Connect Sophos Mobile Threat Defense to Microsoft Intune
This draft does not authorize a production change to access controls or the connector. The Sophos Mobile Threat Defense (MTD) connector links the device status determined by Sophos Intercept X for Mobile to Microsoft Intune. Intune evaluates that status in a device compliance policy; a separately configured Conditional Access policy can deny noncompliant devices access to business resources. The connector neither removes malware itself nor replaces Intune MDM.
Do not confuse these workflows: Intune app protection policies in Sophos Mobile restrict app use based on the business user’s identity and can be used without device management. This article instead covers MTD for devices enrolled in Intune MDM. The existence of general Intune MTD switches for app protection or unenrolled devices does not mean this Sophos connector works in a MAM-only scenario.
Prerequisites and stop conditions
- The intended Android devices, iPhones, and iPads are enrolled in Intune MDM, not managed solely through Intune MAM. The Sophos MTD integration does not support unenrolled devices. Android devices with Intune’s Corporate-owned dedicated devices profile (such as kiosks) are excluded: the required user sign-in to Company Portal is not possible on those devices.
- Azure Government is not available for this direct Sophos–Intune MTD integration; this direct connector also does not support MAM instead of MDM. For both cases, Sophos describes a separate route: configure Intune as a third-party EMM to manage Sophos Intercept X for Mobile for Mobile Threat Defense. Connecting the app through an existing third-party EMM explains this management route and its prerequisites, particularly support for custom app settings and the license and platform requirements. This alternative is not a step in the direct connector workflow; do not infer that the direct connector supports Azure Government or MAM-only, that security status is transmitted to Intune compliance, or that Conditional Access is enforced. Do not run this app enrollment alongside a configured direct Intune MTD connection. Also stop if standalone app enrollment for Intercept X for Mobile has already been configured in Sophos Mobile; clarify the mode before changing it.
- Verify permissions and licenses in the specific tenant: Microsoft lists Intune Plan 1, Microsoft Entra ID P1, and Sophos Mobile Threat Defense. Sophos Mobile Threat Defense permits management of Intercept X for Mobile; the Sophos Mobile license includes MDM and Threat Defense. A Sophos Mobile Device Management license alone does not establish entitlement to Threat Defense. Admin access is required on the Sophos side. For Bind, an authorized Microsoft Entra administrator account must grant consent in the correct tenant. Microsoft lists the permissions Sign in and read user profile, Access the directory as the signed-in user, Read directory data, and Send device information to Intune; among other things, these allow device status to be transmitted and the Entra enrollment group to be matched. Check the actual consent screen before accepting and document the approval. To enable the Intune MTD connector, the Intune account performing the action needs RBAC permissions equivalent to the built-in Endpoint Security Manager role; for a custom role, these include Read and Modify for Intune Mobile Threat Defense. This Intune role does not replace permission to grant Entra consent.
- Microsoft still lists Android 7.0 or later and iOS 14.0 or later on its Sophos connector page for the integration. Separately, Intune requires Android 10.0 or later for the user-based Android Enterprise pilot described here: a work profile on a personal device, a corporate-owned work profile, or a fully managed device. This Intune prerequisite does not extend Sophos support to dedicated or userless devices, AOSP, or MAM-only. For the current Intercept X for Mobile app, however, Sophos lists iOS 15, iPadOS 15, or later. The integration prerequisite therefore does not establish app support on iOS 14. Before installation or enrollment, check the actual app version and OS applicability in the App Store for the target region and on the pilot device. Target devices need Intune Company Portal; iPhones and iPads additionally need Microsoft Authenticator. Do not assume another authenticator app can replace it in this Sophos workflow.
- Also check Intune support for iPhones and iPads. Microsoft currently lists iOS/iPadOS 18 or later as supported, both with and without user affinity. The separately listed permission to enroll from iOS/iPadOS 16 applies to devices without user affinity and does not guarantee full feature support. Intune requires iOS/iPadOS 17.x or later for app configuration; the iOS/iPadOS reference explicitly lists iOS 17.0 or later for Require the device to be at or under the Device Threat Level. These feature limits replace neither current Intune OS support nor the Sophos app prerequisites. Approve the pilot only with an OS supported for its enrollment mode; do not infer full Intune suitability from Sophos’s iOS 14/15 requirements.
- The owners of Intune compliance, Conditional Access, and Sophos Mobile agree on pilot user groups, an acceptable threat threshold, exceptions, a rollback path, and working emergency administrative access. Record existing access rules and device assignments before making changes. Do not assign a policy broadly before observing sign-in and the intended device status in the pilot.
- Before activation, record the existing MTD providers for each tenant and platform and their app and scan requirements. Microsoft recommends one provider per platform: if multiple providers are configured for the same platform, devices must install every associated MTD app and submit each app’s scan; a missing scan prevents the device from becoming compliant. Do not remove an existing provider without checking it or simply enable Sophos as an additional provider. Microsoft’s exception for Defender for Endpoint with separate compliance policies is not general approval for arbitrary provider combinations.
Set up the connector and pilot
This sequence follows the Sophos workflow: Sophos Mobile first, then Intune. Microsoft alternatively documents creating the connector in Intune first and then binding it in Sophos. Do not mix the two sequences without control or create duplicate connectors.
- In Sophos Fusion > My Products > Mobile > Setup > Sophos setup > Intune MTD, select Bind. Sign in with the authorized Microsoft Entra administrator account, inspect the requested permissions, and only then consent.
- Set Owner (ownership type) and Device group for newly added devices. In the optional Mobile Threat Defense policy (Android) and Mobile Threat Defense policy (iOS) fields, select the Sophos default policies for Intercept X for Mobile. These fields do not specify Intune compliance policies; review their target audience and contents in the pilot first. Select Save. In its alternative setup workflow, Microsoft describes the Successful Integration message followed by the available Sophos connector in Intune as the success check. The message and correct tenant do not yet confirm an app scan or transmitted device status.
- In Microsoft Intune admin center > Tenant administration > Connectors and tokens > Mobile Threat Defense, select the Sophos connector or, if required by the interface in use, create it with Add > Sophos > Create. Before choosing switches, check MDM Authority = Intune; Microsoft lists this as a prerequisite for the complete switch list. Investigate missing options by checking MDM Authority, connector permissions, and partner-specific support first, not by changing the management authority without review. After binding, enable and save only the Compliance policy evaluation options actually intended for the supported pilot platforms. Check Connection status and Last synchronized time. Available means configured, but not necessarily enabled for a platform; Enabled means at least one platform switch is active, not that device synchronization has been demonstrated. Microsoft’s general switches for app protection, inventory sharing, and the MTD role are not automatically Sophos-specific prerequisites: App Sync and Certificate Sync can share device data; Microsoft currently identifies certificate synchronization as supported only for another partner. Do not enable them preemptively. In particular, sharing the app inventory of personal devices requires a separate privacy decision.
- Add and assign Sophos Intercept X for Mobile for the pilot platforms as described below. Deploy the app before introducing a blocking compliance or Conditional Access rule. App configuration is optional and does not replace a completed connection on the device.
- Create compliance policies matching the actual enrollment mode and initially assign them only to the pilot user groups. Approve the threat threshold and actions for noncompliance separately; enable Conditional Access for the intended scope only after a positive pilot result.
Assess the optional Grant MTD role permissions to <MTD partner name> on enrolled Android COBO and COPE devices switch separately from compliance evaluation. Microsoft describes it for corporate-owned fully managed devices and corporate-owned work profiles enrolled through the Android Management API, not personal work profiles. Do not infer additional Sophos support for kiosk, AOSP, or MAM-only devices from this.
Google specifies different OS limits for the MTD role in the Android Management API. From Android 14, the MTD app is exempt from suspension, hibernation, and power and background-execution restrictions. The power exemptions described by Microsoft include app standby, starting foreground services from the background, and protecting those services from being stopped by users. From Android 11, user controls for the MTD app are disabled; users cannot clear app data or end the app with Force stop. These limits concern individual effects of the role, not the minimum version for the entire Sophos connector integration. Only one MTD partner per tenant may receive this role. Before enabling it, that partner’s connector must be configured and its MTD app assigned to a user or device group. This app assignment is not the threat rule described below, which supports user groups only. Enable the switch only if it is actually displayed for Sophos and its effects have been approved in the appropriate pilot. The actual role assignment and app effects have not been tested here.
Add the app and assign it to the pilot
The Android pilot described here uses Android Enterprise; a generic Android store entry is not the intake route for it.
- Android Enterprise: First check that the Intune tenant is connected to Managed Google Play. Under Apps > All Apps > Create > Managed Google Play app, search for the Sophos app and verify its fixed package identifier,
com.sophos.smsec. The corresponding store entry ishttps://play.google.com/store/apps/details?id=com.sophos.smsec. Add the correct app with Select, run Sync, and update the Intune app list with Refresh. If the app is missing or unavailable for the target devices, stop deployment and clarify app and mode compatibility; do not switch to an unverified APK or another management mode. - iPhone/iPad: Under Apps > All Apps > Create > iOS store app > Search the App Store, choose the appropriate country or region and search for the exact name Sophos Intercept X for Mobile. Select the actual Sophos result and, under App information, check Name, Publisher, Appstore URL, Minimum operating system, and Applicable device type. The display name must be unique; if names are duplicated, Company Portal shows only one entry. Set the minimum version according to actual app support and also check the Intune OS prerequisites, rather than simply copying iOS 14 from the connector page. A device below the configured minimum version will not receive the app. Add it through Review + create > Create.
For each app, add the intended pilot user group under Properties > Assignments. For deliberate self-installation, choose Available for enrolled devices if offered for the app and device mode; alternatively, choose Required for a targeted installation by Intune. Save the assignment and verify actual installation or availability on the pilot device. Required does not generally mean the app is hidden in Company Portal; required iOS store apps can also appear there. Available with or without enrollment does not extend Sophos support to MAM-only devices.
If an available app is missing from Company Portal, first check its assignment, the signed-in user and Primary user, and app/OS applicability. For Available for enrolled devices, the user signed in there must be the primary user who enrolled the device. On Android, also check synchronization and the managed store for the enrollment mode.
Optional app configuration
Optional configuration can, for example, start the connection wizard automatically or influence naming. Without Device name on Android or deviceName on iOS, Sophos Mobile uses the device name from Microsoft Entra ID. This naming fallback is available without additional configuration. For iOS, the Sophos documentation mentions deviceName in its naming note but does not list the key in its settings table. Before using such an optional naming configuration, clarify the data type and exact value or Intune variable using current manufacturer guidance; no executable deviceName configuration is provided here.
Under Apps > Configuration > Create > Managed devices, create a clearly named pilot entry, choose the platform, and under Targeted app > Select app, select the managed Intercept X app added earlier. Under Settings > Configuration settings format > Use configuration designer, set only settings documented for the target platform:
Android Enterprise: Use Add to select the fields offered by the actual app schema; check data types and values against that schema, rather than deriving them from iOS.
- Device ID: the EMM’s unique device identifier. Intune offers different ID variables; do not enter an Entra or Intune ID without checking it.
- Device name: the name Sophos Mobile uses when adding the device. You can optionally choose Value type > variable > User name for this. Check this deliberate user-based naming choice in the pilot; it is not a substitute for a unique device ID.
- EULA disabled: suppresses the end-user license agreement when the app starts. Use it only with separate legal or organizational approval.
- Connect to Intune: starts the Intune connection wizard automatically. This does not confirm successful enrollment. Check available Android types and defaults in the app schema.
iOS/iPadOS: The target must be an MDM-managed app; this configuration is not intended for DDM apps. Keys are case-sensitive:
eulaDisabled, Value type: Boolean, valuestrueorfalse, defaultfalse.truesuppresses the license agreement at startup and requires the same separate approval as on Android.startIntuneConnection, Value type: Boolean, valuestrueorfalse, defaultfalse.truestarts the connection wizard automatically; it does not establish a verified device connection.macAddress(String) is required only for the additional Synchronized Security feature; the device MAC address identifies it when connecting to a Sophos Wi-Fi access point. It is not a prerequisite for the basic Intune MTD connection.
Under Assignments, select only the pilot group and save through Review + create > Create. Then check the applied configuration status; for iOS/iPadOS, open Devices > All devices, then select the pilot device and App configuration. On the same device, check naming, identity, and behavior when the app starts. Do not add connection codes or keys from another enrollment procedure; a saved configuration alone does not prove it has been applied.
Set compliance for the platform and profile
Under Endpoint security > Device compliance > Create policy, choose iOS/iPadOS or Android Enterprise as the platform. On Android, select the Profile type matching the enrolled device: Personally-owned work profile or Fully managed, dedicated, and corporate-owned work profile. Despite the second UI label, dedicated devices remain excluded from this Sophos integration. If the pilot includes both supported Android profile families, it needs suitable separate Android policies; exactly one Android and one iOS policy will then not cover the entire pilot.
Under Compliance settings > Device Health > Require the device to be at or under the Device Threat Level, choose the approved threshold:
- Secured: no threats allowed. The current Microsoft references for Android Enterprise and iOS/iPadOS use this name for the strictest MTD threshold. Microsoft’s general MTD compliance guide calls the same no-threats threshold Clear. Check the label in the actual platform dialog; no tenant dropdown was observed here. This is a policy selection, not the
securedstatus transmitted by Sophos. - Low: only low threats allowed.
- Medium: low and medium threats allowed, but no high threats.
- High: all threat levels allowed; this option is for reporting, not a strict protection threshold. The MTD app must still be activated. Do not equate this with the Sophos status
activated(no scan yet, noncompliant).
These values determine the threat rule, not the final compliance status or resource access on their own. Under Actions for noncompliance, approve actions and deadlines, including possible blocking or retirement, separately. Under Assignments, assign suitable pilot user groups, then select Review + create > Create. Device groups are not supported for this threat rule. Verify the transmitted status as described below before enabling the separate Conditional Access rule.
Connect pilot devices
- Android with a work profile on a personal device (Personally-owned work profile): On the enrolled pilot device, with the correct user signed in, select Intercept X in Company Portal > Apps and install it through Google Play in the managed profile; for a Required assignment, first verify actual installation. Launch the managed app and follow the Sophos instructions. On the app dashboard, select Tap to connect to Microsoft Intune and complete the wizard.
- Other supported Android Enterprise modes: Check the installation path on the actual pilot device. On fully managed devices, Company Portal redirects to the Microsoft Intune app; available corporate apps are obtained through Managed Google Play, not through the same Portal click path. For Required, verify that Intune has installed the app. Then launch the managed Intercept X app and check the Intune connection wizard offered. If it is missing or the user/device mapping cannot be confirmed, stop and clarify the supported workflow for this mode instead of forcing the work-profile path or an EMM enrollment.
- iPhone/iPad: On a device enrolled in Intune with both Company Portal and Microsoft Authenticator, select View > Intercept X in Company Portal, install and launch it, and follow the Sophos instructions.
Installing the app alone confirms neither Sophos enrollment nor a usable MTD status. First check that the correct user and device are matched in Sophos Mobile and Intune.
Check status and investigate discrepancies
In the pilot, compare the app status and Sophos device record with Intune > Mobile Threat Defense (connector status and last synchronization) and the device compliance report. For the device-level report, open Reports > Device compliance > Reports > Device Compliance. If necessary, run Generate first, then select Device threat level under Columns. Compare the value for the same user and device with the Sophos app scan and the last connector synchronization. Also observe the effective access decision for a pilot resource designated for this purpose; Enabled on the connector does not prove that device status was transmitted, and Compliant alone does not prove that the app is secure.
| Sophos app state | Transmitted MTD status | Intune assessment described by Sophos |
|---|---|---|
| App not managed by Sophos Mobile | deactivated | Noncompliant |
| App managed, not yet scanned | activated | Noncompliant |
| Scan with no malicious apps detected | secured | Compliant under the described MTD mapping; other compliance rules may still apply |
| Malicious apps or root/jailbreak | highSeverity | According to the configured compliance policy |
| No server sync for longer than the maximum synchronization gap in a Sophos Mobile compliance policy | unresponsive | Noncompliant |
After setup, registration of Sophos as an Intune MTD provider can take several minutes; during this period, Intune may show an incorrect compliance status. Do not immediately expand policy assignments or re-enroll the app. If the status remains inconsistent, first compare the correct user/device identity, completed app connection, most recent app scan, and connector synchronization. Then check the applicable Intune compliance policy for the affected platform and its user-group assignment and, if configured, the relevant Sophos Mobile policy and device group. Do not confuse the device-level status unresponsive with Microsoft’s separately configurable interval for an unresponsive MTD partner: Microsoft says Intune can ignore the compliance status of an unresponsive partner. In that case, do not claim the expected access protection; check the actual Conditional Access effect and stop the rollout.
Rollback and approval boundary
If the pilot unexpectedly blocks access, first work with the Intune owner to remove the affected Conditional Access and compliance assignments for the pilot group or restore the previously approved configuration. Observe sign-ins and compliance again afterward. Do not start rollback by uninstalling the Sophos app, deleting devices, unbinding the connector, or revoking Entra consent: an unmanaged app may report deactivated and thus become noncompliant; the effects of disconnecting the connector on existing policies and devices have not been tested in production here.
Before a complete teardown, identify the affected groups, app assignments, devices, and remaining compliance and Conditional Access dependencies. Removing an assignment, disabling/removing the connector, unbinding Sophos, and revoking Entra consent for the Sophos application are distinct actions. Only after documenting the affected devices, remaining compliance rules, and a working alternative access path should the Sophos, Intune, and Entra owners approve the order of a full teardown and test it in the tenant. The sources do not establish a generally safe unbinding/revocation sequence; in particular, do not infer immediate restoration of compliance or access. This draft has no production functional test or approval for that reversal.
Scope
This guide describes documented features and prerequisites, not verified permissions, switches actually available, synchronization, or teardown effects in a specific customer tenant. No device or tenant tests were performed; the pilot checks described here must be carried out locally.