Disable Sophos Central tamper protection
In this article we will show you how to temporarily or permanently disable tamper protection for a client. We will also show you a way to globally disable tamper protection on all clients with one click.
Info: By default, Sophos Central on Sophos Endpoint Client has tamper protection enabled. This prevents a user from making settings on their own or uninstalling the client.
Requirements
- Sophos Central Account
- Sophos Endpoint Client installed on at least one computer
Disable tamper protection permanently for a client
1. log in to the Sophos Central account
Log in to
https://central.sophos.com
to log in to Sophos Central Admin.
2. select computer
Next, in Sophos Central Admin, you can go to the properties of the computer on which you want to disable tamper protection for the Sophos Endpoint Client. To do this, click on the menu item Endpoint Protection
in the sidebar on the left-hand side and then click on Computer
. Select the correct computer from the list and click den Namen des Geräts
to open its properties.
3. deactivate the tamper protection.
In the lower area you will now find the Tamper Protection settings. Click Disable Tamper Protection
to permanently unprotect this computer.

Note: It may take a few minutes for the settings to synchronize with the Sophos Endpoint Client.
Temporarily disable tamper protection for a client (Windows)
We recommend not to deactivate the tamper protection permanently if possible. In most cases, it is sufficient to suspend it only temporarily. In the following steps, we’ll show you how.
1. log in to the Sophos Central account
Log in to
https://central.sophos.com
to log in to Sophos Central Admin.
2. select computer
Next, in Sophos Central Admin, you can go to the properties of the computer on which you want to disable tamper protection for the Sophos Endpoint Client. To do this, click on the menu item Endpoint Protection
in the sidebar on the left-hand side and then click on Computer
. Select the correct computer from the list and click den Namen des Geräts
to open its properties.
3. copy Tamper Protection password
In the lower area you will now find the Tamper Protection settings. Click View details
and use the Show Password
option to display the current password. Now write down this password in order to remove the Tampar Protection on the client in the next step.

4. log in as admin with the Tamper Protection password
On the Windows computer, open the Sophos Endpoint Client and click Admin-Login
in the top right corner. Then enter the previously noted password and confirm with Anmelden
. After that a new menu item Settings appears.

5. deactivate tamper protection
In the settings you have to check Sophos Central-Richtlinie für bis zu 4 Stunden zur Problembehebung ausser Kraft setzen.
and then disable the tamper protection under User control.

Disable tamper protection permanently for all clients
1. log in to the Sophos Central account
Log in to
https://central.sophos.com
to log in to Sophos Central Admin.
2. globally disable tamper protection
Click on the menu item Global Settings
in the sidebar. Under the General Settings section you will now find the item Tamper Protection
. If you now call these settings, you can then deactivate the tamper protection on all your clients by clicking on the toggle.
