Uninstall Sophos Endpoint with Tamper Protection enabled
If a Windows device was deleted from Sophos Fusion (formerly Sophos Central) before the Endpoint Agent was removed locally, a blanket registry hack is not required. Sophos provides supported workflows for deleted devices and devices with expired licences on current Core Agent versions.
The correct path depends on whether the device was only deleted, whether the licence expired, and whether it should be managed again or permanently removed.
⚠️ Do not start with old registry procedures: Sophos documents manual recovery only as a last resort when none of the normal methods of turning off Tamper Protection is viable. Use the Fusion and local standard paths below first. Safe Mode, manual deletion and third-party registry scripts do not belong in this workflow.
Identify the case first
| State | Objective | Procedure |
|---|---|---|
| device deleted less than 30 days ago | continue management | restore the device in Fusion |
| device deleted, agent must be removed | permanent removal | wait for synchronisation, check local protection state and run SophosUninstall.exe |
| licence expired, management must continue | reconnect | resolve licensing and register the agent with –registeronly |
| password requested on an older system | maintenance or removal | retrieve the deleted device password |
The retention periods and behaviour can change with agent versions. Record the operating system, Core Agent version, deletion time and tenant before making changes.
Prerequisites and safety boundaries
- local administrator access and an announced maintenance window
- a current backup or tested recovery plan
- recorded Windows version, architecture, Core Agent version and installed Sophos components
- access to the correct Fusion tenant or a named tenant administrator
- a defined end state: permanent removal or renewed protection in the same tenant
- Server Lockdown disabled on servers; the relevant Fusion offboarding workflow for ZTNA, Device Encryption or MDR
Keep the device in Fusion until local validation succeeds, so its password, health, alerts and diagnostics remain available. Do not loop a failed uninstall; preserve its return code, log and device state first.
Behaviour on current Windows devices
Starting with Core Agent 2023.2, Windows 10 and later and Windows Server 2016 and later generally behave as follows:
- Tamper Protection is disabled locally after deletion in Fusion.
- Active protection components are removed or disabled.
- The Core Agent remains so that supported removal or re-registration is possible.
- Manual password recovery is normally unnecessary.
The device may need time to process the deletion or changed licence state. An offline device receives this information only after a successful connection.
Update Cache and Message Relay roles are also removed from devices that host them. Reinstall and verify these roles after restoration if they are still required.
Turn off Tamper Protection in a controlled way
- Identify the device by computer name, operating system and last activity.
- If it is still active in Fusion, scroll to Tamper Protection in its details and turn it off or select View password details.
- For short local maintenance, use Admin sign-in > Settings > Override Sophos Central Policy for up to 4 hours in Sophos Endpoint.
- If the device was deleted, use the restoration or password workflow below while it remains within retention.
- Confirm locally that Tamper Protection is off before starting the uninstaller or
--registeronly.
The complete standard workflow is in Disable Sophos Fusion Tamper Protection safely. If none of these paths is available, stop local work at the Support handoff; do not derive boot, driver or registry changes independently.
Option 1: Restore the deleted device
Sophos Fusion currently retains deleted devices for restoration for 30 days.
- In Sophos Fusion, open Reports > Reports > Endpoint Protection or Server Protection.
- Select Restore deleted devices and recover Tamper Protection passwords.
- Verify the computer name, operating system and deletion time.
- Select the correct device and click Restore.
- Wait for it to contact Fusion again.
- Check agent mode, policies, health state and last activity.
Restoration is appropriate when the computer should remain protected and managed. For permanent offboarding, it is only needed when the password or management state cannot otherwise be recovered cleanly.
Option 2: Permanently uninstall the agent
If Tamper Protection is already disabled, run the official uninstaller from a Command Prompt opened as administrator:
"C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe" --quiet
On a server, unlock Server Lockdown in Fusion first. Sophos requires a restart after removal; then check installed apps, Sophos services and the registered protection provider. The full procedure is in Uninstall Sophos Endpoint on Windows.
This executable applies to Windows 10 (x64) and later and Windows Server 2016 and later with a supported Core Agent. Legacy platforms use uninstallgui.exe for a normal interactive removal or uninstallcli.exe --quiet for command-line removal from the same agent directory. Do not use the Endpoint command as a substitute for the Fusion removal workflow for protected software such as ZTNA, Device Encryption or MDR.
For batch deployment, save the complete quoted current-agent command above with a .bat extension, retaining the opening quotation mark, and run that script on the intended devices.
Option 3: Register the agent with the tenant again
If the device should remain managed, a current installer from the correct Sophos Fusion tenant can renew registration:
SophosSetup.exe --registeronly
Tamper Protection must be turned off before using --registeronly. Core Agent 2023.2 or later does this automatically after deletion or licence expiry; in other migration scenarios, turn it off in a controlled way before running the command.
Download the tenant-bound installer from My Environment > Installers. Then verify in Fusion:
- correct tenant and computer name
- agent mode and licensed products
- intended computer group
- assigned policies
- healthy state and current components
- no registration or licensing alerts
--registeronly does not repair a damaged installation. Preserve logs and state first if the Core Agent or its communication components are faulty.
Retrieve the password of a deleted device
Sophos Fusion currently retains deleted devices and their Tamper Protection passwords in this report for 120 days, but the device object can only be restored during the first 30 days. The password is mainly relevant to older platforms or agent versions that still request it.
If the audit record is needed beyond 120 days, export the report before that retention period expires and protect the exported password data appropriately.
- Open Reports > Reports > Endpoint Protection or Server Protection.
- Select Restore deleted devices and recover Tamper Protection passwords.
- Identify the device using several attributes.
- In the Tamper Protection password column, click Password details. Fusion lists the current (most recently used) password first, followed by previous passwords.
- Use the current password only for the maintenance window and remove temporary copies afterwards.
Another device’s password will not work. If the record is older than the retention period, use the current Sophos support procedure instead of experimenting with the registry.
Expired licence
Current Windows devices may be recoverable after a new licence is activated if no more than 90 days have passed since the licence expired. After 90 days, run a current tenant installer with --registeronly to reinstall and register the agent. Confirm the tenant and a valid licence first.
For permanent retirement, uninstall locally. If the device remains in use, verify after registration that all expected protection products and policies are active again.
Troubleshooting
The restored device remains offline
Check network, proxy, DNS, system time and Sophos management services. Also verify that the installer and record belong to the correct tenant.
Tamper Protection remains active
Wait for the agent to synchronise its deleted or restored state, then check the Fusion, password, four-hour override and restoration paths above once. If protection remains active, do not force the uninstaller or start SophosZap.
SophosUninstall.exe is missing or fails
This suggests a damaged or incomplete installation. Preserve installation and uninstall logs, the return code and device state. Complete an already pending restart before checking again. Do not remove individual MSI packages, services or registry keys on suspicion, because this can prevent later repair.
Use SophosZap only after standard uninstallation fails
SophosZap is a last-resort Windows cleanup tool only when Tamper Protection is demonstrably off and the standard uninstaller has nevertheless failed or left an incomplete removal. Its heuristic detection carries additional risk, and it cannot turn off Tamper Protection. It is not a way around an unknown password, Server Lockdown or a protected Fusion offboarding workflow.
It supports problematic installations of HitmanPro Alert, HitmanPro, Sophos Central Endpoint/Server, Message Relay, Update Cache, Enterprise Console-managed endpoints, Sophos Home, Sophos Anti-Virus, Sophos Clean and other standalone Sophos products. It stops if it detects Active Directory Sync Tool, Invincea, PureMessage for Exchange, RMS Server/Relay, Sophos Enterprise Console, SafeGuard Enterprise, Server Lockdown, SAV for NetApp, SAVDI, STAS, Sophos IPsec Client, Sophos Connect, Sophos Connect Admin or Sophos Update Manager; remove that incompatible product normally first.
Verify the download and signature
Confirm Windows 7 or later, administrator access, disabled Tamper Protection and current backups. ARM64 requires SophosZap 1.2.3.0 or later. Download a current SophosZap copy immediately before the maintenance window. Check File version under Properties > Details and require a valid Sophos signature under Properties > Digital Signatures. PowerShell can check the local download instead:
$zap = (Resolve-Path .\SophosZap.exe).Path
$sig = Get-AuthenticodeSignature -FilePath $zap
$sig | Select-Object Status, StatusMessage, @{Name='Signer'; Expression={$_.SignerCertificate.Subject}}
if ($sig.Status -ne 'Valid' -or $null -eq $sig.SignerCertificate) {
throw 'SophosZap signature validation failed'
}
PowerShell deliberately checks only, fail closed, that Authenticode status is Valid and a certificate is present; it does not approve the displayed full Subject by substring. An administrator must compare that value exactly with the expected publisher identity verified separately through current official Sophos documentation or Sophos Support. Without an exact match, with a missing or invalid signature, or with an ARM64-incompatible version, do not execute the file; delete it and download it again. A locally recorded hash can document the deployment but, without an independently published expected value, does not replace signature verification.
Run it and handle its output
Run the verified tool from its local directory in an elevated Command Prompt:
SophosZap --confirm
Follow the output exactly. At Reboot and re-execute, restart, run the same command exactly once more as administrator, then restart again. Additional restarts may be required. The appendable log is under %TEMP%. For INFO : Reboot will be required. An update remains in progress., complete the requested restart rather than forcing cleanup in parallel. SophosZap is Windows-only; on some Windows 8.1 systems Windows Defender may need to be started manually afterwards.
Validate the result and hand off to Support
After the final restart, check installed apps, running Sophos services, the Sophos UI and the protection provider registered in Windows Security. A remaining folder alone is not a failure. For permanent removal, confirm that the intended successor protection is active. If the device must remain protected, reinstall or re-register Sophos and verify the correct tenant, agent mode, products, policies and healthy state in Fusion. Delete an obsolete Fusion device object only after local validation succeeds.
If Tamper Protection remains active or no supported turn-off method is available, open a Sophos Support case. Do the same if standard uninstallation and the exactly-once repeated SophosZap run remain incomplete. Sophos manual recovery has separate, non-interchangeable paths for current desktop/server Windows, Server Core 2012 or later, and Windows 7 or Windows Server 2008 R2. Because it may involve Windows Recovery and the Endpoint Defense driver, its platform- and version-sensitive boot, driver and registry changes are deliberately not reproduced here and must only be performed under current Sophos direction.
Provide the tenant and device identifier, Windows version and architecture, Core Agent and SophosZap versions, installed Sophos components, Tamper Protection and Server Lockdown status, intended end state, exact commands with timestamps and return codes, SophosZap log.txt, relevant files containing Sophos from %TEMP% and C:\Windows\Temp, uninstall logs, and a fresh SDU. Upload confidential archives only through the case’s designated upload.
Products are missing after –registeronly
Re-registration does not automatically restore every desired component. Check agent mode and Manage device software under My Environment > Computers & Servers, then allow the device to receive its complete configuration and updates.