional hosts, certificate services, and ports can change, verify actual installer, MCS, and update connectivity. Sophos Firewall allows the required destinations by default, but restricted outbound networks must explicitly permit them. AWS and other non-static addresses or regional restrictions can interrupt service; configurations without wildcards may lose functionality.
- You have chosen Sophos Endpoint or Sophos Endpoint and ZTNA. Profile and licensed installer components must match that choice.
- You have defined a small static pilot group and designated owners for approval, rollback, and escalation.
Do not copy Team IDs, Bundle IDs, or PPPC entries from an old ticket or blog. Sophos changes profiles for new macOS requirements; the current download from your own tenant is the authoritative template.
1. Download Deployment Tools first
- In Sophos Fusion, go to My Environment > Installers.
- Under Endpoint > Deployment Tools, click Download the macOS Deployment Tools (includes MDM profiles). This download contains the macOS configuration profiles and installation script. Obtain the tenant installer and its download URL separately in section 2.
- Extract
SophosMacDeploymentTools.zipin an access-controlled workspace. - Open Sophos Endpoint or Sophos Endpoint and ZTNA and select the profile for the macOS version you use.
The archive contains version-specific configuration files and Install Sophos Script.txt. Use these files together as the current set. After a major macOS or Sophos change, download the archive again and test it in the pilot rather than continuing to use an old profile without checking it.
2. Get the installer and its URL
After downloading the Deployment Tools, download the installer from the same Sophos Fusion tenant:
- Under My Environment > Installers > Endpoint, select Download Complete macOS Installer, or use Choose Components… for the required licensed components.
- Download
SophosInstall.zip. - In Finder, use Get Info > More Info > Where from to copy its download URL. If it is absent, use Copy address for
SophosInstall.zipin the browser download history. - Store the URL only in the Jamf script and treat it as a tenant registration secret. Do not put it in public repositories, tickets, or broadly accessible logs.
The installer knows which Update Caches and Message Relays were available when you downloaded it. Download a fresh installer if that infrastructure changes. The documented standard workflow does not require a custom download command: use the matching Sophos script from the archive.
3. Create a Jamf pilot group
If no suitable group exists:
- Open Computers > Static Computer Groups and click + New.
- Enter a clear Display Name, for example
Sophos Endpoint - Pilot. - Under Assignments, select only pilot Macs and click Save.
- Confirm the group and its members under Static Computer Groups.
Include the major macOS versions used in production and, where available, both Intel and Apple silicon hardware in the pilot. A small group limits the impact of an incorrect profile choice or a communication problem.
4. Upload and assign the signed profile
- In Jamf Pro, open Configuration Profiles and click Upload.
- Click Choose File, select the chosen
Sophos Endpoint.mobileconfig, then click Upload. - Open Scope > + Add > Computer Groups.
- Click Add beside the pilot group and then Save.
- Confirm on a pilot Mac that the profile arrived before triggering installation.
Sophos describes this as a signed configuration profile. Import it unchanged from the freshly downloaded archive. Do not remove its signature, alter payloads or identifiers, or merge entries from older profiles. If an MDM rejects the signed file, follow the vendor’s documented import process or contact Sophos Support rather than creating your own profile.
The profile authorizes Full Disk Access, system extensions, and notifications. Depending on the macOS version, the effective configuration also covers Sophos Detection, Sophos Network Extension, and approval for Web Protection or the proxy. Use the matching current file as the authoritative reference, not a static list of identifiers in this article.
Alternative path: Sophos Mobile (not Jamf Pro)
Use this separate path only for macOS devices managed by Sophos Mobile. Download the current macOS Deployment Tools as described in section 1: go to My Environment > Installers, then under Endpoint > Deployment Tools, click Download the macOS Deployment Tools (includes MDM profiles). Do not download these tools from Sophos Mobile. After extracting the archive, select the appropriate macOS profile. In Sophos Mobile, open Policies > macOS > Create > Import policy, enter a name and description, and select the appropriate .mobileconfig under Upload a file. Click Save to save the imported profile as a policy, then assign it to the managed pilot Macs. Deploy Endpoint only after assigning the policy; obtain the tenant installer and its URL separately as described in section 2. On a target Mac, confirm that the profile preconfigures the required Endpoint permissions without user intervention. This Sophos Mobile import and assignment workflow is not a set of Jamf instructions.
Separate setting in Sophos Mobile: The built-in Privacy preferences policy control configuration in a macOS device policy applies to Security & Privacy > Privacy. Its only setting, Allow Sophos Endpoint to scan all files, permits Endpoint to access data such as Mail, Messages, Safari, Home, and Time Machine backups, as well as certain administrative settings, for all users on the Mac. Before assigning the policy broadly, involve the responsible privacy and data owners and obtain approval for this access.
Users must accept the policy. Devices managed with Apple Business (formerly Apple Business Manager) are exempt; MDM enrollment alone does not qualify for this exception. Before assigning the policy, verify the actual management status and plan for user acceptance where required.
This built-in device policy configuration and the imported .mobileconfig profile described above are different macOS policy types in Sophos Mobile; both are distinct from the Jamf workflow. This does not mean that both paths are always required. The single option neither replaces all permissions in the Endpoint profile nor installs Endpoint. Before including more Macs, use a Mac in a limited pilot to verify that the setting is available, check policy assignment and synchronization, confirm user acceptance where required, and then check Endpoint Self Help > Prerequisites. This article does not describe a tested rollback path for this built-in setting.
5. Create the Sophos script
- At the top right in Jamf Pro, open Settings.
- Select Computer Management > Scripts > New and enter a Display Name.
- Open Script, set Mode to Shell/Bash, and Theme to Default.
- Paste the complete contents of
Install Sophos Script.txtinto the script field. - Replace exactly
"put installer URL in these quotes"with the copied installer URL. - Click Save.
Leave the supplied script otherwise unchanged. Add options only after consulting the current Mac installer command-line options and repeating the pilot. Switches, platform restrictions, product tokens, and restrictions that limit certain options to new installations change with installer releases. If you run an installer directly from the command line, extract it outside Documents, Desktop, and Downloads. XDR Sensor-only is not equivalent to Endpoint protection; verify the current platform and active third-party protection requirements before deployment.
6. Scope the policy to the pilot
- Open Computers > Policies > New and enter a Display Name.
- Select Recurring Check-in as the triggering event.
- Under Scripts > Configure > Add, add the Sophos script.
- Under Scope > Add > Computer Groups, add only the pilot group.
- Click Save.
The policy runs at the next Jamf check-in. Keep the profile and script separate so permissions arrive first and you can pause the software rollout without prematurely removing the protection profile.
7. Validate installation and permissions
Open the policy under Computers > Policies and inspect its logs:
- Pending means the script has not run.
- Completed means the script ran and Endpoint should be installed. You still need to complete the validation checks.
Then check each pilot Mac and Sophos Fusion:
- The assigned configuration profile is present locally.
- Sophos Endpoint is installed and Endpoint Self Help > Prerequisites reports no missing security-critical permission.
- Sophos Detection and Sophos Network Extension are active for that macOS release; Full Disk Access and Web Protection work.
- The Mac appears under My Environment > Computers & Servers in the correct tenant and group.
- The agent version, latest update status, and Health State are as expected; Reports > General Logs > Events contains no related installation, permission, or update errors.
Sophos Service Manager checks permissions about every 30 minutes. After a profile correction, the status may take time to update; restarting the service triggers another check after about 30 seconds. Use Endpoint Self Help to investigate the issue directly. For permission checks, diagnostics, and troubleshooting Updater problems, see the macOS CLI and permissions guide. Apple UI paths, security requirements, and Sophos extensions vary by macOS version; granting Full Disk Access manually requires administrator privileges.
Resolve high CPU usage caused by duplicate Sophos ZTNA profiles
If a Mac shows unusually high CPU usage after MDM enrollment, multiple ZTNA VPN profiles may be the cause. This issue applies to the Sophos Endpoint and ZTNA option; do not remove VPN profiles as a precaution from a deployment of Sophos Endpoint alone.
- On the affected Mac, open System Settings > VPN and look for profiles whose names begin with
Sophos ZTNA. - Before removing anything, identify which profile is managed by MDM. An MDM-delivered profile cannot be removed locally and must be preserved. If ownership is unclear, pause and first check the assignment in Jamf or the MDM in use.
- Remove only duplicate
Sophos ZTNAprofiles that can be removed locally. Do not alter the MDM-delivered profile. - Restart the Mac. Then confirm under System Settings > VPN that only the intended MDM profile remains, and check Activity Monitor to see whether CPU usage has fallen. If it remains high, do not remove additional profiles on suspicion alone; escalate with the profile inventory and diagnostic data.
8. Roll out in stages
Expand the scope in controlled waves only after the pilot passes validation. Monitor the success rate, red Health States, missing profiles, update failures, and unexpected user prompts in every wave. Test each new major macOS release or new Deployment Tools archive in the pilot first.
For ongoing monitoring, use a Jamf Smart Group based on inventory data you have verified is available in your environment. This article does not specify a universal Extension Attribute: its implementation and update interval must fit your Jamf inventory process and be validated in the pilot.
Rollback and escalation
If a wave fails, pause the installer policy or reduce its scope to the validated pilot group. Keep the configuration profile assigned while Endpoint remains installed; removing it early can revoke permissions that Endpoint needs.
Rollback does not mean deploying an arbitrary older .mobileconfig. If you need to remove Endpoint, use the approved Sophos uninstall process and account for Tamper Protection according to your Sophos Fusion policy. For single-device installation and removal, see Install Sophos Endpoint on macOS.
Escalate to Sophos Support, or to Sophos Professional Services for environment-specific design, if you cannot import the signed profile, permissions remain missing despite the correct scope, the supplied installer fails reproducibly, or Sophos Fusion remains red after the documented check interval. Provide the macOS and agent versions, hardware type, Jamf Pro version, profile variant, timestamps, Jamf policy log, and Endpoint Self Help diagnostics, but never expose the installer URL publicly.