Skip to content
Avanet

Sophos Mobile: Find the right tenant, license, and starting point

Quick route for administrators: In the appropriate Sophos Fusion tenant, first confirm the organization, your role, and the Mobile license. My Products > Mobile (in German-language help, Meine Produkte > Mobile) opens product management; My Environment > Mobile Devices (Meine Umgebung > Mobilgeräte) lets you quickly look up registered devices. These are two views, not two enrollment routes. If you need to work on a policy or device, distinguish between Mobile Device Management (MDM), Mobile Threat Defense (MTD), and Sophos Chrome Security first. A visible menu proves neither that you have permission nor that a particular device configuration is supported.

Which product path fits your task?

  • Manage devices or a managed workspace: For ownership, management scope, and the Android or Apple mode, start with Choose MDM or Threat Defense only. Initial tenant setup covers prerequisites in the correct tenant, not enrollment of a specific device. For Windows computers, first read Windows MDM enrollment with support and pilot checks; this path is separate from installing the Sophos Endpoint agent. Then continue with the guide for the chosen platform mode; do not fully manage or reset a personal device as a substitute.
  • Deploy apps to registered devices. For the app catalog, installation, and controlled withdrawal, see the app deployment article. First check the platform, management mode, app source, and permissions there. A catalog entry does not prove installation; managing the MTD protection app is a different task.
  • Manage the protection app on Android or iPhone/iPad: MTD covers Sophos Intercept X for Mobile, not automatically the whole device. For MTD policies, see the MTD policy article. MDM tasks belong to the standalone Sophos Mobile Device Management license or the combined Sophos Mobile license. Device Management alone includes neither MTD nor Chrome Security. Before assuming any management capability, check the license, platform, mode, and intended policy. The distinction between editions does not mean two tenants are required.
  • Secure ChromeOS: Sophos Chrome Security is the path for the managed security extension on Chromebooks and other ChromeOS devices, not Android Enterprise MDM. For prerequisites, Google Workspace assignment, and policy limits, see the ChromeOS security article; the corresponding license choice is covered in Sophos Mobile: Choose a license and check usage. A product page merely mentioning Chromebooks does not confirm that a particular extension or policy will work.
  • Let users enroll themselves or perform permitted actions: The Sophos Fusion Self Service Portal (SSP) is a user-facing route; administrators prepare the groups, options, and permissions. For that setup, see the SSP admin article; for user instructions, see the SSP user handoff. Do not lock, wipe, or take other device actions merely because an SSP menu is available.
  • Assess a device action or offboarding as an administrator. For a lost device, a passcode problem, or planned unenrollment, see the safe device actions article. It explains passcode reset, locking, wiping, and unenrollment by platform and management mode. Before taking action, clarify responsibility, approval, device ownership, data consequences, and the recovery path; stop if the mode is unclear. This administrative route is separate from SSP user permissions, and the link does not authorize any device action.
  • Create and view reports: For Reports in Sophos Mobile Admin, see Reports and other analysis routes. First check in the appropriate tenant which reports your licensed edition and role allow; this link does not imply additional MDM or TEM capabilities.

To determine which edition was purchased, how Mobile usage is counted, or when the license ends, do not infer the answer from a help-guide title: the Mobile licensing guide explains Device Management, Threat Defense, and the combined Sophos Mobile license; the authoritative check is against your own tenant and the License Schedule. Before a production change, check the current prerequisites for the edition actually licensed, rather than assuming a documentation title establishes an entitlement.

Once the tenant, license, platform, device ownership, and management mode are clear, prepare the device group and check its scope. For creating and assigning policies and making later changes, follow the policy workflow. To create, order, and deploy device tasks, use the Task bundles guide. These guides describe the required pilot checks and rollback paths; linking to them does not authorize device changes.

Distinguish administration, device views, and on-device help

In Sophos Mobile Admin, administrators manage policies, compliance, devices, and SSP settings, among other things. For a compliance decision, consult the compliance policies article rather than adopting a rule from this navigation guide. The device view in Fusion is useful for looking things up, but it does not prove that a task reached the device or that protection is active. A portal entry does not replace checking the device’s current status and assigned policy.

Read the local Intercept X dashboard

The Sophos Intercept X for Mobile (IXM) dashboard provides an overview of the device’s security status on Android and iOS. Each color indicates the status of a feature:

  • Green: No issues found.
  • Red: High-severity issues found.
  • Yellow: Medium-severity issues found.
  • Blue: Feature enabled.
  • Gray: Feature disabled or not yet configured.

Blue therefore does not mean “no issues.” These feature colors are neither the configurable device health in administration nor the compliance tiles in Sophos Mobile Control. A green feature status does not prove that all protection features are active or that the device meets every organizational policy.

The Android and iOS app features described here refer to the latest app version. An older installed version may lack features; check the app version if a display or feature is missing.

Platform-specific app features

On Android, Intercept X for Mobile automatically scans apps for malware during installation. This is an installation scan, not a guarantee that every threat will be detected; do not infer that an equivalent app scan exists on iOS.

On iPhone and iPad, touching and holding the Sophos app icon opens the quick actions menu. On a device with 3D Touch, you can alternatively open this menu by briefly pressing the icon. These local app quick actions are not the remote device actions available to administrators or through the SSP.

Managed Android app and Mobile Control

If Intercept X for Mobile on Android is managed by Sophos Mobile, the organization defines app settings centrally and can trigger scans to determine security status. Compliance status is visible on the app dashboard; network access or other features may be restricted if the device is noncompliant. Neither the ability to trigger a scan nor the display proves a completed scan or an enforced block. Follow the organization’s instructions for enrollment; this is not a scan or sanction procedure.

Sophos Mobile Control, by contrast, is the client for managing the device or a work area. Depending on management scope, the organization can, for example, install or remove apps and turn off device features. In that case, compliance status and IT contact are available in Mobile Control. Continue to use the MDM/Threat Defense decision linked above to choose the appropriate scope; distinguishing the clients does not authorize device actions.

Managed iOS app: Compliance

To enroll Intercept X for Mobile on iOS with Sophos Mobile, follow the instructions provided by your organization.

If Intercept X for Mobile on iOS is managed by Sophos Mobile, the app dashboard also shows compliance status against the organization’s policy. The organization configures the app settings centrally; network access or other features may be restricted if the device is noncompliant. However, the displayed status alone does not prove that a network block is actually enforced.

Managed Android and iOS app: IT contact

If Intercept X for Mobile on Android is managed by Sophos Mobile, you can view the organization’s support details under Dashboard > Corporate management. They appear under IT contact and Additional info. On Android, tap Email to write an email to IT, or Phone or Mobile to call IT.

In the managed iOS app, open the configured support details through Dashboard > Corporate management as well. They appear under IT contact and Additional info.

Those details come from the organization; they do not replace its documented internal support route if the app is not yet managed or shows no contact details. The device display is not a second administration interface either.

Scope of this article: It helps you identify the tenant, license, relevant help, and next specialist topic. It does not describe enrollment, activation, policy assignment, remote actions, or offboarding. If the tenant, role, device ownership, or license scope is unclear, stop here and involve the responsible administrators. For changes, continue with the corresponding specialist article linked above, check the current prerequisites for the OS version, enrollment mode, and device state, and use an authorized pilot with its own success checks; platform lists and app dashboards alone prove neither support for every OS/enrollment mode nor the state of a particular device.