Choose a Sophos Mobile license and check usage
MDM and Threat Defense are separate entitlements; Sophos Mobile includes both. Reported usage depends on assigned users and recently synchronized …
Find Sophos Mobile guides by task rather than by product menu. First confirm the tenant, permissions, and device ownership; then choose an enrollment or protection path. Before changing policies, certificates, or devices, check how to reverse the change. Device management, Mobile Threat Defense, and ChromeOS security are separate tasks. A visible menu item does not prove that you have a license or that a change has taken effect on a device.
The topic cards are a guide, not approval for every planned article. If a guide has not appeared yet, or an effect on a device or tenant has not been verified, do not infer that a high-risk action is safe from a cluster description. Check the specific mode, current approval status, and an authorized pilot separately.
The cards below reflect the articles' actual category assignments. Drafts that have not been approved do not appear in the normal published site. This overview does not promise complete coverage or a successfully tested device configuration.
Identify the right tenant, permissions, and management or protection path.
MDM and Threat Defense are separate entitlements; Sophos Mobile includes both. Reported usage depends on assigned users and recently synchronized …
Check the Mobile license and edition, delegated roles, IT contact, message language, and SSP behavior; enroll pilot devices only after separate …
Clarify ownership and the desired level of control first, then choose the appropriate Android or Apple mode, and only then select an enrollment …
Check the tenant and license first, then choose the device management, protection app, ChromeOS, or SSP guide for your task.
Distinguish device ownership, platform, and enrollment method before setup or a pilot.
Sophos Mobile Windows enrollment uses the native Windows MDM client, not the Sophos endpoint agent. Check the invitation, management mode, and exit …
Check the example CSV and roles in your own tenant; an imported device record is not yet an enrolled or protected device.
Enrolling a Mac in Sophos Mobile installs an MDM Enrollment Policy. The local user signed in during manual enrollment is an important decision to make …
Before enrolling the first Android Enterprise device, clarify the license and Google connection, ownership and management mode, and policy and …
Check Apple Business addition and ADE prerequisites, or prepare company-owned iPhones/iPads directly using the Sophos auto-enrollment URL. The two …
This guide takes you from separate work identities through tenant configuration to voluntary enrollment and safe unenrollment. User Enrollment remains …
A personal Android device gets a separate work area; setup and removal require the correct management mode and verification on the device.
Decision aid for fully managed Android kiosk devices, with separate preflight checks for QR, KME and Zero-touch and a documented QR workflow for …
Treat migration cases separately from standard new enrollments.
Corporate devices require a factory reset; personal devices follow a different unenrollment path. Legacy policies do not automatically carry over to …
Do not confuse work profiles and device-specific Android options with fully managed devices.
A work-profile policy does not necessarily affect only the work profile: distinguish device locks from deletion consequences before using it for BYOD.
KSP adds Samsung policies as a managed app. Check compatibility, licensing, and actual policy effects before deployment.
A valid, accessible Google recovery account and device synchronisation matter more than the reset button: FRP can leave a device unusable after a …
Distinguish supervised devices, Activation Lock, profiles, updates, and macOS security options.
Importing stores a profile in Sophos Mobile. Assignment, delivery, and the effect on the target device must be checked separately.
The newer English Sophos help lists macOS 26 or later for three declarative update configurations; the older German Sophos help conflicts with macOS …
Check supervision and OS version for each setting before assignment; account for lockouts, data loss, and lost connectivity when planning rollback.
Save an AirPlay destination in the Apple setup, then request mirroring for a specific iPhone or iPad. A completed task alone does not prove that video …
The iOS & iPadOS settings control receipt of a bypass code from supervised devices and where the device name comes from. A setting alone does not …
Decide the scope first, test security and privacy payloads in a pilot, and selectively remove the obsolete User Restrictions setting when macOS 26 …
Which update option fits which managed Apple device, what limitations apply, and what to check before a pilot.
Check the target group, assignment, and actual effect of policies or app protection separately.
Which Android Enterprise device settings affect fully managed corporate devices, and which irreversible or destructive consequences to check before …
Distinguish MAM from MDM and Mobile Threat Defense; review Microsoft permissions in the actual tenant, limit assignments and plan certificate renewal.
Device group, assigned user, and policy type determine different aspects of scope. Check a pilot and establish the appropriate rollback path before …
Before assigning a Windows policy, check the edition, support lifecycle, BitLocker recovery, and local accounts. Some settings cannot be reversed …
Understand the different dependencies of APNs, SCEP, connections, and Exchange access.
Which network payloads fit managed and personal iPhones and iPads—and how to verify a pilot without losing MDM access.
An architecture decision for mobile mail access: Where does EAS traffic flow, what does Sophos check, and which approvals are needed before a …
Before deploying the EAS proxy, verify mail paths, certificates, installer, and authentication separately; the Basic fallback is unusable with …
Read-only checks for EAS proxy connections and ActiveSync ID mapping; historical Android cases are not a general repair procedure.
Distinguish device and work profile policies, clarify certificate roles, and identify outstanding checks and stop criteria before changing …
The email account policy must match the new Exchange environment. An assigned policy proves neither successful sign-in nor mail delivery or a safe way …
Before rolling out macOS connectivity, establish the policy context, identity, CA trust, and independent management access; then assign only to a …
Windows policy for Wi-Fi, root and client certificates, or SCEP: secure independent management access first, then check the pilot device and …
Annual APNs renewal depends on the original Apple Account and a matching Topic, not just a similar certificate name.
The Sophos examples are not a tested four-way guide: For Exchange Online delivered to iOS through a third-party UEM, Microsoft's additional UPN …
Tenant-side SCEP prerequisites and a limited certificate pilot; Wi-Fi/VPN certificate mapping depends on the platform and requires separate …
Separate shared assignment workflows from platform stores and app licenses.
Prepare, assign, and revoke Apple Business apps in Sophos Mobile safely; distinguish content tokens from ADE service tokens.
A shared workflow for the app catalog, target devices, installation, and controlled removal, with important exceptions for Android Enterprise, Apple, …
Managed Google Play in Sophos Mobile: approve public, private and web apps, install them on selected devices, configure them and withdraw them safely.
Do not mistake the protection app or web filtering for device management.
An iOS MTD policy alone does not prove filtering is active. Supervision and app scope differ; if the classification service is unreachable, all …
The Sophos MTD connector sends device security status to Intune. A suitable device compliance policy, and optionally Conditional Access, determine …
First establish the edition, ownership, and Intune integration; then enroll the protection app deliberately and check its status on a pilot device.
The 2023 Android and iOS app help pages list the same seven client URLs; the 2026 Sophos Mobile technical guide maps services and ports in the Mobile …
Assess Android protection features against app registration, edition and management mode before assigning an MTD policy.
Manage Intercept X for Mobile on iPhone and iPad without confusing MTD with Apple device policies.
For MTD policies, the platform, the configuration actually saved, and device connectivity matter; a support export is not a rollback.
Check the scope of inventory, task bundles, privacy, and platform-specific cases.
A task bundle combines multiple tasks; order, edition, device mode, and asynchronous confirmation determine what actually happens.
Check the Google OU, connection code, extension policy, and web filter separately; define exceptions and a rollback path before rollout.
Sophos Mobile documents a single-app kiosk for Windows policies. Before assignment, the account, UWP app, operating-system lifecycle and an …
Read-only mobile-device inventory workflow: choose the right view, compare status and synchronisation, and follow up on discrepancies.
Apple User Enrollment manages the business area of a personal iPhone or iPad, not the entire device. Before applying a policy, consider the enrollment …
Data Lake uploads are explicitly off by default for Threat Defense; enabling Mobile uploads for Sophos Mobile is documented separately. Location and …
Handle compliance rules, synchronization errors, and responses to a lost device separately.
The right action for a lost device depends on ownership, platform, and management mode. Removing a work profile is not a full device reset.
Keep rule evaluation and response separate: MDM and Mobile Threat Defense differ in the rules and actions they support; Check now is not a risk-free …
Check the rule violation and management mode first, then assess Sophos Wireless access separately. Manual overrides are not a fix; deletion and resets …
A diagnostic path for pending or failed Mobile tasks and device states that appear out of date.
Review admin approvals and the user workflow separately.
Mobile SSP configuration limits device enrollment and user actions. Check group priority, device management mode, and irreversible actions separately …
Mobile displays assigned users differently by edition; accounts and groups remain in Fusion, while Mobile controls Self Service enrollment and, where …
What users can do themselves, when IT approval is required, and which actions affect data or privacy.
Check user assignment, data export, and retiring product paths separately before decommissioning.
The phased retirement of Password Safe has begun on Android; complete removal has not been established. Back up existing KDBX files in time and check …
Sophos Container is no longer supported; an existing Samsung Knox Container policy, however, proves neither a blanket end to Knox support nor a safe …
Assigning an individual device and the tenant-wide action on user deletion are separate controls. Before offboarding, clarify the enrollment mode and …
Clarify authorization, consent, and how a support session ends.
TeamViewer is a third-party access method. Before starting, check organizational approval, licenses, the device, and consent; verify disconnection in …