Replace or decommission a device in Sophos Fusion
When you replace a computer or server, Sophos Fusion (formerly Sophos Central) contains two separate identities: the newly registered device and the old device record. A safe change therefore involves more than selecting Delete. You must protect the replacement, uninstall Sophos locally from the old device, and only then remove the old Fusion record.
Quick procedure: Identify the old and new devices unambiguously. Protect the replacement with the installer from the correct tenant, verify its policies and health, retain any required evidence, uninstall Sophos from the old device by using the appropriate platform runbook, and delete only the confirmed old record. For a tenant change, assess the existing migration workflow before attempting a new installation.
Important: An old Last Active value proves neither decommissioning nor replacement. Deleting a record in Fusion is not a platform-neutral remote uninstall. Confirm the owner, asset ID, and local state before deletion.
Distinguish between replacement, tenant change and decommissioning
Define the required end state before making any changes:
- Hardware replacement in the same tenant: The new device receives its own registration. After a successful handover, uninstall Sophos locally from the old device and then remove its old record.
- Decommissioning without a successor: Retain the required evidence, remove the software locally, and then clean up the record.
- Move to another Fusion tenant: This is a management change, not merely a hardware replacement. For suitable managed computers, follow the piloted Device Migration using Receiving and Sending Jobs.
- Change product scope only: Manage software can change protection components but leaves Sophos Core Agent installed. This is not complete offboarding.
This article defines the sequence of work, but does not repeat platform-specific installation or removal commands. Those commands remain in the relevant platform guides, providing a single authoritative location when Sophos changes its procedures.
Prepare handover
Before the maintenance window, record the old and new devices in a handover list. At minimum, include the device name and type, operating system, owner, serial or asset number, Fusion group, relevant tags, intended products, and expected last contact. When names are similar, rely on the serial or asset number rather than the display name.
Confirm the following before you begin:
- Preserve any open alerts, investigations, recovery information, and audit evidence required from the old device.
- Identify any automatic installation or reinstallation configured through MDM, RMM, software distribution, an image, or a startup script. Update or retire the existing deployment job to match the intended end state.
- For the successor, prepare the current installer from the correct tenant and the intended group, policies, licensing and product assignment.
- For a local uninstall on a supported Windows or macOS device, prepare Tamper Protection specifically for the old device. Retain the device object until local validation so that its password and context remain available. Tamper Protection is not available on Linux.
- Explicitly flag Update Cache, Message Relay, VDI gold images, Server Lockdown, and special-purpose devices that are rarely started. General cleanup rules must not include this infrastructure.
For authoritative guidance on filters, columns, tags, and unambiguous device identification, see the Sophos Fusion device inventory.
Deploy and validate the replacement
Deploy the new device with the current installer from the intended Fusion tenant. For Windows clients, the controlled Windows rollout covers download, parameters, and piloting. Windows servers follow Install and deploy Sophos Server Protection on Windows. For macOS, Install Endpoint on a Mac covers the local workflow; for MDM, use the macOS MDM guide. Linux servers follow Deploy Sophos Protection for Linux.
A completed installer or a new name in Fusion is not sufficient to accept the replacement. Before uninstalling Sophos from the old device, verify at least the following:
- Name, operating system, serial or asset number and user actually belong to the successor.
- The device is communicating with the correct tenant and shows a current Last Active value.
- Group, tags and effective policies correspond to the target state.
- Agent mode, installed products, and licensed features match the plan.
- Health and update status are satisfactory, and an internally approved protection test passes.
- Required encryption, ZTNA, MDR, update cache, message relay, or proxy dependencies work.
Only after these checks pass may you remove protection from the old device. If replacement is delayed, keep the old device protected but isolate it from production access. Leaving an uncontrolled gap in protection is not an acceptable shortcut.
Uninstall Sophos from the old device
Use the procedure owned by the relevant platform team:
- Windows clients follow Uninstall Sophos Fusion Endpoint on Windows.
- Macs follow Uninstall Sophos Fusion Endpoint on macOS.
- Windows servers follow Complete removal of Sophos Server Protection on Windows.
- Linux servers follow Complete removal of Sophos Protection for Linux. Do not apply Windows-client commands or macOS steps to servers or Linux.
The platform runbook defines Tamper Protection, MDM, restart, local success criteria, and escalation requirements. Local work is complete only after its uninstall and verification path succeeds. Removing individual protection products through Manage software, seeing protection components disappear after a Fusion deletion, or seeing the uninstaller process end does not replace this validation.
If uninstallation fails, keep the Fusion record. Preserve the logs and device state, then follow the platform runbook or contact Sophos Support. Do not attempt speculative cleanup of registry entries, files, or agents as part of a replacement.
Clean up old Fusion record
After local validation, search again for the old device under My Environment > Computers & Servers. Before selecting Delete, compare its name, device type, serial or asset number, and Last Active value with the handover list. Never select or delete the active replacement solely because its name is similar.
Deletion removes the record and its associated alerts, so retain any required security and operational evidence first. After Delete, verify that the old record has disappeared from the active list and that the replacement remains current, healthy, and correctly assigned.
Behavior on current Windows systems
Within the documented scope only—Core Agent 2023.2 or later on Windows 10 or later, or Windows Server 2016 or later—Delete or license expiry triggers a back-off. Tamper Protection and the installed protection components are removed, protection ends, and Update Cache and Message Relay are also removed. Sophos Endpoint Agent remains installed. To remove it completely, you must still uninstall it locally by using the supported Windows procedure.
Do not assume this behavior applies to macOS, Linux, or earlier Windows or agent versions. It is not a preferred alternative to the sequence “uninstall locally, verify, then delete the record.”
Manage stale and duplicate records safely
Treat inactive devices as a review list first. Under Global Settings > Products and Services > Endpoint and Server > Removal of Inactive Devices, you can configure separate rules for endpoints and servers. Targeted rules apply to selected groups, while the Global rule applies to all remaining devices. The global period must be longer than the periods in targeted rules.
For MSP and Marketplace customers, the minimum period is 31 inactive days. Sophos evaluates the rules daily at midnight in the tenant’s data region. Exclude update caches, message relays, rarely started systems, and other infrastructure through deliberately maintained groups. For non-persistent VDI, you can use Permanently remove VDI desktops; those records cannot be restored.
Automatically removed records remain in the Recovery Report for 120 days and can be restored during the first 30 days. Permanent VDI removal is excluded. The automatic rule removes the Fusion record; it does not uninstall Sophos software that remains on the device. Assign every rule an owner, a justified inactivity period, documented exceptions, and a separate local removal process.
Do not delete a duplicate or similarly named record based on age alone. First check device identity, Last Active, events, ownership, and the deployment or gold image. With Duplicate Detection in particular, deleting the original object too early can interrupt communication for additional clones. Follow Endpoint devices and groups for the complete decision process.
Understand the licensing impact
Deleting the old record during a hardware replacement does not transfer policies, product assignments, or device configuration to the replacement. Verify the intended license and product scope separately on the new device.
For the current Windows scope described above, a license expiry can trigger the same back-off as a deletion. If a license is activated again within 90 days, the device can recover; after that, a new registration or reinstallation is required. This 90-day statement applies only to this documented Windows back-off and is not a general licensing rule for all platforms or products.
Validation and rollback limit
Replacement or decommissioning is complete when:
- the old device and, where applicable, the replacement have been identified by more than their names;
- the successor is currently communicating in the correct tenant and the intended products, policies and functions are effective,
- local removal from the old device has been confirmed according to the platform runbook;
- only the confirmed old record has been removed from the active Fusion list,
- MDM, RMM, software distribution, and images neither reinstall Sophos on the old device nor register a device with the wrong tenant;
- evidence and ownership of any unresolved deviations are documented.
Until the local uninstallation, you can stop the handover and continue to operate the old protection. After a successful uninstall, there is no undo switch; a return is a new installation with the installer of the correct tenant. A Fusion deletion can be restored within 30 days, but this does not automatically restore already removed local software, update cache or message relay. Permanent VDI removal is not recoverable.
If validation of the replacement fails, do not delete the old record, and stop the next rollout wave. If the old agent has already been removed, restoring the Fusion object does not restore protection: keep the old device out of production until Sophos has been reinstalled by a supported method and the device has passed full validation.