Check and safely update Sophos Connect Client
A Sophos Connect upgrade isn’t an update over the existing installation. Sophos documents the same approach for Windows and macOS: disconnect the active VPN, uninstall the current client, and then install the chosen package. Profiles, the installer, and the rollback path should therefore be ready before changing the first production client.
Find the installed version in Sophos Connect under three dots > About. The Windows and macOS guides cover first-time installation; this guide covers the version decision and controlled transition.
If you’re still choosing between IPsec, SSL VPN, and other remote-access methods, start with the remote-access comparison before selecting a client rollout target.
Choose the target version
Don’t automatically deploy the newest package widely. First compare the release notes, supported operating systems, and VPN functions actually in use. The latest editorial review of the Sophos release notes on 7 September 2026 found:
- Windows: Sophos Connect 2.5 MR1, released 18 June 2026.
- macOS: Sophos Connect 2.0 MR1, released 21 May 2026.
These versions are a review snapshot, not an indefinite approval. Read the current release notes again before a new rollout. Treat a newer release as a pilot version first. Keep an older release as the target only when the platform still supports it and there is a documented reason not to use the newer one. Don’t infer client-specific end-of-life dates from Sophos’s general product lifecycle page.
The following boundaries matter for the decision:
| Platform or function | Boundary |
|---|---|
| Windows 10/11, 64-bit | Sophos Connect 2.5 and later |
| Windows 10/11 on ARM | Sophos Connect 2.5 and later |
| Windows, 32-bit | ends at Sophos Connect 2.4; not a target for new rollouts |
| Windows 11 Enterprise Multi-session / Azure Virtual Desktop | unsupported |
| Entra ID SSO on Windows | Sophos Connect 2.4 or later and SFOS 21.5 or later |
| macOS on Intel or Apple Silicon | macOS Ventura 13 or later; Apple Silicon through Rosetta 2 |
| SSL VPN with Sophos Connect on macOS | Sophos Connect 2.0 and later |
.pro provisioning | Windows; unsupported on macOS |
Sophos Connect isn’t a client for iOS or Android. If a platform or function falls outside these boundaries, don’t deploy experimentally; define a migration path first.
The reviewed releases also contain fixes that can affect the decision. Windows 2.5 MR1 fixes, among other issues, startup for additional users (NCL-2570), incorrect SSO status after an internet outage (NCL-2783), inconsistent OTP prompts on reconnect (NCL-2992), and SSL VPN provisioning when certificates contain special characters (NCL-2795). macOS 2.0 MR1 includes fixes for SSL VPN DNS and restores saved credentials. An issue ID still doesn’t replace a pilot with your own profile.
Prepare the update and rollback
Record the following for each platform and user group before the maintenance window:
- installed client and operating system version;
- IPsec or SSL VPN and profile source (
.scx,.ovpn, or.pro); a.tgbfile, by contrast, is an export for third-party IPsec clients, not a Sophos Connect profile; - local, AD, RADIUS, or Entra ID SSO authentication;
- MFA and reconnect behaviour;
- profile dependencies such as gateway, certificate, DNS, VPN pool, and permitted networks.
Also retain the target package, the previously approved internal package, and the original profile sources in software distribution. A screenshot of a profile name isn’t a backup. A rollback requires the actual export that was used or a reproducible provisioning source.
Admins can obtain the installer under Remote access VPN > IPsec or Remote access VPN > SSL VPN with Download client; users can get it from the VPN Portal. Backup & Firmware > Pattern updates can refresh the download package on the firewall, but it doesn’t update installed endpoints. Verify the package’s source, platform, and version before deployment, and clearly block or label old packages.
Run a pilot
Include at least one device for every production combination. Don’t select only IT admins; include one to three typical users. Where applicable, cover Windows x64, Windows ARM, macOS with IPsec, macOS with SSL VPN, Entra SSO, and OTP/MFA reconnect separately.
Document a baseline test on every pilot device before the upgrade: sign-in, assigned VPN address, internal DNS resolution, access to a representative internal destination, split- or full-tunnel behaviour, and reconnect after a network change. Repeat exactly the same tests afterwards. This separates a client regression from a firewall, routing, or profile problem that already existed.
Start a phased broad deployment only after all expected combinations pass and the helpdesk knows the target version and rollback. One successful Windows test doesn’t approve macOS.
Remove and reinstall the client
Disconnect the active VPN before uninstalling. If the client is the device’s only remote administration path, arrange a local maintenance window or a second administration path: VPN access is interrupted during removal and installation.
Windows
- Under Control Panel > Programs > Uninstall a program, select Sophos Connect and start Uninstall.
- Wait for removal to finish. Don’t postpone a requested restart.
- Install the approved Windows target package with administrator rights.
- Open Sophos Connect and confirm the planned version under three dots > About.
- Check the existing profile or reimport it from the retained source, then run the pilot test.
Don’t roll Windows ARM back to a version before 2.5. Don’t update a 32-bit Windows endpoint to 2.5; it needs a platform migration plan.
macOS
If Sophos Endpoint is installed on the Mac, temporarily turn off its Tamper Protection before removal and turn it back on afterwards. Then open Terminal and run with administrator privileges:
sudo /Library/Sophos\ Connect/uninstall.sh
The expected confirmation is Sophos Connect has been uninstalled. Then:
- Restart the Mac if requested.
- Install the approved macOS package and approve the required system prompts.
- Open Sophos Connect and check the version under three dots > About.
- Provide the profile from the retained source and repeat the pilot checks.
- Turn Tamper Protection back on and verify its status.
A version before 2.0 isn’t a valid rollback for SSL VPN on macOS. After moving to 2.0 MR1, reimport the configuration if users need the restored saved-credentials option.
Handle profile changes separately
A client upgrade doesn’t automatically update every VPN configuration. For manually distributed IPsec .scx files, export and distribute a new file after changes to advanced settings. On Windows, an imported .pro file retrieves configurations through the VPN Portal. After changing the port or protocol under Remote access VPN > SSL VPN > SSL VPN global settings, the user clicks the profile’s gear icon and Update policy.
An SSL VPN profile is tied to the user identity, domain, and authentication method used during import. When moving, for example, from AD to Entra ID SSO or between domains, import a separate .pro or .ovpn configuration. Otherwise, Login failed. Wrong fingerprint of certificate. can appear. This restriction doesn’t apply to IPsec .scx profiles.
Make firewall-side changes with the guides for Sophos Connect with IPsec, SSL VPN remote access, or Entra ID SSO. Then return here and test the updated client/profile pair in the pilot.
Validate and approve the rollout
A displayed target version and a green connection status aren’t enough. Record these results for every pilot combination:
- target version under About is correct;
- sign-in and MFA or SSO behave as expected;
- the correct VPN address is assigned;
- internal DNS names and a representative destination work;
- the matching
VPNzone rule appears in Log Viewer; - split or full tunnel matches the intended design;
- reconnect after a network change, sign-out, and sign-in work.
If a test fails, stop deployment for that combination. First check the target version, OS boundary, and profile actually loaded. Then record the time, visible message, and matching entry under Events. Sophos Connect Client troubleshooting provides the systematic diagnosis for connection, DNS, authentication, policy, and service errors; this update guide deliberately doesn’t duplicate that symptom catalogue.
Roll back and escalate
A rollback temporarily restores service. It isn’t a permanent answer to an outdated or vulnerable client.
- Stop broad deployment and identify the affected platform/profile combination.
- Uninstall the failed client through the same documented path.
- Install only the previously approved package suitable for the platform.
- Reimport the retained profile source.
- Retest version, sign-in, VPN address, DNS, an internal destination, Log Viewer, and reconnect.
- Record the outcome and start another pilot only after the cause is understood.
If the rollback also fails, open three dots > About > Generate Technical Support Report. The report contains VPN configurations, connection events, and endpoint information, so handle it under your organization’s privacy rules. Include target and previous version, OS, profile type, timestamp, visible error, and rollback result in the escalation; never put credentials in a ticket.