Skip to content
Avanet

Sophos Mobile: Limit TeamViewer support access with consent

The TeamViewer integration in Sophos Mobile starts remote support for a managed Android device, iPhone, or iPad from the device view without requiring the administrator to enter a session ID or password. This does not authorize unattended access: The person at the device must allow access to join the session. Sophos does not specify what assistance or control is actually possible during the session; that depends on TeamViewer, the license, the device, and its permissions. This guide covers the Sophos Mobile integration, not Sophos Remote Assistance in the Fusion tenant, Partner Assistance, or general access to devices on other platforms.

Before authorizing access

  1. Record the support case, affected device, person requesting support, responsible administrator, purpose, and planned end time. Use only the explicitly approved device and agreed scope of work; do not exchange credentials or assume that authorization extends beyond the case.
  2. Before the session, check your organization’s privacy and security approval for TeamViewer as a third party, the types of data involved, screen sharing, and the permissions actually required. Separately clarify technical and contractual data processing and any recording and retention settings against current TeamViewer documentation and your own configuration; the Sophos instructions make no specific assurances about these. If approval is missing, do not start a session.
  3. Check with the person at the device whether a remote session is permitted and what content may be visible. Prepare the screen and workflow if sensitive data is involved; if consent is missing or the scope is unclear, do not start a session. Approval at the device does not replace organizational approval.
  4. Check whether the integration is available in the specific tenant and for the device concerned. According to both Sophos editions, it requires a TeamViewer license and the TeamViewer Mobile Device Management Add-on. On the administrator’s PC used to sign in to Sophos, open the official TeamViewer Windows download page, then download and install the TeamViewer full client for Windows. On the target device, install the TeamViewer QuickSupport app from Google Play or the App Store. These are documented prerequisites, not a promise of support for every operating-system version or management mode.
  5. If it has not yet been configured, open Setup > Sophos setup > TeamViewer > TeamViewer configuration wizard in Sophos Mobile. Follow the wizard: create a TeamViewer account, create an application in the TeamViewer Management Console, and link it to Sophos Mobile. Only an administrator authorized to do so should set up the organization-wide link; manage integration access and credentials separately from individual support cases. Do not carry over roles from other Sophos features: The Sophos Mobile integration instructions specify neither a minimum role for the wizard or Start TeamViewer session nor a device-level permission boundary. Separate Sophos Mobile user-role pages describe Administrator (all actions), Helpdesk (support actions but not critical settings), and Read-only (viewing), but do not assign a minimum role to either TeamViewer action. Before production use, separately check and document in your own tenant, for the Mobile edition in use, which assigned roles can configure the integration and which can start sessions for which devices. Grant only permissions shown to be necessary; Fusion roles for Sophos Remote Assistance do not establish permissions for this integration.
  1. Open Devices in Sophos Mobile and select the agreed device.
  2. On Show device, start the session under Actions > Start TeamViewer session. Sophos says this initiates a session on the administrator’s PC and the selected device; the person at the selected device must allow access there to join.
  3. Before providing any support, confirm the identity of the person requesting it and verify the selected device. Do not assume that a connection exists without confirmed approval at the device. Perform only the agreed tasks, and obtain fresh approval for unexpected access requests, additional permissions, or a change of device.

Depending on the TeamViewer license, the number of sessions that can be started per hour may be limited. The Sophos pages document no guarantee of remote control, unattended reconnection, session duration, automatic expiration, or Sophos Mobile command to revoke an active TeamViewer session.

End the session and limit access

  1. Verify session termination as a local procedure: Before production use, test and document with the TeamViewer clients, operating systems, and tenant actually in use how to end an active session and reliably confirm disconnection at both ends. The Sophos sources describe neither specific controls nor the technical effect of disconnecting; therefore, no universally applicable termination procedure is guaranteed here.
  2. After the work, follow the locally verified disconnection procedure and record the end of the session, affected device identifier, changes made, and the person’s feedback in the support case. If the connection state remains uncertain, leave the case open and escalate to the responsible TeamViewer or security administrator; merely closing a window is not proven to revoke all permissions.
  3. A subsequent session is not implicitly covered by the initial consent: obtain authorization for the work and approval at the device again. Sophos explicitly states that before another session with the same device, the person at the device must first close the TeamViewer client.
  4. Once the support request is complete, separately check whether the persistent integration is still needed and who has access to the TeamViewer account or linked application. Treat three levels separately: end the active session at the device and administrator’s PC and verify disconnection; remove Mobile roles or device access that are no longer needed; review and, where appropriate, revoke the persistent TeamViewer account/application link and its credentials under the approved procedure. Neither closing the client nor removing a Mobile role is established here as revoking an already active session or the TeamViewer link. The Sophos Mobile integration instructions provide no confirmed path for removing the integration, no guaranteed revocation of existing TeamViewer permissions, and no automatic expiration time. Before production rollout, define, test, and document each required revocation step using current TeamViewer and tenant settings and an authorized test device; if that cannot be done, do not approve the integration as safely revocable.