Skip to content
Avanet

Sophos Mobile: Check device inventory, status and reports

There are two distinct views of the mobile inventory: My Environment > Mobile Devices in Sophos Fusion shows the mobile-device list and its detail page; Devices in Sophos Mobile Admin opens the mobile-management view with extended filters, Smart Groups and a more detailed device page. My Environment > Computers & Servers, by contrast, is the computer and server inventory, not the mobile-device working list.

This workflow is for read-only inventory and status checks. Detail pages also offer buttons for synchronisation, user assignment, messages, location queries, locking, unenrolling, deleting and wiping. None of these actions is part of an inventory check. For a separately approved message, use the existing Fusion messaging workflow; messages cannot be sent to Windows computers or Macs. In particular, a disappearing entry is not proof that a device has been reset or safely decommissioned.

In Sophos Mobile Admin, the customisable Dashboard is the regular start page. Its widgets provide an overview of the inventory, while Devices takes you to the device list and individual device details. The dashboard information includes:

  • device information for all devices or by group;
  • compliance status by platform or for all devices;
  • management status by platform or for all devices;
  • registration status in the Self Service Portal (SSP), separate from compliance and management status;
  • the managed platform versions.

For an inventory check, read the existing widgets and then investigate any devices that stand out in the list. There is no need to add devices or adjust the dashboard layout.

Dashboard: make optional changes separately

These changes are not part of the read-only inventory check. Adjust the dashboard layout only for an approved need, and first record which widgets are present and how they are arranged. Four controls are available:

  • Add widget adds a widget.
  • Close in a widget’s header removes that widget from the dashboard.
  • Restore default layout resets the page to the default layout, not to a previously customised layout.
  • Drag a widget’s header to rearrange the widgets.

Afterwards, compare the visible widgets and their arrangement with the intended layout. Removing a widget does not delete a device.

Optionally add a new device: On the dashboard, the Add device widget starts the Add device assistant. Adding and enrolling requires separate approval and appropriate administrator permissions. For Android, iPhone and iPad in the Threat Defense edition, use the Intercept X app enrolment wizard workflow: it covers user selection, Device details, the appropriate MTD enrolment type and the final checks. This route enrolls the protection app, not the whole device through MDM; the dashboard entry point does not establish MDM permission.

Find a device in Sophos Fusion

  1. Open My Environment > Mobile Devices. The search above the list matches parts of the device name or operating system. Select criteria under Show filters and apply them with Apply; multiple criteria are considered together.
  2. In the result row, compare Name, Operating system, Management mode, Status, Compliant, Owner, Group, Last active, Email address and, where applicable, User. Operating system gives the operating system and version. User identifies the assigned Sophos Fusion user; clicking their name opens the user details without changing the assignment. Email address normally matches their address, but can be set differently when the device is added or later; the address alone does not establish user assignment. Last active is the time of the last synchronisation with Sophos Mobile, not evidence of current physical use.
  3. Open the device name. The overview at the top shows Device name, Operating system with its version, User, Last active and Device group. Device actions are at the top right; do not run them for an inventory check. The tabs below include Summary and, depending on the device and its management, Events, Policies, Compliance, Properties, Scan results and Installed apps. Open in Sophos Mobile takes you to the more detailed Show device page in Sophos Mobile Admin.
  4. Check a suspicious record against the expected device identity and the correct tenant; if visible and authorised for follow-up, record the device identifier or IMEI. Note the time, applied filters, management mode and exact discrepancy displayed. Do not click Actions > Synchronize to check status: this triggers a device action.

In the overview at the top of the Fusion device detail page, Device name is the name set when the device was added to Sophos Mobile. It can be edited later on Show device; for an inventory check, read only the existing name. User identifies the assigned Sophos Fusion user here. Clicking their name in this overview opens the user details without changing the assignment.

The list columns describe different aspects: Name is the device name, and Management mode is the mode selected during enrolment, which depends on the device type. Status shows whether the device is managed and, where applicable, why it is not. Owner distinguishes Corporate (organization) from Personal (user); Group identifies the device group it belongs to.

Read health and compliance separately: The health status in the mobile-device list is based on violations of the configured compliance policy; it can also be set manually. Compliant indicates compliance status. On the Fusion device detail page, the icon at the top left shows the platform; each platform, such as Android or iOS, has a different icon. The health badge shows the health status: Green = Good health, Yellow = With warnings, Red = Needs attention. Hover over the badge to read the status. Supervised iPhones and iPads also display Supervised. A green icon alone confirms neither recent synchronisation nor correct user assignment. Treat an older synchronisation as a lack of recent feedback first, not as an instruction to delete the device.

Interpret the Summary fields

In the Fusion detail view, Summary is divided into three sections:

Device summary contains Management mode and Owner for management and ownership. Description is the description entered when the device was added. Like the device name, it can be edited on Show device, but not as part of this inventory check. Created at shows when the device was added to Sophos Mobile, normally the enrolment date. However, devices can also be added without enrolment, so this timestamp does not prove completed enrolment.

The app timestamps are also under Device summary. Last Sophos Mobile Control sync is that app’s last synchronisation and is available only when Sophos Mobile manages it. Last Intercept X for Mobile sync gives that app’s last synchronisation. If Sophos Mobile does not manage Intercept X for Mobile, the field shows Never.

Under Device health, the section heading shows the health status. Compliance status indicates whether any compliance policy rules have been violated. Management status shows managed or not managed and, where applicable, the reason. Compliance and management are not the same thing.

Under Device information, Model name is the manufacturer’s model name. Phone number and Email address normally come from the assigned Fusion user, but can be set differently when the device is added or later on Show device. Neither field replaces checking User. Last known location shows the last known coordinates and the date of the last Find action, not a live location. For this inventory check, read only existing information; do not trigger a new location request.

Created at in Summary therefore describes the device record; the field with the same name under Properties describes the individual property and is explained below.

Check management status in Sophos Mobile Admin

In the Sophos Mobile Admin sidebar, Devices lists the devices and Device groups lists the device groups. Device groups is not the same as the dynamic sets of filter results under Smart groups.

Under Devices, open the device name to reach the Show device page. The upper section contains the key device information; the lower section distributes the details across several tabs. Status shows management type, management status and compliance status; Compliance violations lists the specific violations for non-compliant devices. Tasks shows completed tasks from recent days as well as all pending and failed tasks. Investigate failed tasks separately rather than trying to “fix” management status by taking an action. Edit on Show device opens device editing, but is not part of the read-only check.

The Sophos management-status help identifies the Managed icon on Devices as the place to hover to read the status. The device-view help also identifies the Not managed icon for the more specific reason, such as Unenrolled or Checked out. Both descriptions come from the documentation; they do not verify the actual tooltip behaviour in your tenant. For Not compliant, the tooltip shows severity as high, medium or low. Sophos distinguishes, among others:

  • Managed: enrolled in Sophos Mobile; Not managed: added but not yet enrolled.
  • Enrolling: enrolment in progress; Unenrolled: a previously managed device has been unenrolled.
  • Checked out: the user manually removed the management profile rather than unenrolling through the regular process; this status applies to iPhones and iPads.
  • Wiped: a previously managed device was remotely reset through Sophos Mobile. This status is a historical management record, not an instruction to reset the device again.

In the Android/iPhone/iPad app enrolment described for the Mobile Threat Defense edition, Managed means that Sophos Mobile manages Intercept X for Mobile. It does not establish MDM management of the whole device. Checked out remains tied to manual removal of the device management profile, and Wiped to a recorded remote wipe through Sophos Mobile. Do not infer either status from uninstalling an app, removing a web-filter profile or clearing app data. The general status definitions do not establish which values each individual management mode actually produces in the tenant.

Use filters and Smart Groups for the intended review

A Smart Group is a dynamic set of devices matching defined filter criteria, not a device group. One example is “Company-owned Android devices created within the last three months”: ownership, platform and creation time together narrow down the selection. Adapt names and criteria to your own review; the example is not a requirement for your inventory.

For a one-off review, open Extended filter above the device list on Devices, set criteria such as management status, and select Filter. Do not save a Smart Group. For reuse, open Smart groups above the list and select the required saved entry.

When a Smart Group or extended filter is active, the filter icon in the table header changes from blue to green. When you no longer need the restriction, select Extended filter > Reset: this clears the active Smart Group or extended filter and shows all devices again. It does not delete the saved filter definition. Check filters before a new review and reset any you no longer need; otherwise expected results may be missing from lists or reports. This does not mean every report automatically inherits all list filters. Check the actual scope of the generated file separately.

Save or change Smart Groups: These steps change the saved filter definition and are separate from a one-off read-only review. First check the tenant, intended criteria and, for changes, the correct saved entry; these steps do not trigger an installation, deletion or wipe task for the selected devices.

  1. Create: Set the criteria under Devices > Extended filter, enter a suitable name in Smart group, and select Save.
  2. Decide after saving: Filter applies the new Smart Group to the device list. Close closes the filter window without applying it. Save and applying the filter are therefore separate steps; you can select the saved entry later through Smart groups.
  3. Edit: First apply the relevant Smart Group, then open Extended filter, change the required criteria, and select Save. Afterwards, select the saved entry again and check the criteria and displayed devices.
  4. Delete: Under Smart groups, select the trash icon next to the intended Smart Group. This deletes the saved filter definition, not the devices. Record its name and criteria first in case you need the definition again; afterwards, check that exactly that entry has disappeared from the selection. To clear only the active restriction, use Reset, not the trash icon.

Table pitfalls: Search all fields shows only rows that contain the entered text in any column. Columns can be shown or hidden with Show or hide columns. Clicking a column heading sorts the rows by that property; clicking the same heading again reverses the sort order. Use the navigation buttons below the table to select a particular table page. In many tables, clicking an entry name opens Edit by default; the blue triangle opens additional actions. To view a device, specifically use Devices > device name > Show device; do not save changes. For a table export, use the export icon below the table to export the entire table or only the current page as a Microsoft Excel or CSV file; with an active row filter, only visible rows are exported. This says nothing about the scope of a separately generated report. Excel and CSV files may contain personal device identifiers: save them locally only where there is an authorised need, and handle access, sharing and deletion according to approved organisational policy.

Read device details and reports

Properties, policies and certificates

On Show device in Sophos Mobile Admin, the tabs provide different information:

For Custom properties and Internal properties, Expert mode must be enabled under Setup > General > Personal. These personal settings apply only to the administrator currently signed in; they control that administrator’s display, not the stored device properties. A hidden tab therefore does not prove that values are missing. Obtain separate approval for any necessary setting change and save it with Save.

  • Device properties shows the model, model name, operating system version and whether an Android device is rooted or an iOS device is jailbroken, among other details. These are reported properties, not a new check on the device.
  • Internal properties contains values reported by the device, such as the IMEI (International Mobile Equipment Identity).
  • Custom properties shows custom device properties in addition to reported values. User-specific information can also be added here as part of approved device editing. Viewing these values proves neither policy assignment nor placeholder substitution. The separate custom-properties workflow explains syntax, individual assignment and defaults.
  • Policies shows assigned policies and provisioning profiles. The table’s search field also finds IDs, even though the table does not display them. iOS device policies containing only Roaming/Hotspot or Wallpaper do not appear here: a missing row does not prove that no configuration is in effect. Policies can also be assigned and removed on this tab; both are changes and are not part of an inventory check.
  • Declarative policy shows details of the assigned declarative policy. Assign assigns a policy rather than opening further read-only details; do not use it for an inventory check.

Certificates shows certificates in use. Hover over Subject or Issuer in the table to read certificate details. The list has platform-specific limitations:

  • Android Enterprise: Root certificates are included, client certificates are not.
  • Macs: Device certificates are included, user certificates are not.
  • Windows: User-store certificates are included, device-store certificates are not.

The list is therefore not a complete record of trust. A missing entry does not prove that the corresponding certificate is absent from the device.

App inventory and pending installations

Installed apps in Sophos Mobile Admin shows installed apps. Size gives the storage used by the app itself; Data gives the additional storage for user data, configurations and similar content. Data here is not mobile data usage; TEM handles that separately.

Consider the platform and visibility when reviewing the list:

  • The Hide installed apps privacy setting can hide the entire Installed apps tab from administrators. App reports still provide a consolidated app list for all devices; this is not an individual device’s app list.
  • On Android, the list also includes preinstalled apps. On other platforms, preinstalled or system apps are not visible.
  • With Apple User Enrollment, personal apps remain invisible: these are apps from the user’s personal Apple Account.
  • For Macs, apps from all user accounts are listed, not just the assigned user’s account.
  • The separate System apps tab shows Android system apps; these cannot be uninstalled.
  • On Samsung devices, Knox apps shows apps installed by the user in the Knox container, while Knox system apps shows that container’s system apps.

Installed apps also offers installation and uninstallation. Do not perform these actions to check inventory. On iPhones and iPads, apps marked Managed can be uninstalled without user interaction; on Windows computers, uninstallation is limited to apps installed by Sophos Mobile. These differences matter for a later approval, but do not authorize a task as part of the inventory check.

For Android Enterprise, Installed apps also contains Apps pending installation, showing the installation status of managed Google Play apps. The underlying workflow starts with an approved Install task on Apps - Android Enterprise: Sophos Mobile sends an installation request to a Google server, and Google installs the app on the device. For the inventory check, read only the existing status:

  • Installation request to be sent to Google: The Install command has been executed; the request has not yet been sent to Google.
  • Installation request sent to Google: Sophos Mobile has sent the request to Google. This does not yet prove installation is complete.
  • Once Google has installed the app, Sophos Mobile moves the entry from Apps pending installation to Installed apps. This change is the visible success criterion in the management view.

For an approved deployment, use the separate Managed Google Play installation workflow. The same section explains how to check country, device type and pending Play Store downloads when requests are stuck. Do not start a second installation just because the request has been sent but the app is still pending.

Read the last scan and threat details

To review scan results in Sophos Fusion, open My Environment > Mobile Devices > [Device] > Scan results. Type a threat name, app name, version or app identifier in the search field to filter the results list. The filter options above the list narrow the results by detection type: Threat, Suspicious, PUA or Low reputation. For example, search for the identifier of a suspicious app or use PUA to narrow the list to those detections; use the identifier from your own findings, not a sample value. To check the results, compare the displayed matches with the search term or selected detection type. If an expected match is missing, first check the search text and selected type restriction; for a broader comparison, clear the search text and remove the detection-type restriction. An empty filtered view does not prove that the device is free of threats.

Scan results is available when Sophos Mobile manages Intercept X for Mobile on the device and shows results from the last scan, not a continuous live status. If a threat was detected, follow the information using read-only checks:

  1. Click the threat name on Scan results.
  2. In the search results, select the entry whose title matches the threat name. This is usually the first result, but the title match is what matters.
  3. On the page opened in the Sophos Threat Center, read the further links about the threat.

Missing tabs or data do not prove that software or certificates are absent, or that there are no threats.

Read apps and properties in Sophos Fusion

Sophos Fusion has its own tabs for devices managed by Sophos Mobile. To view the app inventory, open My Environment > Mobile Devices, click the device name and select Installed apps. The columns mean:

  • Source: The installation source. Store includes Google Play, Apple App Store, Microsoft Store and Chrome Web Store; for iPhones and iPads, it also includes alternative app marketplaces. Nonstore means installation from an app package file. System identifies operating-system components or apps preinstalled by the device manufacturer.
  • Name and Version: The app name and version reported by the operating system.
  • Identifier: The internal app identifier.
  • Installed at: The app installation date.

Type an app name, version or identifier in the search field to filter the list. For the installation source, use the Source filters above the list. These fields belong to Installed apps in Fusion, not to the Size and Data storage fields or the separate System apps tab in Mobile Admin.

For properties in Sophos Fusion, open My Environment > Mobile Devices > [Device] > Properties. Type distinguishes System (reported by the device to Sophos Mobile) from Custom (created manually and assigned to the device). Name gives the property name, and Value gives its value. Use the search field to filter by name or value; the type filters above the list also narrow the results by property type. This path belongs to the Fusion detail view, not the Custom properties tab in Sophos Mobile Admin. Do not use Add, editing or deletion functions for an inventory check. A separately approved change is described in the separate Fusion workflow.

On both Fusion tabs, the Refresh icon at the top right reloads the displayed information. It does not replace device synchronisation.

Created at indicates when Sophos Mobile first recorded the property for the device:

  • for a system property, the device’s first synchronisation with Sophos Mobile;
  • for a custom property created for an individual device, when that property was created;
  • for a default device property, when the device was added to Sophos Mobile.

Updated at shows when the property last changed. Updated by shows the Sophos Fusion user who changed it, or System if the change was due to device synchronisation.

Reports and other analysis routes

For a larger review, open Reports in Sophos Mobile Admin, choose a suitable report and select Excel or CSV in the format dialog. The file is saved on your computer. Do not assume that list filters carry over to the report or that a time period can be selected: Before sharing it, check the actual generated file for its scope, time coverage and sensitive fields. Approved organisational requirements for access, sharing, retention and deletion apply to local copies; neither a specific retention period nor automatic masking is established here. For large tables, Sophos recommends reports or the Mobile API instead of table exports because these approaches are significantly faster for large amounts of data.

Optional: query data already collected in the Data Lake. First check the existing licences and upload settings for this route. According to Sophos, in Sophos Fusion you need a Sophos Mobile or Sophos Mobile Threat Defense licence plus an Endpoint, Server or MDR licence that includes Sophos XDR. If these prerequisites are met and Data Lake uploads for Sophos Mobile are already enabled, you can use Live Discover in the Threat Analysis Center to query the collected device information. This is a separate analysis route alongside reports and the Mobile API.

Sophos documents Mobile uploads for Android devices, iPhones, iPads and Chromebooks. The data available depends on the management mode. For example, a fully managed Android Enterprise device supplies more data than a device on which Sophos Mobile manages only Intercept X for Mobile. The full Sophos Mobile edition’s help lists the following query examples; the Threat Defense help confirms the Data Lake route but does not list these examples:

  • devices that have not synchronised for a specified number of days;
  • devices on which a particular app is currently installed or was installed previously;
  • network connections by device or app, provided the required network data has already been collected.

For network connections, the optional Network logging setting must also already be selected. To read the existing Mobile settings, open the Global Settings icon and Products and Services > Mobile, without toggling anything or saving. Sophos documents Network logging for Android devices on which Sophos Mobile manages the Sophos Mobile Control app, and for iPhones and iPads on which it manages Sophos Intercept X for Mobile. Merely installing either app does not establish this management relationship.

These queries use the collected Data Lake information; in particular, a previous app installation cannot be established independently of that information. Hide installed apps also excludes installed-app information from the data Sophos Mobile uploads to the Data Lake. Do not infer that this deletes app data already collected. For this read-only workflow, do not enable uploads or additional data collection. If a licence or upload prerequisite is missing or unclear, stay with the device list and reports and involve the responsible administrators. Do not assume network data is available without existing Network logging and the appropriate app management. Live Discover query syntax and setup belong to a separate workflow, not this inventory check. These prerequisites are documented; this does not confirm that they are met or which data is actually available in your tenant.

Read and interpret TEM usage

Telecom expense management (TEM) monitors mobile data usage for individual devices. This is not the storage usage under Installed apps > Data. TEM requires monitoring to be configured, a SIM card and a mobile data plan. TEM is not available for Android Enterprise work profiles, Apple User Enrollment, Macs, Windows computers or Chrome devices.

To read current usage, open the device name under Devices and go to Show device > Actions > Configure telecom expense management. The same dialog is also used for configuration: for an inventory check, read only the usage, do not change any values, do not toggle Turn on monitoring, and do not select Save. Opening the view is separate from applying changed settings.

For an overall review, select Reports > Cellular data usage. This report shows usage for all devices with TEM enabled. In Choose format, select the Excel or CSV icon; the file is saved on your computer. As with other reports, check the actual scope and time coverage and protect sensitive device information; do not assume that list filters carry over automatically or that you can choose any reporting period.

Account for measurement limits: Devices report usage each time they synchronise with Sophos Mobile, not as a guaranteed live value. Traffic from installed apps is recorded; system updates, system-app updates and similar traffic are omitted. The values may differ from the provider’s bill. On iOS, no usage is reported while the Sophos Mobile Control app is closed, for example if the user has not reopened it after restarting the device. If information is missing or old, first check the last synchronisation, platform, enrolment mode and, on iOS, the app’s state; do not switch monitoring off and on as a test.

The usage value is reset:

  • monthly at the end of the configured day;
  • when TEM is switched off for the device;
  • when the device is unenrolled from Sophos Mobile (Unenroll).

TEM is therefore not a permanent usage archive. A reset value alone does not prove successful offboarding. Configuration and the special case of shorter months are covered in the following workflow, which requires separate approval.

Configure TEM only with an approved change

This write workflow is not part of the read-only inventory check. Before making a change, check the correct tenant, approved target devices and their actual mobile data plan. Record the previous monitoring state, field values and, if needed, reported usage; protect local records according to organisational requirements. Before disabling monitoring in particular, note that this resets the usage value.

Approval does not replace technical permission: proceed only with a Sophos Mobile administrator authorised for the specific TEM change. First check the effective permission in the tenant and whether TEM applies to the target devices. If permission is missing or applicability is unclear, stop and involve the responsible Sophos Mobile administrators; do not change roles or assume permissions for custom roles.

  1. Open Devices in Sophos Mobile Admin and select the target devices. Select devices together only if they have the same mobile data plan; configure different plans separately.
  2. Open Actions > Configure telecom expense management and set the following fields:
    • Turn on monitoring: Enables mobile data usage monitoring for the selected devices when checked.
    • Data volume of plan: The mobile data plan’s allowance in MB. Enter the actual contracted allowance, not a monetary amount or the usage already measured.
    • Alert threshold: The usage threshold in MB. Choose a threshold that suits the plan and your early-warning process. If a device exceeds this value, Sophos Mobile creates an Event, visible on the device detail page, and an Alert. Do not infer automatic data blocking or guaranteed avoidance of additional provider charges from this behaviour.
    • Usage cycle reset date: Enter the day of the month from 1 to 31 on which the usage value should reset; choose a day that matches the billing cycle. If a month has fewer days than the entered value, the reset occurs on the last day of that month. The regular reset occurs at the end of the day.
  3. Recheck the target devices, shared plan and values. Select Save to apply the settings to the selected devices.

Check after the approved change: Reopen the dialog for the relevant devices and compare the saved monitoring state and values with the approval, without saving again. After the next regular synchronisation, check the reported usage and the Cellular data usage report. If the threshold is exceeded during normal operation, follow up on the event on the device detail page and the alert; do not generate artificial data traffic as a test. If notifications are missing, first consider the measurement limits and last synchronisation rather than reconfiguring TEM.

Correction or rollback: Only with approval, use the same configuration path to replace incorrect values with those recorded previously, apply them with Save, and check again. To switch newly enabled monitoring off again, clear Turn on monitoring for the correct target devices and apply with Save. This resets the usage value. Re-enabling monitoring is not a reliable way to restore that value; recovery of deleted usage values is not documented here. Do not disable monitoring just to fix a discrepancy in the display.

Custom properties only with an approved change

This write workflow is not part of the inventory check. Create properties only with separate approval and using an administrator authorized for that specific creation; first verify the correct tenant, target device or intended default scope. If the required permission is missing or applicability is unclear, stop and involve the responsible Sophos Mobile administrators. Custom properties supplement values reported by the device. For both individual assignment and defaults, their names must not match the name of a standard device property.

Before entering data, record whether the property already exists on the target object and, if so, its previous name and value; if Expert mode needs to be changed, also record its previous state. Enter only approved data necessary for the purpose, and check who may view the value or use it in downstream configurations. Do not enter passwords, tokens or other secrets unless an explicitly approved, supported workflow exists for doing so.

An individual property is assigned to the selected device. By contrast, Sophos Mobile automatically assigns Default device properties to new devices as custom properties when those devices are created. Do not assume that a new default populates existing devices or that subsequent changes to a default update their values.

In policy settings, you can reference a value with %_DEVPROP(my property)_% if the property is named my property. For example, for a location you could give my property the value Zuerich. The name and value are freely chosen examples; choose a suitable name and the actual location for your inventory. The placeholder must contain the name of the property you created; the syntax %_DEVPROP(...)_% stays unchanged. Placeholders are substituted when the policy is assigned. A visible property alone confirms neither that substitution nor the policy’s effect on the device.

Device placeholders can use all properties listed under Device properties and Custom properties on Show device; do not infer that all Internal properties are suitable as well. Separately, %_EMAILADDRESS_% substitutes the Email Address property of the user assigned to the device, and %_USERNAME_% substitutes that user’s Exchange Login. On macOS, this user information comes from the user assigned in Sophos Mobile for the local Mac account, and from the LDAP user account for network accounts. These percent-sign placeholders in policies are not equivalent to the dollar-sign placeholders in a managed Android app configuration.

Choose the appropriate creation path in Sophos Mobile Admin:

  • Individual device: Open Devices, select the blue triangle next to the target device, then Edit. The Custom properties tab on Edit device also requires Expert mode to be enabled under Setup > General > Personal. If the tab is missing, check the signed-in administrator’s personal setting. Under Custom properties, click Add custom property.
  • Default for new devices: Open Setup > Sophos setup > Default device properties > Add custom property.

For both paths, enter the name and value, then click Apply, followed by Save. Apply alone does not complete the documented save process.

As a read-only check after the approved change, review the saved name and value again on the correct object: under Show device > Custom properties with Expert mode enabled for an individual device, or Default device properties for a default. If there is a discrepancy, first check the tenant, target object, personal tab-visibility setting and completion of Save, rather than triggering a device action. This checks the visible entry, not placeholder substitution or policy effect.

Correction or rollback: If a saved entry is incorrect, stop making further changes and agree on an approved correction path with the responsible administrators, using the recorded previous state. The creation workflow described here does not establish a rollback path for saved properties or policy effects that have already occurred. Restoring the previous Expert mode setting changes the personal display but does not undo a property change.

Fusion Custom properties only with an approved change

This write workflow is not part of the read-only inventory. It applies to Properties on the Fusion details page of a device managed by Sophos Mobile. Creation, value changes and deletion each require separate approval for the specific tenant, device and property. Proceed only with an administrator whose effective permissions cover the approved change. If permissions are missing or applicability is unclear, stop and involve the responsible administrators; do not change roles speculatively.

First, check the device identity and the existing property. Before changing or deleting a property, record its current name and value and clarify whether downstream configurations use the value. Protect records in accordance with organisational requirements. Enter only required, approved data, not passwords or tokens. Checking a saved row proves neither placeholder substitution nor a policy effect on the device.

This route is separate from the existing workflow in Sophos Mobile Admin. Do not transfer its Expert mode, Add custom property, Apply > Save, defaults or the example my property to Fusion. The following naming rules apply when creating properties in Fusion.

Create a property in Fusion

  1. Open My Environment > Mobile Devices, click the approved device name and select Properties. Before creating a new property, check whether the desired property already exists; check the search and type filters if necessary.
  2. Select Add above the list and enter the property name and value. The name must begin with the fixed prefix custom.. It may contain only letters, digits, hyphens, underscores and full stops. The value may be any string of up to 4096 characters. This is a character limit, not a byte limit.
  3. For example, use custom.location with the value Zuerich if the approved property describes the location. location and Zuerich are replaceable example values; choose a name appropriate to your purpose and the actual location. The prefix custom. and the permitted characters remain mandatory.
  4. Check the target device, name and value again, then select OK. In this Fusion workflow, OK completes creation, not Apply > Save.
  5. Reload the list using the Refresh icon at the top right or reopen the tab. On the correct device, compare Type = Custom, the full name and the saved value against the approval. If there is a discrepancy, first check the tenant, device and filters rather than creating another property or triggering device synchronisation.

Change a value in Fusion or discard unsaved input

  1. On the same Properties tab, identify the approved Custom property by its name and current value. Select the Edit icon next to this property.
  2. Enter the new approved value, observing the limit of 4096 characters. This workflow changes the value, not the property name.
  3. The tick icon saves the change. The cross icon discards the input that has not yet been saved.
  4. Reload the list using Refresh or reopen it. After saving, the new value must be visible; after discarding, the previous value must be visible. If the result is unexpected, stop making further changes and involve the responsible administrators.

The cross does not undo a change that has already been saved. To reset a saved value, enter the previously recorded value via the same Edit route only after obtaining renewed approval, save it with the tick and check it again. Do not infer that this reverses any policy effects that have already occurred.

Permanently delete a property in Fusion

The deleted property cannot be restored. Before deleting it, check the approval for this exact tenant, device and property, as well as any possible dependencies. Record the current name and value; this record does not provide a means of restoration. Do not delete the property if its use is unclear.

  1. Under Properties, select the Delete icon next to the approved Custom property. Do not use the device deletion action.
  2. In the confirmation dialogue, check the intended deletion again. OK permanently deletes the property.
  3. Reload using Refresh or reopen the tab. Check that this exact property is missing and that the other expected entries are still present. Take search and type filters into account so that a hidden entry is not considered deleted.

Deleting a property is neither Unenroll, device deletion nor Wipe. Creating it again later with separate approval would produce a new entry, not restore the deleted property or its history. Nor is it a proven rollback route for effects on downstream configurations.

If a device or status does not match

  • No result: Check the tenant and view (Mobile Devices versus Computers & Servers); vary the device-name or operating-system search term, and reset filters and the Smart Group in Mobile Admin. A missing result proves neither deletion nor a wipe.
  • Conflicting status: Consider Last active, management mode, Status, Compliance violations and, where applicable, Tasks together. Offline devices or devices with delayed synchronisation can show old values. Do not confuse manually removed iOS/iPadOS management with a proper unenrolment.
  • Missing tab or data: For Custom properties or Internal properties on Show device, first check the signed-in administrator’s personal Expert mode setting. For other tabs, check the edition (Mobile or Mobile Threat Defense), platform and enrolment mode; for Installed apps, read only the existing setting under Setup > General > Privacy > Hide installed apps, without toggling it or selecting Save. Do not relax the privacy setting to make a missing tab visible. For Scan results, check whether Sophos Mobile manages Intercept X for Mobile. If a discrepancy remains unexplained, involve the responsible Sophos Mobile administrators rather than changing permissions, policies or synchronisation on suspicion.
  • Change required: Assignment, device editing, custom properties and all remote or deletion actions require a separate approved procedure. Fusion Computers & Servers > Delete: If a device is enrolled in Sophos Mobile, Sophos requires unenrolment first and warns that otherwise the device may become unusable; merely scheduling unenrolment or seeing the entry disappear does not prove it has been completed. Fusion Mobile Devices > Delete is a separate route. On the detail page under My Environment > Mobile Devices, Sophos already warns: unenroll a device from Sophos Mobile before deleting it, or it may become unusable. The documented deletion procedure additionally filters for Not managed and does not establish that managed devices can be selected. The description of unenrolment of still-enrolled mobile devices only at the next sync (not for Windows computers) does not override this warning or prove immediate or guaranteed completion. It does not authorise deletion of managed devices. For mobile devices, follow the separately approved user assignment and offboarding procedure. This inventory workflow authorises neither Unenroll nor Delete.