Skip to content
Avanet

Choose a Sophos Mobile license and check usage

At a glance: To manage devices with policies, choose Sophos Mobile Device Management. To manage Sophos Intercept X for Mobile or Sophos Chrome Security through Sophos Mobile, choose Sophos Mobile Threat Defense. If you need both entitlements, consider the combined Sophos Mobile license. These are product entitlements, not three apps that must automatically be installed on every device. Before rollout, confirm that the edition, platforms, quantity and term actually purchased for your Sophos Fusion tenant match the License Schedule.

Which Sophos Mobile license fits your needs?

  • Sophos Mobile Device Management (formerly Central Mobile Standard) provides the MDM features for managing Android devices, iPhones, iPads, Macs and Windows computers. Here, MDM means device management through enrollment and appropriate policies; it does not automatically include management of the mobile protection app.
  • Sophos Mobile Threat Defense (formerly Intercept X for Mobile) provides management of Sophos Intercept X for Mobile on Android, iPhone and iPad, and Sophos Chrome Security on Chromebooks and other ChromeOS devices, through Sophos Mobile. Its name does not mean that it also enables MDM features.
  • Sophos Mobile (formerly Central Mobile Advanced) includes the features of both licenses above. Do not confuse this current license name with a reference to the “Sophos Mobile” management interface alone.

The platform lists describe the scope of each license, not a promise that every policy or protection feature works equally on every operating system. For a mixed fleet, check the required features on each platform before enrolling devices at scale or deploying policies. For example, “manage iPads and run Intercept X for Mobile through Sophos Mobile” is a different requirement from “manage iPads only through MDM.” Choose the purchased license based on that requirement, not on a similar-sounding former product name.

Who consumes a license?

Sophos describes Mobile usage as user-based: a user assigned a device managed by Sophos Mobile consumes one Mobile license, even if several devices are assigned to that user. A managed device without an assigned user, by contrast, counts as one license in its own right. When calculating displayed usage, Sophos considers only devices that have synchronized with Sophos Mobile in the past 30 days.

A simple distinction helps with inventory: if a work phone and tablet are both assigned to the same person, that person is counted once for Mobile usage. A shared device with no assigned user is counted separately. These examples describe the usage calculation, not the number of technical enrollment slots or a pricing tier. The 30 days are a lookback period for device synchronization, not a guaranteed period of continued operation after license expiration or a reason to exclude deliberately offline devices from contractual requirements.

The Sophos licensing FAQ states a general technical limit of ten Android Enterprise devices enrolled concurrently by the same user; the enrollment documentation explicitly states this limit for the Managed Google Play Account registration mode. These differently scoped statements do not clearly establish whether the limit also applies to managed Google domain. Before a rollout that depends on more than ten concurrent devices per user, clarify the specific registration and enrollment mode with Sophos; do not assume unlimited capacity. Keep this separate from license usage: someone with multiple devices may count once for licensing but still reach the enrollment limit. If portal usage is higher than expected, first check user assignments, devices without users and the time of their last synchronization. Sophos notes that the displayed figure can be inaccurate in some cases and that a calculated overage does not immediately block further Mobile management. That does not remove the need for an appropriate contractual license quantity: resolve any discrepancy with your partner rather than treating it as free extra capacity.

Check before activation and expiration

Check roles and permissions before taking action: In the correct Sophos Fusion tenant, first check your administrative role and access to the Sophos Mobile product. Read access permits only the views allowed by that role: a Read-only role cannot apply license keys or start trial licenses; with Custom Roles, product access and permissions to manage and assign policies may be restricted further. Seeing a license or device does not authorize activation, enrollment or policy changes. Refer license actions to an authorized license administrator; for a pilot, confirm the necessary Mobile and platform permissions and identify someone responsible for reversing or changing actions in the tenant. Do not perform write actions based solely on a role name or a view you can read.

  1. Record the specific tenant and intended scenario: MDM, Threat Defense or both, together with the platforms to manage and which users the devices are assigned to. Check the order confirmation or License Schedule for product name, quantity and end date.
  2. In Sophos Fusion, go to Profile icon > Licensing to see which Mobile license is active in the correct tenant and what usage and term information is available for that license. For a purchased license, compare the binding end date in the License Schedule with the available tenant information; the Expires column is documented for trial licenses but is not established as a standard display for every purchased Mobile or Flex license. Mobile product management is separate: a visible device-management view alone does not confirm the right edition or an adequate contractual quantity. For the general activation process, see Activate, check and renew Sophos Fusion licenses.
  3. Before a pilot rollout, test the feature you actually need on a suitable test device: is the desired MDM policy or intended Threat Defense management available, and does the device show the expected assignment and synchronization after setup? Only then check license usage again; if the usage figure remains unchanged immediately afterward, that alone neither proves a missing entitlement nor confirms that the required entitlement is in place.
  4. For a purchased license, coordinate renewal with your Sophos partner well before the end date agreed in the License Schedule, then recheck the product, edition, quantity and term. For a trial license, note its separately displayed expiration date; do not infer the term of a purchased license from it. Sophos warns generally that expired licenses can result in loss of protection and functionality. That does not establish a reliable Mobile-specific grace period or guarantee that existing devices can still be managed after expiration.

If MDM policies are missing, first check the Device Management versus Threat Defense license and the target platform instead of hastily deleting enrollment or device records. If usage seems unexpectedly high, check user assignments and devices without users; if it seems unexpectedly low, check the last Mobile synchronization and the actual fleet. For cross-product counting models and contractual limits, see How is Sophos Fusion licensed?. This article, by contrast, addresses Mobile-specific edition selection before rollout.