Skip to content
Avanet

Test Sophos Fusion Early Access Programs safely

Early Access Programs, or EAPs, make upcoming Sophos functions available before general release. They are not a shortcut to new production features. Because the features are still in development, they can change during the programme.

Sophos recommends EAPs for small, non-critical test environments. Production servers, medical systems, point-of-sale systems, machine controls, and core infrastructure do not belong in the first assignment.

Open and invitation only

Central distinguishes between:

  • an Open EAP, which anyone can join directly,
  • Invitation only, which must first be added to the program list with a Sophos invitation code.

Availability depends on product, region, license model, and tenant. Because of licensing restrictions, partners using monthly Flex licensing may be unable to enable certain EAPs for customers.

Plan the pilot before joining

Assign a technical owner and write a short test definition that covers:

  • expected benefit,
  • supported operating systems and agent versions,
  • maximum device scope,
  • test cases and success criteria,
  • logging and alert monitoring,
  • known incompatibilities,
  • rollback and support path,
  • end date.

Pilot devices should represent the real environment but remain replaceable. Keep at least one comparable control device on the normal recommended software so differences remain visible.

Enable an EAP

The path is Global Settings > Platform > EAP Settings.

  1. Open the Global Settings icon, select Platform > EAP Settings, and find the required program in the list.
  2. For a closed program, enter the invitation code under Invitation only programs. The program then appears in the list.
  3. Select Join next to the program, read the description and terms, and select Continue.
  4. Review the agreement in the End User License Agreement & Privacy Policy dialog and select Accept.
  5. If an endpoint program shows Add devices, open it. On Manage devices, select only the prepared systems from Eligible devices, then select Save.
  6. Then monitor the update, device health, events, and affected applications.

Selected devices receive the new function by software update. Joining an endpoint program alone does not assign devices; Add devices is a separate required step.

Monitor during the test

Compare at least these areas on pilot devices:

  • agent health and update status,
  • CPU, RAM, and I/O behavior,
  • startup and sign-in time,
  • business applications and network access,
  • new events, alerts, and false positives,
  • installation and update failures,
  • interaction with existing policies and exclusions.

Feedback to Sophos should include the program name, tenant region, operating system, agent version, reproducible steps, timestamps, and support data. Assumptions without a comparison device make analysis more difficult.

Remove devices or leave the EAP

There are two distinct exit paths:

  • Remove individual or all devices: On EAP Settings, select Manage next to the programme. On Manage devices, use the picker to remove the systems from Assigned devices. You can add or remove devices at any time during the programme. Sophos does not specify another Save step in this procedure.
  • Leave the entire program: Select Leave next to the program. This ends the tenant’s participation.

Sophos describes removing all devices as the way to stop using the new feature, but does not give a fixed transition time or target agent version. Treat the rollback as a software change: keep devices online and, once the assignment has been processed, check that the feature is no longer active, Agent Health remains clear, and affected applications still work. A changed EAP list alone is not a technical verification.

Do not confuse Evaluation Modes with a normal EAP

Under Profile > Account preferences > Evaluation modes, there are two particularly far-reaching endpoint test modes. Both belong exclusively in a separate test network:

  • Monitor mode detects threats but does not block them. It requires participation in the New Endpoint Protection Features EAP and the Super Admin role. Regardless of Endpoint and Server policies, it disables protection on all computers and servers in the tenant. To run a detection-only agent alongside a third-party product, use the designated XDR Detection Sensor instead.
  • Aggressive threat detection monitors and classifies application behavior much more intensively. This slows computers and servers and causes Central to generate substantially more detections and automatically created investigations. Use it only for a limited diagnostic run with a comparison system and a fixed shutoff time.

Before enabling either mode, document the number of affected devices, test duration, responsible Super Admin, and rollback. After saving, verify on several representative devices that the expected mode really applies. Disable an unneeded Evaluation Mode immediately and verify the change in the Audit Log.

Common problems

Program is not shown

Check the license, data region, tenant type, and invitation code. Flex licensing may exclude the program. A code for another tenant or an ended program does not work.

Device cannot be selected

Check its operating system, agent version, existing EAP assignment, device group, and online status. Not every program supports every platform.

Device remains assigned to the program

On EAP Settings > Manage > Manage devices, check whether the device remains under Assigned devices and use the picker to remove it. Then monitor update status and Agent Health. If the assignment remains, collect logs and Sophos Diagnostic Utility data and contact Sophos Support.

Error remains after leaving

Check Agent Health, update status, and the components actually installed. Then retain logs and Sophos Diagnostic Utility data. As Sophos gives no fixed transition time, contact Sophos Support if the state does not change.

Afterward, verify activation, assignment changes, and withdrawal in Analyze and retain Sophos Central Audit Logs. An EAP does not replace the product’s regular update and pilot strategy.

Frequently asked questions

Can a production server join an EAP?

A program may technically support the server. Operationally, testing should still begin on a few non-critical systems with a documented rollback and comparison device.

Can a tenant join several EAPs at once?

Central permits multiple programs. On the same device, however, assess potential overlaps and software packages.

Is removing the device from the EAP list sufficient?

Sophos describes removing all devices from Assigned devices as the way to stop using the new feature. Even so, check Agent Health, update status, and the affected application because the documentation gives neither a transition time nor a target version.