Skip to content
Avanet

Automate Sophos Endpoint rollout on Windows

This article covers only unattended deployment of SophosSetup.exe through software distribution, RMM or scripts. Use the separate linked articles for a single interactive installation and detailed troubleshooting.

RMM is a generic execution route here, not a Sophos-certified product integration. The selected tool must run the installer as SYSTEM or a local administrator, stage the package and wrapper together, preserve the real exit status, and provide controlled timeout and retry behavior.

Define scope and rollout contract

Before the first run, record target devices, maintenance window, expected product, destination group, network path and owner. Start with a few representative pilot devices and proceed only in bounded waves. Review Core Agent release changes before each wave with Sophos Endpoint updates, cache and Message Relay; a published version may not yet be available everywhere because releases are phased.

The deployment job is not successful merely because of a process code. It must return the real exit status, and the device must reach the agreed local and Sophos Fusion (formerly Sophos Central) state.

Prepare the installer and prerequisites

Download a fresh Windows installer from the correct tenant under My Environment > Installers with Download Complete Windows Installer. Despite that label, SophosSetup.exe is a lightweight installer that downloads the features available under the licence. Sophos explicitly supports transferring it to other computers and running it at scale with automated tools such as SCCM. Don’t use a user-specific installer from the Email Deployment workflow: all devices would be associated with the sender’s Sophos Fusion account.

The installer is tenant-bound and confidential: an outsider cannot use it for portal access, but can register devices in the tenant. Delete copies after rollout and distribute it only through access-controlled storage. After disclosure, Expire Previously Downloaded Installers under My Environment > Installers blocks all earlier downloads; the action cannot be undone.

Before the pilot:

  • Confirm that the Windows version is currently supported by Sophos Fusion.
  • Ensure that the deployment context provides the elevation required to install endpoint software.
  • Confirm licensing. A requested product for which the tenant has no license isn’t installed.
  • Apply the Sophos Endpoint network and proxy requirements, including outbound TCP 443 and DNS 53, through the firewall or proxy. Recheck the documented requirements before each rollout instead of preserving a static shortlist in an old deployment script.
  • Test the removal or coexistence decision for existing competing protection.
  • Stage SophosSetup.exe and its arguments locally or through controlled software distribution. The package must belong to the tenant where the device is expected.

Build the pilot command

This PowerShell example installs XDR silently, places the computer in the Pilot subgroup of Workstations, applies two tags, and returns the real process code to the deployment system:

$ErrorActionPreference = 'Stop'
$agentPaths = @(
    if (${env:ProgramFiles(x86)}) {
        Join-Path ${env:ProgramFiles(x86)} 'Sophos\Management Communications System\Endpoint\McsClient.exe'
    }
    if ($env:ProgramFiles) {
        Join-Path $env:ProgramFiles 'Sophos\Management Communications System\Endpoint\McsClient.exe'
    }
)
$installedAgent = $agentPaths | Where-Object {
    Test-Path -LiteralPath $_ -PathType Leaf
} | Select-Object -First 1
if ($installedAgent) {
    Write-Output "Sophos agent already installed: $installedAgent"
    exit 0
}

$installer = Join-Path $PSScriptRoot 'SophosSetup.exe'
if (-not (Test-Path -LiteralPath $installer -PathType Leaf)) {
    throw "SophosSetup.exe must be staged beside this wrapper: $installer"
}
$arguments = @(
    '--quiet'
    '--products=xdr'
    '--devicegroup=Workstations\Pilot'
    '--tag=Rollout:wave-0'
    '--tag=ManagedBy:RMM'
)
$process = Start-Process -FilePath $installer -ArgumentList $arguments -Wait -PassThru
$exitCode = $process.ExitCode
Write-Output "SophosSetup.exe exit status: $exitCode"
exit $exitCode

This wrapper is for new installations. If it finds McsClient.exe, it exits with code 0 and changes neither tenant registration nor product scope, group or tags. Check existing installations separately in Sophos Fusion and use the dedicated migration or management workflow when they need changes.

Backslashes express group hierarchy for --devicegroup. Quote the full path when a group contains spaces, for example --devicegroup="Application Servers\Terminal Servers". A group or subgroup that doesn’t exist is created. A pilot must therefore use an intentional path and verify it in Sophos Fusion afterward.

Tags use --tag=<name>:<value>; a name-only tag such as --tag=Pilot is also valid. Supply each additional tag as another argument.

Choose a deployment route

Acceptance criteria remain the same whichever tool you use: run the tenant-bound installer in the computer context, evaluate its process code, and verify the expected state locally and in Sophos Fusion. The AD and Intune routes described here use the wrapper to detect an existing installation and return the installer code unchanged. With direct MECM execution, an Application uses its Detection Method; for a Package, assignment and schedule must prevent unintended repeat installations. Sophos documents Active Directory startup scripts, Microsoft Intune and MECM.

Active Directory startup script

Save the PowerShell wrapper above as Deploy-SophosEndpoint.ps1. It can be assigned as a computer startup script. Unlike a login script, it runs with computer rights before user sign-in; a login script would require the signed-in user to be a local administrator. Keep the wrapper and SophosSetup.exe in an access-controlled location that only administrators can modify and target computer accounts can read.

In Group Policy Management Console (gpmc.msc), first link the GPO to a pilot OU. The exact path is Computer Configuration > Policies > Windows Settings > Scripts (Startup/Shutdown) > Startup; use the PowerShell Scripts tab for PowerShell. Open Show Files… and copy both Deploy-SophosEndpoint.ps1 and the tenant’s SophosSetup.exe into that folder. They must be side by side so $PSScriptRoot resolves the installer. Then use Add… > Browse to select Deploy-SophosEndpoint.ps1. Verify Links and Security Filtering under Scope; grant Read and Apply Group Policy only to the pilot computers or a dedicated computer group. Run gpupdate /force on a pilot and restart the computer.

Sophos’s batch example detects an existing installation through Sophos\Management Communications System\Endpoint\McsClient.exe: under %ProgramFiles(x86)% on 64-bit systems and %ProgramFiles% on x86. A custom wrapper may instead use an internally validated, at least equally specific detection. Before wider assignment, verify share access, computer-context execution, no reinstall on every startup and exit-status logging.

Microsoft Intune

Use an account permitted to manage Intune. Create dedicated source, output and tool folders; the documented examples use C:\Temp\IntunePackageSource, C:\Temp\IntunePackageOutput and C:\Temp\Intune-Win32-App-Packaging-Tool-master. Put SophosSetup.exe and the approved wrapper in the source folder, then run Microsoft’s IntuneWinAppUtil.exe. Supply the source folder, SophosSetup.exe as the setup file and the output folder, and answer Catalog folder: N. Success is reported as INFO File 'C:\Temp\IntunePackageOutput\SophosSetup.intunewin' has been generated successfully.

In the Microsoft Intune admin center, go to Apps > All Apps > Add, select Windows app (Win32) and upload SophosSetup.intunewin through Select app package file. Under Program, the published baseline uses SophosSetup.exe --quiet; for this rollout, set Install command exactly to powershell.exe -NoProfile -NonInteractive -ExecutionPolicy Bypass -File ".\Deploy-SophosEndpoint.ps1". The package must contain Deploy-SophosEndpoint.ps1 and SophosSetup.exe side by side, so the wrapper supplies the pilot arguments and $PSScriptRoot resolves correctly. For the current supported Windows and Core Agent scope in the linked uninstall runbook, set Uninstall command exactly to "C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe" --quiet (the SophosUninstall.exe --quiet invocation). On legacy platforms only, use "C:\Program Files\Sophos\Sophos Endpoint Agent\uninstallcli.exe" --quiet (the uninstallcli.exe --quiet invocation) instead; follow that runbook for prerequisites, protected products and restart handling. Keep the standard Return code and Code type mappings unchanged unless your tested deployment contract requires different handling. Under Requirements, select the target architecture and Minimum OS for your fleet.

The documented minimum detection under Detection rules is a manually configured file rule: Rule type: File, Path: %ProgramFiles%\Sophos\Sophos UI, File or folder: Sophos UI.exe, Detection method: File or folder exists. Test it against your product mix first; it prevents repeats but proves neither Sophos Fusion registration nor the correct products and group. Leave Dependencies and Supersedence unchanged unless they are deliberately designed. Under Assignments > Required, add only the pilot group first; after Review + create, observe automatic installation on enrolled devices. Windows Autopilot is Sophos’s recommended enrolment route, not a requirement of the packaging logic.

Microsoft Endpoint Configuration Manager (MECM)

MECM provides Packages as a simpler legacy route and Applications with detection, dependencies, requirements and versioning. For a package, use Software Library > Application Management > Packages > Create Package. Point This package contains source files to the protected SophosSetup.exe source; create a Standard program using SophosSetup.exe --quiet, Program can run: Whether or not a user is logged on, Run mode: Run with administrative rights and Drive mode: Runs with UNC name. During Deploy, deliberately choose the pilot Device Collection, Distribution Point, Purpose: Required, schedule and user experience.

For an application, use Applications > Create Application > Manually specify the application information in the same area. Its Deployment Type uses the UNC source and sets Installation program exactly to SophosSetup.exe --quiet; this direct MECM command is distinct from the wrapper-backed Intune command above and does not automatically include the pilot example’s product, group or tag arguments. Add such options deliberately to the direct command or to a wrapper tested for MECM. Sophos documents three file clauses joined with And: C:\Program Files\Sophos\Endpoint Defense\SEDService.exe without the 32-bit association, plus C:\Program Files\Sophos\AutoUpdate\SophosUpdate.exe and C:\Program Files\Sophos\Management Communications System\Endpoint\McsClient.exe, each associated with a 32-bit application on 64-bit systems; each file must exist. Under User Experience, use Installation behavior: Install for system, Logon requirement: Whether or not a user is logged on, Installation program visibility: Normal, no user interaction and the documented ten-minute estimate. Only then deploy the application like the package to a pilot collection and distribution point with Purpose: Required.

For every route, replace the package under change control when refreshing the installer. Remove old copies, startup-script references and assignments only after the new pilot wave has been accepted. The options below can be added to a direct install command or wrapper as appropriate for the route; the direct MECM commands do not inherit the pilot parameters automatically.

Choose options deliberately

The current Windows CLI documentation includes these supported options:

  • --quiet, --noproxydetection, --nocompetitorremoval and --language=<ID> control the UI, proxy detection, competitor removal and installer language.
  • --products=<list> accepts endpoint, xdr, xdrsensor, deviceEncryption, ztna, all and none; separate multiple values with commas.
  • --devicegroup, --tag, --computernameoverride and --domainnameoverride control placement and displayed identity. Use overrides only with an unambiguous naming design.
  • --crtcatalogpath=<path> points to a custom catalog of competitors to remove.
  • Use --customertoken=<UUID> and --epinstallerserver=<URL> only when the specific automation or partner workflow requires the Sophos-provided values.
  • --registeronly re-registers existing Sophos protection with another account. Tamper Protection must first be turned off on the device, and the installer must come from the destination account.
  • --goldimage, --notificationmode, --goldimagetimeout=<seconds> and --nonpersistent belong in a separately validated VDI gold-image workflow using Sophos’s stated minimum versions, not in a normal workstation rollout.

Sophos limits --bypassacscheck to Windows 10 x86 legacy platforms. --bypasstaegisidcheck bypasses a Taegis tenant-ID check. Don’t add either bypass pre-emptively to a standard package.

Decide product and competitor handling

endpoint installs anti-malware protection without XDR. xdr includes XDR and all endpoint protection. xdrsensor installs XDR capabilities but no anti-malware protection, so third-party protection is required. none installs only core agents and can support a gradual compatibility exercise. all installs every licensed product and ignores unlicensed ones.

When Sophos Anti-Virus is installed, the installer attempts to remove detected competitors by default. --nocompetitorremoval prevents that attempt. It is not a general coexistence guarantee. Before deploying endpoint or xdr, test detection, removal, restart requirements and restoration with the exact third-party product. Choose xdrsensor only when the retained third-party product explicitly owns protection.

Configure proxy, Message Relay and local source

Set an installation-only proxy with --proxyaddress=<host>:<port> or --pacurl=<URL>. For authenticated proxies, Sophos says Windows endpoints support Digest Authentication only; pass credentials with --proxyusername and --proxypassword. --noproxydetection disables automatic proxy detection.

Supply Message Relays as a comma-separated host:port list. The documented default port is 8190:

SophosSetup.exe --quiet --products=endpoint `
  --messagerelays=relay01.example.net:8190,10.20.30.40:8190

There is no CLI option to assign an Update Cache. The installer automatically assesses connectivity to caches configured in the Sophos Fusion account.

--localinstallsource=<path> reduces downloads but doesn’t remove the internet requirement: some files are still downloaded. A SophosLocalInstallSource folder must exist at the specified location. An empty folder is populated during the first installation; for pre-population Sophos names content from %ProgramData%\Sophos\AutoUpdate\data\repo or %ProgramData%\Sophos\UpdateCache\www\v3.

Protect secrets, exit status and logs

Keep the installer, customer token and proxy password out of public shares, source control, command output and tickets. Where possible, inject values at runtime from the deployment platform’s secret store. Command lines can be visible to local administrators and inventory tools, so an authenticated proxy without purpose-limited credentials is a risk.

Capture start time, target, non-secret arguments and the unchanged process exit status as in the example. The official CLI page doesn’t publish a stable mapping of numeric exit codes, so this article doesn’t invent one. A code is a technical signal; Sophos Fusion and local checks remain authoritative for acceptance.

Installer logs are stored under C:\ProgramData\Sophos\CloudInstaller\Logs\ with the timestamped pattern SophosCloudInstaller_<date>_<time>.log. Use the file that matches the failed attempt. --traillogging records message content between the device and Sophos Fusion. Use it only when directed by Sophos Support; Support must also provide the explicit shutdown procedure from the current MCS diagnostic workflow and verify that logging is off. Review logs for secrets before sharing.

Accept the pilot and release waves

On every pilot, confirm that the expected Sophos protection is active, there is no unintended gap in third-party protection, and any required restart is complete. After the agent is installed, open My Environment > Computers & Servers in Sophos Fusion and confirm that the device appears with the expected health, installed products, last-active value and group. Open the computer’s detail page for further details.

After an agreed observation window, release a small representative wave, then larger waves. Compare installation completion, Sophos Fusion registration, health, restarts and conflicts for each wave. Include distinct sites, proxy routes, Windows versions and third-party products in the pilot before broad deployment.

Stop, roll back and escalate

Stop the next wave when devices don’t appear in Sophos Fusion, protection doesn’t become active, failures exceed the agreed threshold, or network, restart or competitor issues cluster. First pause targeting and automated retries in the deployment platform; don’t place failed devices in a blind reinstall loop.

Rolling back the job does not automatically restore a competitor removed by the installer. If acceptance fails, handle affected devices in isolation: correctly uninstall Sophos, restore the previous product, or retain the working Sophos state according to the pre-approved plan. Don’t blindly alter Sophos Fusion device records, Tamper Protection or installer validity. The separate uninstall article covers complete Sophos removal.

For escalation, collect tenant/region, timestamp, device, Windows version, non-secret arguments, unchanged exit status, wave and the matching SophosCloudInstaller_<date>_<time>.log file. Remove secrets. Send this evidence to Sophos Support for unexplained or reproducible installation failures; for release differences, also record the Core Agent version actually offered.

For one interactive installation, see Install Sophos Endpoint on Windows. Manage Sophos Endpoint Agent Mode and software explains Agent Modes. VDI has different identity and cloning requirements; use Prepare Sophos Endpoint in a VDI gold image. For complete removal, see Uninstall Sophos Endpoint on Windows. Deeper diagnosis is outside this rollout flow.