Enroll Sophos Intercept X for Mobile: app, QR code, or third-party EMM
This guide describes enrollment of the Sophos Intercept X for Mobile app in Sophos Mobile for Mobile Threat Defense (MTD). The steps described do not replace authorization to operate in your own environment. App enrollment is not the same as enrolling the entire Android device or an iPhone/iPad in MDM. An MTD policy configures the protection app; plan the threat-protection features and compliance actions that actually apply separately for each platform and edition.
Choose the right enrollment path
- Sophos Mobile manages the app without an existing third-party EMM: For a single test device, use the Add device wizard with Enroll Sophos Intercept X for Mobile with policy, or an appropriate MTD task bundle. Alternatively, a reusable static QR code from Intercept X enrollment can be used for Android, iPhone, and iPad. The QR code contains no Sophos Mobile user; assigning a user afterward is a separate step.
- Another EMM already manages the device: The EMM deploys the app and its managed app configuration; Sophos Mobile enrolls the app using a connection code. The EMM remains responsible for device management. It must support custom app settings. Do not describe this deployment as an additional Sophos MDM enrollment.
- Self Service Portal (SSP): In the Threat Defense edition, users can also add devices through the Sophos Fusion Self Service Portal. Check separately in the SSP configuration whether this path is enabled in your tenant and which app-enrollment task it triggers. Do not present the addition of a record in the SSP as completed Intercept X enrollment or MDM enrollment; approvals and user instructions belong in the separate SSP procedure.
- Intune: For Intune-managed devices, first check the separate Intune MTD path and the actual connector configuration. The full edition prohibits configuring Intercept X app enrollment, as well as static QR and generic third-party EMM enrollment, when Intune Mobile Threat Defense is already configured. This is not a blanket prohibition for every Intune-managed device. The Threat Defense help does not state this restriction on all corresponding pages; do not infer from that omission that two parallel enrollment paths are permitted. Do not configure the Intune connector here or portray app enrollment as an MDM-free Intune connector.
To manage the app, the tenant needs Sophos Mobile Threat Defense or the combined Sophos Mobile license; check the purchased entitlements in your own tenant beforehand. Sophos Mobile Device Management alone is not an established MTD entitlement. Keep the Mobile licensing decision separate from enrollment. Before the first write operation, record the tenant, administrative permissions, platform, actual ownership (Corporate or Personal), existing management, device group, permitted app permissions, and intended MTD policy scope. For personal devices, first clarify user notification and approval concerning permissions and transmitted device data. A visibly installed app is not yet proof of enrollment. The separate decision guide explains MDM mode selection. Android MTD protection rules must be checked in the relevant platform policy procedure; the iOS MTD policy has different limits. This enrollment article does not replace either protection policy.
Android prerequisites before installation: The Android release notes reviewed on October 6, 2026 specify smartphones and tablets with Android 9 or later and arm-v7a or arm64-v8a architecture for Intercept X for Mobile. Android (Go edition) is not supported. Before deployment, check the intended device’s operating-system version, architecture, and Go edition against device or manufacturer information; an Android version number alone is not enough. These are Android app requirements, not approval for a particular management mode, MDM enrollment, or iPhone/iPad. Licensing, EMM, and Intune prerequisites must still be checked separately.
iPhone/iPad prerequisites before installation: The iOS release notes reviewed on October 6, 2026 specify iOS 15 or later, or iPadOS 15 or later, for Intercept X for Mobile. This app requirement also applies without Intune: to the Add device wizard, static QR code enrollment, and deployment through a third-party EMM. Before deployment, compare the device’s actual operating-system version with the requirements of the intended app version; if the app is already installed, record its version too. The documented minimum version does not guarantee that every later app version can be installed on this device. Check the requirements in effect before the pilot. App support, MDM management mode, supervision, and web-filter prerequisites remain separate checks; a suitable OS version does not replace licensing, EMM, or Intune checks.
When Sophos Mobile manages the Intercept X app, you can also assign a compliance policy to the device to monitor its compliance status. This policy is separate from the MTD policy for app configuration. Check separately which compliance rules and follow-up actions are available and approved for the relevant platform and edition; monitoring alone does not enforce requirements or give the app MDM control. The Sophos Mobile compliance guide explains rule and action selection, group assignment for corporate and personal devices, and the subsequent checks of status and actual effects.
With this app management through Sophos Mobile or Sophos Mobile Threat Defense, you can run a malware scan on Android devices. Do not extend this capability to iPhone or iPad. Completed app enrollment or an enrollment task proves neither that a scan has run nor that its result found no malware. The Trigger and evaluate an Android malware scan section in the task and synchronization troubleshooting guide explains the prerequisites, scan task, and separate evaluation under Scan results.
Prepare the connection code and assignment for a limited pilot
- In Sophos Fusion > My Products > Mobile > Setup > Sophos setup > Intercept X, select Configure Intercept X for Mobile enrollment. Check the proposed Enrollment configuration before saving. Set Owner to the actual ownership (Corporate for an organization-owned device, Personal for a privately owned device), choose Device group deliberately, and optionally select the appropriate Mobile Threat Defense policy (Android) or (iOS). Do not assume any particular protection without a suitable policy.
- Save the configuration if you changed it. Sophos Mobile creates a Connection code. Treat the code and the QR code printed from it as enrollment credentials: give access only to authorized pilot participants, and do not copy them into public tickets or unprotected distribution channels. A code can be revoked for future app enrollments; this does not mean that already enrolled apps are unenrolled.
- If you deliberately create a device record first, it is advisable to prepare one or more device groups before adding the first device. This path does not enroll the protection app yet. Under Devices > Add, select the platform in the Add device manually section. In Edit device, enter a unique Name, Description, Owner (Corporate or Personal), Email address, a Phone number in international format with the country code if applicable, and the intended Device group; use only the details relevant to your assignment. To assign a user, select the Edit user assignment icon next to User, then Assign user to device. If you need custom device properties, select Add custom property under Custom properties. Once you have entered the relevant details, select Save and check the new entry under Devices. Save creates the record but does not enroll the Intercept X app. For an existing record, establish the supported MTD path separately as described below; do not use Actions > Enroll without verification or create a second record. A CSV import likewise initially creates records; its format, duplicate imports, and retries belong in the separate bulk-import procedure, not this app-enrollment procedure.
Enroll the app through Sophos Mobile
Wizard for a new Android device, iPhone, or iPad.
The Add device wizard creates a new device record and guides you through app enrollment. User assignment and a task bundle are optional. For a pilot that sends instructions to a specific person, use that person’s existing Sophos user.
- Open the wizard under Devices > Add > Add device wizard.
- On User, search for the intended user. The search matches partial strings only at the start of a field, not anywhere within a name or email address. On User selection, select the matching entry from the list. If the device should initially have no user, select Skip user assignment instead.
- On Device details, check the following fields:
- Under Platform, select the platform that matches the device. Under Name, use a device name that is unique in Sophos Mobile.
- Description and Phone number are optional. If you enter a phone number, use international format with the country code. Neither a description nor a phone number is required for the pilot.
- Email address is the address to which Sophos sends enrollment instructions. If a user is assigned, the address comes from that user’s entry in Sophos Fusion user management. Before a pilot without an assigned user, clarify the delivery path for Skip user assignment in your own tenant. Do not assume that you can use an arbitrary recipient address without an assigned user.
- Under Owner, select the actual ownership as Corporate or Personal. Under Device group, select the intended pilot group. Default is always available, even if no device group has been created. This fallback group does not automatically limit the pilot’s scope. Check its existing assignments before using it.
- On Enrollment type, select the app-enrollment path. Android and iOS/iPadOS have the same two choices:
- Select Enroll Sophos Intercept X for Mobile with policy, then select the intended Mobile Threat Defense policy.
- Alternatively, select Enroll Sophos Intercept X for Mobile with task bundle and choose a task bundle containing a Mobile Threat Defense enrollment task. Further tasks can, for example, assign additional policies or display a message on the device afterward. These are optional additions, not required app-enrollment steps. The task bundle lifecycle explains how to create and transfer a bundle.
- On Enrollment, follow the displayed instructions on the approved pilot device. Select Finish only after enrollment has completed successfully. You may also close the wizard early after making all selections. Sophos then processes an enrollment task in the background. Closing the wizard is not proof of success. If you selected a task bundle to transfer after enrollment, check its progress under Task view.
The options on Enrollment type depend on the platform and the policies and task bundles created for it. If the MTD choice is missing, first check these prerequisites and the licensing and Intune limits described above. The full edition’s Android full-device/work-profile and Apple device/user enrollment options are different management modes, not substitutes for the missing MTD option.
You can also start the same wizard from the Add device widget on the Sophos Mobile dashboard. Sophos Fusion also provides the entry point My Environment > Installers > Unified Endpoint Management and Sophos Intercept X for Mobile > Use the enrollment wizard to manage and/or protect a device. These optional entry points replace step 1. You do not need to use them as extra steps.
ChromeOS is outside this app procedure. The Chrome OS branch of the wizard enrolls Sophos Chrome Security, not the Android/iOS Intercept X for Mobile app. The Chrome Security guide distinguishes manual token enrollment from automatic Google Workspace deployment. Its automatic procedure does not replace instructions for the manual Chrome wizard.
Static QR code: Under Setup > Sophos setup > Intercept X > QR code enrollment > Print, make the code available in a controlled way. On the test device, install Intercept X for Mobile from Google Play or the Apple App Store, respectively. Open the app and follow the setup assistant’s instructions. Then, in the app, select Corporate management > Enroll with Sophos Mobile > Enroll > Scan QR code; grant requested permissions according to the agreed approval and scan the code with the device’s camera. “Corporate management” is an app button here, not proof of ownership or a promise of MDM enrollment.
During QR enrollment, Sophos Mobile uses the settings previously configured in the Connection code for Owner, Device group, and, if selected, the Android/iOS MTD policy. Afterward, compare these values on the same pilot record with the approved configuration; the code assigns no user and proves neither MDM management nor effective protection. If the pilot assignment requires a user, use the individual assignment procedure for the existing device in the Assign, reassign, or unassign an individual device section rather than creating a second record. Do not distribute the reusable code widely before verifying the result.
Android enrollment without an assigned user: The Android release notes document enrollment of devices without users through QR code and Android zero-touch as a historical addition. For the Intercept X app managed by Sophos Mobile covered here, this describes enrollment without an assigned Sophos user, not a separate MDM mode. The static app QR code explained above and QR/zero-touch provisioning of a fully managed Android device are different procedures. To fully manage a dedicated corporate device, use the separate Android provisioning path and check device eligibility, management mode, and integration of the protection app there. The historical release entry provides neither standalone zero-touch instructions solely for the protection app nor authorization for a factory reset, and it does not demonstrate a rollout successfully tested today. Before deployment, establish the supported procedure for the current app and management versions, and check user assignment, app enrollment, and MTD policy separately on the authorized pilot device.
Existing device record: The generic Sophos instructions for Devices > [device] > Actions > Enroll specify neither a Mobile Threat Defense choice nor the type of iPhone/iPad configuration profile. Therefore, do not use that action as a step to enroll the Intercept X app. The Add device wizard described above documents the explicit mode Enroll Sophos Intercept X for Mobile with policy, or a task bundle with a Mobile Threat Defense enrollment task, for newly added devices; it is not an established route for an existing record. If a record already exists, establish the supported MTD route for that exact record, edition, and profile type using current Sophos guidance and an authorized tenant pilot before taking further enrollment actions; do not blindly create a second record or fall back to MDM. The generic single-device page warns that an iPhone/iPad configuration profile must be installed in Settings within eight minutes (exception: devices assigned through Apple Business Manager or Apple Configurator). Without confirmation of the specific mode, do not present this deadline as an app, MDM, or web-filter profile instruction or extend it to QR/EMM enrollment.
Device already managed by an EMM: connect only the app
For an approved pilot, use Copy to copy the Connection code under Setup > Sophos setup > Intercept X > Automatic enrollment (third-party EMM) and add Intercept X for Mobile to the EMM. Edit the managed app configuration for the target platform before installation. Consult the EMM’s own documentation for its exact interface.
- Android: The app settings are predefined; enter values in the fields provided. The Sophos fields are Connection code, optionally Email, Device ID, Device name, and EULA disabled. Use the code copied earlier for Connection code.
- iOS/iPadOS: For each setting, enter the exact name, the String or Boolean type, and the value. The names are case-sensitive:
smcData, of typestring, contains the connection code; optional settings areemail,deviceId,deviceName, andmacAddress, each of typestring, pluseulaDisabled, of typeboolean, with valuestrueorfalseand a default offalse.macAddresscontains the device’s MAC address, which is used to identify the device when it connects to a Sophos WLAN access point.macAddressis required for Synchronized Security; do not infer that this additional integration follows from app enrollment alone.
The optional Android Device ID setting or iOS deviceId key contains the unique device identifier used by the EMM. Device name or deviceName is the optional device name that Sophos Mobile uses when adding the device.
The optional Android Email setting or iOS email key determines which user Sophos Mobile should assign to the device. If a user with that email address already exists, Sophos Mobile assigns that user; it creates a user only if no matching user exists. If the chosen EMM supports it, Sophos recommends variables for the user’s email address and device name. Check the syntax and available variables in that EMM’s documentation; do not copy tokens from another EMM. First check the identity and resolved values on an authorized test device.
EULA disabled or eulaDisabled suppresses the license agreement when the app starts and must not be enabled casually. Protect the connection code, device ID, and email address against unauthorized access; a widely assigned configuration could affect many devices. If the iOS web-filter profile is to be deployed beforehand, complete the following procedure first. Then install Intercept X for Mobile through the EMM. Sophos describes enrollment at the device’s first startup after EMM installation using the configuration; merely pushing the app is not proof of success.
iPhone/iPad with web filtering: Predeployment requires devices already managed through a third-party EMM, EMM support for custom iOS configuration profiles, supervised iPhones/iPads, and Intercept X for Mobile not yet installed. Deploy the Sophos web-filter profile before the app only to this approved device scope:
- Download
activate-smsec-plain.mobileconfigfrom the Sophos addresshttps://secureservices.sophosmc.com/webfiltering/activate-smsec-plain.mobileconfig. This is the specific web-filter file, not an arbitrary Apple enrollment profile. - Create a custom iOS configuration profile in the chosen EMM and upload the downloaded
.mobileconfigfile into it. - Send this profile to the authorized, supervised pilot iPhones/iPads. Use the provider’s documentation for the exact EMM menus; for Intune, first establish the separate MTD mode as described above.
- Only then install Sophos Intercept X for Mobile through the EMM, using the managed app configuration prepared earlier.
Without this EMM predeployment, the user must install the profile during app enrollment. This profile serves web filtering and is not itself Apple MDM enrollment; app enrollment also does not automatically make an unsupervised personal device supervised. On the same pilot device, separately check the profile’s assignment/installation status in the EMM and the profile and app actually present on the device. The iOS MTD policy explains the filter pilot, troubleshooting, and fallback limits. Neither a successful download nor a profile assignment proves active filtering; assess actual web-filter behavior only in this separate iOS protection test.
Self-host an Android APK – only as an approved exception
An internal web server can serve as the installation source for Intercept X for Mobile instead of Google Play. In the Threat Defense edition, this applies only to Intercept X; the full Mobile edition also includes Sophos Mobile Control. The Intercept X source requires Sophos Mobile or Sophos Mobile Threat Defense, not an MDM license alone. Hosting does not replace app enrollment or the decision about the management mode.
This route requires installations from outside Google Play to be allowed generally, not just for Sophos. Keep Google Play unless there is an approved reason for an exception, and do not bypass existing security policies to troubleshoot problems. Before switching, clarify permissions, edition, Android management mode, and the affected device scope: selecting a pilot device does not automatically limit a shared installation source to that device. Do not switch without an approved APK source, an integrity check, and assigned responsibility for updates.
Prepare the APK and save the installation source
First, make the approved APK available on your own web server. Check and document its origin, version, and integrity; a file does not become trustworthy simply because it is hosted on your own server. Provide a file URL that the devices can access over HTTPS, for example https://mobile-apps.example.org/ixm/intercept-x.apk. Replace the hostname and path with your own address; the filename is arbitrary. From the intended device network, check that the URL returns the correct APK rather than a login page. Do not put credentials in the URL or disable security controls for the download.
Check the version: On September 30, 2026, the Mobile download page offers SMSec-9.7.3909.apk, while the Android release notes list 9.8.4146 as the latest entry. Do not treat the offered APK as the latest version. Before deployment, confirm with Sophos the current APK source supported for the intended mode; do not guess a download path by substituting a different version number.
In Setup > Google setup, open the Android tab. Under Select installation source, select Hosted APK file. In the full Sophos Mobile edition, enter the separate file URL for the hosted Sophos Mobile Control app in URL of the SMC APK file. This SMC entry is not required for MTD-only app enrollment and is not part of the Threat Defense edition. For Intercept X, enter the actual file URL in URL of the Intercept X for Mobile APK file; this step requires Sophos Mobile or Sophos Mobile Threat Defense and does not grant MDM entitlement to the Threat Defense license. Select Save. Then reopen the screen and compare the selection and URL with the intended settings. This configures the installation source—it does not yet install or enroll an app on any device.
Deploy the APK and check the result on the device
For device installation, use a task bundle appropriate to the edition and management mode. The hosting setting does not imply that Install app is available for all Threat Defense or Android Enterprise devices. Confirm the appropriate task type before transferring the bundle; do not switch to a different enrollment type because a task type is missing.
Under Task bundles > Android, select the blue triangle for the intended bundle, then Transfer. On Select devices, initially select individual approved devices, continue with Next, and under Schedule task, select Now or Date with a date and time; Finish transfers the bundle at the selected time. Before doing so, check every subtask for unwanted policy changes, unenrollment, or a wipe. The task bundle lifecycle explains target scope and retry limits.
Check task progress in Task view, and on the same device compare the installed version with the approved version. Start the app and check enrollment and MTD policy assignment separately. A saved URL, an upload, or a submitted bundle proves neither installation nor enrollment nor effective protection. If errors occur, stop further deployment and check the file, URL accessibility, installation approval, and the failed subtask before transferring again.
Take responsibility for updates and restoring the previous source
With self-hosting, the responsible team must regularly check Sophos Mobile downloads for the latest APK, obtain the version approved under the freshness check above, verify it, and upload it to the web server. Installation on the devices must then be triggered again through an appropriate task bundle, and the actual installed version must be checked. Uploading the file and updating devices are separate tasks; neither automatic updates nor an APK already verified here are promised.
Before switching, record the previous source selection and URL. If problems occur, restore those settings only after reviewing running tasks and obtaining approval, then verify the result. This does not reset already installed apps or app data, and it guarantees neither a downgrade nor an automatic package rollback. Before transferring again, check which subtasks have already taken effect; app uninstallation, record deletion, work profile removal, or a factory reset are not blanket rollback methods for this source change.
Check the pilot and narrow down errors
After setting up the app, check the record, platform, ownership, group, user assignment, and expected MTD policy in Sophos Mobile Devices for the same test device. Under Task view, look for pending or failed enrollment/bundle tasks; on the device, check that the app starts, its requested permissions, and the iOS web-filter profile if applicable. This is a suggested pilot check, not a device or tenant test performed here. A record, a submitted task, or an app-store download alone proves neither effective policy nor active protection.
- Wizard does not offer MTD: Check edition/license, platform, policy or task bundle, and Intune MTD connector. Do not choose full-device enrollment as a substitute on a personal device.
- EMM app installed but not enrolled: Check that the app starts and is actually assigned on the pilot device, the Connection code, EMM configuration, and, on iOS, the exact names/types (
smcDataasstring). Record the current status before another fleet assignment; do not redeploy blindly. - QR device without a Sophos user: This is expected with the static QR code. Assign the user separately; also check Owner, group, and MTD policy.
- iOS web filter missing: Check profile installation and, if EMM predeployment was planned, supervision, timing, and EMM profile support. Do not confuse the profile with Apple MDM.
- iPhone/iPad configuration profile expired: Only if the actual, approved procedure requires a profile in Settings, check the documented eight-minute warning on the generic single-device page or in the full-edition wizard: if that profile is not installed within eight minutes, it is deleted; then restart the approved enrollment procedure. First establish the enrollment mode and profile type; do not use Actions > Enroll as an app troubleshooting step without MTD evidence, and do not extend the deadline to QR, EMM, or the web-filter profile.
Assess rollback and privacy separately
Rollback: Before removal from the pilot device, note whether Sophos Mobile or an existing EMM assigned the app and whether an MDM profile also exists. Involve the user and device owners, clarify the implications for protection, policies, and transmitted data, and only then approve the offboarding procedure appropriate to the actual management mode. According to Sophos, revoking the Connection code prevents new app enrollments; it is not an established offboarding procedure for already enrolled devices. Uninstalling the app through the EMM, deleting a Sophos device record, and removing an MDM profile are distinct actions. Neither app uninstallation nor a disappearing record proves here that existing MDM management was removed or stored data was deleted. After an approved pilot rollback, check the actual state on the device and in Sophos Mobile; without a verified procedure, do not automate fleet-wide actions or perform a blanket wipe.
Privacy: Before the pilot, clarify the app permissions actually approved, identity and device data, data flows, and retention with those responsible for privacy. The enrollment pages establish neither a general “no telemetry” promise nor a retention period. Privacy settings and Data Lake uploads are a different administrative operation, not part of app enrollment.