Skip to content
Supported migration paths

Migration checklist

This checklist is a condensed version of the “Prepare for migration”, “Migration”, and “Post-migration tasks” sections. Use it to track your migration status.

  1. Check that you’re not using a feature that blocks migration:

    • Windows Mobile or Windows Phone devices
    • Corporate keyring synchronization with SafeGuard Enterprise
    • Sophos UTM integration
    • Integration with third-party Network Access Control (NAC) software
    • Duo Security integration for Android devices
    • LDAP user management, except for Active Directory
    • App Groups API integration with a third-party app reputation vendor
    • Other Sophos Mobile REST APIs
  2. Check that all devices have a supported operating system.

    See the Requirements section in the Sophos Mobile release notes.

  3. Check that your firewall allows inbound connections from Sophos Central.

    See IP addresses for AD and SCEP connections.

  4. If applicable, check that the following is up to date:

    • Your Sophos Mobile server
    • Your APNs certificate
    • Your external EAS proxy
  5. Set up your Sophos Central account.

  6. Download a migration token from Sophos Central.
  7. If applicable, turn off Sophos Mobile auto-enrollment:

    • Revoke the Android Enterprise QR code.
    • Revoke the Android zero-touch configuration.
    • Revoke the Samsung Knox Mobile Enrollment (KME) configuration.
    • Revoke the Google Workspace connection code for Sophos Chrome Security.
    • Revoke the third-party connection code for Sophos Intercept X for Mobile.
    • Turn off iOS auto-enrollment with Apple Configurator in the device group settings.
  8. If applicable, turn off TeamViewer integration.

  9. Unenroll and delete inactive devices that don’t synchronize anymore.
  10. Update the Sophos Mobile apps.
  11. If applicable, turn off mail filtering with the Sophos Mobile EAS proxy.
  12. Start the migration assistant.
  13. Correct issues that the migration assistant reports.
  14. Start migration from the final page of the migration assistant.
  15. Wait until the migration assistant starts to migrate devices. Then continue as follows:

  16. Check your migrated data in Sophos Central.

  17. Set up user management in Sophos Central and invite users to Sophos Central Self Service Portal.
  18. Do the following if applicable:

    1. Configure Intune app protection in Sophos Central.
    2. Configure Sophos Mobile auto-enrollment in Sophos Central.
    3. Turn on mail filtering with the Sophos Mobile EAS proxy.


When you migrate iPhones, iPads, Macs, or Windows computers, you must keep your Sophos Mobile server running after migration. These devices remain connected with your Sophos Mobile server even after migration.

However, you’re not required to update licenses or the Sophos Mobile server software. Because the server load after migration is reduced, you may consider scaling down server hardware.