Import Sophos Mobile devices by CSV – check before enrollment
CSV import is a write operation that creates device records, not device enrollment. Sophos documents the same basic procedure for Sophos Mobile / Mobile Device Management and Sophos Mobile Threat Defense. Confirm the applicable edition and arrange the subsequent enrollment or app setup separately. A record under Devices does not establish either MDM management or active Intercept-X protection. The steps here have been checked against documentation, not carried out with a CSV file in a tenant.
Before importing: authorization and example file
- Check the edition and role in the correct tenant. Sophos maps Super Admin and Admin to the Mobile Administrator role, which can perform the available actions. Help Desk/Helpdesk cannot create devices, Read-only can only view information, and User has no Mobile access. Before performing the write operation, check any differing or restricted permissions and verify that Devices > Add > Import devices is actually available in your tenant. The import documentation does not provide a more granular import-permissions matrix.
- Users and device groups must already exist in Sophos Mobile. Match the target devices and intended assignments against the approved inventory. Treat the CSV as potentially containing personal data: work on it only in approved storage and with authorized people. This is a precaution, not a claim about particular CSV columns.
- On Import devices, download the Example CSV offered there for the edition and environment actually in use. Check its columns, their order, and required versus optional fields before preparing your file. The public import documentation does not list these columns. Do not infer column names, unique keys, or required fields from the manual add-device form. Without a verified, current Example CSV, do not prepare a production file or start an import.
- Choose a small, authorized pilot and plan an inventory check afterward. On these pages, Sophos does not describe how existing devices or duplicate keys are handled, whether reimports overwrite records, whether repeating an import is idempotent, or how to roll back a completed import. If there may be matches or repeat-import behavior is unclear, stop before Finish and establish the behavior in a controlled way in the approved tenant.
CSV format and documented procedure
For no more than 500 devices per import, the first row is a header row and is not imported; values are separated by semicolons, not commas. Every row needs the correct number of semicolons, even when optional values are empty. The file extension must be .csv; the file must be encoded as UTF-8 for non-English characters to import correctly. The 500-device limit applies per import: it is not a promise about license capacity or about splitting a larger inventory without risk.
- In the authorized tenant, open Devices > Add > Import devices and use Upload a file to select the file prepared from the verified Example CSV. The imported rows are initially displayed for review.
- Compare the preview with the approved inventory. According to Sophos, if the data is incorrectly formatted or inconsistent, the entire file cannot be imported; error messages appear beside the affected entries. Correct the file and upload it again. This is not a documented guarantee of duplicate detection and says nothing about partial states after Finish.
- Select Finish only after the preview has been approved and identities and target groups have been clarified. Sophos says that the created devices then appear under Devices. Compare the expected records there with the approved inventory rather than treating the click or the preview as proof of success.
Enrollment and configuration take place afterward through a separate process appropriate to the edition and platform. For Mobile Threat Defense in particular, an import does not confer MDM management or confirm that the protection app has been activated. If the state after Finish is unclear, do not blindly reimport the unchanged file: first inspect the created records and obtain authorized clarification of the consequences for duplicates and corrections. Deleting a device record is not recommended here as a safe rollback.
Gate before production use: Inspect the current Example CSV in the authorized tenant, verify the actual import permissions and edition, and test duplicate, reimport, and error/retry behavior in an approved small pilot. This guide, checked against documentation, does not replace authorization for a production fleet-wide import; the tenant and pilot checks listed above must be carried out separately before such use.