Uninstall Sophos Endpoint with Tamper Protection enabled
If a Windows device was deleted from Sophos Central before the Endpoint Agent was removed locally, a blanket registry hack is not required. Current Sophos Core Agent versions have a defined process for deleted or expired devices.
The correct path depends on whether the device was only deleted, whether the licence expired, and whether it should be managed again or permanently removed.
⚠️ Do not use old procedures: Disabling Sophos services and Tamper Protection registry keys in Safe Mode can leave an inconsistent agent. The registry commands that used to circulate are no longer part of a normal administrator workflow.
Identify the case first
| State | Objective | Procedure |
|---|---|---|
| device deleted less than 30 days ago | continue management | restore the device in Central |
| device deleted, agent must be removed | permanent removal | check local protection state and run SophosUninstall.exe |
| licence expired, management must continue | reconnect | resolve licensing and register the agent with –registeronly |
| password requested on an older system | maintenance or removal | retrieve the deleted device password |
The retention periods and behaviour can change with agent versions. Record the operating system, Core Agent version, deletion time and tenant before making changes.
Behaviour on current Windows devices
Starting with Core Agent 2023.2, Windows 10 and later and Windows Server 2016 and later generally behave as follows:
- Tamper Protection is disabled locally after deletion in Central.
- Active protection components are removed or disabled.
- The Core Agent remains so that supported removal or re-registration is possible.
- Manual password recovery is normally unnecessary.
The device may need time to process the deletion or changed licence state. An offline device receives this information only after a successful connection.
Update Cache and Message Relay roles are also removed from devices that host them. Reinstall and verify these roles after restoration if they are still required.
Option 1: Restore the deleted device
Sophos Central currently retains deleted devices for 30 days.
- Open the deleted devices area in Sophos Central.
- Verify the computer name, operating system and deletion time.
- Restore the correct device.
- Wait for it to contact Central again.
- Check agent mode, policies, health state and last activity.
Restoration is appropriate when the computer should remain protected and managed. For permanent offboarding, it is only needed when the password or management state cannot otherwise be recovered cleanly.
Option 2: Permanently uninstall the agent
If Tamper Protection is already disabled, run the official uninstaller as a local administrator:
C:\Program Files\Sophos\Sophos Endpoint Agent\SophosUninstall.exe
--quiet is available for unattended removal. After the restart, check installed apps, Sophos services and the registered protection provider. The full procedure is in Uninstall Sophos Central Endpoint on Windows.
Option 3: Register the agent with the tenant again
If the device should remain managed, a current installer from the correct Sophos Central tenant can renew registration:
SophosSetup.exe --registeronly
Tamper Protection must be turned off before using --registeronly. Core Agent 2023.2 or later does this automatically after deletion or licence expiry; in other migration scenarios, turn it off in a controlled way before running the command.
Download the tenant-bound installer from My Environment > Installers. Then verify in Central:
- correct tenant and computer name
- agent mode and licensed products
- intended computer group
- assigned policies
- healthy state and current components
- no registration or licensing alerts
--registeronly does not repair a damaged installation. Preserve logs and state first if the Core Agent or its communication components are faulty.
Retrieve the password of a deleted device
Sophos Central currently retains Tamper Protection passwords for deleted devices for 120 days. This is mainly relevant to older platforms or agent versions that still request a password.
- Open the area for deleted devices or Tamper Protection passwords.
- Identify the device using several attributes.
- Use its password only for the maintenance window.
- Remove temporary password copies after successful work.
Another device’s password will not work. If the record is older than the retention period, use the current Sophos support procedure instead of experimenting with the registry.
Expired licence
Current Windows devices may be recoverable for a limited period after licence expiry. Sophos currently states up to 90 days for reconnection. Confirm the tenant and a valid licence before re-registering.
For permanent retirement, uninstall locally. If the device remains in use, verify after registration that all expected protection products and policies are active again.
Troubleshooting
The restored device remains offline
Check network, proxy, DNS, system time and Sophos management services. Also verify that the installer and record belong to the correct tenant.
Tamper Protection remains active
Wait for the agent to synchronise its deleted or restored state, then use the device password from Central. The standard temporary procedure is Disable Sophos Central Tamper Protection safely.
SophosUninstall.exe is missing or fails
This suggests a damaged or incomplete installation. Preserve installation and uninstall logs. Do not remove individual MSI packages, services or registry keys on suspicion, because this can prevent later repair.
Products are missing after –registeronly
Re-registration does not automatically restore every desired component. Check agent mode and Manage device software under My Environment > Computers & Servers, then allow the device to receive its complete configuration and updates.