Replacing endpoint security software across a fleet of Windows and Mac devices is one of the more disruptive IT changes organisations make — because unlike a firewall or email gateway, every device in the organisation is affected. Done correctly, the transition is invisible to end users and protection is continuous throughout. Done incorrectly, there are gaps in protection, software conflicts that cause application crashes, or deployment failures on remote machines.
This guide covers the complete migration to Sophos Intercept X from Windows Defender, Symantec Endpoint Protection, McAfee/Trellix, Trend Micro, or any other legacy antivirus — using Sophos Central for centralised deployment and management.
Why Organisations Move from Legacy AV to Sophos Intercept X
The endpoint security migration decision in India is typically triggered by one of these situations:
Windows Defender is not enough for business. Windows Defender (Microsoft Defender Antivirus) provides solid protection against known malware signatures and integrates with Microsoft Defender for Endpoint for enterprise threat intelligence. It does not include CryptoGuard (ransomware file rollback), deep learning-based malware detection (Intercept X's neural network model), or Synchronized Security with Sophos XGS Firewall. Organisations that have experienced a ransomware incident — or been advised by their insurer to improve endpoint security — move to Sophos Intercept X for these specific capabilities.
Legacy AV contract expiry. Symantec Endpoint Protection, McAfee Enterprise (now Trellix), and Trend Micro OfficeScan are being replaced across Indian organisations as on-premise management servers reach end-of-life and cloud-managed alternatives offer more capable protection without the server infrastructure.
Completing the Sophos stack. Organisations already running Sophos XGS Firewall add Sophos Intercept X to activate Synchronized Security — where a compromised endpoint automatically triggers network isolation via Security Heartbeat, without manual intervention.
Compliance requirements. Indian organisations undergoing ISO 27001 certification, SOC 2 preparation, or insurance security audits are asked to demonstrate EDR (Endpoint Detection and Response) capability. Windows Defender Antivirus alone does not satisfy EDR requirements. Sophos Intercept X Advanced includes full EDR.
Sophos Intercept X — Understanding the Licence Tiers
Before migration, confirm the correct Sophos Intercept X licence tier for your deployment:
Sophos Intercept X Essentials:
- Deep learning AI malware detection
- CryptoGuard (ransomware file rollback)
- Exploit prevention (stack pivot, ROP chain, privilege escalation prevention)
- Web protection and application control
- Sophos Central cloud management
- Security Heartbeat with Sophos XGS Firewall
Sophos Intercept X Advanced:
- Everything in Essentials, plus:
- EDR (Endpoint Detection and Response) — Root Cause Analysis, threat hunting, Live Response remote shell
- Guided investigation interface
Sophos Intercept X Advanced with XDR:
- Everything in Advanced, plus:
- Cross-platform telemetry — email, network, firewall, cloud
- Sophos Data Lake for 90-day historical event retention
- Advanced threat hunting across the full environment
For most Indian SMBs, Sophos Intercept X Advanced is the right choice — it satisfies EDR compliance requirements and provides the Root Cause Analysis capability that is most useful after an incident.
Pre-Migration Planning
Inventory Your Devices
Before deploying Sophos, build an accurate device inventory:
- Total Windows devices (workstations, laptops)
- Total macOS devices
- Total Windows Server instances (Sophos Intercept X for Server is a separate licence)
- Remote/WFH devices that cannot be reached via local network
For Windows endpoints, Sophos Central can discover devices via Active Directory — sync your AD OUs to automatically populate the device list.
Identify Your Current AV Deployment Method
How was your existing AV deployed? This determines how you will deploy Sophos:
- Group Policy / SCCM / MECM: Use the same tool to deploy the Sophos installer
- Intune / Microsoft Endpoint Manager: Use Intune to package and deploy Sophos
- Manual installation: For small deployments (under 30 devices) or remote devices
Check for Known Software Conflicts
Sophos Intercept X cannot run alongside another active endpoint security product with real-time scanning enabled. Two scanning engines create system instability and performance problems.
The migration sequence must be: remove existing AV → install Sophos. Not the other way around.
Sophos provides a standalone removal tool (SEDRemovalTool) for some third-party AV products. Check Sophos's compatibility documentation or ask Cloudfy to confirm whether your existing AV product has a Sophos-compatible removal path.
Step 1 — Set Up Sophos Central
- Log in to Sophos Central (central.sophos.com) — access and credentials provisioned by Cloudfy at licence activation
- Navigate to Endpoint Protection
- Confirm your Sophos Intercept X licences are allocated and available
Configure Policies Before Deployment
Configure your endpoint policies in Sophos Central before deploying to any device. Policies can be applied globally or per device group.
Threat Protection Policy: Navigate to Endpoint Protection → Policies → Threat Protection:
- Deep Learning: Enable (on by default — do not disable)
- Malicious Traffic Detection: Enable
- Exploit Prevention: Enable all exploit mitigation techniques
- CryptoGuard (Ransomware Protection): Enable — this is the most critical setting. CryptoGuard monitors for ransomware-pattern file access (mass encryption of user files) and rolls back encrypted files to their original state
- Live Protection: Enable (real-time cloud lookups for new threats)
Web Protection Policy:
- Enable Web Control — configure categories to block (adult content, gambling, malware distribution)
- Enable Download Reputation — blocks downloads of files with low reputation scores
- Enable HTTPS Inspection if required (adds certificate to managed devices)
Application Control Policy: Configure which application categories to allow or block — P2P file sharing, remote desktop tools not authorised by IT, potentially unwanted applications (PUAs).
Peripheral Control Policy: Configure USB device control if required — block unauthorised USB storage, allow known corporate USB devices by serial number.
Tamper Protection: Enable Tamper Protection — this prevents end users or malware from uninstalling Sophos or disabling its protection. Set a Tamper Protection password for authorised uninstall operations.
Step 2 — Sync Active Directory with Sophos Central (Optional but Recommended)
For Windows environments with Active Directory:
- In Sophos Central → Directory Services → Active Directory Sync
- Download the Sophos Directory Connector installer
- Install on a domain-joined Windows Server (can be any server with LDAP access to your DC)
- Configure the connector with your AD domain, DC hostname, bind account credentials, and the OUs to sync
- Run the initial sync — Sophos Central imports all users and computers from the specified OUs
With AD sync active, Sophos Central shows all computers in your estate, their OS version, logged-in user, and current Sophos protection status. This is your deployment dashboard.
Step 3 — Remove Existing AV Software
Removing the existing AV before installing Sophos is critical. Do not skip this step.
Windows Defender (Built-in)
Windows Defender is automatically suppressed — not uninstalled — when Sophos Intercept X is installed and detected as the primary security provider. Windows Security Centre shows Sophos as active and marks Defender as disabled.
You do not need to manually uninstall Windows Defender. Sophos's installer handles the co-existence automatically.
However: if your organisation also runs Microsoft Defender for Endpoint (the enterprise EDR product, separate from the built-in antivirus), check with Sophos before deploying both — they can co-exist in a specific configuration mode (passive mode for Defender), but this requires deliberate configuration.
Symantec Endpoint Protection
- Confirm the Symantec management server (SEPM) is accessible
- Deploy an uninstall policy from SEPM to remove SEP from endpoints
- Alternatively, use the CleanWipe tool from Symantec for forced removal on devices where SEPM deployment fails
- Verify removal: check Add/Remove Programs — SEP should not appear
McAfee / Trellix Endpoint Security
- Use the McAfee Agent (MA) management server to push an uninstall task to all endpoints
- For devices unreachable via ePolicy Orchestrator (ePO), use the McAfee Consumer Product Removal tool (MCPR) for manual removal
- Reboot required after McAfee removal on most versions
Trend Micro OfficeScan / Apex One
- From the OfficeScan/Apex One management console, push an uninstall task to target devices
- For unmanaged devices, use the Trend Micro Diagnostic Toolkit or standard Add/Remove Programs
- Reboot required
Third-Party AV Removal — Sophos SEDRemovalTool
Sophos provides the Sophos Endpoint Defense Removal Tool (SEDRemovalTool) for removing Sophos's own products. It is not designed for third-party AV removal. Use the respective vendor's removal tools for third-party AV.
If a third-party AV removal fails or leaves residual services, the Sophos installer may fail or produce errors. Run a reboot and check for remaining AV services via services.msc before re-attempting Sophos installation.
Step 4 — Deploy Sophos Intercept X
Download the Installer from Sophos Central
- In Sophos Central → Endpoint Protection → Protect Devices
- Select the platform: Windows or macOS
- Download the installer:
SophosSetup.exe(Windows) orSophosSetup.dmg(macOS) - Optionally generate a deployment URL — this is a URL that bundles your Sophos tenant credentials, allowing the installer to automatically register the device to your Central account without manual token entry
Deployment via Group Policy (Windows)
For domain-joined Windows environments:
-
Copy
SophosSetup.exeto a network share accessible by all domain computers -
Create a new Group Policy Object (GPO) linked to the OUs containing your target computers
-
Navigate to Computer Configuration → Software Settings → Software Installation
-
Add a new package pointing to the network share path
-
Alternatively, use a GPO Startup Script with the command:
\\server\share\SophosSetup.exe --quietThe
--quietflag runs the installer silently without user prompts -
Apply the GPO — Sophos installs on next Group Policy refresh (typically at next device reboot or within 90 minutes for background refresh)
Deployment via Microsoft Intune
- In Microsoft Endpoint Admin Centre → Apps → Windows apps → Add
- Select app type: Line-of-business app (if using .exe) or Win32 app (recommended for .exe with wrapping)
- Package the
SophosSetup.exeusing the Microsoft Win32 Content Prep Tool to create an.intunewinpackage - Add a detection rule: check for the presence of
C:\Program Files\Sophos\Endpoint Defense\SophosED.exe - Assign the app to All Devices or a target device group
- Monitor deployment status in Intune — devices show as Installed once Sophos is deployed
Deployment via SCCM/MECM
- Create a new Application in SCCM/MECM
- Use
SophosSetup.exe --quietas the install command - Use
MsiExec.exe /X{PRODUCT-CODE} /quietas the uninstall command (product code available from Sophos documentation for your version) - Deploy to target device collection with Install action
Manual Deployment (Small Deployments / Remote Devices)
For organisations with under 30 devices or for remote devices that cannot be reached via management tools:
- Generate a deployment link from Sophos Central (share-able URL)
- Send the link to each device's user
- User downloads and runs
SophosSetup.exe— the installer uses the embedded tenant token to register the device to your Central account automatically - No admin console access required on the device during installation
Step 5 — Verify Deployment in Sophos Central
After deployment:
-
In Sophos Central → Endpoint Protection → Computers
-
Each deployed device should appear with:
- Status: Protected (green checkmark)
- Last Seen: within the last hour
- Sophos version: current version
- Policy: the policy you configured in Step 1
-
Filter by Unprotected to identify devices where deployment failed or Sophos has not yet registered
For deployment failures:
- Check whether the device was rebooted after AV removal (some AV products require a reboot before Sophos can install)
- Check whether the device has internet access to reach Sophos Central
- Check Windows Event Log on the device (Application log) for Sophos installer errors
Step 6 — Activate Synchronized Security (If Running Sophos XGS Firewall)
If your organisation runs a Sophos XGS Firewall, activate Security Heartbeat to complete the Synchronized Security loop:
On Sophos XGS Firewall:
- Log in to the Sophos Firewall admin console or Sophos Central Firewall Management
- Navigate to Synchronized Security → Security Heartbeat
- Enable Security Heartbeat
- Confirm the firewall can reach Sophos Central (heartbeat communication uses HTTPS to Sophos's cloud infrastructure)
On Sophos Central (Endpoint Policy):
- In your Threat Protection policy → Security Heartbeat
- Enable Security Heartbeat for all endpoints
- Endpoints begin reporting their health status (Green/Yellow/Red) to the XGS Firewall
Configure the Heartbeat-triggered isolation policy (on XGS):
- Navigate to Firewall Rules → create or edit rules for LAN to WAN traffic
- Apply Minimum Source Heartbeat condition: set to Green for sensitive traffic
- Any endpoint sending a Red heartbeat (compromised) has its internet access automatically blocked by the firewall rule — until the endpoint is cleaned up and reverts to Green heartbeat
This is the Synchronized Security capability that no other vendor delivers: automatic, firewall-level network isolation of compromised endpoints with zero manual intervention.
Post-Migration Validation Checklist
Complete these checks 24–48 hours after deployment:
- All expected devices show as Protected in Sophos Central
- No devices showing Unprotected or Not Seen Recently (investigate any exceptions)
- Tamper Protection is active on all endpoints (visible in device details)
- CryptoGuard is enabled in the threat protection policy
- Threat alerts tab — review any detections since deployment; investigate any that require attention
- Root Cause Analysis (Advanced): confirm RCA is available for any detected events
- Security Heartbeat: if XGS Firewall is in use, confirm endpoints show Green heartbeat in the firewall console
- Web filtering test: attempt to access a blocked category from a client device — confirm block page appears
- Legacy AV software: confirm old AV is not present on any devices (check via Sophos Central device inventory)
- Removal of old AV management server/console: decommission after confirming all endpoints are on Sophos
Frequently Asked Questions
Can we run Sophos Intercept X alongside Windows Defender? Windows Defender Antivirus is automatically disabled (not uninstalled) when Sophos Intercept X becomes the primary security provider, as registered in Windows Security Centre. They do not run simultaneously. Microsoft Defender for Endpoint (the enterprise product, separate from the antivirus) can co-exist with Sophos in a specific configuration — contact Cloudfy if you have both products.
How long does the migration take for 100 endpoints? With Group Policy or SCCM/Intune deployment, the full deployment to 100 devices completes within 2–4 hours (assuming existing AV was pre-removed). Policy configuration in Sophos Central takes 1–2 hours. Allow a total project timeline of one business day for an organised migration, including validation.
Do end users experience any interruption during the Sophos installation? The Sophos installer runs silently in the background. Users may see a brief notification when installation completes and a reboot prompt if required. Some AV removal steps (particularly Symantec and McAfee) require a reboot — factor this into your deployment timing. Schedule deployments outside business hours via GPO or SCCM deployment window.
What happens if CryptoGuard triggers — will it interrupt work? CryptoGuard monitors for ransomware file access patterns. If it detects ransomware behaviour, it immediately blocks the process responsible and rolls back affected files to their pre-encryption state. This is logged in Sophos Central and an alert is sent to the admin. End users may experience a brief pause in the affected application while CryptoGuard acts — but their files are protected and restored, not lost.
We have remote employees across India. Can we deploy Sophos to them without bringing devices into the office? Yes. Generate a deployment URL from Sophos Central and share it with remote users. The installer downloads from Sophos's cloud and registers the device to your Central tenant automatically via the embedded token. Remote employees install it themselves — no VPN, no office visit required.
What is the difference between Sophos Intercept X for Endpoint and Sophos Intercept X for Server? These are separate licence SKUs. Endpoint licences cover workstations and laptops. Server licences are required for Windows Server, Linux servers, and virtual machines (VMs). The features are similar but tuned for each environment — Server includes server-specific exploit mitigations. Contact Cloudfy to license both if you need to protect servers as well.
Ready to move your Indian organisation to Sophos Intercept X? Contact Cloudfy Systems — authorised Sophos Partner for endpoint security deployment. We handle Sophos Central setup, device deployment, and policy configuration with no disruption to end users.
