Licensing Sophos Server Protection: Servers, VMs, RDS, and XDR Sensor
Short answer: Sophos Server Protection licensing is not simply based on how many users sign in to a server. The Sophos licensing guidelines list Sophos Endpoint for Server and Sophos XDR (per Server), among others, as distinct server-based units; they also list XDR per User for a different use case. Which of these a particular server may use depends on the line item and quantity ordered in the Sophos Schedule, the governing contract, and the tenant actually licensed—not just a button in Sophos Fusion (formerly Sophos Central). Before rollout, inventory physical and virtual servers separately and record the intended agent mode.
What counts as a server—including VMs and RDS?
Sophos defines a server as a computing environment on which the product is installed or which benefits from the product and provides at least one application, client service, or capability. The underlying definition of “Computer” expressly includes virtual machines and non-persistent environments. A guest VM running on a hypervisor is therefore not automatically covered by its host’s license. For planning, inventory each guest instance to be protected; for changing or cloned instances, clarify the contractual counting method with the Sophos partner. Cloud VMs are not automatically entitled through some other Sophos cloud product or a host purchase.
For Remote Desktop Services (RDS), the Sophos FAQ expressly says that RDS sessions are supported under a Server Protection license; an additional Endpoint Protection license solely for those sessions is not required. This concerns protection of the RDS server, not a blanket licensing assurance for all connected clients, other servers, XDR features, or third-party software. Check the specific server edition and quantity against the order. Planning one Endpoint license per signed-in RDS user as a substitute for the required server entitlement is therefore the wrong starting point.
Example: Two Windows Server VMs run on a virtualization host, one of them an RDS session host. If both are to be protected, assess both guest environments and their functions—neither a single host purchase nor the number of RDS logins determines their entitlement across the board.
Full protection or XDR Sensor?
Under My Environment > Installers, Sophos shows Windows and Linux server installers for full protection in the Server Protection section, alongside separate XDR Sensor installers. Choose full protection if Sophos itself is to provide malware protection on the server. The Windows installer lets you select components under Choose Components…; the standard download includes the products covered by the license. Even so, check which features are actually licensed against the specific order.
XDR Sensor is not a protection edition: Sophos notes that this sensor does not prevent threats and that third-party protection software must be installed. Sophos requires a license with XDR for both the Windows and Linux XDR sensors. A visible sensor download or an existing Server Protection license alone therefore proves neither XDR entitlement nor the presence of prevention. Sophos Linux Sensor (SLS) is also a separate agent and must not be confused with XDR Sensor.
The device overview distinguishes Endpoint (Sophos protection), XDR (Sophos protection plus detection and response), and XDR Sensor (detection and response only, without Sophos prevention). XDR and XDR Sensor are therefore not interchangeable names for the same protection.
Reconcile the order and tenant before rollout
Before changing a pilot server: Adding or upgrading Sophos software can remove installed third-party protection. Moving from XDR Sensor to XDR/full protection is a coordinated protection migration, not a license correction; Uninstall removes Sophos protection components and does not correct a license either.
- Inventory the estate: Record each server’s hostname/inventory ID, operating system, physical or VM status, RDS role, intended protection type, and short-lived instances. For clones or autoscaling, also check peak usage and the contractual counting method, not just today’s portal inventory.
- Read the order: Reconcile the product/SKU, ordered server units, term, and tenant in the Sophos Schedule or order against the inventory. Ask the partner about unclear editions, bundles, or legacy contracts before purchasing or rolling out; public licensing guidelines do not replace the individual contract.
- Cross-check the display: In Fusion, compare product, quantity, and expiration date under Profile icon > Licensing with the order. The portal counter may understate actual usage under the EULA; if they conflict, the EULA takes precedence. For activation and renewal, see Check Sophos Fusion licenses.
- Pilot one server: Before making a change, document the installed third-party and Sophos protection, current agent mode, and intended selection. Under My Environment > Computers & Servers, select exactly one server, open Manage Software, and check the entitled selection under Manage Device Software > Agent mode before Save. Investigate a Server agent mode warning in Account Health Check via Agent mode status (Product unassigned or Upgrade available), but do not blindly run Fix automatically for every server.
Success criterion: The ordered line item, purchased units, and term can be traced to the tenant; the inventoried server environments have been reconciled with the partner and contract. After the pilot server’s next online/update contact, check the agent mode actually installed and active prevention on the host; with XDR Sensor, the separate third-party protection must still be effective. Neither a fixed update deadline nor entitlement solely on the basis of low portal usage follows from this.
When the display does not match expectations
- Server is missing from the list or shows “Product unassigned”: First check the tenant, device identity, and connectivity; then filter for the server and agent-mode status under My Environment > Computers & Servers. If the matching server line item is missing from the Schedule, do not distribute a different installer as a trial; clarify the assignment with the partner.
- XDR is ordered, but Agent mode reports “Upgrade available”: Check the product and term under Licensing; inventory existing Sophos and third-party protection before selecting anything on the individual pilot server. Review the offered components under Manage Software > Manage Device Software > Agent mode. An upgrade may remove third-party protection and is permissible only after a coordinated protection migration; check agent mode and prevention on the host after online/update contact.
- Portal counter is lower than the inventory, or overuse appears: Reconcile VM clones, decommissioned instances, and instances coming back online against the inventoried protected environments. Do not infer entitlement from a low counter or automatic shutdown from an overuse warning alone; actual usage and the contract govern. If figures differ, give the partner the Schedule, tenant, and an anonymized server list to resolve the discrepancy.
- RDS logins appear to trigger Endpoint usage: Check whether Endpoint agents are also installed on the clients, and compare the server and Endpoint products separately. The RDS statement in the Sophos FAQ replaces neither client protection nor checks for other licenses.
If a decision proves wrong: Do not “free up” a license merely by deleting a server from the console, remove third-party protection to use the sensor, or use Uninstall as a license correction. If the pilot is not protected as expected after a change, stop further rollouts, verify actual protection on the host, and coordinate safe restoration of the previously documented protection setup with Sophos Support or the third-party vendor. Going back is not a guaranteed reversible click: adding/upgrading can remove third-party protection, while Uninstall can remove Sophos prevention. Resolve an incorrectly assigned order or tenant commercially with the partner rather than repeatedly switching agents.