Skip to content
Avanet

Plan Sophos Endpoint system requirements and lifecycle

An installed agent does not automatically remain supported in the long term. The operating system, architecture, Sophos components, certificates and licensing model evolve independently. Reliable Endpoint operations therefore check not only whether installation works today, but also when platforms leave support and how new agent versions are introduced.

Use current sources, not a static version list

Specific version numbers become outdated quickly. Always use three current Sophos sources for approval:

  1. System requirements for Windows or macOS.
  2. Release Notes for the affected Endpoint components.
  3. Retirement Calendar for platforms and operating systems.

This KB explains the process and deliberately avoids a seemingly permanent list of all supported builds.

Sophos distinguishes between Maintenance and Retirement. Maintenance normally ends 12 months before the retirement date and marks the end of new features for the platform. During approximately the final three months before Retirement, software changes are generally no longer planned either. Protection Updates can continue until the stated final support date. A device therefore becomes a lifecycle risk before the final calendar day.

Assess Windows platforms

For Windows, check the edition, 32-bit or 64-bit architecture, ARM, patch level and root certificate store. Older platforms may be classified as Legacy and require an Extended Support licence. Legacy systems may lack functions, fixes or component updates even while the agent remains installed.

Current Sophos guidance from May 2026 distinguishes between Endpoint protection alone and EDR, XDR or MDR:

ResourceSophos EndpointEDR, XDR and MDR
Free disk spaceminimum 4 GB, recommended 8 GB8 GB
Memory4 GB16 GB
CPU cores24

Sophos explicitly recommends an SSD for the system drive. Temporary load peaks during Threat Case creation and Sophos Clean remediation are normal; Threat Case creation can occupy up to one complete core on a typical four-core notebook. Treat these figures as planning guidance and test them with the organisation’s own software load before broad rollout.

Approve Windows 10 and Windows 11 on ARM64 only according to the current platform matrix. Windows Insider Preview builds are unsupported. Azure Code Signing requires the corresponding cumulative Microsoft updates and Microsoft Identity Verification Root Certificate Authority 2020 in the local computer certificate store. Without ACS, a new installation or Core Agent upgrade can fail even though existing protection initially continues.

Full Protection and Sensor Mode use the same resource guidance. Sensor Mode is unsupported on legacy platforms.

An approval decision documents:

  • Windows version and Microsoft end-of-support date,
  • Sophos support status and required additional licence,
  • available agent components for the architecture,
  • known limitations,
  • planned migration or replacement date.

Assess macOS platforms

On macOS, functionality is affected not only by the operating-system version, but also by Apple Silicon, System Extensions, Network Extensions and privacy permissions. Test an upgrade to a new major macOS version on a pilot Mac with the current MDM profiles.

Release Notes can contain time-critical information, for example that a fresh installation is no longer possible on an older macOS version while existing devices continue in a different state. Do not derive such distinctions from a general statement that “macOS is supported”.

Components, not one agent version

Sophos Endpoint consists of several components, including AutoUpdate, Endpoint Defense, Health Service, Management Communication, Network Threat Protection, Endpoint UI and other licence-dependent modules.

The product stage visible in Central and one local version number therefore do not describe the complete state. When troubleshooting, search the Release Notes for the affected component.

Treat HDD systems as technical debt

Sophos explicitly recommends SSDs rather than rotating HDDs for the system drive. On older HDD devices, Event Journals, Scheduled Scans and Deep Scanning can substantially increase I/O latency. Put these systems in a separate pilot or exception group instead of lowering protection for every endpoint.

First establish disk health, queues, free space and the Sophos process actually causing the load with Performance Analysis. If a scheduled scan remains necessary, disable Enable deep scanning for the affected HDD group and move the scan window.

Disabling Event Journals has much greater consequences: Threat Graphs disappear, Live Discover and Data Lake are restricted and Forensic Snapshots are unavailable. MDR customers must not disable them because MDR Operators lose visibility, and Account Health Check marks the configuration as not recommended. Replacing the system drive or device remains the sustainable action.

Check third-party compatibility before rollout

Two installed security or injection products are not automatically compatible. Acronis Cyber Protect Agent with DeviceLock Redirection and Sophos Endpoint 2023.1 or later can cause a black screen during Windows sign-out. Sophos classifies the combination as incompatible; remove the Acronis Agent.

Final Code Encryption can also deadlock Microsoft applications through suspended threads. Prefer removing it or applying its vendor fix. Disabling Protect Office Applications in the Sophos Threat Protection policy reduces protection and is at most a targeted, time-limited transition.

Do not hide these cases with global exclusions. Pilot groups must also include encryption, DLP, backup, remote-control and application-allowlisting products that deeply affect processes or file access.

Understand phased releases

Sophos sometimes publishes Release Notes on the first day of a rollout that lasts several weeks. A documented new version may therefore not be available immediately to every tenant or Endpoint.

This prevents two misinterpretations:

  • A device is not automatically out of date because it has not received the new version on release day.
  • A manual reinstall does not reliably force a software stage that has not yet been released to that device.

Pilot and production stages

Software Packages and Update Management Policies support controlled stages. A practical model consists of:

  1. Pilot: IT and representative devices receive new versions early.
  2. Early production: a small production cross-section after a successful pilot.
  3. Production: broad release after defined observation criteria are met.
  4. Fixed term or LTS: only for justified stability requirements and with expiry monitoring.

Do not treat a Fixed-Term package as a permanent “old version”. Sophos defines minimum durations and overlaps; expiring packages must be replaced in time.

Recommended updates product versions automatically and does not expire. Fixed-term support (FTS) holds a release’s feature level while continuing protection content during its validity; Sophos guarantees at least 120 days of availability and 60 days of overlap with its successor. Long-term support (LTS) expires 18 months after release. This choice controls product releases, not ongoing security-content updates. After FTS or LTS expires, Sophos does not force an automatic move. The endpoint retains its existing protection level but no longer receives new Protection Updates.

A Maintenance Release (MR) is a Special Package based on the current Recommended version with specific fixes. Add it under Global Settings > Products & Services > Endpoint & Server > Software packages using the current Sophos token, then assign it only to a bounded Update Management policy. Return devices to Recommended when the fix is incorporated. Do not copy MR tokens and versions permanently into a runbook because they expire; failing to switch packages in time can end current Security Updates.

Extended Support is transitional

Legacy platforms require an additional Sophos Endpoint for Legacy Platforms licence from the date specified by Sophos. Without it, new installations and updates fail; purchasing it automatically resumes updates for existing eligible devices. Extended Support continues technical support, Security Updates and selected critical fixes, but does not guarantee new features or every fix.

Since April 2026, this includes several old Windows and Linux generations such as Windows 7, 8.1, Server 2008 R2/2012, RHEL 7, CentOS 7, Oracle Linux 7, Debian 10 and older Ubuntu or SUSE lines. Check the current Retirement Calendar for the exact list and dates before a licence decision. macOS has no Extended Support.

For term licences, license Extended Support per user or device. In MSP Flex it is a site licence; MDR Complete includes it only for monthly or Flex accounts, not automatically for term accounts. A long-inactive legacy device can still consume a licence when assigned to an active user. Review and remove inactive objects deliberately rather than merely filtering them from view.

Plan restarts

Sophos does not always force an immediately required restart. Protection and Detection updates can continue while a component waits for the next maintenance restart.

Devices that have not restarted for a long time can require several consecutive update states, each followed by another restart. Allow enough time between cycles for the first update to be processed completely. Recheck Central Alerts and local software status after each restart.

Early Access Programs

An Early Access Program is not a normal production channel. Before joining, define the purpose, target devices, expected changes, support route, exit plan and privacy implications.

EAP devices belong in a clearly named pilot group. After leaving, verify when they return to the regular software version. Do not enable an EAP on critical devices merely to bypass one problem without root-cause analysis.

Monthly lifecycle review

A useful operational rhythm includes:

  • reviewing new Endpoint and Central Release Notes,
  • comparing the Retirement Calendar with platforms in use,
  • exporting devices by operating system, architecture and Agent Mode,
  • assigning an owner to Legacy and inactive devices,
  • checking expiring Fixed-Term or LTS packages,
  • resolving restart and update Alerts,
  • documenting pilot results.

The technical update architecture is explained in Sophos Endpoint updates, Cache and Message Relay.

Frequently asked questions

Why has an Endpoint not received the new version despite published Release Notes?

Sophos often rolls out software over several days or weeks. Release Notes can appear on the first day. The tenant, package stage and Update Policy determine when a device receives it.

Is an installed agent on Legacy Windows automatically fully supported?

No. A Legacy platform may require an Extended Support licence and still not receive every new function or fix. Its current support status must be checked explicitly.