We have Sophos Enterprise running with an excess of 1000 client machines.
I have noticed over time that the number of client systems with errors updating increases, and after troubleshooting a few, I believe I have narrowed down why this is happening:
From time to time, Sophos updates client AV software. This is essentially performing an unattended uninstall and reinstall of one or more of the client software components.
The uninstall uses MSIEXEC. For whatever reason, each time these updates are performed, some subset of computers do not get updated properly, and wind up unprotected.
The most recent PC that I worked on showed all three components installed, with Antivirus being installed on 6/15. I found that the SophosAdministrator group was empty. Up until a week ago, the system was keeping up-to-date just fine. After I added the logged on user to SophosAdministrator group, I could uninstall 2/3 components, but I could not uninstall Sophos Anti-virus.
I used Microsoft's web-based MSI clean up utility, which successfully removed AV, and after that, I was able to successfully deploy AV, and the system downloaded updates.
I have been using Sophos Enterprise for two years, and these problems seem to be much more frequent lately. I believe that behind-the-scenes, Sophos has been more frequently updating Client software components.
What I would like is the following:
#1. Notification when any software components are being updated, and the ability to deploy in test groups, or to opt-out (IE, right to approve software install, just like any other software vendor). Also, if the update will require a reboot to complete, I *need* to know this first, before I approve any software.
#2. A concise AV troubleshooting guide that covers common AV client issues. I have been writing my own for my helpdesk, but really, this should be part of documentation provided by Sophos. The KB is far too scattered. If I google "Sophos won't update", there are more than a half-million hits (many of them look similar to the issues I'm seeing)- yet if I search Sophos support with the same search term, I get 29 results, none of which look even remotely helpful.
#3. When software updates occur, I want a report from the Sophos Console of the status of the update. I want a view that allows me to see which version of client AV software is on each client PC, when the update was attempted, and why the update failed. Also, please update your KB with information from error codes that my helpdesk workers can use to systematically troubleshoot failing Updates.
This thread was automatically locked due to age.