Sophos Mobile: Choose MDM or Threat Defense Only
Quick decision: If Sophos Mobile is to manage an entire company-owned device, consider Android Enterprise Full device or Apple Device Enrollment, respectively. For personal devices where only organizational data should be managed, Android Enterprise Work profile and Apple User Enrollment, respectively, are the appropriate BYOD modes. If the goal is only to use Sophos Intercept X for Mobile against mobile threats, choose Mobile Threat Defense (MTD): it manages the protection app, not the device or a work area. Owner: Corporate/Personal records ownership but does not, by itself, limit the technical scope of management. Whether a mode is available depends, among other things, on the license, platform, and prepared policies/task bundles in the relevant tenant.
Which mode fits?
| Device and goal | Mode | Important limitation |
|---|---|---|
| Company-owned Android, manage the entire device | Android Enterprise Full device | Only before initial setup or after an authorized reset; QR/Zero-touch for eligible fully managed devices. |
| Personal Android, manage only the work area | Android Enterprise Work profile | Manages apps, accounts, and data in the work profile rather than the personal area. |
| Company-owned iPhone/iPad, manage the entire device | Apple Device Enrollment | Apple Business is an alternative automated provisioning path for eligible company-owned devices. |
| Personal iPhone/iPad, manage organizational content to a limited extent | Apple User Enrollment | A Managed Apple Account is required for each user; supervised devices are excluded. |
| Android or iPhone/iPad, manage only the protection app | Mobile Threat Defense (MTD) | Intercept X for Mobile; not a substitute for MDM or a work profile. |
Check Apple BYOD requirements before inviting users: With Apple User Enrollment, administrators cannot view personal data or device identifiers such as the UDID, IMEI, or MAC address; Network Access Control (NAC) cannot be used for these devices, and a forgotten device passcode cannot be reset. Managed apps must have been acquired through Apple Business; a managed app cannot be installed if the same app is already installed privately. If NAC, passcode reset, or deployment of a conflicting app is required, review the requirements and device ownership and agree on an approved alternative—do not fully enroll a personal device instead.
The mode is not the enrollment method: the Add device assistant, individual enrollment of an existing device, and the Sophos Fusion Self Service Portal (SSP) are distinct paths. Additional platform-specific methods are available for eligible company-owned devices. An Android Enterprise dedicated device is not another management mode but a fully managed device with a kiosk configuration that restricts it to a single app or a defined selection of apps. Userless kiosk devices can be enrolled through a QR/Zero-touch path prepared for that purpose: no email account is connected, and Sophos Mobile does not assign a user to the device. The Android Enterprise overview clarifies identity and prerequisites; the separate dedicated Android device preparation guide covers provisioning paths, kiosk configuration, and a safe exit. Automatic user assignment for user-associated, automatically enrolled devices is supported with Android Zero-touch, Samsung Knox Mobile Enrollment (KME), and iPhones, iPads, and Macs enrolled through Apple Business: on the user-associated Zero-touch path, assignment is automatic; for KME and Apple Business, the corresponding option must be configured. Do not assume that SSP or BYOD enrollment automatically assigns a user. Authentication and setup belong in the relevant platform guide; the automatic user assignment prerequisites distinguish the three sign-in methods.
Migrate legacy Android devices separately: Android device administrator is a legacy management mode and cannot be used in Sophos Mobile on Android 10 or later. Devices still managed this way should be unenrolled and re-enrolled in an appropriate Android Enterprise mode under an approved migration plan specific to their ownership and management mode. The Device Administrator migration guide distinguishes company-owned from personal devices and the different interventions they require; do not start Enterprise enrollment through the old management or reset personal devices indiscriminately.
The decision table covers Android and iPhone/iPad. Check the management scope for Mac, Windows, and Chrome separately:
- Mac: Sophos Mobile uses only one management mode. For the classic policy types, a Device policy applies to all users who sign in to the Mac; a User policy applies to the local user who enrolled the Mac and to network users known to Sophos Mobile through the SSP’s external LDAP directory. Do not assume that a User policy isolates management to exactly one person. In addition to device and user policies, there are declarative policies and imported policies; do not assume there are exactly two policy families today. Check the scope and policy families before assignment in the macOS security and privacy planning guide; Wi-Fi, VPN, and certificates remain in the separate macOS connectivity guide.
- Chrome: For Chromebooks and other Chrome devices, Sophos Mobile uses the single management mode Sophos Chrome Security. It manages Sophos Chrome Security on the device—the enrolled extension and its policy—not Android Enterprise MDM. Deployment, Google assignment, and the exit path belong in the separate Chrome Security guide.
For individual Sophos Mobile enrollment of a Mac, the user whom Sophos Mobile is to manage must enroll the Mac themselves and enter an administrator password to install the enrollment policy. Clarify the local enrolling user and verification in the Mac enrollment guide. Deploying Sophos Endpoint through, for example, Jamf Pro for macOS is a different task.
Edition and legacy Windows gate: Sophos Mobile Device Management (formerly Central Mobile Standard) covers MDM for Android, iPhone/iPad, Mac, and Windows; Sophos Mobile Threat Defense (formerly Central Intercept X for Mobile) covers the protection app on Android and iPhone/iPad; Sophos Mobile (formerly Central Mobile Advanced) includes both. Check the actual license in Sophos Fusion before selecting a mode. Windows has one Sophos Mobile management mode, Device—not an Android work profile or Apple User Enrollment. Do not treat Windows record deletion as unenrollment: a still-enrolled Windows computer does not automatically unenroll on the next sync after deletion. Arrange authorized manual unenrollment first; if Forbid manual MDM unenrollment is enabled, Sophos documents a factory reset instead. Do not delete or reset an unclear-ownership or personal computer; escalate the offboarding decision.
Check the mode and prerequisites before inviting users
In the correct Sophos Mobile tenant, first clarify ownership and privacy requirements, any consent that may be required, existing management, and the intended boundary between personal and business data. Prepare the user assignment, device group, platform prerequisites, and suitable policy and, where applicable, a task bundle (Task Bundle). Then check the actual entitlement and the mode offered. If the intended mode is missing, stop here: have the edition/entitlement, platform, prepared task bundles/policies, and tenant configuration checked; do not substitute another management mode. The assistant’s MTD view offers different options from full Mobile management; do not infer MDM entitlement from it.
Android Enterprise identity preflight: Check the tenant’s registration mode in Setup > Google setup > Android Enterprise. If the tenant was registered in Managed Google Domain mode before April 9, 2024, and managed Google domain device enrollment has not been enabled, administrators cannot initiate Android Enterprise enrollment; users can enroll only through the SSP. If managed Google domain device enrollment is enabled, all intended users need accounts in the managed domain; for admin-initiated tasks the assigned Sophos Mobile email address must match the Google authentication address. For managed Google domain device enrollment only, check Sophos Mobile Control 9.8 or later; for a work profile using that enrollment mode, also check all available OS and app updates. These are not general prerequisites for Managed Google Play account BYOD. Do not change the tenant’s registration mode or reset a device merely to bypass this gate.
Prepare automatic user assignment
During user-associated automated enrollment, the user enters their credentials during initial setup. Sophos Mobile finds the corresponding user account and assigns it to the device. The same applies during setup after an independently authorized factory reset; this is not a recommendation to reset a device for user assignment. The userless Zero-touch path described above remains separate.
Before provisioning, decide which sign-in method will be used: Sophos Fusion credentials, Active Directory credentials, or federated authentication. Here, the federated option is available only for iPhones and iPads enrolled through Apple Business, not for Macs or Android devices.
AD synchronization is a separate identity process: Adding search bases (Base DN) or changing filters can exclude previously synchronized Fusion users and groups from the search scope and cause them to be deleted in Fusion. During setup and after such changes, the responsible directory administrators must run Preview and Sync, review the proposed additions, changes, and deletions as well as the LDAP filters, and clarify the affected assignments. Select Approve Changes and Continue only after approval; then check the resulting users and groups in Fusion. The AD sync guide to search bases and filters is part of this preparation. Selecting an enrollment mode does not authorize filter changes, user deletions, or device cleanup.
With Sophos Fusion credentials:
- Provision the intended user accounts in Sophos Fusion, either by creating them manually or synchronizing them from Active Directory.
- Before sending, check that each intended user has a valid email address not already used by another Sophos sign-in account. In Sophos Fusion Admin > My Environment > Users & Groups, select the users, choose Email Setup Link > Sophos Fusion Self Service Welcome/Setup Email, and send with Save. Users with no address or an invalid address can also be selected without an error message; they receive no usable invitation. Each user must open the link they receive, activate their account, and set a password. The device invitation through Actions > Enroll does not replace this account activation. If there is an account conflict—for example, an address already used for a Fusion Admin trial—or the invitation does not arrive, stop and hand off to the responsible identity administrators or Sophos Support. An audit-log entry for sending proves neither that an email was generated or delivered nor that the account was activated. Do not resend blindly or delete a Fusion user or sign-in account on suspicion; account cleanup requires separately confirmed vendor instructions and approval.
- For Apple Business, open the profile actually used for the intended devices under Setup > Apple setup > Apple DEP profiles. On the Enrollment tab, select the value appropriate to the platform under Assign user to device:
- For iPhones and iPads, select Yes - Self Service Portal authentication in the iOS profile. The user is redirected to sign in to the Sophos Fusion Self Service Portal.
- For Macs, select Yes - LDAPS authentication in the macOS profile. Despite the field name, this option also accepts the Sophos Fusion email address and Fusion password. AD credentials are used when a Sophos Mobile LDAP connection is configured; the selected field value alone therefore does not prove that AD authentication is being used. Do not apply the iPhone/iPad option to Macs.
- Confirm the edited Apple profile with Apply, then select Save on Apple setup. For KME, save the User authentication settings described below; assignment is automatic on the user-associated Zero-touch path.
With Active Directory credentials:
- Have the responsible directory administrators prepare synchronization of the AD directory with Sophos Fusion; observe the deletion warning and preview/approval checks described above. It provisions the user accounts and is neither a Mac domain join nor an LDAP configuration for Mac address books.
- On the firewall, allow connections from Sophos Fusion to the AD server over LDAPS, TCP 636. Determine the appropriate source IP addresses from the Fusion account’s region using the AD/LDAP preparation guide; do not copy an address from a different region.
- Check the configured Sophos Mobile LDAP connection to the AD server already required in the KME guide. This is the connection for user authentication, not the LDAP payload of a Mac policy. For KME, User authentication must be enabled. For Apple Business, open the iOS or macOS profile being used under Setup > Apple setup > Apple DEP profiles. On the Enrollment tab, select Yes - LDAPS authentication under Assign user to device. Assignment remains automatic on the user-associated Zero-touch path.
- Confirm the edited Apple profile with Apply, then select Save on Apple setup. For KME, use the following save step.
For KME with Fusion or AD credentials, open the existing Enrollment settings under Setup > Google setup > Samsung KME in the correct Sophos Mobile tenant, enable User authentication, and select Save. The Google identity prerequisites and the approved KME provisioning path must still be checked in the Android Enterprise guide. Saving this setting replaces neither the KME provider configuration nor device setup and is not proof of enrollment. Do not switch userless devices to this user-associated path.
With federated authentication on Apple Business iPhones/iPads: First have an authorized Super Admin prepare federated sign-in in Sophos Fusion: verify the domain → configure the Identity Provider → set the sign-in settings. All administrators and users must be assigned to the intended domain and an appropriate IdP; each user can have only one domain and one IdP. The Fusion federation guide covers setup, fallback access, and sign-in verification. Federating Apple Business with Entra ID for Managed Apple Accounts is a different process.
Fusion sign-in settings apply to all Fusion products, not just Mobile. With Federated credentials only, users receive no SSP email for password setup; they sign in to the portal directly through the IdP, and local Sophos password reset is unavailable. A missing password email is not a delivery failure in this case. If domain/IdP assignment, sign-in verification, or approval is unresolved, stop here. This mode-selection guide does not authorize changes to tenant-wide sign-in settings. Only after the prerequisites are clarified should you edit the profile actually used for the intended iPhones/iPads:
- In Sophos Mobile, open Setup > Apple setup and select the Apple DEP profiles tab.
- Click the name of the appropriate iPhone/iPad profile.
- On the Enrollment tab, select Yes - Self Service Portal authentication under Assign user to device.
- Confirm with Apply, then select Save on Apple setup. Both steps are part of this procedure.
After saving, reopen the Apple profile or KME settings being used and check the saved value against the approved platform and intended sign-in method. This is a configuration check, not proof of successful sign-in. Check the prepared sign-in with the intended identity and actual user assignment on the authorized pilot device together with the enrollment evidence described below. If an option is missing or sign-in fails, have account provisioning, the selected method, and its prerequisites checked; do not switch to another mode or attempt a reset as a repair.
Platform path after selecting the mode
These mode boundaries are orientation, not a complete enrollment procedure; use the platform guide or a separately approved company-device/MTD runbook:
- Android Full device: Only company-owned devices before setup or after an authorized reset. Eligible QR/Zero-touch and userless kiosk routes are separate, not BYOD work-profile methods. Confirm ownership and approved offboarding first: ending full management requires a device wipe. Hand off setup to an approved fully managed Android procedure; never reset a personal device.
- Android Work profile: Personal-device work area, not Full device. The user participates with a personal Google account; a work-profile policy and bundle must be prepared. Use the Android BYOD guide for consent, setup, verification and safe removal; never apply full-device wipe steps to BYOD.
- Apple Device Enrollment: Eligible company-owned iPhone/iPad only; supervised Apple Business provisioning is not personal User Enrollment. For ADE, clarify ownership, the device addition method, APNs/token continuity, and profile assignment using the Apple Business preflight checks. These are not a complete rollout guide; approve execution separately. Do not fully enroll a personal device.
- Apple User Enrollment: Unsupervised personal iPhone/iPad with its own Managed Apple Account, Apple Business app management and prepared user policy. Account-driven enrollment needs Service Discovery and effective SSP configuration; assistant profile-based enrollment is supported only through iOS/iPadOS 17, not as a later-version fallback. Enrollment without Apple Account is a separate device mode and does not waive the User Enrollment account requirement. Review the Apple BYOD guide for limits and consent; use a separately approved enrollment procedure for actual setup.
- MTD: Sophos Intercept X for Mobile manages the protection app, not device MDM or a work profile. Check license, platform, policy/bundle and offered option; hand off activation to a separately approved MTD procedure.
Match the mode in the Add device assistant to the appropriate task: On Enrollment type, check the following selection against the approved management scope. The English labels identify the documented options; their availability depends on the license, platform, and prepared task bundles/policies. If the appropriate option is missing or the bundle contains a different enrollment task, stop and involve the responsible administrators—do not switch to another mode.
- Android Full device: Select Enroll device with task bundle and choose a bundle containing a Full device enrollment task. A policy alone does not determine this enrollment mode. Selecting a bundle replaces neither the company-ownership check nor setup/reset authorization. Do not apply the rules of the separate userless QR/Zero-touch path to this assistant enrollment; for Work profile, continue to use the Android BYOD guide linked above.
- Apple Device Enrollment: For ordinary enrollment of an eligible company-owned iPhone/iPad, select Enroll device; alternatively, select Enroll device with task bundle and a bundle containing a Full MDM enrollment task. This is neither Apple User Enrollment nor an ADE profile assignment. For Apple User Enrollment, continue to use the Apple BYOD guide linked above; the profile installation time limit and its exceptions remain binding as described below.
- MTD on Android and iPhone/iPad: Select either Enroll Sophos Intercept X for Mobile with task bundle and a bundle containing a Mobile Threat Defense enrollment task, or Enroll Sophos Intercept X for Mobile with policy and a Mobile Threat Defense policy. The bundle option can run additional tasks after enrollment, such as installing apps or assigning further policies; the policy option does not require such a task bundle. Both enroll the protection app and provide neither Full MDM entitlement nor device or work-profile management. A complete MTD rollout still requires separate approval.
- Mac without an initial policy: Select Enroll device. A task bundle is not required for this selection.
- Mac with Device policy for all signed-in users: Select Enroll device with task bundle and a bundle containing Enroll and Assign device policy. Before starting, check the device-wide scope against the approved policy.
- Mac with User policy for the selected enrolling user: Select the intended person on User selection; then select Enroll device with task bundle and a bundle containing Enroll and Assign user policy. This person must perform enrollment themselves as the intended local Mac user and enter an administrator password to install the enrollment policy. The scope covering known LDAP network users explained above still applies; this selection does not promise general isolation to a single person. Check user selection and device verification in the Mac enrollment guide.
Before starting, review the enrollment task, policy type, and additional tasks in the selected bundle together. The Mac selection determines the initial policy assignment but does not authorize later, unchecked scope changes; use the macOS security and privacy planning guide linked above for those. For these ordinary assistant paths, a task bundle is required only for the respective bundle option, not as a blanket prerequisite for every enrollment or automated provisioning. A selected bundle and a closed assistant still do not prove completion; the task and device checks below remain necessary.
The Add device assistant, individual enrollment of an existing record and SSP are distinct initiation paths; a record or started task does not prove completed enrollment. In the Add device assistant, a user must be selected for Android Enterprise; Skip user assignment is not permitted on this path. Hand off userless Android Enterprise kiosks to the prepared QR/Zero-touch path, not to the assistant. Use the linked BYOD guidance or approved mode-specific company-device/MTD and SSP procedures, then verify on an authorized pilot device.
Choose Apple Configurator 2 for direct Sophos enrollment
For eligible company-owned iPhones and iPads, Apple Configurator 2 on a Mac provides a separate automated Sophos enrollment path: administrators prepare the device for the Sophos Mobile MDM server; it enrolls automatically when first turned on and taken through Setup Assistant. Whether the device is supervised depends on the Configurator configuration. The user activating it must already be registered for the Sophos Fusion Self Service Portal; check portal access appropriate to the selected sign-in method before handover.
This direct path using a Sophos device group’s Auto-enrollment URL does not, by itself, add the device to Apple Business or replace an ADE assignment. It is neither Apple User Enrollment for personal devices nor MTD. Read the distinction between Apple device addition methods and their data risks before choosing. For USB preparation, the auto-enrollment device group, Prepare Assistant, supervision/host identity, and handover, use the separately maintained procedure for direct Sophos enrollment with Apple Configurator. Do not begin device preparation without clarified prerequisites and approval; choosing a method does not authorize a reset.
Prepare a company-owned iPhone or iPad without an Apple Account
An eligible company-owned iPhone or iPad can be enrolled in Sophos Mobile without signing in with an Apple Account, for example to set it up before handing it to a user. Either automated enrollment or the Add device assistant can be used. Automated provisioning remains part of the separately approved company-device guide; the procedure here covers only enrollment without an Apple Account, starting on the assistant’s Enrollment page.
First check company ownership, approved Apple Device Enrollment, MDM entitlement, and the appropriate enrollment task bundle. This path is not Apple User Enrollment for personal devices or MTD activation. The Managed Apple Account requirement for Apple User Enrollment still applies. If the appropriate mode or a prepared bundle is missing, stop and involve the responsible administrators; do not substitute a mode change or reset.
Before downloading the profile: A manually downloaded configuration profile must be installed in the Settings app within eight minutes. Otherwise, it is deleted and enrollment must be restarted. This time limit does not apply to devices assigned to Sophos Mobile through Apple Business or Apple Configurator; nor is it a general deadline for account-driven Apple User Enrollment.
- In the Add device assistant, select the Enrollment without Apple ID tab on the Enrollment page. The tab still uses the older Apple ID term.
- Open the enrollment URL provided there in the browser on the iPhone or iPad being enrolled. The Sophos Mobile enrollment form appears.
- Enter the corresponding token in that form and select Enroll.
- Follow the instructions on the device to install the enrollment task bundle. Install the downloaded configuration profile in Settings within the time limit stated above.
Acceptance of the token or a closed assistant does not prove that enrollment is complete. Before handover, check the actual management scope on the authorized pilot device, along with user assignment, device group, policy, management status, and completed tasks under Tasks in Sophos Mobile, as described in Verify the pilot and clarify the exit path in advance. If an error occurs, retain task and error details and involve the responsible administrators rather than switching to another enrollment path.
Create a device record and start individual MDM enrollment
The following steps describe how to create a record manually and start individual MDM enrollment using the common steps. They replace neither the mode decision nor platform-specific setup. Work only with approved administrator permissions in the correct tenant; if an option appropriate to the intended mode is missing, stop and have the prerequisites checked.
Manual device record: Add device manually
Sophos recommends creating one or more device groups before adding the first device, so devices can be assigned to a group and managed more easily. The device group preparation guide describes Device groups > Create device group and how to check the group’s scope.
- Open Devices and select Add. In the Add device manually menu section, select the appropriate platform. Edit device opens. This is not the Add device assistant.
- On Edit device, enter the details for the approved device:
- Name: assign a unique name to the new device record.
- Description: enter a description of the device.
- Owner: select Corporate or Personal according to actual ownership. This setting does not limit the management scope.
- Email address: enter the intended email address; where applicable, observe the Android Enterprise identity requirements described above.
- Phone number: enter the device’s phone number in international format, including the country code.
- Device group: select the prepared target device group.
- Optionally assign a user: Next to User, click the Edit user assignment icon, then Assign user to device. Find and select the intended user, then confirm with Apply. The individual user assignment guide describes searching, selection, and limits on later changes. This optional assignment during manual record creation does not remove the requirement to select a user in the Android Enterprise assistant.
- Optionally add custom device properties: Open the Custom properties tab and select Add custom property. Add only approved properties needed for the device; these are not the same as tenant-wide Customer properties.
- After checking all relevant details, select Save. The new record appears under Devices. Provisioning or management can then proceed through the approved path for the platform and mode. Save stores the device record; it does not complete enrollment. Reopen the record and check its details, group, and, where applicable, user assignment before starting enrollment.
iPhone/iPad name during synchronization: Only if name synchronization is configured does Sophos Mobile replace the name entered under Name with the device name obtained during synchronization. The iPhone/iPad settings for Synchronize device name explain the name source and how to check it. In that case, do not assume a manually assigned name will remain unchanged.
Individual enrollment of an existing device record
These common starting steps apply only to an existing device record and an MDM mode and platform path approved for it. They are not an MTD activation procedure or a substitute for account-driven Apple User Enrollment. The Android Enterprise identity and SSP limitations described above also remain binding; do not assume Actions > Enroll is universally available.
- Under Devices, open the device to be enrolled. On Show device, check the device, platform, and intended user assignment against the approval.
- On the device page, select Actions > Enroll. The enrollment task starts and is displayed on Task view; the user receives enrollment instructions by email.
- The user follows the steps provided for this device. For a Mac, the local user to be managed must enroll it themselves and enter an administrator password to install the enrollment policy; the specific procedure and verification are covered in the Mac enrollment guide linked above. For manually downloaded iPhone/iPad configuration profiles, the installation in Settings, eight-minute time limit, and exceptions for Apple Business or Apple Configurator described below apply. Do not apply this time limit to account-driven Apple User Enrollment.
- Then check the platform and pilot evidence described below. Task view shows the started task; neither its start nor the sent email proves completion. Checking the individual device tasks under Tasks and the actual management scope remains necessary. If an option is missing or a task fails, do not substitute another enrollment method or a reset; retain task and error details and involve the responsible administrators.
Verify the pilot and clarify the exit path in advance
If an enrollment task is pending or has failed: Use the task and error diagnostics guide with the read permissions actually granted: open Tasks > State, then the Show magnifying-glass icon for Task details; retain the state sequence, timestamps, and error codes. The Details button, if available, shows the device commands. Check older tasks in the Task archive. This read-only check is separate from resending, synchronizing, requesting logs, or deleting a task; those interventions require their own permissions and approval. Escalate with the retained details rather than retrying enrollment or a reset on suspicion.
On an authorized pilot device, check the area actually managed and, in Sophos Mobile, the user, group, assigned policy, management status, and completed task status. After successful Android work-profile enrollment, Devices shows Work profile and Managed; individual tasks on the device page show Successful under Tasks. With Apple User Enrollment, a Sophos Mobile entry is visible on the device under Settings > General > Device Management. A created device record or closed assistant is not sufficient proof of success either. For iPhone/iPad profile installation through the Add device assistant, individual enrollment, or the without-Apple-Account method, when a configuration profile is downloaded for manual installation, the user must install it in Settings within eight minutes; otherwise, it is deleted and enrollment must be restarted. Do not apply this assistant warning indiscriminately to account-driven Apple User Enrollment. This time limit does not apply to devices assigned to Sophos Mobile through Apple Business or Apple Configurator.
After successful MDM enrollment: Users can perform the tasks available for their device and effective configuration in the Sophos Mobile Control app, such as syncing, viewing and resolving policy violations, or installing offered work apps. If the organization offers apps for the device in the Enterprise App Store, open Apps on the Sophos Mobile Control Dashboard, tap the app you want, and follow the installation steps. The guide to offering and installing apps describes this route. On Android devices where Sophos Mobile manages only the work profile, install approved work apps through the Google Play Store with the briefcase icon in the work profile instead, not through Apps in Mobile Control or the personal Play Store; use the separate work-app procedure. Most of these app tasks require the device to have an internet connection. The IT contact details configured by the organization are also available in Mobile Control. The Sophos Mobile Control user handoff covers policy violations and the support contact. These user actions in the Control app are neither the administration console’s Tasks status nor SSP enrollment; SSP enrollment belongs in the SSP guide. Do not promise every action for every operating system or for app-only MTD.
Approve the SSP test separately: The Add device assistant does not replace the final enrollment test in the Sophos Fusion Self Service Portal. Before inviting users, sign in to the SSP with a dedicated, authorized test account from the intended user group. Using approved test devices, check the effective configuration (priority, device limit, platform, Owner, Device group, Enrollment package) and actual enrollment for every planned platform and ownership/management mode. Compare the management scope on the device with the user, device group, policy, and completed task status in Sophos Mobile. If there are discrepancies, retain task and error details and escalate to the responsible administrators without changing modes or making further attempts on production devices. Performing and approving the SSP configuration and pilot test belong to the separate admin topic Mobile SSP configuration and device actions; this mode-selection guide is not an SSP procedure.
Clarify user-data impact before enrollment and offboarding: Depending on the effective MDM profile and assigned apps/accounts, new managed apps may be offered or added, and work email, calendar, and contacts may be configured. Depending on the mode and policy, device features or apps (such as the camera, YouTube, or App Store) may be restricted; policy violations may trigger notices. Protected apps may require an app protection password to be set up when first opened; Sophos Mobile Control may ask for the email password. On supported Samsung Knox Android devices, users may be asked to accept the Knox license. If this consent is requested, it is required to register Sophos MDM functionality on the device. The Knox license described for this purpose is free; a Knox Premium license is not required for this registration. This is not a general Android Enterprise setup step. No conclusions about the licensing of additional Knox Premium features or KME profile assignment can be drawn from this. Check the actual policy and management mode before inviting users: An Android work profile does not manage the personal area; do not apply device-wide examples indiscriminately to BYOD. If the configuration is removed on unenrollment, the managed apps and the email, calendar items, and contacts introduced by it are removed from the device too. Inform affected users and agree on the approved, mode-specific handoff before enrollment or removal; do not assume personal data is deleted or that app-only MTD has the same effects.
Do not infer cleanup steps from this mode-selection guide: Removing an Android work profile deletes its business apps and data, not the entire device, and does not apply to fully managed devices. After user-initiated removal—whether accidental or intentional—the console may still show “Work profile” even though synchronization has stopped: check the status on the device rather than inferring from the console entry that the profile still exists. To find potentially affected devices, in Sophos Mobile select Reports > Devices not synchronized in last 7 days. A report entry is not proof that a profile was removed; confirm the actual profile status with the user on the device. If the profile was removed accidentally and re-enrollment is approved, follow the safeguards in the Android BYOD guide linked above; do not delete a device record solely on the basis of the report. When a device with Apple User Enrollment is unenrolled from Sophos Mobile, the Managed Apple Account and the managed APFS volume containing work data are removed from the device; personal data remains separate. For fully managed devices, the exit path may be substantially more disruptive. Therefore, clean up test devices only through approved, mode-specific offboarding; never reset them indiscriminately or initiate deletion when ownership is unclear.