Install and remove the Sophos ZTNA Agent
The Sophos ZTNA Agent is deployed as a component of the Sophos Endpoint Agent. It enables access to on-premises applications and supplies device health information for ZTNA policies. Without the agent, ZTNA can control only web-based applications. On already managed computers, the component is added or removed through Manage software in Sophos Fusion (formerly Sophos Central); new devices receive it through the tenant-specific Endpoint installer.
The safe sequence is: check the prerequisites and target tenant, install ZTNA on representative pilot devices, verify its status in Sophos Fusion and access to a real resource, and only then roll it out more widely. Before removal, decide whether to remove only ZTNA or all Sophos software.
Prerequisites, licensing, and roles
Before installation, clarify the following:
- The tenant has a ZTNA licence, and the installer offers ZTNA as a selectable component. The licence and component selection actually available in your tenant are what matter.
- The operator has a role in Sophos Fusion that permits selecting devices and managing their software. Running the installer locally and approving macOS security permissions require the necessary administrator rights on the device.
- According to the current ZTNA installation requirements, Windows 10 1803 or later and macOS Big Sur 11 or later are supported. Before a wider rollout, still check the operating-system versions you use against current product support.
- The ZTNA Agent is required for on-premises applications. Agentless access is possible if only web-based applications are needed; this article deliberately covers the agent-based path.
- The ZTNA environment has a supported wildcard certificate, a gateway, suitable DNS records, a directory service, an identity provider, and the required outbound connections. User groups from Microsoft Entra ID or Active Directory are synchronized with Sophos Fusion.
- A self-hosted gateway runs on ESXi or Hyper-V; alternatively, a Sophos Cloud Gateway can be used. Sophos Firewall integration is optional. If used, the firewall needs SFOS 19.5 MR3 or later and must be managed by Sophos Fusion.
- Use a fresh installer from the correct tenant. Do not publish its download link or package, as the package associates devices with that tenant.
- The pilot group covers the Windows and macOS versions and network paths actually in use, along with at least one real ZTNA resource.
ZTNA configuration is available in Sophos Fusion under My Products > ZTNA. The gateway, certificate, DNS, identity, resources, and policies must be set up before acceptance testing. Set up Sophos ZTNA describes the end-to-end sequence.
Important: A successful Endpoint installation proves neither that ZTNA was selected nor that the gateway, policy, DNS, and resource work. Check these layers separately.
Install ZTNA on already managed computers
Use this path for devices on which Sophos Core Agent is already running and which are registered in the correct tenant:
- In Sophos Fusion, open Devices > Computers and servers.
- First select one or more comparable pilot devices.
- Open Manage software.
- For ZTNA, choose Install. Leave other products and Agent mode at Do not change unless they are part of the same approved change.
- Confirm with Save and leave the device online until it has processed the software change.
- Check the ZTNA and Agent mode columns in the device list. The ZTNA column must show that the component has been installed.
Manage software changes the product scope of a registered device. Manage Sophos Endpoint Agent Mode and software explains how this differs from Agent Mode, XDR Sensor, and a complete uninstall.
Install on new devices
Windows
- In Sophos Fusion, open Devices > Installers.
- Choose Download Complete Windows Installer if all licensed Endpoint products are to be installed. For a targeted selection, open Choose Components, select ZTNA and the other approved components, and download the installer.
- Run
SophosSetup.exefrom the correct tenant on the pilot device with the required local rights. - Restart if prompted, then check registration in the intended tenant.
For automated Windows deployment, a current installer from the target tenant can be run in an administrative PowerShell session as follows:
.\SophosSetup.exe --products=ztna --quiet
This command installs ZTNA through the shared Endpoint installer; it is not a standalone ZTNA installer. Proxy, group, and deployment options, as well as exit-code and log evaluation, are covered in the controlled Windows Endpoint rollout. The installer process finishing alone does not mean the deployment has passed acceptance checks.
macOS
Under Devices > Installers, use either the complete macOS installer or Choose Components. The package must come from the intended tenant. After installation, grant all Sophos permissions requested by macOS. These include the applicable System or Endpoint Security extensions and Network Extensions, as well as Full Disk Access.
Sophos checks the required permissions regularly. If any are missing, Sophos Endpoint displays a notification. For MDM deployment, assign the current Sophos profiles to a pilot group before running the installer; the full procedure is described in Deploy Sophos Endpoint on macOS with Jamf Pro.
Do not apply Windows switches to macOS: The documented macOS installation uses the complete or component-specific tenant installer and the appropriate security profiles. The Windows value
--products=ztnais not a documented macOS installation method.
Validate installation and access
Reliable acceptance combines the management, device, DNS, and application perspectives:
- Under Devices > Computers and servers, the Agent mode and ZTNA columns show the expected installed state for the pilot devices. Resolve
Product unassignedorNot supportedbefore a wider rollout. - For a detailed check, open Devices > Computers > [device] > Status. Alternatively, go to My Environment > Computers & Servers, select the device name, and open Status. Communication, services, system, and update status should be healthy; a required restart is also shown there.
- Open the Sophos icon on a pilot device. ZTNA must appear on the local status page.
- Open a real on-premises application as an authorized pilot user. Then verify that access is denied as intended for a pilot user without authorization.
- Resolve the gateway and resource FQDNs deliberately. After ZTNA installation,
nslookupmay use the ZTNA TAP adapter by default. For applications outside the ZTNA gateway, therefore, specify the DNS server that is actually responsible:
nslookup <application-FQDN> <DNS-server>
Replace <application-FQDN> and <DNS-server> with values from your environment. The expected result is a response from the responsible DNS server, not just any locally cached resolution.
On Windows, the network used by the ZTNA TAP adapter must not overlap an existing network. If the endpoint already has an interface in the 100.64.0.0/16 range, the ZTNA TAP adapter uses the next available range, 100.65.0.0/16, and adds the associated routes.
Troubleshooting by symptom
ZTNA is missing in Sophos Fusion or on the local status page
First check whether the device is online, appears in the correct tenant, and has actually had ZTNA > Install saved in Manage software. Then check the ZTNA and Agent mode columns and Devices > Computers > [device] > Status. If Sophos Fusion shows Product unassigned, the assignment is missing; for Not supported, check the operating system and licence. If installation remains pending, preserve the time, device status, and diagnostic data before assigning the component again.
The agent is installed, but the application will not open
This alone is not a reason to reinstall immediately. Check in this order:
- Does the responsible DNS server resolve the gateway and resource FQDNs?
- Is the user in the intended synchronized group, and does sign-in with the identity provider work?
- Can the device reach the destinations and ports required for ZTNA?
- Does the same resource work for a second authorized pilot user or device?
- Is there an overlap with
100.64.0.0/16or100.65.0.0/16?
For a targeted DNS query, specify the DNS server explicitly as shown above. If the problem persists, preserve timestamps and diagnostic data. Diagnose Sophos Endpoint with Self Help and SDU describes how to collect evidence.
macOS reports missing permissions or poor integrity
Open the Sophos notification and approve the extensions required for the macOS version and Full Disk Access. On centrally managed Macs, check that the current MDM profile is actually installed on the device. Restart the Mac or affected Sophos services only if macOS or the approval prompt requests it, then check the device status again.
The local status is Inactive (On-premises mode)
On current Windows agents, this is a distinct status display and is not equivalent to Not configured. First check whether the device is intentionally on the local network path and whether direct access matches the intended operating mode. Check DNS, groups, and reachability only if resource access fails contrary to the plan.
The state remains unclear
ZTNA is maintained through the Sophos Endpoint update process. Before changing components or reinstalling, check update status, pending restarts, Sophos Fusion communication, and platform-specific permissions, and preserve SDU data from the time of the error. If the state remains unclear, stop local attempts and contact Sophos Support. Cleanup tools and speculative manual changes to files, services, or the registry are not a safe repair path.
Remove only the ZTNA component
This is the right removal path if the device should remain managed through Sophos Fusion and protected by its other Endpoint components.
Before the change: Identify affected users and on-premises applications, provide an alternative access path, and select at least one pilot device. The device must stay online. Deleting the device object is neither a prerequisite for nor a substitute for removing the component locally.
- In Sophos Fusion, open My Environment > Computers & Servers and select the pilot devices.
- Open Manage software.
- For ZTNA, choose Uninstall. Leave Agent mode, Encryption, and other unaffected products at Do not change.
- Confirm with Save and wait for the devices to process the request.
- Check that the ZTNA column no longer shows the component as installed. The previously tested ZTNA access must no longer work; the intended Endpoint protection and communication with Sophos Fusion must remain healthy.
The Sophos Core Agent intentionally remains installed because it handles communication and policy management. If the change must be rolled back, reinstall through Manage software > ZTNA > Install on the same pilot device and repeat the full validation in this article.
Remove all Sophos software
Complete removal is a separate, platform-specific procedure. First determine which applications will no longer be reachable without ZTNA and how alternative access will work. Then remove ZTNA through Manage software as described above. For the remaining Endpoint Agent, follow only the supported platform procedure:
These procedures cover Tamper Protection, restarts, MDM or software-deployment assignments, local success checks, and later cleanup of the device object. Do not delete the record prematurely: it contains status and diagnostic context. Direct deletion of ZTNA files, removal of individual services, or speculative use of a cleanup tool is not part of controlled removal.
Changing tenants
An installer belongs to its source tenant and must not be reused for the target tenant. For larger moves, first assess the documented Device Migration process. Because suitability depends on the specific migration path, operating system, device type, and installed components, confirm the pilot combination in the live tenant or with Sophos Support before each wave. Migrate Sophos devices between Sophos Fusion tenants describes the full procedure.
SophosSetup.exe --registeronly is a separate re-registration procedure documented only for Windows and for Sophos protection that is already working. It is neither a ZTNA repair nor a macOS procedure. After a tenant change, revalidate device identity, ZTNA assignment, update status, and real resource access. Plan a return as a separate change using a current installer from the original tenant.
Operations, review, and lifecycle
The Windows and macOS ZTNA Agents have separate version histories and release notes. A single old version number is therefore not a suitable target for both platforms. In operation:
- after an agent update, check the ZTNA column, device status, and a real resource on representative Windows and macOS pilot devices;
- assess new status displays and known issues in the current ZTNA Agent release notes before treating a state as an error;
- regularly review operating-system support, macOS permission profiles, and the minimum version of an optionally integrated Sophos Firewall;
- establish a pilot and rollback path before changing licensing, the gateway, identity, or DNS;
- during offboarding, confirm that the ZTNA component was actually removed rather than merely deleting the device object.
Historical product announcements are not reliable evidence of current migration deadlines, licence removals, or an end-of-life date. Base such decisions only on the latest lifecycle and release information.
Frequently asked questions
Can I remove only the Sophos ZTNA Agent?
How can I tell whether installation succeeded?
Is Inactive (On-premises mode) the same as Not configured?
Inactive (On-premises mode). Assess the status alongside the intended network path and a real resource test.