Skip to content
Avanet

Completely remove Sophos Server Protection from Windows

Completely removing Sophos Server Protection involves three separate tasks: release the protection controls in a controlled manner, uninstall the software locally, and validate the result after a restart. Only then should you clean up the server record in Sophos Fusion (formerly Sophos Central). Deleting the record is not a remote uninstall.

Security boundary: The server loses its existing protection during removal. Do not start the maintenance window until the backup, console access and replacement protection are ready. If removal remains incomplete, do not delete MSI packages, drivers, services, folders or registry keys on suspicion.

Quick procedure

  1. Record the server, Sophos Fusion tenant, Windows version, Core Agent version and installed Sophos products.
  2. Check Server Lockdown on the correct host. If Server Lockdown is installed, unlock the server in Sophos Fusion, remove Lockdown locally with the Sophos command below, and plan the required restart. If the status is unclear or a step fails, stop and contact Sophos Support.
  3. Turn off Tamper Protection for this server and allow the change to synchronise locally.
  4. Remove separately protected ZTNA, Device Encryption, or MDR software first through Sophos Fusion’s Install or uninstall software workflow.
  5. Resolve dependent roles and products, and prepare the replacement protection.
  6. Run SophosUninstall.exe as a local administrator only after Lockdown removal has been resolved and Tamper Protection is off.
  7. Restart Windows and validate complete local removal.
  8. Only then delete the obsolete server record in Sophos Fusion or protect the server again.

Scope and prerequisites

This procedure applies only to an existing Sophos Server Protection installation whose exact Windows Server edition, full build, architecture, Core Agent version, and required components are approved at the time of removal. It neither sets Windows Server 2016 as a fixed minimum nor treats an installed agent as proof of support. Before removal, document approval using the Server Protection platform-approval procedure, checking the current Server Protection requirements and lifecycle entries. If the exact entry is missing, the sources conflict, or they are unavailable, do not uninstall until Sophos Support has clarified eligibility for that server.

Do not apply this command unverified to older server operating systems, unsupported agents or product-specific appliances. Use the current Sophos procedure for that platform and agent version, or open a support case. This guide removes Sophos Server Protection; it does not cover removing Sophos Firewall, Sophos Connect, SafeGuard, PureMessage or other standalone Sophos software.

Before starting, provide:

  • local administrator access and working console or out-of-band access
  • a current backup and tested recovery path
  • an announced maintenance window that includes a restart
  • access to the correct Sophos Fusion tenant
  • recorded Server Lockdown and Tamper Protection status
  • an inventory of installed Sophos components and server roles
  • prepared replacement protection, or an approved and time-limited unprotected window

This guide makes no blanket vendor compatibility claim for combinations with other security software. Inventory the actual products and versions, pilot that combination on a representative machine, and escalate anomalies with logs to the vendors involved. An unverified coexistence assumption does not replace that test.

If ZTNA, Device Encryption, or MDR is separately protected on the server, use the current Sophos Fusion Install or uninstall software workflow for that product before removing the Endpoint Agent. Do not treat the agent command as an override for separate product protection.

Release protection controls in Sophos Fusion

Check Server Lockdown

Server Lockdown protects the defined system state and can block removal. The server status in Sophos Fusion shows the Lockdown state and the Unlock function for previously locked servers. Complete removal requires unlocking, local removal of Server Lockdown, and a restart as separate steps. Migration to Unauthorized File Protection is a separate task, not a prerequisite for complete removal here.

Server Lockdown reaches end of support in October 2026. Since March 3, 2026, the feature has no longer been available to Sophos Central tenants that did not previously use it. For Lockdown components already installed, use the following removal procedure.

Before any change, match the tenant, server name, operating system, last contact and local Lockdown state to the target host. For older installations, use the Legacy device list if necessary. If Server Lockdown is installed, remove it as follows:

  1. Select the correct server under My Products > Server > Servers, click Unlock and confirm with Unlock. Verify that the unlocked status has taken effect. Unlocking does not remove the product.

  2. Open Command Prompt as administrator on that exact server and run this Sophos command unchanged:

    MsiExec.exe /X{77F92E90-ED4F-4CFF-8F60-3E3E4AEB705C}
    

    Confirm any prompts during removal; record the progress and return code. This targeted MSI command removes Server Lockdown, not Sophos Endpoint Agent or arbitrary other MSI components. It is not general approval for manual MSI cleanup.

  3. Restart Windows during the maintenance window so the Lockdown product can be deleted, then recheck the local installation and Lockdown status in Sophos Fusion. The restart need not immediately follow the command, but is required for complete removal. For this full removal procedure, validate it before allowing the agent-uninstall step. An unlocked console status or completed MSI process alone does not prove local removal.

If Lockdown is not installed, skip this component branch and record the finding. If the host or Lockdown state is unclear, Unlock is unavailable, the status does not change, or local removal or post-restart validation fails, do not proceed with SophosUninstall.exe, SophosZap or individual cleanup. If Unlock is unavailable or ineffective, first check the tenant, administrator role, network connection and last contact; then preserve the status and logs and refer the specific case to Sophos Support.

Turn off Tamper Protection

In the same server details, scroll to Tamper Protection. Turn it off for this device, or use the displayed device-specific password to sign in to Sophos Admin in the local Sophos interface. This is not the Windows local-administrator password. Then confirm locally that Tamper Protection is actually off.

The complete standard procedure is in Disable Sophos Fusion Tamper Protection safely. A password-free removal is not a general promise. It is documented only for Core Agent 2023.2 or later on Windows Server 2016 or later when the device was deleted from Sophos Fusion or its licence expired: Tamper Protection is turned off, installed protection components are removed, protection stops, and any Update Cache or Message Relay is removed. Sophos Endpoint Agent remains installed and still requires the local uninstall in this guide. Do not infer this branch for older agents, older Windows Server versions, macOS, or Linux.

The recovery windows also differ: a deleted device can be restored in Sophos Fusion for 30 days after deletion; after that the agent must be reinstalled. An expired device can recover when a new licence is activated within 90 days of expiry; after that the agent must be reinstalled. These windows concern Sophos Fusion recovery, not proof that the residual local agent was uninstalled.

Keep the server in Sophos Fusion until local validation succeeds. This preserves its state, password, alerts and diagnostics for recovery or escalation.

Run the standard uninstall

Only when an installed Server Lockdown has been removed and checked after its required restart as described above (or shown not to be installed), and Tamper Protection is demonstrably off, should you follow the documented standard Endpoint Agent uninstall. The Lockdown MSI command does not replace this agent uninstall. Complete or control any running installations, updates and pending restarts before proceeding. Then open Command Prompt as administrator.

For an interactive uninstall, run:

"C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe"

For controlled unattended deployment, the same uninstaller can run silently:

"C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe" --quiet

--quiet suppresses only the user interface, not the prerequisites. The deployment system must capture the return code, start and end times, and any required restart. A process ending does not by itself prove complete removal.

Restart Windows after completion. Do not delete the server from Sophos Fusion or make parallel manual cleanup changes during this process.

Validate complete removal

After the restart, validate the local target state:

  • Sophos Endpoint Agent is absent from installed applications.
  • Any previously installed Server Lockdown is no longer locally installed after its separate MSI step and restart; its status in the correct Sophos Fusion server record has been checked.
  • The local Sophos interface is gone.
  • Sophos protection services belonging to the removed Server Protection scope are no longer running.
  • No further Sophos restart or uninstall process is pending.
  • Windows Security shows the intended protection provider.
  • Replacement protection is active, current and reporting without errors.

A remaining folder alone proves neither an active installation nor a failed uninstall. Registered applications, running protection components, Windows security status and logs are decisive. If other Sophos software intentionally remains, assess only components belonging to the removed product.

Only after this validation should you select the obsolete record under My Environment > Computers & Servers and remove it with Delete. Preserve any required alerts and evidence first. If the server appears again, investigate software deployment, the golden image, RMM jobs and remaining management components rather than repeatedly deleting the record.

If the uninstall fails

Do not run SophosUninstall.exe repeatedly after an error. First preserve the return code, time, visible message, Windows version, architecture, Core Agent version, and Server Lockdown and Tamper Protection status. For current installations, the uninstall log is under C:\Windows\Temp\Sophos Endpoint Agent; also collect a fresh Sophos Diagnostic Utility (SDU) archive.

Complete a clearly pending restart in a controlled manner and assess the state once more. A general Update failed alert after the Lockdown MSI step can persist until its restart; it proves neither successful nor failed removal. If Lockdown remains installed afterward or its state is unclear, escalate before the agent uninstall. If the agent uninstaller is missing, Tamper Protection remains active or the installation is only partly removed, stop local standard remediation. Apart from the specific Lockdown MSI command documented above, do not manually remove individual MSI packages, drivers, services, folders or registry keys.

SophosZap is a heuristic last-resort cleanup tool only after the standard uninstall has failed or remained incomplete. Tamper Protection must be demonstrably off. If Lockdown is installed, its state is unclear, or binding product-specific prerequisites for its removal are missing, do not start SophosZap; this page does not establish Lockdown-specific approval for its use. Confirm prerequisites for the specific server against current SophosZap documentation and, where necessary, with Sophos Support. The section SophosZap only after a failed standard uninstall covers the download, stop list, restarts, log and success checks. If the prerequisites are not clearly met, hand the case to Sophos Support. Perform platform- and version-specific manual recovery steps only under current Sophos guidance.

For the Sophos Support case, provide at least the tenant and device identifiers, intended end state, Windows version and architecture, Core Agent version, installed Sophos products, Lockdown and Tamper status, exact command, return code, timestamps, uninstall log and SDU. Upload confidential archives only through the case’s designated upload facility.

Abort, rollback and restore protection

There is no automatic rollback for an uninstall. If you abort, record the actual software state, Lockdown and Tamper status, and any pending restarts. If the Endpoint Agent remains unchanged, check its protection and management functions; restore previously disabled Tamper Protection only through the documented device-specific procedure and verify it locally. Clicking Lock does not prove missing Lockdown software has been reinstalled.

If Lockdown has been unlocked, removed by MSI or possibly altered, do not assume that relocking, reinstalling Lockdown, or switching to Unauthorized File Protection provides an automatic recovery path. A restart may still be pending for complete removal. Keep available protection and management channels intact. Before making further changes, obtain current, explicit recovery steps from Sophos Support for the specific host and installed versions. If protection cannot be verified, keep the server isolated under incident and network procedures.

If the Endpoint Agent has already been removed and the server is to receive Sophos protection again, a fresh installation using a current installer from the correct Sophos Fusion tenant is a separate task. Then check the computer group, assigned policies, licensed products, update state, health state and alerts. This proves neither restoration of Lockdown nor migration to Unauthorized File Protection; obtain the applicable Sophos Support procedure first for an affected host.

If another protection product is taking over, prove that it works before deleting the Sophos record. If validation of both protection paths fails, isolate the server according to incident and network procedures until protection is restored or the case is escalated.

Frequently asked questions

Does Delete in Sophos Fusion remove the software from the server?

No. Delete cleans up the Sophos Fusion record. Uninstall the local software separately first and validate it after a restart.

Can Server Lockdown or Tamper Protection be bypassed for removal?

No. Release both states through supported Sophos Fusion or local procedures. If that is not possible, stop the local attempt and escalate with diagnostic evidence.

Does Unlock also remove the Server Lockdown software?

No. After unlocking, remove Server Lockdown locally with the Sophos MSI command above; a restart completes product removal. Uninstall the agent separately.

When can the server record be deleted?

Only after complete local removal has been validated and the intended replacement protection is active. Until then, retain the record for status, password, alerts and diagnostics.