Sophos Endpoint Security — Rollout Procedure
Section: Security Tags: sophos, endpoint, antivirus, security, rollout, intercept-x, mac, windows, softcat Source tickets: #15960 Confidence: High — standard rollout procedure confirmed across multiple sites
Overview
This article covers the end-to-end process for deploying Sophos Intercept X (or Endpoint Standard) across a client site — from licence procurement through to installation and verification. This is typically a project-level task requiring a planned site visit when most machines are on-site.
Phase 1 — Licence Procurement (via SoftCat)
Purple Computing sources Sophos licences through SoftCat. For new clients:
- Contact SoftCat account manager
- Provide:
- Request that SoftCat invoice the client directly — Purple Computing does not process this through its own accounts
- Once ordered: SoftCat will contact Sophos who will email the licence file to the address provided
-
Receive licence confirmation → log in to
https://cloud.sophos.comwith the client's account (or create a new Sophos Central account for the client)
Phase 2 — Pre-Rollout Preparation
-
Create the Sophos Central account for the client (if new):
https://cloud.sophos.com → Start Free Trial→ convert to paid once licences arrive - Log in to Sophos Central → Global Settings → Policies — review the default policy:
- Plan the site visit: confirm a time when the majority of machines will be on-site and powered on
- Identify existing AV software on each machine — note what needs to be removed before Sophos installs:
-
Prepare the Sophos installer:
Sophos Central → Endpoint Protection → Protect Devices → Download Installer
— download the
.pkg(Mac) and.exe(Windows) — ideally place on the client's Synology/NAS accessible to all machines
Phase 3 — Installation (Site Visit)
For each machine:
Mac
- Remove existing AV:
NortonRemoval.pkg
- McAfee: Applications → McAfee → McAfee Uninstaller
- Old Sophos: Applications → Sophos → Sophos Uninstaller
- Other: use the vendor's official removal tool; do NOT just drag to Trash (leaves
kernel extensions)
- Reboot after removal
-
Install Sophos: run the
.pkginstaller from the NAS or USB - Complete the macOS permissions prompts: System Preferences → Security & Privacy → Privacy:
- Reboot if prompted
- In Sophos Central: confirm the machine appears under Computers within 5 minutes
Windows
- Remove existing AV via Control Panel → Programs
- Reboot
-
Run the Sophos
.exeinstaller — accept the UAC prompt - Wait for installation to complete and services to start
- Confirm in Sophos Central
Phase 4 — Post-Rollout
- In Sophos Central → Computers — confirm all expected machines are listed and showing "Protected"
- Check for any machines showing alerts or failed installation
- Update the ticket with:
- Inform client: standard Sophos scan will run automatically within 24 hours of install; no action needed
Verification
In Sophos Central → Computers — all machines show:
- Status: Protected
- Threat Protection Policy: applied
- Last seen: within the last hour
http://amtso.org/check-the-basics/test-your-anti-phishing/ — Sophos
should block it and display a block page.
Ongoing Management
- Sophos Central sends automated alerts for detections, policy failures, and offline machines — confirm the client or Purple Computing receives these alerts (set under Global Settings → Notifications)
- Annual licence renewal: SoftCat will send renewal notices — forward to client finance for approval
- If a machine is replaced: remove the old entry from Sophos Central and install on the new machine (licences float within the seat count)
If Installation Fails
IssueFix ------------ Mac installer blocked by GatekeeperRight-click → Open (first time); or System Preferences → Security → Allow Full Disk Access permission grayed outUnlock the padlock in Security & Privacy before ticking Sophos Machine not appearing in Central after installCheck internet connectivity; verify the installer is the correct one for this Central account Old AV removal leaves kernel extensionBoot into Recovery → Startup Security Utility → reduce security temporarily; remove kext; restore security Windows installer fails silentlyRun as Administrator; check Windows Event Viewer → Application log for error details
Comments
0 comments
Please sign in to leave a comment.