What are the core benefits of Sophos Central Intercept X for Mobile?
Central management – Policies and alerts run through Sophos Central.
Malware scanning – Deep learning app scanning on Android devices.
Web filtering – Blocks phishing and unwanted sites by category.
Network protection – Detects man-in-the-middle attacks on public Wi-Fi.
Compliance signals – Device health can gate Microsoft Intune access.
Important note – No device management, that needs Mobile Advanced.
Mobile Threat Defense app – Protects Android phones, iPhones and iPads against mobile threats.
Sophos Central management – One cloud console for policies, alerts and device status.
Android malware scanning – Deep learning engine checks installed apps and storage media.
Web filtering – Category-based blocking of malicious and unwanted web pages.
Chromebook protection – Sophos Chrome Security is covered by the same license.
Important – Mobile device management is not part of this license.
Sophos Central Intercept X for Mobile is a Mobile Threat Defense product for Android devices, iPhones, iPads and ChromeOS devices, configured centrally in Sophos Central instead of device by device. Sophos introduced it as the successor to Sophos Mobile Security, so older documentation and search results still use that earlier name.
Phishing blocked on device – Web filtering stops malicious links outside corporate email gateways.
Rooting and jailbreak alerts – Flags compromised devices before they reach company data.
Conditional access signals – Device health feeds Microsoft Intune access decisions.
Works with existing EMM – Deploy through your existing EMM or the public app stores.
No on-premises server – The console is hosted, nothing to install internally.
Single console with endpoints – Mobile alerts sit beside existing Sophos endpoint alerts.
The product suits any organisation that hands out phones or allows business email on personal devices and wants the security state of those devices visible in one console. The dividing line is not headcount but whether you also need to configure and lock down the devices themselves, because that function sits in a different license of the same family.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | Rarely | By sector | By sector |
| Security questionnaire from large customers | Increasing | ✓ | ✓ |
| Device management needed as well | Often no | Often yes | ✓ |
| This product fits | ✓ | ✓ | With MDM |
The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure in nine defined sectors, not to every Swiss company, and sector thresholds decide who is actually covered. Those operators must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further period to complete the report. Sophos Central Intercept X for Mobile supports that deadline in one narrow but useful way: detections on phones and tablets arrive in the console with a timestamp and device identity, which is the information a first report needs and which is otherwise scattered across individual devices. It does not submit anything to BACS, has no incident case management, and sees nothing outside the mobile devices running the app, so servers, workstations and network events need separate coverage. It also cannot enforce a device configuration, which means a finding cannot be remediated centrally through this license alone. This text is general product information and not legal advice.
No product makes an organisation compliant with the NIS 2 Directive, because the directive addresses management responsibility, risk analysis and documented processes rather than software features. NIS 2 requires categories of measures including incident handling, business continuity, supply chain security, access control, cryptography, cyber hygiene and training, and multi-factor authentication. Sophos Central Intercept X for Mobile contributes to incident handling and access control for the mobile part of the estate: it detects compromised or rooted devices, blocks phishing pages before the browser opens them, and can pass device health to Microsoft Intune so that access to company data depends on that state. It contributes nothing to business continuity, backup, supply chain assessment, awareness training, or encryption key management, and the Authenticator built into the app is an end-user one-time password tool rather than an enterprise authentication service. Treat it as one documented technical control for mobile devices, not as coverage of a measure category.
Partly, and it helps most with the questions that are otherwise hardest to answer honestly. It lets you answer yes to malware protection on mobile endpoints, to central visibility of device security state, to jailbreak and rooting detection, to web and phishing filtering on company phones, and to reporting that shows which devices are protected and which are not. It does not answer questions about enforced device configuration, passcode policy, remote wipe, application allow lists, disk encryption enforcement, or separation of business and private data, because all of those belong to the device management side of the product family. It also answers nothing about servers, mail, backup or patching. If a questionnaire keeps failing on the device management questions, moving to Central Mobile Advanced within the same family is usually simpler and cheaper than adding a second vendor's MDM, because it keeps one console, one agent and one reporting source.
The decisive difference is device management: Intercept X for Mobile secures devices but cannot configure them, while Central Mobile Standard provides the Mobile Device Management features and Central Mobile Advanced combines both. Intercept X for Mobile is the right choice when devices are already enrolled in an existing management tool such as Microsoft Intune, or when employees use personal phones that the company does not administer. Central Mobile Advanced is the right choice when the same console should also enrol devices, push profiles and applications, and manage Macs and Windows computers. Because Advanced contains everything in the other two, moving up later does not mean replacing the app or re-enrolling the devices.
| Capability | Intercept X for Mobile | Central Mobile Standard | Central Mobile Advanced |
|---|---|---|---|
| Mobile device management | ✕ | ✓ | ✓ |
| Mobile Threat Defense app | ✓ | ✕ | ✓ |
| Android malware scanning | ✓ | ✕ | ✓ |
| Web filtering policy | ✓ | ✕ | ✓ |
| Sophos Chrome Security | ✓ | ✕ | ✓ |
| Windows and macOS management | ✕ | ✓ | ✓ |
The most expensive surprise concerns Android Enterprise work profiles: the web filtering configuration does not apply there, because the app is installed inside the work profile and cannot reach the Android accessibility service that web filtering depends on. On iPhones and iPads, web filtering works on supervised devices or when the app runs in managed mode, so an unsupervised personal iPhone gets device and network checks but not category-based filtering. Malware scanning of installed apps is an Android capability, since Apple does not permit an app to scan other apps, which means iOS protection rests on device state, network checks and link checking instead. Sophos has announced that the Password Safe feature will be removed from the app, so it should not be counted as part of the value. Finally, the license covers mobile and ChromeOS devices only, which is the usual reason for a follow-up purchase when the same console is expected to show Windows and macOS as well.
It is the same app, but the license unlocks managed mode. In managed mode the app connects to Sophos Central, receives policies set by an administrator and reports device state back, none of which the free unmanaged installation can do.
No. It is a standalone license and works without Sophos endpoint or firewall products. If you already use Sophos Central for other products, mobile devices appear in the same console rather than in a separate one.
Either users install it from Google Play or the Apple App Store and connect it using an enrolment code, or an existing enterprise mobility management tool pushes it and supplies the connection settings automatically. The second route is the practical one for larger fleets because it removes the user step.
Mobile threat defense for Android and iOS, managed in Sophos Central. Adds web filtering and Wi-Fi attack detection, not device management.
Sophos Central Intercept X for Mobile, Sophos, Sophos Mobile, Sophos Mobile Security, Sophos Central, mobile threat defense, mobile device security, web filtering, malware protection
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies