This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Endpoint not connecting to Sophos Central; Can't Uninstall due to Tamper Protection

I have a computer that Sophos was installed on, but it has never reported to Sophos Central (not listed when I search, I even got the computers unique ID and put that into the 'https://cloud.sophos.com/manage/devices/computers/UNIQUE_id_HERE/summary'  URL, but it only shows a blank page. )

I checked the logs at \programdata\sophos\management communication system\endpoint\logs\, and the logs show some warnings like the below, but that's from the 14th so it is like sophos isn't trying to check in?

2019-12-14T20:54:12.833Z [ 3732] WARN  The flags file 'C:\ProgramData\Sophos\Management Communications System\Endpoint\Persist\centralFlags.json' could not be opened.

 

Anyone know what else I should check?  I tried to uninstall to just reinstall and hope that would fix it, but i can't get around tamper protection as there is no entry to provide a password. 



This thread was automatically locked due to age.
Parents
  • Hi S Carter,

     

       If the machine was accidentally removed from central, you should be able to find the last known Tamper Protection password here:

    Central.Sophos.com>Logs&Reports>Recover Tamper Protection Password.


    If not, you will need to boot the machine to safemode to disable Tamper Protection: https://community.sophos.com/kb/en-us/124377

    Once Tamper Protection has been disabled, you need only run the installer through command line as per the following steps:
    1. Turn off TP
    2. Download installer from correct Central instance
    3. Run:  SophosSetup.exe --registeronly
    4. Turn on TP
    The above steps will cause the machine to register itself with Central.

    Once you see the machine in Central again, please let me know if this also resolves the Management Communication 401 error you are seeing.

     

    ZGV
    Community Support Engineer | Sophos Technical Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link
Reply
  • Hi S Carter,

     

       If the machine was accidentally removed from central, you should be able to find the last known Tamper Protection password here:

    Central.Sophos.com>Logs&Reports>Recover Tamper Protection Password.


    If not, you will need to boot the machine to safemode to disable Tamper Protection: https://community.sophos.com/kb/en-us/124377

    Once Tamper Protection has been disabled, you need only run the installer through command line as per the following steps:
    1. Turn off TP
    2. Download installer from correct Central instance
    3. Run:  SophosSetup.exe --registeronly
    4. Turn on TP
    The above steps will cause the machine to register itself with Central.

    Once you see the machine in Central again, please let me know if this also resolves the Management Communication 401 error you are seeing.

     

    ZGV
    Community Support Engineer | Sophos Technical Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link
Children