Skip to content
Last update: 2022-06-28

Alerts for Installation, Updating and Compliance

These are the alerts for Installation, Updating and Compliance.

There are the following types of alerts for issues that affect installation of Sophos agents, updating of Sophos agents, or policy compliance:


Alert type Description
Failed to protect computer or server A computer has started installation of the agent software but has not become protected for one hour. The installer that has been run on the affected computer may provide more information about the reason of the failure.


Alert type Description
Computer or server out of date A computer that has not been updated in the last 24 hours has been communicating with Sophos Central in the last 6 hours, and did not update in the following 2 hours. Normally, a computer will attempt to update about 5 minutes after it has been started, and then regularly every 60 minutes. If re-applying the policy fails repeatedly, it may be due to a more serious problem. In those cases, re-installation may solve the problem.
Policy non-compliance A device may not comply with a policy for various reasons, for example because the settings have been changed on the device itself. In that case, after two hours of non-compliance, the system will raise an alert and will try to re-apply the corresponding policy. When the device is back in compliance, the alert will be automatically cleared. If re-applying fails repeatedly, it may be due to a more serious problem. In those cases, re-installation may solve the problem.
Peripheral detected A removable media or peripheral device has been detected on a device monitored by Sophos Central.
Duplicate device detection A duplicate device has been detected. If devices have been cloned from an image they have the same ID. Duplicate IDs can cause management issues. Duplicate devices are re-registered with a new ID.

Note the following:

  • Computers running Windows XP/Vista or Server 2003/2008 are not detected as duplicates. However, if they have the same ID as the one running a supported OS (for example Windows 10), they are detected as duplicates but not re-registered.
  • Any Windows servers with the server lockdown product installed and locked are not re-registered if they are detected as duplicates.
  • We don't support duplicate device detection on VDI style environments such as VMware Horizon or Citrix PVS or Citrix MCS.
Back to top