Systematically troubleshoot a failed Sophos Endpoint installation
This runbook covers a failed initial installation of Sophos Fusion Endpoint on Windows. The product is managed in Sophos Fusion (formerly Sophos Central). It does not replace the standard Windows or macOS installation guides or the automated rollout guide. Do not diagnose from the final error alone: first identify the phase where setup stopped, then correlate the first relevant installer-log message with the network and system state.
Quick way: Determine error phase
- Note the exact time with time zone, visible message and unchanged process status.
- Check whether
SophosSetup.exestarts, completes the preliminary check, reaches Sophos Fusion, downloads components or only fails with one component. - Save the Windows installer log for the attempt,
C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller_<date>_<time>.log, and read from the first error in the relevant period. - Check the cause in this order: supported and patched Windows, rights and pending reboot, DNS/HTTPS, proxy/TLS, existing security software, specific component.
- Only repeat once after a documented correction and then check local protection and registration in Sophos Fusion.
A numeric exit code table is intentionally not included here. The process status is recorded unchanged for the deployment or support ticket; the actual cause is determined with message, phase and log.
Preserve the log chain and volatile evidence
SophosSetup.exe first extracts into %temp% for the user that runs it and creates the timestamped SophosCloudInstaller_<date>_<time>.log under C:\ProgramData\Sophos\CloudInstaller\Logs. The thin installer then downloads SophosSetup_Stage2.exe. Stage 2 connects to Sophos Fusion with customertoken and mcscustomerid and installs the components licensed for the tenant. These identifiers are registration data: state their context in a ticket, but do not expose their values through an unprotected channel.
Before a restart, retry, user-context change, or cleanup, copy the complete CloudInstaller log for the failure period and the matching component logs from %temp% and C:\Windows\Temp. %temp% means the context in which setup actually ran; for a deployment running as SYSTEM, it is not the signed-in user’s temp directory. Filenames contain date and time, so do not search only for an undated file or select the newest file without matching timestamps. Do not assume a fixed rotation limit; preserve the complete matching set as evidence.
Prerequisites before any repair attempt
Before running again, the following points must be clarified:
- The specific Windows version is listed in the current Sophos system requirements and is fully patched.
- A local administrator account or a deployment context with the necessary elevated privileges is available.
- A restart requested by Windows or another installer is complete. Parallel installation or update processes are terminated, not forcibly bypassed.
- A fresh installer was loaded from the correct tenant under My Environment > Installers. Old or non-tenant copies will no longer be used.
- The licence matches the required product scope. If full Sophos protection is planned, decide how existing protection software will be replaced.
- The system date, time and time zone are correct; certificate checks and registration depend on them.
If the platform is unsupported, do not proceed with registry, certificate or installer bypasses. First bring the operating system to a supported level, or agree an explicitly supported approach with Sophos Support.
Symptom: Installer does not start or stops during pre-check
Save the installer locally and run it with the intended administrator privileges. Record the file source, tenant and download time. If the preliminary check reports an unsupported operating system, missing patches, a pending reboot or another running installer, correct that condition first.
Do not delete temporary files, installer registry keys or Sophos components speculatively. This can destroy the original evidence or make a partial installation worse. If the pre-check still fails after a normal restart and use of a fresh installer, escalate with the message and log.
Symptom: Download or connection to Sophos Fusion fails
For Endpoint, EDR, XDR and MDR, Sophos lists outbound port 443 for HTTPS and port 53 for DNS. The complete, current domain list on the Sophos page is authoritative; regional firewall rules can still override otherwise permitted targets.
The check is carried out from the same network and execution context as the installation:
- Does DNS resolve the Sophos address mentioned in the first error message?
- Do the firewall and web filter allow outbound HTTPS to the current Sophos domains?
- Does the installer use direct internet, system proxy, PAC or explicit proxy parameters?
- Can the proxy process the authentication method used and are the access data valid?
- Does TLS inspection by the firewall, proxy, VPN client or security software prevent certificate validation? Sophos connections must be able to validate the expected certificate.
- Does the Sophos Fusion communication check indicate an incident in Sophos Fusion during the exact error period?
A successful browser call is not enough: a software distribution often runs as SYSTEM and can use a different proxy and certificate path. With restrictive egress, implement the current official list rather than permanently allowing individual old hostnames copied from a ticket.
For a connection failure, read the first HTTP request, PAC discovery, selected proxy type, WinHTTP error or HTTP status, and the first failed system check as one chain in the CloudInstaller log. Cannot connect to Sophos Central is the summary, not necessarily the root cause. The installer supports PAC files, WPAD, and system proxies; explicit proxy settings must use the supported installer argument that applies to the actual execution context. If the path remains unclear, take a time-bounded packet capture during exactly one controlled attempt and handle it as sensitive data.
Symptom: A component cannot be installed
The CloudInstaller log separates connection errors from errors while downloading or installing a component. Around Failed to install product, inspect the preceding Trying to load setup.dll line, folder short name, and version. For example, if setup.dll loads from sed64, Sophos Endpoint Defense is the failing candidate; then read that component’s own installation log for the same period. The warning alone is not a root cause.
This mapping covers the modern components; * represents the timestamp in the filename:
| Short name | matching component log in %temp% |
|---|---|
avremove | avremove.log |
amsi64 | Sophos AMSI Protection Install Log *.txt |
crtsetup | Sophos CRT Install Log *.txt |
encrytion | Sophos Device Encryption Install Log *.txt |
ui64 | Sophos Endpoint Agent Install Log *.txt or Sophos UI Install Log *.txt |
sed64 | Sophos Endpoint Defense Install Log *.txt |
efw64 | Sophos Endpoint Firewall Install Log *.txt |
esh64 | Sophos Endpoint Self Help Install Log *.txt |
sfs64 | Sophos File Scanner Install Log *.txt or SophosFSVerify Validator Log *.txt |
shs | Sophos Health Install Log *.txt |
hmpa64 | Sophos HitmanPro.Alert Install Log *.txt |
liveterminal64 | Sophos Live Terminal Install Log *.txt |
livequery64 | Sophos LiveQuery Install Log *.txt |
mcs | Sophos Management Communications System Install Log *.txt |
sme64 | Sophos ML Engine Install Log *.txt or Sophos ML Engine Validator Log *.txt |
ntp64 | Sophos Network Threat Protection Install Log *.txt |
sauxg | Sophos SAU Install Log *.txt |
sdu64 | Sophos SDU Install Log *.txt |
sse64 | Sophos Standalone Engine Install Log *.txt or Sophos Standalone Engine Validator Log *.txt |
The processing order helps delimit the failure: a later component may simply not have been attempted yet.
Modern platforms:
- Third-party Security Software Removal
- Endpoint Uninstaller
- Endpoint Defense
- MCS
- Standalone Engine
- File Scanner
- Health
- UI
- AMSI Protection
- ML Engine
- Endpoint Self Help
- Live Terminal
- Endpoint Firewall
- Device Encryption
- Live Query
- Malicious Traffic Detection
- SDU
- HitmanPro Alert
- AutoUpdate
Legacy platforms:
- SDU
- Third-party Security Software Removal
- Endpoint Uninstaller
- Endpoint Defense
- MCS
- Standalone Engine
- Device Encryption
- File Scanner
- Sophos Clean
- Health
- UI
- ML Engine
- Endpoint Self Help
- Live Terminal
- Endpoint Firewall
- Live Query
- Malicious Traffic Detection
- HitmanPro Alert
- AutoUpdate
Correlate these sequences with timestamps; absence of a later log is not by itself evidence that the component failed.
Legacy platforms can use Setup rather than Install filenames. The exact workflow-relevant mappings in %temp% are:
| Short name | Legacy filename |
|---|---|
avremove | Avremove.log |
sauxg | Sophos AutoUpdate Setup Log *.txt |
ui64 | Sophos Endpoint Agent Setup *.log or Sophos UI Install Log *.txt |
sed64 | Sophos Endpoint Defense Setup *.log |
efw64 | Sophos Endpoint Firewall install log *.txt or Sophos Endpoint Firewall setup log *.txt |
esh64 | Sophos Endpoint Self Help Install Log *.txt |
sfs64 | Sophos File Scanner Install Log *.txt |
shs | Sophos Health 2.8.213.0 Install Log *Z.txt |
hmpa64 | Sophos HitmanPro Alert Initial install log *.txt |
liveterminal64 | Sophos Live Terminal Install Log *.txt |
livequery64 | Sophos LiveQuery Install Log 2*Z.txt |
mcs | Sophos Management Communications System Install Log *.txt |
ml | Sophos ML Engine Install Log *.txt or Sophos ML Engine Validator Log *.txt |
ntp64 | Sophos Network Threat Protection Install Log *Z.txt |
sdu | Sophos SDU Install Log *.txt or Sophos SDU Setup Log *Z.txt |
sse64 | Sophos Standalone Engine Install Log *.txt or Sophos Standalone Engine Validator Log *3.txt |
Also collect Sophos CRT Uninstall Log *.txt, CRT Install Log *.txt, Sophos Device Encryption Install Log *.txt, and Sophos Device Encryption Setup Log *.txt from C:\Windows\Temp when their timestamps match. Do not infer the cause from a filename alone: Agent/UI logs the user interface and system-tray application, Endpoint Defense the enhanced tamper-protection module, MCS preflight and registration, Health configuration/preflight, CRT or avremove competitor removal, and validator logs their named checks. The MCS log can include the registration token and must be protected accordingly.
If third-party protection is present, the Windows installer tries to remove detected competing products by default when installing Sophos Anti-Virus. --nocompetitorremoval prevents this attempt, but is not a general promise of coexistence. Therefore, the product name, version, uninstallation status and required restart are checked. An outdated or only partially removed product will only be cleaned according to the manufacturer’s instructions. Sophos directories, services or drivers are not manually deleted on suspicion.
If the log names a specific Sophos component, the name, first error, and previous download or installer lines are collected. Do not try an unrelated service restart or third-party MSI command. The next step depends on the current Sophos KBA for that exact message or on guidance from Sophos Support.
Symptom: Setup ends but device is missing from Sophos Fusion
A local software copy does not prove that registration has been completed. Check the matching SophosCloudInstaller_<date>_<time>.log and contemporaneous MCS log for completed connection and registration. Then in Sophos Fusion, search for the expected computer name under My Products > Endpoint > Computers and check Group, Last Active, Health and installed products.
If the installer was used from an incorrect tenant, the device will not be “moved” by repeating it blindly. Tenant, installer source and possible existing device objects are clarified first. Registration and complete reinstallation are different repair cases.
Symptom: Device appears but is not protected
Open the Sophos shield locally. Status should show a green tick and Your device is protected; About lists the installed products and update state. If the status is red, open Open Endpoint Self-Help Tool and record the reported component or prerequisite text.
In Sophos Fusion, simultaneously check health, installed products, Last Active, open alerts and a requested restart. A device can be enrolled even though a component is missing. Conversely, a single missing historical Windows service does not prove an error because Sophos can change components between agent versions. The decisive factors are the expected licensed product scope, the current local status and the current Core Agent version.
Controlled retry and acceptance
Before the retry, the log and time window are saved, the cause is corrected and a required restart is carried out. Then a fresh installer from the same correct tenant is started locally and with the intended rights once. Automatic endless loops are stopped.
The attempt is only successful if all agreed criteria are met:
- the installer no longer reports errors;
- locally, Status shows the protected state and About shows the expected products;
- the device appears under My Products > Endpoint > Computers in the correct tenant and in the expected group;
- Health, Last Active, products and alerts match the target state;
- a required restart is completed and the status remains stable afterwards.
If the same step fails again, it will not be started a third time unchanged. The error package is escalated.
Data for Sophos Support
Collect for a reproducible escalation:
- Tenant and Sophos Fusion region, device name and affected user;
- Windows edition, version, build, patch level and system architecture;
- Error time with time zone, visible message, installation phase and unchanged process status;
- installer source and download time, without attaching the installer, tokens or proxy passwords to an unprotected ticket;
C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller_<date>_<time>.logand the associated component logs from%temp%and, where applicable,C:\Windows\Temp;- network path used: location, direct connection, proxy/PAC, TLS inspection and relevant firewall/proxy events;
- existing or recently removed security software including version and restart status;
- screenshot or export of the local status and device object in Sophos Fusion;
- a current Sophos Diagnostic Utility collection if support requests it.
Logs and SDU can contain hostnames, users, paths, IP addresses and configuration data. They are transmitted protected and checked in advance for publicly visible passwords, tokens and other secrets.
Appropriate installation instructions
For a single computer, follow Install Sophos Fusion Endpoint on Windows. For Apple-specific permissions and errors, see Install Sophos Fusion Endpoint on macOS. For software distribution, supported Windows parameters, pilot waves and exit-status capture, use Roll out Sophos Endpoint automatically on Windows.
Avanet maintains the current platform and lifecycle boundaries in Plan Sophos Endpoint system requirements and lifecycle. Domains, ports, proxy order and TLS inspection are covered in Sophos Endpoint network and proxy requirements. Sophos Endpoint services and logs on Windows explains version-dependent services and logs, while Diagnose Sophos Endpoint with Self Help and SDU covers the complete data collection workflow.