Manage the Sophos Fusion device inventory
The Sophos Fusion (formerly Sophos Central) device inventory is under My Environment > Computers & Servers. It combines protected computers and servers, includes devices inactive for more than 30 days by default, and supports combined filters. This makes it a useful operational worklist—as long as an old timestamp is not mistaken for proof that a device has been retired.
Quick workflow: First narrow the inventory with Filters, then assess Name, Last Active, Health, Tamper protection, Agent mode status, Agent mode installed, and product columns together. Make changes on a small pilot set and verify them in the same view. Use Delete only after confirming the offboarding state.
Which devices belong in this view
My Environment > Computers & Servers contains computers and servers in one place. Mobile devices are managed separately under My Environment > Mobile Devices. The shared list is gradually replacing the separate computer and server lists in product menus.
A Sophos Fusion record is not the physical device itself. It reflects the latest identity and telemetry processed by Sophos Fusion. For product-specific groups, policies, duplicate detection, and automated cleanup, continue with Manage Sophos Central Endpoint devices and groups.
Edit tamper protection requires global tamper protection to be enabled and a Super Admin, Admin, or suitable custom role. Keep permissions narrow as described in Sophos Fusion administration roles.
Read the inventory list correctly
Use the Column selector icon to show the fields required for your review. Name cannot be removed. The selection lasts until the session ends; bookmarking the customized page URL can preserve it for the next visit.
The main values answer different questions:
- Last Active is the last contact with Sophos Fusion. Online has a green dot; inactive devices show their last contact time.
- Health is the security health state. Green does not prove that ownership, software scope, or inventory data is correct.
- Tamper protection is On, Off, or Not applicable. The last value means the operating system does not support it.
- Agent mode status shows Product unassigned, Upgrade available, Installed, or Not supported; Agent mode installed shows the installed scope: Endpoint, XDR, or XDR Sensor. XDR Sensor provides detection and response, but not Sophos malware protection.
- MDR managed, Encryption, and ZTNA show whether the function is managed, installed, unassigned, or unsupported.
- Group, Tags, Last user, operating system, serial number, and IP addresses help map the record to an owner and lifecycle.
Clicking a device name may first open a slide-out details pane. The Open in new tab icon opens the full page with Summary, Security Status, Events, and other device-dependent tabs. The pane is being rolled out gradually and may not yet appear in every tenant.
Servers: Review Summary and switch to Policies
For a specific server, open My Environment > Computers & Servers or My Products > Server > Servers, select its name, and open Summary on the full details page. Sections and actions depend on the license, enabled features, and sometimes the operating system. The top bar shows security alerts; its Health value may differ from the shared device list. Recent Events is only a selection—open Events for a complete review.
In Agent Summary, record Last Sophos Fusion Activity, Last Agent Update, MDR managed, Assigned Products including Software (Endpoint, XDR, or XDR Sensor) and Versions, IPv4/IPv6 addresses, operating system, Group, Tamper Protection, and Lockdown Status for inventory reconciliation. Update Now can initiate an agent update; Change group can change the server’s single group membership. Use these only after checking the maintenance window or target policies, respectively: changing groups can also change other effective policies.
Do not confuse the separate Summary sections with Agent Summary: Update Cache and Message Relay Status appears when update caches or message relays are in use and, depending on the server’s role, shows its status as a cache/relay or details of a cache/relay configured elsewhere. On Windows, Windows Firewall shows, among other things, Group Policy usage, active network profiles, and other registered active firewalls. Which sections actually appear depends on the server and its configuration.
Depending on the server and permissions, Actions can include Scan and Lock Down (neither is available for XDR Sensor), Diagnose, Reset health status, Delete, isolation, Adaptive Attack Protection, and Live Response; not every option is available on Linux. Reset health status fixes neither the agent nor a threat. Delete removes the server record in Sophos Fusion; Sophos recommends uninstalling the software before deleting it. In the Windows behavior documented from Core Agent 2023.2 onward, deletion can disable tamper protection, remove installed protection components, and end protection. If the Sophos Endpoint Agent is still present afterward, uninstall it separately for complete removal. Do not apply this sequence across other server or agent configurations. Lock Down and Unlock relate to the older server lockdown state; they are not a confirmed migration to Unauthorized File Protection or instructions for removing lockdown. Document the status only, and consult the Lockdown and UFP inventory and decision guide for any potential transition.
Summary does not show the effective policy: On the same server, switch to the Policies tab and compare the policy name shown for each Type with the expected server policy. If they differ, check the target group, activation, and priority under My Products > Server > Policies; the server groups and policies workflow describes host-level verification. Clicking a policy name opens the shared policy—changing it can affect every assigned server. Even a matching name alone does not establish that protection is actually working on the host.
Build a verifiable worklist
- Open My Environment > Computers & Servers.
- With Column selector, show at least Last Active, Health, Tamper protection, Agent mode status, Agent mode installed, Group, and licensed product columns.
- Open Filters and define the target set. Criteria can be combined.
- Select Apply. The count beside the filter icon shows active filters; Reset to defaults clears them.
- Open unusual devices individually and review details and events before taking action.
Useful separate worksets include:
- Last Active for an appropriate period plus Device type set to Computer or Server to review inactivity by lifecycle;
- Tamper protection: Off to separate approved exceptions from misconfiguration;
- Agent mode status: Product unassigned or Upgrade available to find incomplete software assignments;
- Tags: Only devices with no tags to identify unclassified devices;
- Last OS update with an age range matching the patch process to trigger follow-up.
Free-text search accepts device name, operating system, IP address, last user, tags, or groups and is limited to 256 characters. Use the dedicated filter for a serial number. A result remains only a workset: an old laptop record is not safe to delete until ownership, the asset system, or an offboarding ticket confirms its lifecycle.
Make controlled changes
Maintain tags
Select one or more devices and open Actions > Manage tags. Enter Tag name and optionally Tag value, then add the tag using the Add icon. Review the changes with Next, run the job with Start job, and track it under Jobs running before checking the tags on the device. A device can have up to 15 tags, and up to five tags can be pinned in the list.
A consistent scheme such as site=zurich, owner=finance, or lifecycle=pilot is more useful than changing free text. After the job completes, filter by name and value and confirm that exactly the expected devices appear. Remove a wrong tag through Actions > Manage tags, Next, and Start job; Unassign all removes every tag from the selected device and is not a shortcut for a single correction.
Edit tamper protection
When global tamper protection is enabled and the role permits it, select devices and use Actions > Edit tamper protection to choose Turn ON tamper protection or, deliberately, Turn OFF tamper protection. Select Start job, track the job under Jobs running, then check the column again. Reverse a temporary disablement through the same dialog after maintenance.
Change the software scope
Select devices and open Actions > Manage software. On computers already protected or managed by Sophos Fusion, Protection, Encryption, and ZTNA are available according to the license; servers offer Protection only. For Protection, Do not change preserves the current protection, while Uninstall current protection removes protection components but leaves the Sophos Core Agent required for communication and policy management. On computers, Encryption offers Install, Uninstall, or Do not change; ZTNA offers Install or Uninstall.
Caution: Adding or upgrading Agent Mode installs Sophos protection and removes existing third-party protection. XDR Sensor, by contrast, does not install Sophos malware protection. Confirm the license, intended outcome, and pilot group before Start job.
Select Start job, track progress under Jobs running, then check Agent mode status, Agent mode installed, Encryption, and ZTNA where applicable. If the outcome is unexpected, do not expand to the fleet. Verify the selection and license, then choose the previous supported software scope in Manage software.
Reset health status
Select devices, then choose Actions > Reset health status and Start job; track the job under Jobs running. Reset health status is a diagnostic aid, not a repair. It clears local threat alerts so devices can report their current state again and does not change protection. It is unavailable for Macs.
Online devices update in the list after a few minutes. Offline devices do not change. If a device remains red or soon returns to bad health, an active threat or broken Sophos installation remains; investigate device details and events instead of repeatedly resetting it.
Handle deletion and license expiry safely
Before Delete, confirm the owner, device identity, required alerts, Mobile enrollment, duplicates, and local removal plan. Only then select the devices and choose Actions > Delete device. Deletion removes the Sophos Fusion record and its associated alerts. A device enrolled with Sophos Mobile must first be unenrolled or it might become unusable. Do not delete a record shared by duplicates: the duplicates can then no longer communicate with or re-register with Sophos Fusion.
For Windows devices, Sophos describes the following behavior from Core Agent 2023.2 onward when a device is deleted in Sophos Fusion or its license expires: tamper protection is automatically disabled, installed protection components are removed, and protection ends. The remaining Sophos Endpoint Agent must be uninstalled separately on the device for complete removal. Update Cache and Message Relay are also removed. The password exception is separate: On Windows 10 or later and Windows Server 2016 or later, uninstalling Sophos software does not require recovering the tamper-protection password; this also applies to deleted devices and those with expired licenses. That OS-version threshold is not a condition for the deletion/expiry behavior described above.
A deleted device can be restored in Sophos Fusion within 30 days. After that, register or install the Endpoint Agent again. Following license expiry, recovery is possible within 90 days after activating a new license; afterward, registration or installation is also required. The supported Windows removal process is covered in Uninstall Sophos Central Endpoint on Windows.
Verify the outcome and isolate errors
A review is complete when the filtered scope is documented, every exception has an owner or ticket, and each change is visibly confirmed in a column or device detail. Use these distinctions when something is wrong:
- The device is missing: Use Reset to defaults to clear filters and check the correct name, operating system, IP address, or tag. Mobile devices are not in this list.
- Health does not change after a reset: The device must be online. Offline devices remain unchanged; active threats or broken installations report bad health again.
- The tamper-protection action is missing: Check the global setting and administrative role. Not applicable is expected on an unsupported operating system.
- A software action is unavailable: Check the license, device type, and supported product scope. Not every column or option applies to every operating system.
- A deleted device is needed again: Restore it in Sophos Fusion within 30 days; later, register or install the agent again. The license-expiry window is 90 days.
Monthly inventory review
- Review inactive computers and servers separately by lifecycle.
- Investigate bad Health through details and events.
- Classify Off and Not applicable tamper protection deliberately.
- Review Product unassigned, Upgrade available, and unsupported products.
- Assign an owner to missing or contradictory tags and groups.
- Check deletion candidates against Mobile enrollment, duplicates, and offboarding evidence.
- Validate changes on a small selection before expanding them.