Sophos Endpoint: How to disable Tamper Protection *

https://community.sophos.com/kb/en-us/119175

Sophos Endpoint: How to disable Tamper Protection

  • 119175

  • 23 Aug 2019

  • 42 people found this helpful

  • English | Español | Italiano | 日本語 | Français | Deutsch

Overview

Tamper Protection must be disabled before changes are made to the local Sophos configuration or if there is a need to uninstall the existing Sophos product. Disabling the Tamper Protection requires that the logged in user knows the actual password that was set in the policy and that the user is a member of the local group SophosAdministrator.

This knowledge base article describes the steps to disable Tamper Protection from various Sophos products.

Please be advised that there is no Tamper Protection for the standalone Sophos on a Mac.

The following sections are covered:

Applies to the following Sophos products and versions
Enterprise Console
Sophos Endpoint Security and Control 10.8.4
Central Mac Endpoint
Sophos Central Admin
UTM Managed Endpoint

Managed by Sophos Enterprise Console

On the SEC via policy

  1. Go to Policies followed by Tamper protection .

  2. Double-click your concerned policy then deselect the box for Enable tamper protection .

  3. Click the OK button.

Note: Adjusting this policy will affect all endpoints wherein this policy is applied to. For more information about configuring policies, take a look at the Enterprise Console Help.

On the installed Sophos on a Windows endpoint

  1. Double-click Sophos Endpoint Security and Control on the Taskbar .
  2. Click Authenticate user .
  3. Type the Tamper Protection password that is configured in your Tamper Protection policy then click the OK button.
  4. Click Configure tamper protection .
  5. Uncheck the box for Enable Tamper Protection then click the OK button.

On the installed Sophos on a Mac endpoint

  1. Open Sophos Anti-Virus Preferences .
  2. Click the padlock and Sophos icons then type the tamper protection password in in the dialog box.
  3. Click the OK button.

Note: Tamper Protection cannot be disabled permanently.

Managed by Sophos Central

Disable for all endpoints

  1. In Sophos Central , click Global Settings .
  2. Under General , click Tamper Protection .
  3. Move the slider to the left then click the Save button.

Per endpoint

  1. In Sophos Central , go to Devices .
  2. Click your concerned endpoint.
  3. In the SUMMARY page, scroll down and then click Disable Tamper Protection .

Note: In Settings of the Sophos Endpoint , it will show that the Tamper Protection is already turned off.

On the installed Sophos on a Windows endpoint

  1. In Sophos Central , go to Devices .
  2. Click your concerned endpoint.
  3. In the SUMMARY page, scroll down then click View details under Tamper Protection .
  4. Take note of the password shown when you select the Show Password box that is under Tamper Protection Password Details .
  5. Log in to your concerned Windows endpoint.
  6. Double-click the Sophos Endpoint on the Taskbar .
  7. Click Admin login then type in the password you have taken note earlier.
  8. Click the Log in button.
  9. Select Settings from the top menu.
  10. Tick the box near the top for Override Sophos Central Policy for up to 4 hours .
  11. Move the slider of Tamper Protection to the left.

Notes:

  • Sophos Central will automatically enable Tamper Protection after four hours.
  • If Sophos Endpoint cannot be launched, open a Command Prompt then run SEDcli.exe -TPoff <password> . This file is located in C:\Program Files\Sophos\Endpoint Defense\

On the installed Sophos on a Mac endpoint

  1. Click Sophos Endpoint on the Dock bar.
  2. Click Admin login .
  3. Type the Mac admin password and then click the OK button.
  4. Click the padlock and Sophos icon then type the tamper protection password in the dialog box.
  5. Click the OK button.

Note: Tamper Protection cannot be disabled permanently.

Click for the rest of the Tech Note