Test Sophos Central Early Access Programs safely
Early Access Programs, or EAPs, make upcoming Sophos functions available before general release. They are not a shortcut to new production features. Behavior, interface, and supported platforms can change during the program.
Sophos recommends EAPs for small, non-critical test environments. Production servers, medical systems, point-of-sale systems, machine controls, and core infrastructure do not belong in the first assignment.
Open and invitation only
Central distinguishes between:
- an Open EAP, which eligible customers can join directly,
- Invitation only, which appears only after entering a Sophos invitation code.
Availability depends on product, region, license model, and tenant. Because of licensing restrictions, partners using monthly Flex licensing may be unable to enable certain EAPs for customers.
Plan the pilot before joining
Assign a technical owner and write a short test definition that covers:
- expected benefit,
- supported operating systems and agent versions,
- maximum device scope,
- test cases and success criteria,
- logging and alert monitoring,
- known incompatibilities,
- rollback and support path,
- end date.
Pilot devices should represent the real environment but remain replaceable. Keep at least one comparable control device on the normal recommended software so differences remain visible.
Enable an EAP
The path is Global Settings > Platform > EAP Settings.
- Open the required program and read its description, prerequisites, and restrictions.
- Enter the invitation code for a closed program.
- Select Join and review the license and privacy terms.
- For endpoint programs, use Add devices to assign only the prepared pilot devices.
- Monitor the update, device health, events, and application function.
Selected devices receive the EAP components by software update. An EAP software package can override other assigned software packages until the program ends or the device is removed.
Monitor during the test
Compare at least these areas on pilot devices:
- agent health and update status,
- CPU, RAM, and I/O behavior,
- startup and sign-in time,
- business applications and network access,
- new events, alerts, and false positives,
- installation and update failures,
- interaction with existing policies and exclusions.
Feedback to Sophos should include the program name, tenant region, operating system, agent version, reproducible steps, timestamps, and support data. Assumptions without a comparison device make analysis more difficult.
Remove devices or leave the EAP
Use Manage to remove individual devices from the assignment at any time. Leave ends participation in the program. Before doing so, determine how and when Sophos moves the devices back to a regular software package.
Treat the return as an update. Devices must remain online, receive the normal package assignment, and be verified technically after the change. A disappearing EAP switch does not prove that every prerelease component has been removed.
Do not confuse Evaluation Modes with a normal EAP
Under Profile > Account preferences > Evaluation modes, there are two particularly far-reaching endpoint test modes. Both belong exclusively in a separate test network:
- Monitor mode detects threats but does not block them. It requires participation in the New Endpoint Protection Features EAP and the Super Admin role. Regardless of Endpoint and Server policies, it disables protection on all computers and servers in the tenant. To run a detection-only agent alongside a third-party product, use the designated XDR Detection Sensor instead.
- Aggressive threat detection monitors and classifies application behavior much more intensively. This slows computers and servers and causes Central to generate substantially more detections and automatically created investigations. Use it only for a limited diagnostic run with a comparison system and a fixed shutoff time.
Before enabling either mode, document the number of affected devices, test duration, responsible Super Admin, and rollback. After saving, verify on several representative devices that the expected mode really applies. Disable an unneeded Evaluation Mode immediately and verify the change in the Audit Log.
Common problems
Program is not shown
Check the license, data region, tenant type, and invitation code. Flex licensing may exclude the program. A code for another tenant or an ended program does not work.
Device cannot be selected
Check its operating system, agent version, existing EAP assignment, device group, and online status. Not every program supports every platform.
Normal software package does not apply
An EAP package can override the normal package assignment. Remove the device from the EAP, verify the regular package assignment, and wait for the update cycle.
Error remains after leaving
Check the agent version and actually installed components. Then retain logs and Sophos Diagnostic Utility data. Rollback may complete only after the next successful update.
Afterward, verify activation, assignment changes, and withdrawal in Analyze and retain Sophos Central Audit Logs. An EAP does not replace the product’s regular update and pilot strategy.