Uninstall Sophos Endpoint on Windows
A clean Endpoint uninstall consists of two separate tasks. First remove the Sophos software from the Windows device. Only then delete the device record that is no longer needed in Sophos Fusion (formerly Sophos Central).
This order matters. Deleting a device in Sophos Fusion is not a remote uninstall. It removes the record and its alerts but leaves an installed agent on the computer.
Before starting
- local administrator access
- an active maintenance window
- Tamper Protection disabled for this device
- the uninstaller language matches the language of the installed Sophos Endpoint version
- a recovery or rollback plan
- no active cleanup or investigation that still requires the endpoint
Disable Sophos Fusion Tamper Protection safely explains the local four-hour override and the per-device setting in Sophos Fusion.
Do not delete too early: Keep the device in Sophos Fusion until local removal has succeeded. This preserves access to the password, status and diagnostic information.
Supported uninstall method
Sophos provides a central Windows uninstaller:
C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe
- Disable Tamper Protection for the device.
- Open Command Prompt or PowerShell as an administrator.
- Run SophosUninstall.exe from the path above.
- Complete the wizard and then restart Windows to finish removal.
- Check that Sophos services, the protection interface and installed Sophos applications have been removed.
Alternatively, uninstall Sophos Endpoint Agent through Settings > Apps > Apps & features on Windows 10 or Settings > Apps > Installed apps on Windows 11. Windows starts the same supported uninstaller.
Unattended uninstall
For software distribution or controlled offboarding, the program supports a silent invocation:
PowerShell
& "C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe" --quiet
Command Prompt or a .bat file
"C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe" --quiet
For a few devices, interactive removal through Settings > Apps or the uninstaller remains the normal method; reserve --quiet for controlled, repeatable deployment. This invocation applies to Windows 10 (x64) and later, and Windows Server 2016 and later, with a supported Core Agent. On legacy platforms, Sophos specifies uninstallcli.exe --quiet in the same directory instead; interactive legacy removal uses uninstallgui.exe. Inventory the operating system, architecture and Core Agent version before broad deployment. In a batch file, retain the quotation marks around the full path and save the file with a .bat extension.
--language=<LanguageID> sets the language of the uninstaller and accepts a standard decimal or hexadecimal language ID. It must match the language of the installed Sophos Endpoint version. The deployment system must evaluate the exit code, installed applications and any required restart. A finished process alone is not proof of success.
Do not interpret the numerical return values as general Windows codes:
| Code | Meaning |
|---|---|
0 | successful, no restart required |
1 | successful, restart required |
2 | failed |
3 | failed, restart required |
4 | unknown state |
5 | Tamper Protection is still active |
6 | process does not have administrator rights |
7 | Server Lockdown is active; normally not relevant to endpoints |
8 | an already pending restart blocks the process |
Sophos documents the uninstall log as C:\Windows\Temp\Sophos Endpoint Agent. For code 8, complete the already pending restart first and then reassess the device state. For other failure codes, Avanet recommends not continuing with repeated restarts or invocations. After removal, restart Windows before performing the validation below. This final restart is mandatory for both interactive and command-line or batch removal, even when code 0 means that the uninstaller itself does not request one.
Limits and rollback for silent deployment
--quiet hides the wizard; it does not remove prerequisites or product dependencies. On devices protected by ZTNA, Device Encryption or MDR, use the Install or uninstall software workflow in Sophos Fusion before the generic uninstall command. Confirm encryption recovery, continued device access and continuity of the agreed monitoring service before the maintenance window.
There is no reliable current matrix from which blanket vendor approvals can be inferred for combinations with other security software. Before broad removal, inventory the products and versions actually installed and test that exact combination in a small pilot group. If a product blocks or affects removal, escalate the specific case and its logs to the vendors involved; unsupported or unverified vendor-specific coexistence assumptions are no substitute for this test.
There is no automatic rollback for an uninstall. Avanet recommends starting with a small pilot group and keeping a current tenant-bound installer and access to recovery information available. If validation fails, do not mark the device as successfully offboarded: preserve logs and state and, as an Avanet safety recommendation, isolate it if necessary, then either restore the documented protection or escalate to Sophos Support.
Do not confuse this with Manage software
Under My Environment > Computers & Servers, Manage software can remove individual protection products or change the agent mode. The Sophos Core Agent remains installed for management and later product changes.
A complete device removal therefore still requires SophosUninstall.exe. Manage software is for controlled product-scope changes, not complete offboarding.
Verify the uninstall
After the wizard or silent command finishes and Windows has been restarted, check at least:
- Sophos Endpoint Agent is no longer listed under installed apps.
- The Sophos shield and local Endpoint interface are gone.
- Sophos protection services are no longer running.
- The intended replacement product is active and current.
- Windows Security shows the expected protection provider.
- No Sophos restart or incomplete uninstall process remains.
A remaining folder alone does not prove that Sophos is active. Running services, registered products and the protection provider are more meaningful.
Remove the device from Sophos Fusion afterwards
Only after local validation should the record be cleaned up in Sophos Fusion:
- Open My Environment > Computers & Servers.
- Select the uninstalled device.
- Confirm Delete.
- Check that it no longer appears in the active device list.
Deleting a device also deletes its associated alerts. Preserve any required information first. Sophos currently retains deleted devices for 30 days for recovery.
If the device was already deleted or the licence expired
With Core Agent 2023.2 or later on Windows 10 or later or Windows Server 2016 or later, manual Tamper Protection password recovery is normally unnecessary after device deletion or licence expiry. A deleted device can be restored for 30 days; its Tamper Protection password remains listed for 120 days under Reports > Reports > Endpoint Protection (or Server Protection) > Restore deleted devices and recover Tamper Protection passwords. Do not use the old Registry and Safe Mode procedure. For the supported process and exceptions, follow Uninstall Sophos Endpoint after deletion from Sophos Fusion.
Troubleshooting
SophosUninstall.exe reports active Tamper Protection
Recheck the Tamper Protection status: open My Environment > Computers & Servers, select the device name and scroll to Tamper Protection. The local four-hour override is suitable for short maintenance. If the device has already been deleted or its licence has expired, use the separate recovery procedure linked above instead.
SophosUninstall.exe is missing
Check whether the Sophos Core Agent is still installed correctly. Do not clean up a damaged or partially removed agent with arbitrary individual MSI files or registry deletions. Preserve the Sophos installation logs and use the current Sophos repair or support process.
The device reappears in Sophos Fusion
An active or redeployed management component probably remains. Check software distribution, gold images, RMM jobs and the local Core Agent. Deleting the record again without investigating the cause will not solve the problem.
The uninstall does not finish
First check that the uninstaller language matches the language of the installed Sophos Endpoint version. Also check running Sophos cleanup, Windows Installer, pending restarts and other security software. Preserve the installation and uninstall logs before further intervention.
RemoveSIPSSubmitterUserAccount fails
An error in RemoveSIPSSubmitterUserAccount indicates an already partially removed agent. Collect complete SDU and uninstall logs, but do not create or change unverified registry values. As an Avanet recommendation, after resolving a clearly evidenced blocker, run SophosUninstall.exe no more than once more.
If removal remains incomplete, do not try manual MSI, registry or Safe Mode cleanup, and do not run SophosZap speculatively. Send Sophos Support the SDU archive, uninstall log, return code, operating system and architecture, Core Agent version, exact command and time, plus the status of Tamper Protection and, where applicable, ZTNA, Device Encryption or MDR.
SophosZap is a last resort only
SophosZap is neither the normal uninstall method nor a way around active Tamper Protection. Consider this heuristic cleanup tool only after Tamper Protection has verifiably been disabled and SophosUninstall.exe has nevertheless failed or left an incomplete uninstall. If these prerequisites are not unambiguous, stop local attempts and hand the case to Sophos Support.
The controlled procedure for a current, signed download, supported and incompatible Sophos products, restart handling, log location and stop conditions is in the SophosZap section of Uninstall Sophos Endpoint despite Tamper Protection. Recheck that detailed procedure immediately before use; do not include SophosZap pre-emptively in general uninstall packages.
Frequently asked questions
Does deleting a computer in Sophos Fusion remove the agent?
Can Sophos Endpoint be uninstalled silently?
--quiet. The deployment must check the exit code, restart and actual removal of protection.