What are the key advantages of Sophos Central Mobile Advanced?
Central console – All devices managed from Sophos Central online.
Platform coverage – Android, iPhone, iPad, Mac, Windows and ChromeOS.
Threat defence – Intercept X for Mobile blocks malware and phishing.
Compliance rules – Non-compliant devices lose access automatically.
BYOD separation – Work profiles keep private data untouched.
Important note – Windows and Mac get management, not malware protection.
Sophos Mobile UEM – Enrols and configures Android, Apple, Windows and ChromeOS devices.
Intercept X for Mobile – Mobile threat defence against malware, phishing and rogue Wi-Fi.
Compliance policies – Rules with automatic actions, including PCI and HIPAA templates.
App management – Distribute Managed Google Play and Apple apps to groups.
Self Service Portal – Users enrol their own devices without helpdesk involvement.
Important – Windows and Mac management excludes Sophos endpoint malware protection.
Sophos Central Mobile Advanced is the full licence tier of Sophos Mobile, the unified endpoint management platform that Sophos previously sold as Sophos Mobile Control. Everything is administered from the Sophos Central cloud console, with no on-premises management server to run.
One console – Mobile devices sit beside your other Sophos products.
BYOD without intrusion – Apple User Enrolment and Android work profiles separate data.
Zero-touch rollout – Zero-touch enrolment via Apple Business and Samsung Knox.
Automatic reaction – Non-compliant Android devices have their apps disabled immediately.
Intune coexistence – Sophos works as Microsoft Intune mobile threat defence connector.
European data residency – Accounts can be hosted in Germany or Ireland.
The deciding factor is not headcount but whether company data reaches phones and tablets you cannot currently list by name. A company with fifteen employees and fifteen iPhones carrying business mail has the same evidence problem as a company with five hundred.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | By sector |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Occasionally | ✓ | ✓ |
| Device inventory and remote wipe on loss | Often manual | ✓ | ✓ |
| This product fits | ✓ | ✓ | Partial |
Swiss cybersecurity law does not apply to every company. The reporting obligation in the revised Information Security Act applies to operators of critical infrastructure, and organisations in scope must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Sophos Central Mobile Advanced supports that deadline in one specific way: the device inventory together with the compliance and threat detection records in Sophos Central shows which devices were affected, which operating system versions they were running and when the detection occurred, which is much of what an initial report asks for. It does not write the report, it does not cover servers, network equipment or mailboxes, and it holds no forensic timeline beyond the mobile detections and the network logs that Intercept X for Mobile sends to the Sophos Data Lake when an administrator turns that on. Reporting duties also cover incidents this product never sees, such as a compromised finance mailbox or a ransomware event on a file server. This description is general product information and not legal advice, and whether your organisation falls under the reporting obligation should be clarified with your own legal advisors.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses governance, processes and evidence rather than features. NIS 2 requires essential and important entities to take risk management measures covering areas such as incident handling, asset and access management, cyber hygiene, cryptography, multi-factor authentication and supply chain security. Sophos Central Mobile Advanced contributes to asset management with a maintained inventory of every enrolled phone, tablet and computer, to cyber hygiene by flagging devices running outdated operating system versions, and to access control by disabling apps on an Android Enterprise fully managed device the moment it breaks a compliance rule. It contributes nothing to supply chain security, business continuity, staff awareness training or the governance documentation an auditor will ask to see. Encryption support is limited to the platform mechanisms that iOS and Android expose through device management, so it is not a key management system with central recovery.
Partly, and it is worth knowing exactly which part before you promise anything to a customer. It answers the mobile block of a typical questionnaire with evidence rather than assertions: whether a device management system is in use, whether a current inventory of company devices exists, whether screen lock and device encryption are enforced, whether company data can be wiped remotely when a phone is lost, whether private and business data are separated on personal devices, whether mobile malware protection is active, and whether jailbroken or rooted devices are detected and cut off. It does not answer the questions that usually sit immediately above and below that block: endpoint protection on laptops and servers, detection and response, email and phishing protection, patch management for third-party applications, disk encryption with central key recovery, backup and restore testing, staff awareness training, penetration testing and formal certification. The cheaper route to closing those gaps is normally to add Sophos Intercept X Endpoint and Sophos Central Device Encryption inside the same Sophos Central account rather than introducing a second vendor, because questionnaires increasingly ask for one console and one reporting source, and mixing vendors means producing two sets of evidence for every answer.
The single decisive difference is on-device security: Central Mobile Standard is device management only, while Central Mobile Advanced adds the Intercept X for Mobile licence and with it mobile threat defence and Sophos Chrome Security for Chromebooks. Both tiers enrol and configure Android devices, iPhones, iPads, Macs and Windows computers from the same console, so the choice is not about platform reach. Advanced is a complete licence in its own right, not an add-on layered on top of Standard, so you buy one or the other rather than both. The word Corporate in the retail name refers to the customer segment Sophos uses in its price list for ordinary businesses, as distinct from the education and government variants of the same licence; the product scope is identical.
| Capability | Central Mobile Standard | Central Mobile Advanced |
|---|---|---|
| Enrolment and device policies | ✓ | ✓ |
| Android, iPhone, iPad, Mac, Windows | ✓ | ✓ |
| Intercept X for Mobile threat defence | ✕ | ✓ |
| Sophos Chrome Security for Chromebooks | ✕ | ✓ |
| On-device malware scan | ✕ | Android only |
| Malware protection on Windows and Mac | ✕ | ✕ |
Regional availability is the limitation that catches people out: Sophos Mobile is not supported in the Australia, Brazil, Canada, India and Japan data regions of Sophos Central, and the data region is fixed when the account is created and cannot be moved afterwards, so an existing account in the wrong region has to be recreated. There is no Swiss data region, and European customers are hosted in Germany or Ireland. Platform coverage is uneven in ways the feature list does not show: on-device malware scanning runs on Android only, web filtering on iPhones and iPads requires a supervised device in managed mode, and Linux, Apple TV and Fire OS are not supported at all. The most common follow-up purchase is endpoint protection, because managing a Windows laptop through device management configures it but does not defend it against malware. The former Sophos container apps are also gone, so separating business and private data now relies on the Android work profile and Apple User Enrolment mechanisms built into the platforms themselves.
No. Sophos withdrew both container apps from the app stores in December 2023 and no longer supports them. Sophos directs customers to the platform equivalents instead, which are the Android work profile and Apple User Enrolment.
Android Enterprise fully managed devices, work profile devices for personally owned phones, and dedicated kiosk devices, which are fully managed devices with a kiosk mode configuration applied. The legacy device administrator mode cannot be used on Android 10 or later and Sophos recommends re-enrolling any device still using it.
Yes. Sophos is selectable as a Mobile Threat Defense connector in the Microsoft Intune admin centre, and the Intercept X for Mobile app can be deployed from Intune. Enrolment and device policy stay in Intune while Sophos supplies the threat signal that feeds an Intune device compliance policy.
Unified endpoint management for Android, iOS, Mac, Windows and ChromeOS, including Intercept X for Mobile threat defence on phones and tablets.
Sophos Central Mobile Advanced, Sophos, Sophos Mobile, Sophos Mobile Control, Intercept X for Mobile, unified endpoint management, mobile threat defence, android enterprise
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies