Skip to content
Avanet

Sophos Mobile: troubleshoot failed tasks and device synchronization

A Mobile policy appears not to have reached a device, a task remains pending, or the device shows an outdated state? A newer “Last active” timestamp confirms a device synchronization, not that every command was applied. First identify the affected task and its result; neither another task nor another synchronization automatically fixes the underlying error.

Scope and preliminary checks

This diagnostic path covers tasks in Sophos Mobile and Sophos Mobile Threat Defense. It is not a guide to the firewall Task Queue, reenrolling a device, or changing policy assignments. Known product issues are only a later, case-specific point of comparison, not the starting point for a general repair attempt.

Role and action boundary: Reviewing tasks and the archive as described below is read-only; use the access actually granted in the signed-in tenant. Sophos Mobile distinguishes Administrator, Helpdesk, and Read-only; being able to see a device or read a task does not automatically authorize Synchronize, Get log files, or Set log level. Before taking any such action, check the specific permission in the signed-in tenant and approval for that particular action. If permission is lacking, stay with read-only diagnosis and hand off to an authorized person. The general role categories do not establish specific permissions for Helpdesk actions.

Before investigating, record:

  • Tenant and edition, device/platform, ownership and management mode, and managed app (Sophos Mobile Control, Sophos Intercept X for Mobile, Sophos Chrome Security) or native MDM agent. The Threat Defense edition does not automatically include the full Mobile edition’s synchronization paths for Mac, Windows, or native iOS MDM.
  • Affected policy or task, target device and assignment, time of the change with time zone, last known good state, and the specific symptom on the device. Is one device affected, or several of the same type? Is there still network connectivity, and is the required app reachable?
  • Whether the task involves an installation, message, scan, or potentially destructive action. A message to managed devices is not a test of policy application. Scan for malware creates a scan task only for Android devices whose Intercept X for Mobile is managed by Sophos Mobile; in the full edition, this requires Sophos Mobile or Sophos Mobile Threat Defense. The scan result appears separately under Scan results, not in the “Last active” timestamp alone.

Identify the task and error using read-only checks first

  1. In Sophos Mobile Admin > Tasks, filter by task type and status and, if useful, sort by device name, package name, creator, or scheduled date. The task view shows unfinished and failed tasks as well as recently completed ones; it updates automatically. On the Task view page, use Refresh interval (in sec.) to select how often the task view updates. This value changes neither device synchronization nor its compliance intervals. Refreshing this view does not synchronize the device.
  2. Read the affected task’s status under State and open it using the Show magnifying-glass icon. The Task details page shows general task information and can be opened from both Tasks and Task archive. This information includes, for example, the device name, package name, and creator. The Details button, when available, instead opens the device commands. Record the sequence and timestamps of states, error codes, and any available device commands. Code 0 means no error was reported in this command view; other codes do not always have a description. After reviewing the device commands, select Back to return to Task details.
  3. For older completed or failed tasks, select Tasks in the sidebar to return to Task view, then open Task archive. Select Reload if needed. The detailed View task archive instructions describe the archive in both editions as showing all completed and failed tasks. The Monitor tasks overview, however, says “all tasks”. The documentation does not resolve this conflict, and it does not establish that unfinished tasks also appear in the archive. During your read-only review, check which tasks actually appear in your tenant; do not generalize those findings to other tenants. Reload refreshes the archive view, not the device.
  4. Compare the intended policy and the observed device state separately. In the full Mobile edition, Successful means commands were successfully executed or a package was installed. During initial setup of Sophos Mobile Control, the task must finish with Installed. This means the app was successfully installed and the device is now provisioned. In Sophos Mobile Threat Defense, Successful likewise means a package was installed or commands were successfully executed. Initial setup of Sophos Intercept X for Mobile, however, must finish with Installed. In that edition, Installed means Intercept X for Mobile was successfully installed and the device is now provisioned. Neither status replaces checking the actual intended effect on the device.

Delete only as an approved intervention, not as read-only diagnosis: In Tasks, use the Delete icon directly next to the affected task to delete that specific task, for example one that cannot finish and is blocking the device. In Task archive, the Delete icon next to a task removes it from the archive; to remove multiple archived tasks, first select them and then select Delete selected. Before any such step, check permissions and approval and preserve the required evidence. Deletion changes the task inventory and removes diagnostic evidence. It proves neither successful execution nor reversal of a device command that has already partly executed.

Quick triage: If the task is waiting for an app, user, or unlock, check that prerequisite first; for command errors, preserve the state sequence and Details; for Skipped or Unknown, clarify support for the action or the missing server status. Documented time limits apply only to the states named below.

Task status and next safe step

  • Accepted: The task has been created. Continue monitoring its progress; do not confuse this with device synchronization.

  • Started: The task has been started. This does not yet establish successful execution on the device.

  • In progress / Task bundle in progress: Execution of the individual task or task bundle is being prepared; monitor its progress.

  • Delayed / Not started: Delayed is waiting for other tasks; Not started is an unprocessed item in a task bundle. Check the preceding task’s progress; do not create a second identical task.

  • Will be retried: Connection to a third-party service such as a push or mail server is unavailable. Sophos Mobile retries this state every three minutes; after five attempts, totaling 15 minutes, the task fails. This is not a general deadline for policy delivery.

  • Notified: The app has been notified: Sophos Mobile Control in the full Mobile edition, Sophos Intercept X for Mobile in Threat Defense. If the relevant app does not respond within 72 hours, the task fails. Check app reachability and the user specifically; do not simply resend.

  • Waiting for user interaction / Device is locked: Wait for a user action or an iOS device to be unlocked, respectively; up to 72 hours before failure is documented for each of these states. Check the user and device specifically; do not simply resend.

  • Commands sent: Sophos Mobile has sent the task to the app: Sophos Mobile Control in the full Mobile edition, Sophos Intercept X for Mobile in Threat Defense. If the relevant app does not acknowledge receipt within 15 minutes, the task fails. Check the acknowledgment and task progress.

  • Result evaluation started: The app has received the task and is processing it: Sophos Mobile Control in the full Mobile edition, Sophos Intercept X for Mobile in Threat Defense. If the relevant app does not report success within 15 minutes, the task fails. Check task progress and the specific result.

  • Waiting for task completion: Installation has been sent to the device; completion can take time. Check installation status and actual device state separately.

  • Result incomplete, Task partly failed: Check missing individual results or specific command errors in Details, if available. Do not treat partial execution as either complete failure or complete success.

  • Result evaluation failed: Result evaluation could not be performed. Check the state and any available error details, and escalate the failed evaluation with that evidence; do not infer that a device command failed.

  • Failed (retry queued) / Task failed / Completely failed: Distinguish whether another attempt is queued, none will follow, or retry is impossible. Preserve the error code and preceding states; do not restart blindly.

  • Skipped / Unknown: The action is unsupported on the device, or no server status is available. Infer neither success nor an automatically defective device.

Each task status has a color code for its status category. The colors apply in both the task view and archive; always read the status name as well to determine its specific meaning.

Colors and status categories

  • Blue: Open: Accepted, Delayed, Will be retried

  • Yellow: In progress: Started, In progress, Task bundle in progress, Notified, Commands sent, Result evaluation started, Result incomplete, Waiting for user interaction, Waiting for task completion, Device is locked

  • Green: Success: Successful, Installed

  • Red: Failure: Result evaluation failed, Task partly failed, Failed (retry queued), Task failed, Completely failed

  • Gray: Other: Not started, Skipped, Unknown

Red therefore does not always mean that no further attempt will follow; green does not replace checking the effect on the device as described above. The app-related state definitions above distinguish Sophos Mobile Control in the full Mobile edition from Sophos Intercept X for Mobile in Sophos Mobile Threat Defense. Check the actual app and edition context; a status name alone does not establish that an app or action is available in that management mode.

Preserve relevant log evidence before intervening

After reviewing the task view and archive, decide whether the available states and error codes are enough to narrow down the issue or whether app logs are needed. Preserve required evidence before a manual synchronization, a new task, or a change in log level; if requesting logs is unauthorized or the recipient has not been approved, remain with read-only diagnosis and escalate using the information already available. Get log files is not mandatory in every case.

Preserve existing Android evidence: The user can view the local log in Intercept X for Mobile > Menu > Log; Delete erases it. Viewing existing entries is distinct from changing the log level.

On Android, Intercept X for Mobile records important events in its own app log in addition to the Android log. For background app activity, such as malware scans when other apps are installed, the user receives no direct feedback on the result. The local app log provides a detailed report of this activity, including when it ran and the relevant results. For diagnosis, view these entries and compare them with the observed activity. This is distinct from a scan task requested through Sophos Mobile and its Scan results; a local entry does not prove successful device synchronization or policy application.

Change and verify the log level for selected devices

Set log level controls how much log information the Sophos Mobile client collects on the device. The action applies to Android devices, iPhones, iPads, and Chromebooks with a Sophos Mobile client. It is not a general MDM command for devices without that client. Use a higher log level only with approval, a documented initial setting, and a restoration plan.

  1. In Sophos Mobile Admin, open Devices in the sidebar.
  2. Select one or more devices whose log level you want to change. Check the platforms before selecting multiple devices.
  3. Select Actions > Set log level.
  4. Select the required log level. Alternatively, select Device default to let users set the log level on the device themselves.

Available levels depend on the platform; in each list below, the amount of information logged increases from left to right:

  • Android: Error, Warn, Info.
  • iPhone/iPad and Chromebook: Error, Warn, Info, Debug, Trace.

For a mixed selection of Android and other supported devices, Sophos Mobile excludes the Android devices from the action if Debug or Trace is selected. Sophos’s recommendation to enable Trace before requesting logs therefore cannot be applied to Android through this action. This says nothing about locally available logs or their levels.

Check the override: Open the individual device under Devices and check client.log.level.serverOverride on Show device > Internal properties. It shows a configured server-side override, not necessarily the effective local log level. In particular, with Device default, check the local setting separately. Do not treat an excluded Android selection as a successful change. After diagnosis, restore the documented initial setting as approved and check the override again.

Request logs remotely

In Sophos Mobile Admin, open Devices in the sidebar, click the target device and select Actions > Get log files on the Show device page. Alternatively, in Sophos Fusion > My Environment > Mobile Devices, open the device name and then Actions > Get log files. The action requests logs from all Sophos Mobile apps managed by Sophos Mobile on that device. On Android and iPhone/iPad, these are Sophos Mobile Control and Sophos Intercept X for Mobile; on Chrome devices, Sophos Chrome Security. It is neither an arbitrary single-app export nor necessarily a device-wide log; Windows and Mac are not documented for this action. Sophos Mobile emails the files to the requesting administrator. Request them only with approval, an approved recipient, data minimization, and secure storage.

iPhone/iPad – open the appropriate app within 72 hours: After the Fusion action, the user must open Sophos Mobile Control according to the Fusion and full Mobile instructions. The separate remote retrieval instructions for Mobile Threat Defense instead require Intercept X for Mobile. In each case the window starts when the request is made; if the appropriate app is not opened in time, the request fails. Before requesting logs, determine which app is required for the actual management mode from the edition and the app actually managed; do not infer from the Fusion instructions alone that a Threat Defense-only device must have the SMC app. If the request fails, record the failure and clarify the edition, app, and reachability before another approved request; opening the app late is not evidence of a successful retrieval. On iOS, use Send log files in Intercept X only at the request of Sophos Support.

For Android Enterprise, the full Mobile edition also lets you request an Android bug report with diagnostic data from the whole device. In kiosk mode, this addition is unavailable if Show notifications is disabled because the user cannot confirm the required notification. Remote retrieval of managed app logs remains separate.

Export logs directly from the device

Local export is also possible for an app not managed by Sophos Mobile. In that case, export that app’s logs from the app itself; this does not give Sophos Mobile remote access. Export through Sophos Mobile Control, by contrast, collects the logs of all Sophos Mobile apps managed on the device.

Check restrictions before local export: In kiosk mode, users cannot send logs from Sophos Mobile Control; remote retrieval through Sophos Mobile remains possible. On Samsung devices, an assigned Knox container policy with Allow “Share via” disabled prevents export directly from the device. Do not extend this Knox restriction to remote retrieval or loosen it without review for diagnostic purposes.

Sophos Mobile Control on Android or iPhone/iPad

  1. Open Sophos Mobile Control and select Send log to Sophos in the app menu. This route collects logs from all Sophos Mobile apps managed by Sophos Mobile on the device.
  2. Select an email app and enter or check the sender and recipient. On Android, the user’s Google account is the default sender, and the IT contact configured in Sophos Mobile Admin is the default recipient. Find the IT contact under Setup > General > IT contact. Do not assume these Android defaults apply to iPhone/iPad.
  3. Send the email only after checking the actual addresses and approving the recipient. The menu name does not mean you should send the files to Sophos without checking.

Intercept X for Mobile on Android

  1. Open Intercept X for Mobile and select Settings > Send log to Sophos in the app menu. This export contains Intercept X logs, not automatically those of other managed apps. The function passes trace and log files to another app for sending.
  2. Select the email app and enter or check the sender and recipient. The default sender is the user’s Google account. The Mobile Threat Defense instructions additionally specify the configured IT contact as the default recipient; the full Mobile edition’s instructions do not specify a recipient default for this Intercept X export. Check the address displayed on the actual device instead of assuming the SMC default applies.
  3. Send the email only to the approved recipient.

Intercept X for Mobile on iPhone/iPad

  1. Open Intercept X for Mobile and, according to the Intercept X app help, select Settings > Send log files.
  2. Select Mail and check the sender and recipient addresses actually displayed. The Mobile manuals place Send log files under Settings > Diagnostics and specify the email address associated with the Apple Account (formerly Apple ID) as the default sender. The Intercept X app help specifies Sophos Support as the default recipient; the address can be changed if needed.
  3. Send to Sophos Support only at its request. For another approved handoff, change the recipient accordingly and only then select Send. These are also Intercept X app logs, not iOS system logs.

iOS system logs require separate collection on a Mac; app exports do not replace it. First confirm the device owner, authorization, recipient, and secure storage. With Apple Configurator installed, connect the iPhone/iPad to the Mac, double-click the connected device, and open Console. Reproduce only the authorized issue, save with Save, and inspect the file before handing it over. Xcode is an alternative; agree its version-specific collection procedure with support. Do not start device preparation, enrollment, or restoration as part of log collection.

Sophos Chrome Security

  1. Open Chrome and select Sophos Chrome Security in the extensions bar.
  2. Select About > Export log. Log files are saved in the device’s download folder, not automatically emailed.
  3. Check that the export exists in the download folder. Only then share it through the transfer method approved by the organization.

Check export and handoff

A prepared or sent email does not yet prove the approved recipient received the files. Have receipt of the required attachments confirmed; for Chrome, first check the saved export. If export or sending fails, record the error and the affected app and management mode. Do not bypass kiosk or Knox requirements as a supposed sync fix.

For exported files, Avanet recommends handling rules defined by the organization: Store downloads, attachments, and email copies only for the intended purpose, limit access to the responsible people, and clean them up through the approved retention and deletion process. This is a recommendation for your own copies, not a statement about a Sophos retention period or deletion of support-case attachments. Do not treat exports as guaranteed to be anonymized.

Check expected device synchronization

After reviewing tasks in Mobile Admin, go to the Mobile device page under Sophos Fusion > My Environment > Mobile Devices and compare Last active with the app, platform, and configured interval. Synchronization can be periodic, event-driven, or manual. For example, an event-driven synchronization occurs when Sophos Intercept X for Mobile detects a threat; this is distinct from a specifically requested scan task. Each synchronization restarts the next regular interval. Do not assume a universal 15-minute or 24-hour target for policy application.

  • On Android with Sophos Mobile Control, distinguish the server-side compliance rule Maximum interval between SMC synchronizations from the separate device-initiated interval under Setup > Google setup > Android > SMC app sync interval. Sophos Mobile sends a synchronization request to the device at the compliance rule’s interval; 24 hours is documented when no value is set. In addition, the device itself regularly initiates synchronization at the configured SMC app interval, even if it receives no notifications. For managed Intercept X for Mobile on Android, the compliance rule Maximum interval between Intercept X for Mobile synchronizations applies instead.
  • On iPhone/iPad with Sophos Mobile Control, the SMC rule applies (no value: 24 hours); with managed Intercept X for Mobile, the rule Maximum interval between Intercept X for Mobile synchronizations applies. For iPhone/iPad without a Sophos Mobile app, the full Mobile documentation names the rule Maximum interval between native MDM agent synchronizations (no value: 24 hours). Do not apply this native MDM variant to Threat Defense.
  • For Chrome Security, Sophos Mobile sends a synchronization request to the device at the interval of the compliance rule Maximum interval between Sophos Chrome Security synchronizations; the full Mobile documentation specifies 24 hours when no value is set. In addition, the device synchronizes itself every 24 hours, even if it receives no notifications. Macs are mentioned only in the full edition, with 24 hours.
  • For Windows in the full edition, distinguish the server-side compliance rule Maximum interval between native MDM agent synchronizations from the device-initiated interval under Setup > Microsoft setup > MDM polling interval. Sophos Mobile sends a synchronization request to the device at the compliance rule’s interval; this interval is 24 hours when no value is set. In addition, the device itself initiates synchronization at the configured polling interval, even if it receives no notifications. Changing the polling interval later does not reach devices already enrolled. Do not infer anything about current support for a particular Windows version from this.

Do not shorten intervals reflexively: according to Sophos, the default setting for the device-initiated Android SMC and Windows intervals is sufficient in most cases; do not infer a numerical default from this. More frequent synchronization increases battery, data, and server usage and does not replace error analysis.

Change the device-initiated interval only with approval

If diagnosis justifies an interval change, check permissions and approval first and record the previous value. This setting is separate from the server-side compliance rule:

  • Android with managed Sophos Mobile Control: Under Setup > Google setup, open the Android tab. In the SMC app sync interval section, select the approved interval from the Sync interval list and select Save.
  • Windows, full Mobile edition: Under Setup > Microsoft setup, open the MDM polling interval tab. Select the approved interval from the list and select Save. The new value does not apply to devices already enrolled; do not bypass this restriction by reenrolling a device as a sync fix.

Then reopen the relevant setting and compare the saved value. If approval requires restoring the previous value, follow the same settings path, select the documented initial value, select Save, and read it again. This confirms the saved configuration, not its application to a particular device. Continue checking Last active, task progress, and the specific effect on the device separately.

Targeted action and verification

Before a new request, preserve the state sequence and error codes, and request any needed logs as described above only when appropriate and approved. First establish the cause and authorization; for a compliance violation, address its cause first. Then request only the manual synchronization appropriate to the edition and device:

  • Administrator in Sophos Fusion: On the Mobile device page, select Actions > Synchronize. This initiates device synchronization; it does not yet confirm success.
  • User with Sophos Mobile Control: Pull down on the app dashboard.
  • Authorized user in the Sophos Central Self Service Portal: Sign in to the portal, open Mobile, select your own assigned device, and on its device page select Actions > Refresh data. The action is not available for certain device types; if it is absent or the device is not assigned to the signed-in user, do not substitute another action, but hand off to the responsible administrator. This initiates synchronization; it does not prove successful policy application.

If the device has been powered off for an extended period and has therefore not synchronized with the Sophos Mobile server, it is noncompliant in this scenario. As a result, email reception may be restricted, for example. Synchronization with the Sophos Mobile server is required for the device to become compliant again in this scenario. If the device is noncompliant for another reason, such as prohibited apps, first resolve the underlying cause. Then synchronize the device with Sophos Mobile to update its compliance status. This guarantees neither the immediate restoration of compliance nor the immediate restoration of email reception.

Decide by management mode, not by a blanket fix: If the SMC app is not responding, check its reachability and user action on the affected SMC device. For managed Intercept X for Mobile, check the Intercept X connection and its task result; do not assume an SMC dashboard exists. For native iOS MDM, Mac, or Windows, compare only the synchronization source documented for the full Mobile edition; do not apply the SMC app gesture to devices without that app. For Skipped, do not retry an action unsupported on that device. If a third-party service is unavailable or a retry is queued, wait for the state sequence or escalate with the specific error. Neither manual synchronization nor a scan or message substitutes for fixing a faulty policy or connection.

These actions are not read-only diagnosis and are not a universal “Force Sync” repair. Afterwards check both: Did Last active change as expected, and did the specific task and its commands succeed and produce the intended state on the device? If only the timestamp is newer, return to status and error analysis. If synchronization still does not occur, check reachability and the app/agent mode, and escalate with the preserved states rather than repeatedly sending requests.

Trigger and evaluate an Android malware scan

If the specific task is a malware scan, you need a license for Sophos Mobile (formerly Central Mobile Advanced) or Sophos Mobile Threat Defense (formerly Intercept X for Mobile). Device scanning is available on Android devices where Sophos Mobile manages Sophos Intercept X for Mobile. The license names alone do not establish that the app is actually managed on the target device; check this, permissions, and approval before taking the action.

  1. In Sophos Mobile Admin, open Devices in the sidebar.
  2. Click the device you want to scan.
  3. On Show device, select Actions > Scan for malware.

This creates a device-scan task and sends it to Sophos Intercept X for Mobile. Creating the task is not yet a scan result. To evaluate the result, open the Scan results tab on Show device. On devices whose Sophos Intercept X for Mobile is managed by Sophos Mobile, this tab shows the results of the last scan. Do not attribute an already displayed result to the new task merely because you have created it. Check task progress and the scan result separately; a newer Last active timestamp does not replace this evaluation. If no result appears, return to task and error checks rather than repeatedly requesting the scan.

If the scan detected a threat, access additional information from SophosLabs as follows:

  1. On the Scan results tab, click the displayed threat name.
  2. In the search results, select the entry whose title matches the threat name. This is usually the first result, but the matching title matters, not its position.
  3. The overview page for that threat opens in the Sophos Threat Center. Links on this page lead to further information.

Send a custom message to managed devices

Send message lets you send your own message text to managed devices, for example to coordinate a required user action. Check permissions, approval, and intended recipients beforehand. This remains a communication action, not a test of policy application.

Sophos Fusion: send a message from the device details

Messages cannot be sent to Windows computers or Macs. Before proceeding, check the platform of the target device managed by Sophos Mobile.

  1. In Sophos Fusion > My Environment > Mobile Devices, click the device name of the intended target device.
  2. At the top right of the device details, select Actions > Send message.
  3. Enter the required text in the message field. The message must contain no more than 500 characters.
  4. Check the approved target device and text before sending, then select OK. In Fusion, OK sends the message, not Finish from the separate Mobile Admin workflow below.

For this Fusion workflow, Sophos describes the message appearing in a notification window on the device. Users can read earlier messages in Sophos Mobile Control on Android devices, iPhones, and iPads, and in the Sophos Chrome Security extension on Chromebooks. The message history in the task-bundle context is described separately; its Threat Defense statement about Intercept X for Mobile does not establish additional message-history support for this Fusion action.

OK confirms neither delivery nor that the user has read the message. If the message requests a user action, confirm with the user that it was carried out, then check the affected task or intended device state. A message sent through this route does not prove successful policy application either.

Sophos Mobile Admin: send a message to selected devices

  1. In Sophos Mobile Admin, open Devices in the sidebar. The Devices page appears.
  2. Select one or more target devices and select Actions > Send message.
  3. Enter the required text in the Enter message dialog. The message must contain no more than 500 characters.
  4. Check the target selection and text before sending, then select Finish.

Finish sends the message; it does not confirm that the user has read it. If the message requests a user action, confirm with the user that it was carried out, then check the affected task or intended device state. Do not infer successful policy application from a sent message.

Escalate without losing evidence

For a support case, record a device identifier without unnecessary personal data, edition, platform/management mode, app, task type, state sequence with times and error codes, Last active, intended versus observed state, and actions already authorized. Match a known issue only when the Mobile product section, issue ID, platform, management mode, and specific symptom agree; also compare the version if the entry specifies one. The Sophos known-issues list is dynamic; its HTML response can contain unfiltered product sections. An entry without a version is only a lead for Support, not proof that the device is affected. In particular, an issue with synchronization of network logs is not automatically an issue with synchronization of policies or tasks. The list is not a blanket repair procedure and in particular does not justify a restart as a general sync fix. For general handoff, see Open a Sophos support ticket.

Open the current Sophos Mobile known-issues list at this action point and select the Sophos Mobile section; also check Fix version and Workaround for the matching entry. The following snapshot from October 7, 2026 supports diagnosis, not a claim about every current tenant: SMCIOS-895 describes a silent iOS trigger sometimes failing to start automatic background synchronization of Sophos Mobile Control; for a matching case, users should synchronize the app manually and then check app and task states separately. SMCSRV-13893 concerns Send message in an enrollment task bundle: delayed APNS/FCM information can cause the failure; the captured snapshot had no available workaround. SMCSRV-13803 concerns some Windows 10 devices: WNS push registration expires after 30 days, renewal can return old invalid registration data and thereby prevent push notifications for synchronization of the built-in MDM agent; no workaround was listed for this either. Before making changes, confirm current applicability, fix version and the action with Support. Do not infer a new network allowance, blanket restart, reenrollment or device wipe from these cases.

Stop before intervening: Do not delete tasks or archive evidence as a standard diagnostic step; do not use reenrollment, profile removal, device wipe, reset, restart, or certificate/Wi-Fi changes as a blanket “sync fix.” If there is no recovery path, the device passcode is unknown, or there is only one Wi-Fi connection, involve the device owner and Sophos Support first. For changes to an interval or log level, record the previous setting and restore it deliberately only with approval; then check the device and task again independently.