Skip to content
Avanet

Systematically troubleshoot a failed Sophos Endpoint installation

This runbook covers a failed initial installation of Sophos Fusion Endpoint on Windows. The product is managed in Sophos Fusion (formerly Sophos Central). It does not replace the standard Windows or macOS installation guides or the automated rollout guide. Do not diagnose from the final error alone: first identify the phase where setup stopped, then correlate the first relevant installer-log message with the network and system state.

Quick way: Determine error phase

  1. Note the exact time with time zone, visible message and unchanged process status.
  2. Check whether SophosSetup.exe starts, completes the preliminary check, reaches Sophos Fusion, downloads components or only fails with one component.
  3. Save the Windows installer log for the attempt, C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller_<date>_<time>.log, and read from the first error in the relevant period.
  4. Check the cause in this order: supported and patched Windows, rights and pending reboot, DNS/HTTPS, proxy/TLS, existing security software, specific component.
  5. Only repeat once after a documented correction and then check local protection and registration in Sophos Fusion.

A numeric exit code table is intentionally not included here. The process status is recorded unchanged for the deployment or support ticket; the actual cause is determined with message, phase and log.

Preserve the log chain and volatile evidence

SophosSetup.exe first extracts into %temp% for the user that runs it and creates the timestamped SophosCloudInstaller_<date>_<time>.log under C:\ProgramData\Sophos\CloudInstaller\Logs. The thin installer then downloads SophosSetup_Stage2.exe. Stage 2 connects to Sophos Fusion with customertoken and mcscustomerid and installs the components licensed for the tenant. These identifiers are registration data: state their context in a ticket, but do not expose their values through an unprotected channel.

Before a restart, retry, user-context change, or cleanup, copy the complete CloudInstaller log for the failure period and the matching component logs from %temp% and C:\Windows\Temp. %temp% means the context in which setup actually ran; for a deployment running as SYSTEM, it is not the signed-in user’s temp directory. Filenames contain date and time, so do not search only for an undated file or select the newest file without matching timestamps. Do not assume a fixed rotation limit; preserve the complete matching set as evidence.

Prerequisites before any repair attempt

Before running again, the following points must be clarified:

  • The specific Windows version is listed in the current Sophos system requirements and is fully patched.
  • A local administrator account or a deployment context with the necessary elevated privileges is available.
  • A restart requested by Windows or another installer is complete. Parallel installation or update processes are terminated, not forcibly bypassed.
  • A fresh installer was loaded from the correct tenant under My Environment > Installers. Old or non-tenant copies will no longer be used.
  • The licence matches the required product scope. If full Sophos protection is planned, decide how existing protection software will be replaced.
  • The system date, time and time zone are correct; certificate checks and registration depend on them.

If the platform is unsupported, do not proceed with registry, certificate or installer bypasses. First bring the operating system to a supported level, or agree an explicitly supported approach with Sophos Support.

Symptom: Installer does not start or stops during pre-check

Save the installer locally and run it with the intended administrator privileges. Record the file source, tenant and download time. If the preliminary check reports an unsupported operating system, missing patches, a pending reboot or another running installer, correct that condition first.

Do not delete temporary files, installer registry keys or Sophos components speculatively. This can destroy the original evidence or make a partial installation worse. If the pre-check still fails after a normal restart and use of a fresh installer, escalate with the message and log.

Symptom: Download or connection to Sophos Fusion fails

For Endpoint, EDR, XDR and MDR, Sophos lists outbound port 443 for HTTPS and port 53 for DNS. The complete, current domain list on the Sophos page is authoritative; regional firewall rules can still override otherwise permitted targets.

The check is carried out from the same network and execution context as the installation:

  1. Does DNS resolve the Sophos address mentioned in the first error message?
  2. Do the firewall and web filter allow outbound HTTPS to the current Sophos domains?
  3. Does the installer use direct internet, system proxy, PAC or explicit proxy parameters?
  4. Can the proxy process the authentication method used and are the access data valid?
  5. Does TLS inspection by the firewall, proxy, VPN client or security software prevent certificate validation? Sophos connections must be able to validate the expected certificate.
  6. Does the Sophos Fusion communication check indicate an incident in Sophos Fusion during the exact error period?

A successful browser call is not enough: a software distribution often runs as SYSTEM and can use a different proxy and certificate path. With restrictive egress, implement the current official list rather than permanently allowing individual old hostnames copied from a ticket.

For a connection failure, read the first HTTP request, PAC discovery, selected proxy type, WinHTTP error or HTTP status, and the first failed system check as one chain in the CloudInstaller log. Cannot connect to Sophos Central is the summary, not necessarily the root cause. The installer supports PAC files, WPAD, and system proxies; explicit proxy settings must use the supported installer argument that applies to the actual execution context. If the path remains unclear, take a time-bounded packet capture during exactly one controlled attempt and handle it as sensitive data.

Symptom: A component cannot be installed

The CloudInstaller log separates connection errors from errors while downloading or installing a component. Around Failed to install product, inspect the preceding Trying to load setup.dll line, folder short name, and version. For example, if setup.dll loads from sed64, Sophos Endpoint Defense is the failing candidate; then read that component’s own installation log for the same period. The warning alone is not a root cause.

This mapping covers the modern components; * represents the timestamp in the filename:

Short namematching component log in %temp%
avremoveavremove.log
amsi64Sophos AMSI Protection Install Log *.txt
crtsetupSophos CRT Install Log *.txt
encrytionSophos Device Encryption Install Log *.txt
ui64Sophos Endpoint Agent Install Log *.txt or Sophos UI Install Log *.txt
sed64Sophos Endpoint Defense Install Log *.txt
efw64Sophos Endpoint Firewall Install Log *.txt
esh64Sophos Endpoint Self Help Install Log *.txt
sfs64Sophos File Scanner Install Log *.txt or SophosFSVerify Validator Log *.txt
shsSophos Health Install Log *.txt
hmpa64Sophos HitmanPro.Alert Install Log *.txt
liveterminal64Sophos Live Terminal Install Log *.txt
livequery64Sophos LiveQuery Install Log *.txt
mcsSophos Management Communications System Install Log *.txt
sme64Sophos ML Engine Install Log *.txt or Sophos ML Engine Validator Log *.txt
ntp64Sophos Network Threat Protection Install Log *.txt
sauxgSophos SAU Install Log *.txt
sdu64Sophos SDU Install Log *.txt
sse64Sophos Standalone Engine Install Log *.txt or Sophos Standalone Engine Validator Log *.txt

The processing order helps delimit the failure: a later component may simply not have been attempted yet.

Modern platforms:

  1. Third-party Security Software Removal
  2. Endpoint Uninstaller
  3. Endpoint Defense
  4. MCS
  5. Standalone Engine
  6. File Scanner
  7. Health
  8. UI
  9. AMSI Protection
  10. ML Engine
  11. Endpoint Self Help
  12. Live Terminal
  13. Endpoint Firewall
  14. Device Encryption
  15. Live Query
  16. Malicious Traffic Detection
  17. SDU
  18. HitmanPro Alert
  19. AutoUpdate

Legacy platforms:

  1. SDU
  2. Third-party Security Software Removal
  3. Endpoint Uninstaller
  4. Endpoint Defense
  5. MCS
  6. Standalone Engine
  7. Device Encryption
  8. File Scanner
  9. Sophos Clean
  10. Health
  11. UI
  12. ML Engine
  13. Endpoint Self Help
  14. Live Terminal
  15. Endpoint Firewall
  16. Live Query
  17. Malicious Traffic Detection
  18. HitmanPro Alert
  19. AutoUpdate

Correlate these sequences with timestamps; absence of a later log is not by itself evidence that the component failed.

Legacy platforms can use Setup rather than Install filenames. The exact workflow-relevant mappings in %temp% are:

Short nameLegacy filename
avremoveAvremove.log
sauxgSophos AutoUpdate Setup Log *.txt
ui64Sophos Endpoint Agent Setup *.log or Sophos UI Install Log *.txt
sed64Sophos Endpoint Defense Setup *.log
efw64Sophos Endpoint Firewall install log *.txt or Sophos Endpoint Firewall setup log *.txt
esh64Sophos Endpoint Self Help Install Log *.txt
sfs64Sophos File Scanner Install Log *.txt
shsSophos Health 2.8.213.0 Install Log *Z.txt
hmpa64Sophos HitmanPro Alert Initial install log *.txt
liveterminal64Sophos Live Terminal Install Log *.txt
livequery64Sophos LiveQuery Install Log 2*Z.txt
mcsSophos Management Communications System Install Log *.txt
mlSophos ML Engine Install Log *.txt or Sophos ML Engine Validator Log *.txt
ntp64Sophos Network Threat Protection Install Log *Z.txt
sduSophos SDU Install Log *.txt or Sophos SDU Setup Log *Z.txt
sse64Sophos Standalone Engine Install Log *.txt or Sophos Standalone Engine Validator Log *3.txt

Also collect Sophos CRT Uninstall Log *.txt, CRT Install Log *.txt, Sophos Device Encryption Install Log *.txt, and Sophos Device Encryption Setup Log *.txt from C:\Windows\Temp when their timestamps match. Do not infer the cause from a filename alone: Agent/UI logs the user interface and system-tray application, Endpoint Defense the enhanced tamper-protection module, MCS preflight and registration, Health configuration/preflight, CRT or avremove competitor removal, and validator logs their named checks. The MCS log can include the registration token and must be protected accordingly.

If third-party protection is present, the Windows installer tries to remove detected competing products by default when installing Sophos Anti-Virus. --nocompetitorremoval prevents this attempt, but is not a general promise of coexistence. Therefore, the product name, version, uninstallation status and required restart are checked. An outdated or only partially removed product will only be cleaned according to the manufacturer’s instructions. Sophos directories, services or drivers are not manually deleted on suspicion.

If the log names a specific Sophos component, the name, first error, and previous download or installer lines are collected. Do not try an unrelated service restart or third-party MSI command. The next step depends on the current Sophos KBA for that exact message or on guidance from Sophos Support.

Symptom: Setup ends but device is missing from Sophos Fusion

A local software copy does not prove that registration has been completed. Check the matching SophosCloudInstaller_<date>_<time>.log and contemporaneous MCS log for completed connection and registration. Then in Sophos Fusion, search for the expected computer name under My Products > Endpoint > Computers and check Group, Last Active, Health and installed products.

If the installer was used from an incorrect tenant, the device will not be “moved” by repeating it blindly. Tenant, installer source and possible existing device objects are clarified first. Registration and complete reinstallation are different repair cases.

Symptom: Device appears but is not protected

Open the Sophos shield locally. Status should show a green tick and Your device is protected; About lists the installed products and update state. If the status is red, open Open Endpoint Self-Help Tool and record the reported component or prerequisite text.

In Sophos Fusion, simultaneously check health, installed products, Last Active, open alerts and a requested restart. A device can be enrolled even though a component is missing. Conversely, a single missing historical Windows service does not prove an error because Sophos can change components between agent versions. The decisive factors are the expected licensed product scope, the current local status and the current Core Agent version.

Controlled retry and acceptance

Before the retry, the log and time window are saved, the cause is corrected and a required restart is carried out. Then a fresh installer from the same correct tenant is started locally and with the intended rights once. Automatic endless loops are stopped.

The attempt is only successful if all agreed criteria are met:

  • the installer no longer reports errors;
  • locally, Status shows the protected state and About shows the expected products;
  • the device appears under My Products > Endpoint > Computers in the correct tenant and in the expected group;
  • Health, Last Active, products and alerts match the target state;
  • a required restart is completed and the status remains stable afterwards.

If the same step fails again, it will not be started a third time unchanged. The error package is escalated.

Data for Sophos Support

Collect for a reproducible escalation:

  • Tenant and Sophos Fusion region, device name and affected user;
  • Windows edition, version, build, patch level and system architecture;
  • Error time with time zone, visible message, installation phase and unchanged process status;
  • installer source and download time, without attaching the installer, tokens or proxy passwords to an unprotected ticket;
  • C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller_<date>_<time>.log and the associated component logs from %temp% and, where applicable, C:\Windows\Temp;
  • network path used: location, direct connection, proxy/PAC, TLS inspection and relevant firewall/proxy events;
  • existing or recently removed security software including version and restart status;
  • screenshot or export of the local status and device object in Sophos Fusion;
  • a current Sophos Diagnostic Utility collection if support requests it.

Logs and SDU can contain hostnames, users, paths, IP addresses and configuration data. They are transmitted protected and checked in advance for publicly visible passwords, tokens and other secrets.

Appropriate installation instructions

For a single computer, follow Install Sophos Fusion Endpoint on Windows. For Apple-specific permissions and errors, see Install Sophos Fusion Endpoint on macOS. For software distribution, supported Windows parameters, pilot waves and exit-status capture, use Roll out Sophos Endpoint automatically on Windows.

Avanet maintains the current platform and lifecycle boundaries in Plan Sophos Endpoint system requirements and lifecycle. Domains, ports, proxy order and TLS inspection are covered in Sophos Endpoint network and proxy requirements. Sophos Endpoint services and logs on Windows explains version-dependent services and logs, while Diagnose Sophos Endpoint with Self Help and SDU covers the complete data collection workflow.