How to Uninstall Sophos Home Completely
A complete removal is not a race to delete every file named Sophos. It is an ordered handoff: identify the product, use its signed uninstaller, restart, prove the local agent is gone, clear the correct dashboard record and confirm that one protection provider is active.

First confirm whether this is Sophos Home or a managed business product
The name “Sophos” covers consumer software, employer-managed endpoint agents, school deployments, network products and separate tools. Their removal rights are not interchangeable. Sophos Home is tied to a personal Home dashboard at my.sophos.com. A work or school computer may instead be enrolled in Sophos Central, where the organization owns policy and Tamper Protection.
The fastest discriminator is the password behavior. Sophos’s current Home Tamper Protection article says the consumer product does not use a separate Tamper Protection password. Home asks for the local Windows administrator password or PIN when an authorized setting change needs elevation. If removal asks for a distinct tamper password, especially on a former work, school or second-hand computer, stop: you are probably dealing with a managed product.
Do not apply Home cleanup scripts to a business agent and do not try to bypass a legitimate policy. Contact the organization that provisioned the computer or the seller who transferred it. Current community threads often called “impossible Sophos uninstall” turn out to be this ownership problem, not a broken Home uninstaller. A factory recovery may ultimately be appropriate for an abandoned managed device, but only after data ownership and recovery media are settled.

Uninstall, device removal and subscription cancellation solve different problems
A local uninstall removes protection from one computer. Removing that computer in the Home dashboard frees a device slot but, according to the official device-removal article, does not uninstall the software still running on the machine. Turning off renewal changes the future Cleverbridge charge, while deleting the Home account is a separate irreversible step.
Decide the outcome before touching the app. If the computer is being retired, uninstall locally and verify the dashboard slot. If you are troubleshooting, preserve the account and plan a clean reinstall. If you are leaving Sophos entirely, handle every protected family computer, billing and account evidence separately. Our complete Sophos Home review owns the product decision, while the cancellation and refund guide owns the financial steps; an uninstall alone never proves that auto-renewal is off.
| Goal | Correct action | What it does not change | Evidence |
|---|---|---|---|
| Remove protection from this PC or Mac | Run the official local uninstaller | Subscription billing | Agent absent after restart |
| Free one license slot | Remove the device in Home | Locally installed software | Device absent from dashboard |
| Stop the next charge | Turn off auto-renewal | Current local installation | Subscription says Expires |
| Repair a damaged installation | Uninstall, restart and reinstall | Existing entitlement | Fresh device install is healthy |
| Remove a managed endpoint | Contact its administrator | Organization policy | Admin-approved offboarding |
Prepare the handoff before removing real-time protection
Use an administrator account, save open work, install pending operating-system updates and complete any restart already waiting. Keep a stable internet connection so the online uninstaller can report its state and the Home dashboard can reconcile the device. If this is a troubleshooting reinstall, delete stale installer downloads only after you know how to retrieve a fresh installer from your account.
Choose the next protection state now. On Windows, Microsoft Defender is built in, but the handoff still needs to be checked after restart. On a Mac, decide whether you will use the operating system’s built-in security layers or install another antivirus. Do not install two real-time suites in advance “for safety”: Microsoft warns that concurrent antimalware products can slow or destabilize Windows, and security vendors commonly block one another’s drivers.
If the computer contains irreplaceable work, create a normal backup before using any advanced cleanup tool. A standard uninstaller is low-risk; a heuristic remover working around damaged components deserves more caution. Record the Home device name, operating-system version, exact error and any Sophos case number. That small evidence bundle prevents you from removing the wrong family computer or losing the one log Support needs.
Use the shortest supported route that reaches a verified result
Most installations need only the standard uninstaller and a restart. The “complete” part comes from verification, not from adding aggressive deletion steps. On Windows, Apps/Installed apps is rung one and SophosZap is the last rung. On macOS, Remove Sophos Home is rung one and the current SophosRemoval.sh script is the advanced recovery route.
Search results often reverse that order. Some Mac pages sell a cleaner before the official utility, while others publish broad Terminal commands that recursively delete Sophos paths. One prominent cross-platform guide still tells Mac readers to drag the application to Trash, directly contradicting Sophos’s July 2026 instructions. Those shortcuts can remove the very components the signed uninstaller needs, leave system extensions behind or catch unrelated files. We do not reproduce them.
Follow this rule throughout the guide: if a standard step succeeds, restart and verify; do not “clean” a healthy result. If it fails, capture the exact message, correct the documented cause and retry once. Only then use the vendor’s current platform-specific cleanup tool. Never download an old binary or script from a forum mirror.
Uninstall Sophos Home normally on Windows 11 or Windows 10
Sign in with a Windows administrator account. Open Start, type programs, and select the result that opens Installed apps or Apps & features. Find Sophos Home, open its menu and choose Uninstall. Approve the Windows elevation prompt and let the signed Sophos remover finish; do not end its services in Task Manager while it is working.
The Sophos Home Windows uninstall guide updated July 9, 2026 treats the restart and dashboard state as part of the removal. Keep the computer online if practical. When the remover completes, restart Windows even if the desktop appears normal. Security drivers and Windows Security provider registration can remain loaded until that reboot.
After signing back in, do not immediately run a registry cleaner or delete ProgramData folders. First check Installed apps, the notification area and the Home dashboard. If the ordinary removal completed and the protection handoff is correct, you are done. Leftover text in an old log or browser history does not mean an active antivirus engine remains.
If Windows says a reboot is required, restart before trying again
A repeated “restart required” message feels like a loop, but the first response should remain simple. Close the uninstaller, use Windows Start → Power → Restart rather than Shut down, sign back into the same administrator account, wait for the desktop and services to settle, then open Installed apps and run the Sophos Home uninstall again.
Restart matters because Windows Fast Startup can preserve part of a kernel session after a normal shutdown. The official Sophos article specifically tells users who see the reboot prompt to restart and repeat the removal. Do not disable services, rename folders or launch SophosZap before completing this clean restart attempt; those actions can convert a recoverable pending operation into a partial installation.
If the prompt returns after a real restart, record it and check for pending Windows updates, another antivirus installer, or a previously used third-party uninstaller. Then move to the failure diagnosis below. A loop is evidence that the standard path did not settle, not permission to download the first “Sophos removal tool” hosted outside Sophos.
Verify Windows Security after the required restart
Open Windows Security from Start. Check Virus & threat protection and open the provider information if Windows offers it. Confirm that the intended real-time antivirus is active, then check Firewall & network protection. Microsoft’s current PC protection guidance says Defender turns off when another antimalware application takes over and warns users to make sure Defender Antivirus and Windows Firewall are enabled after removing a security program.
Do not promise yourself an invisible automatic transition. If Windows Security still names Sophos, shows no active provider or displays an action-needed state, wait for the completed restart, run Windows Update and open the provider screen again. If you are installing a different antivirus immediately, finish that vendor’s supported setup and verify it becomes the single primary provider.
Run a Windows Security quick scan only after the provider state is stable. The goal is not to stack scanners during the handoff. If Sophos still appears as active after a successful uninstaller, capture the provider screen and move to the official recovery path rather than trying to delete its registration by hand.
Check the Sophos Home dashboard and free the correct device slot
While the Windows computer was online, the standard uninstaller may remove its Home record automatically. Sign in to the dashboard, compare the displayed computer name with the one you recorded, and verify. If the stale device remains, select it and use Remove. This frees the slot and ends remote management for that record.
The direction also works the other way: remove the device in Home does not remove the program on an offline laptop. The local owner still needs to run the operating-system uninstaller. That distinction matters for family plans, where a parent may control the account but not physically hold every computer. Our Sophos Home dashboard and device guide covers account ownership, Direct Access and naming in detail.
For a reinstall, clear only the stale record for this machine and restart before downloading again. Do not remove several similarly named devices to “start fresh.” History, ownership and active protection on the other computers can be lost from view even though their local agents continue running.
Diagnose a failed Windows uninstall before using SophosZap
Sophos documents several causes: damaged or residual installation files, an interrupted earlier removal, another antivirus, a third-party uninstaller that deleted components the Sophos remover expects, permissions trouble and broader Windows corruption. An error about stopping Sophos AutoUpdate, a failed service removal or a reinstall that says Sophos is already present all point to the same question: can the signed standard remover still complete after a clean restart?
Confirm the exact product again, log into an administrator account, finish Windows updates and remove any abandoned installer running in the background. If a commercial cleanup utility was already used, do not run a second one. Retrying layers of heuristic deletion makes the installation state harder for Sophos Support to interpret. Preserve screenshots and the error text.
| Symptom | Likely boundary | Safe next action | Avoid |
|---|---|---|---|
| Restart required | Pending operation | Real Restart, then normal uninstall | Deleting services |
| Separate tamper password | Managed Endpoint, not Home | Contact the owning admin | Password bypass instructions |
| Failed to stop/update service | Damaged Home install | Capture error; official recovery article | Task-killing every Sophos process |
| Reinstall says Sophos exists | Residual components | Fresh SophosZap as last resort | Registry-cleaner scripts |
| No active AV after removal | Provider handoff incomplete | Restart; check Windows Security | Running two new suites at once |
Disable Home Tamper Protection only for a documented advanced step
Tamper Protection exists to stop malware or a standard user from changing Sophos files, folders, components and logs. It is not a routine off switch. Sophos says to disable it only during advanced troubleshooting documented by the vendor or when Support directs you. Never turn it off while you suspect the computer is actively compromised; scan and get help first.
For Sophos Home on Windows, open the local shield, choose Help → Troubleshooting and use the Tamper Protection slider while signed in as an administrator. The slider is absent for a standard account. Windows asks for the local administrator password or PIN, not a special Sophos Home tamper password. Sophos says the protection turns itself back on after four hours or when the computer restarts.
That automatic return affects the cleanup sequence. Prepare the official tool, backup and command window before changing the setting, then follow the current article without detours. If a password prompt belongs to Sophos Endpoint/Central, this paragraph does not authorize removal; return to the product-family boundary and contact the administrator.
Use SophosZap only as the official Windows last resort
Sophos describes SophosZap as a last-resort cleanup tool focused on Sophos endpoint components. It works from whatever installation information remains, so its heuristics carry more risk than the normal uninstaller. Use it only after the standard path has failed and only from the current Sophos Home Windows recovery article. Download a fresh copy; do not reuse a binary from an old support case or third-party mirror.
Create an appropriate backup and open Command Prompt as Administrator in the folder that contains the current tool. Sophos’s documented command follows.
SophosZap --confirmLet it finish and restart when prompted. Sign back in, open another Administrator Command Prompt, run the same current tool a second time, and restart again. Sophos says the second pass and second reboot are part of the procedure, not optional polishing. The tool is Windows-only and cannot disable Tamper Protection itself.
SophosZap appends a log in the current user’s %Temp% folder. Preserve that file if the second pass fails or a reinstall remains blocked. Do not follow it with generic registry removal, driver-store deletion or service commands from a forum; send the log and exact symptom to official Home Support.
After SophosZap, prove removal before installing anything else
Following the second restart, check Installed apps, the notification area and Windows Security. The absence of a Sophos shortcut alone is not proof; the provider screen is more useful because it shows whether Windows still considers Sophos the active antivirus. Confirm the firewall state and run Windows Update before introducing another suite.
Then inspect the Home dashboard. Remove the stale device only when its computer name and ownership are certain. If you intend to reinstall Sophos, do not download from an old email attachment. Use Add Device → Install in Home so the installer and entitlement are current. If you are switching vendors, follow that product’s official installation order and keep only one primary real-time engine.
If Sophos still registers after both supported Zap passes, stop. Collect the Zap log, Windows version, exact provider state, screenshots and the Sophos Home account email without exposing credentials. Repeatedly forcing the tool or deleting drivers manually is less likely to help than a support case with a complete evidence set.
Uninstall Sophos Home on Mac with Remove Sophos Home—not Trash
Press Command + Space, type Remove Sophos Home, and open the matching removal application. Choose Continue, enter the Mac administrator password when requested, approve Install Helper and let the signed utility finish. Close it and restart the Mac. This is the standard route in Sophos’s Mac uninstall article updated July 28, 2026.
Do not drag Sophos Home to Trash. The visible app is only one part of a security product that also uses privileged helpers and system components. Trashing the icon can leave an incomplete state while removing the ordinary entry point to the vendor uninstaller. Likewise, do not pre-emptively quit every process in Activity Monitor or delete files under Library because a cleaner blog labels them leftovers.
After the remover reports completion, restart before judging the result. A menu-bar icon may persist until logout or reboot, and an extension state may not settle in the current session. Once the Mac returns, verify the local signals and dashboard record described below.
If the Mac remover is missing or macOS blocks it, recover the signed path
If Spotlight cannot find Remove Sophos Home, use the download link in the current official Mac article rather than a copied script from a forum. Sophos periodically changes its supported package, and a fresh download avoids stale signing and compatibility problems. Do not install a third-party “app cleaner” merely to recreate functionality the vendor supplies.
When macOS blocks the downloaded remover, the correct override depends on the macOS generation. Sophos documents right-click → Open for older releases. On macOS 15 and newer, attempt to open the tool, then go to System Settings → Privacy & Security → Security and choose Open or Open Anyway for that specific blocked application. Apple makes the override available for a limited period after the launch attempt, so do not search for it hours later.
Authenticate the prompt, confirm that the file came from the official Sophos Home page, run the remover and restart. An “Open Anyway” control is not permission to bypass Gatekeeper for unrelated downloads. If the signature, publisher or download origin is unexpected, delete that copy and retrieve it again from Sophos.
A failed Mac removal usually points to a damaged install or permissions state
Sophos lists interrupted or corrupted installation, another antivirus, manual Trash deletion and a migrated installation as common reasons its normal remover is missing or fails. Migration Assistant can copy visible app material without reproducing the privileged installation state expected by the remover. A cleanup utility can create the same mismatch by deleting some files and leaving others.
Restart the Mac, confirm you have an administrator account, close other security installers and try the current signed remover once more. Record the exact message. If the normal path still fails, Sophos provides a Home-specific script for advanced users. Premium subscribers who are uncomfortable with Terminal should use official Home Support rather than improvising shell commands.
Do not borrow business-product removal commands. Sophos explicitly says its Home advanced script is for Sophos Home only. A corporate endpoint, Sophos Connect VPN client or organization profile follows a different owner and toolchain. Product classification remains the first step even when the computer is a Mac.
Run the fresh SophosRemoval.sh only on a confirmed Home installation
Open the current Sophos Home advanced Mac article and download a fresh SophosRemoval.sh from the official linked Sophos Community location. Place it on the Desktop. Do not reuse a script saved months earlier; Sophos tells users to delete it after the procedure and download a current copy next time.
Open Terminal from an administrator account and run the three commands Sophos currently documents:
cd ~/Desktop/
sudo chmod u+x SophosRemoval.sh
sudo ./SophosRemoval.shEnter the Mac password when sudo requests it; Terminal does not display password characters. Read the script’s prompts rather than pasting extra commands around it. When it completes, restart the Mac, remove the correct stale device from the Home dashboard and delete the script from the Desktop.
This is the deepest command sequence we reproduce because it is current, vendor-published and narrowly scoped. We intentionally omit broad rm -rf, launch-daemon deletion and whole-disk name searches promoted by third-party pages. Those commands can remove the wrong files and do not prove that macOS extension registration is clean.
Handle Terminal permissions and the removal log without leaving new exposure
If zsh reports “operation not permitted,” the official article explains that Terminal may need Full Disk Access for the documented cleanup. Open System Settings → Privacy & Security → Full Disk Access, authenticate and enable Terminal only for this recovery session. Close and reopen Terminal before retrying the current script. When the removal and verification are complete, turn off that extra access if you do not otherwise need it.
The advanced remover can write a log named like /tmp/product_removal_[timestamp].log. Keep the newest relevant file if the script fails or Sophos Support asks for it. Review screenshots and filenames before sharing; logs can contain device paths or account context even when they do not contain passwords. Use the official Sophos upload route and case submission ID, not a public forum attachment.
If the script says the product is not Sophos Home, or if an organization profile reinstalls Sophos after restart, stop. The problem has crossed from consumer cleanup into device management. Do not grant more privacy permissions or disable macOS security controls in an attempt to defeat that management.
Treat system-extension and SIP cleanup as an exceptional support path
Sophos’s standard Mac article contains an optional system-extension removal route that involves macOS Recovery and System Integrity Protection. It explicitly says this is optional and is not required for a normal uninstall. That makes it inappropriate as a generic “complete removal” checklist. Disabling SIP changes a core macOS security boundary and should not be the next step merely because a filename appears in a search.
First restart and verify whether any active Sophos system extension is actually present. If the signed remover and advanced Home script completed but macOS still reports a Sophos extension, use the current official article or open a Support case for the exact OS version. Apple Silicon and Intel Recovery entry differs, and macOS releases change extension controls; copied commands age badly.
If Support directs you through Recovery, follow that article exactly and re-enable SIP immediately after the documented operation. We do not reproduce the commands here because casual readers are more likely to weaken the Mac than improve an already successful uninstall. A complete result is an inactive product and healthy protection state, not the absence of every historical log string.
Verify the Mac result after restart instead of hunting every Sophos string
After the restart, confirm that Sophos Home and Remove Sophos Home are no longer active, the Sophos shield does not return to the menu bar, and no Sophos permission prompt appears during normal use. Check System Settings only for active extensions, login items or profiles that affect the current machine. A support log, browser bookmark or inert receipt does not constitute a running security agent.
Sign in to Home and verify whether the Mac device was removed automatically. If it remains, remove the matching record to free its slot. Do not confuse a dashboard card with local installation: an offline Mac can retain software after its account record disappears, and a locally removed Mac can leave a stale card until the account is reconciled.
If you plan to rely on macOS built-in protections, complete system updates and keep Gatekeeper and the normal security settings enabled. If you plan another antivirus, install it only after the Sophos restart and verify its required extensions and Full Disk Access. Our current Mac antivirus guide compares replacement choices without turning this repair page into a sales detour.
Reinstall Sophos Home with a fresh dashboard download
For a repair reinstall, do not stop at “Sophos disappeared.” The current Sophos reinstall guide says to complete the removal and restart first. Make sure the operating system is supported and updated, remove conflicting third-party antivirus software and delete stale SophosInstaller downloads.
Sign in to Home, choose Add Device and then Install. Download and run the fresh installer. Sophos says no new license key is required after the initial activation; entitlement follows the Home account. On macOS, approve only the current permissions requested by the installed version. On Windows, let the provider registration settle before judging Windows Security.
Verify the new device record, protection controls and update state. If the reinstall was intended to fix excessive CPU, update errors or a vulnerable status, reproduce the original condition only after the baseline is green. Our Sophos Home setup guide covers the clean install, while the not-working and high-CPU guide owns fault isolation.
Switch to another antivirus without overlapping two real-time engines
Download the replacement from its official site, but wait to install until the Sophos removal and restart are complete unless that vendor explicitly documents a handoff tool. On Windows, check the Security provider screen before and after installation. On Mac, grant extensions and disk permissions only to the product you deliberately chose, then verify Sophos does not return.
If you have not chosen a replacement, keep the device online only long enough to update and verify the built-in protection state. Our Windows 11 antivirus guide, Windows 10 guide and Sophos Home for Mac review organize current platform context. The dedicated Sophos Home alternatives comparison will own like-for-like migration decisions when its own research and QA are complete.
Do not uninstall Sophos across every family computer at once if you cannot verify them. Move one device through remove → restart → protection check → dashboard check, then continue. That sequence limits the blast radius of a bad credential, stale installer or unexpected managed device.
Close billing separately because uninstalling never cancels renewal
The local remover has no authority over the Cleverbridge order. If you are leaving Sophos, sign in to Home, open My Account and inspect the subscription label. Renews means automatic renewal is on; Expires means it is off for the next term. Save the status and date. Do not delete the Home account before billing and device evidence are settled.
A refund is another separate request and can deactivate the associated license when completed. That matters if other family computers still use the entitlement. Use our cancellation/refund guide for the current 30-day window, order lookup and proof sequence, then schedule local removals without creating an unplanned protection gap.
Likewise, removing the device card only frees a slot. Sophos says the software on that machine continues until locally uninstalled. Keep these layers distinct: money and entitlement, dashboard record, local agent, replacement protection and finally account deletion. “I deleted the app” is evidence for only one of them.
Give Sophos Support a small, useful evidence package
If a supported path still fails, collect the product name shown locally, Windows or macOS version, administrator-account status, exact error text, time of the failure and the Home account email. Add the SophosZap log from %Temp% or the newest Mac product-removal log when applicable. State which standard and advanced steps completed and how many restarts occurred.
Use the official Sophos Home web support routes. Current Home support has no consumer phone support, so phone numbers surfaced in search PDFs or pop-ups are not a shortcut. Our fake Sophos support warning explains what to do if someone already obtained remote access or payment details.
Redact passwords, full payment numbers, recovery keys and unrelated usernames. A precise error plus the right removal log is more useful than a complete desktop recording. If the product is managed, provide the device owner and organization instead of sending Home logs to the wrong support team.
Use one final proof checklist for Windows or Mac
A successful uninstall has four independent proofs: the signed remover completed, the device restarted, no active Sophos Home agent returned, and the intended protection state is healthy. Add a fifth proof if the license slot matters: the correct dashboard record is gone. Add billing proof only if leaving the subscription.
| Proof | Windows | Mac | If it fails |
|---|---|---|---|
| Local product absent | Not in Installed apps or active tray | No active app or menu-bar shield | Use the platform recovery path |
| Restart completed | Full Restart after remover/tool | Restart after remover/script | Restart before further cleanup |
| Protection active | Windows Security names intended provider | Updates/security or new AV healthy | Stabilize before normal browsing |
| Dashboard correct | Only the intended device record is removed | Compare device name and owner | |
| Billing correct | Renewal/refund handled separately | Use subscription guide | |
Do not turn the proof check into a whole-disk hunt. Security software leaves receipts, logs and browser records like other applications. The meaningful question is whether a signed component, service, system extension or dashboard-managed agent remains active—not whether the word Sophos exists anywhere.
Sophos Home uninstall FAQ
How do I completely uninstall Sophos Home on Windows 11?
Open Start, search for installed programs, select Sophos Home and choose Uninstall. If the remover asks for a restart before continuing, close it, restart Windows and run the normal uninstaller again. Restart after completion, verify Sophos is absent from Installed apps and the Home dashboard, then open Windows Security to confirm the intended antivirus provider and firewall are active.
How do I completely uninstall Sophos Home on a Mac?
Press Command-Space, search for Remove Sophos Home and open that utility. Choose Continue, authenticate with the Mac administrator password, approve Install Helper, finish and restart. Do not drag the Sophos Home application to Trash. If the remover is missing or fails, use the current official Sophos support article and its fresh Home-only removal script rather than deleting Library files yourself.
Why will Sophos Home not uninstall?
The common documented causes are a pending restart, damaged or incomplete Sophos files, another security product, a third-party uninstaller that removed required components, permissions problems or operating-system corruption. Start with a real restart and the official standard remover. Escalate to SophosZap on Windows or the official SophosRemoval.sh path on Mac only after the normal method fails.
Should I turn off Sophos Home Tamper Protection before uninstalling?
Not for every normal uninstall. Sophos says to disable Home Tamper Protection only for documented advanced troubleshooting or when Support directs it. A Windows administrator account is required, and the setting returns after four hours or a reboot. Never disable it while you suspect active malware, and do not treat a separate tamper-password prompt as a Home feature.
What if Sophos asks for a Tamper Protection password?
Sophos Home does not use a separate Tamper Protection password. That prompt strongly suggests Sophos Endpoint or another business-managed product, especially on a work, school or second-hand computer. Stop using the Home removal guide and contact the organization or administrator that owns the policy. We do not recommend bypassing a legitimate managed-security control.
Is SophosZap safe to use?
SophosZap is Sophos's official Windows cleanup tool, but Sophos describes it as a last resort because it works from incomplete installation information. Use a freshly downloaded copy from the current official support article, create an appropriate backup, run it from an Administrator Command Prompt with SophosZap --confirm, restart, run it a second time and restart again. Do not substitute old download links or registry-cleaning scripts.
Can I drag Sophos Home to Trash on Mac?
No. Sophos's current Mac removal guide explicitly says not to drag Sophos Home to Trash because that does not remove the full security product. Use the bundled Remove Sophos Home utility. If that utility is unavailable, download the current remover or advanced Home-only script through the official Sophos support page.
Does uninstalling Sophos Home cancel my subscription?
No. Local software removal, dashboard device removal, auto-renewal cancellation, a refund request and account deletion are separate actions. Uninstalling does not stop Cleverbridge billing. If you do not want the next charge, turn off auto-renewal and verify that the Sophos Home subscription says Expires; request an eligible refund separately.
Will Microsoft Defender turn on after Sophos Home is removed?
Windows includes Microsoft Defender, but do not assume the transition has completed just because Sophos disappeared. Restart, open Windows Security, inspect Virus & threat protection and Firewall & network protection, and confirm the intended provider is active. Microsoft warns against running multiple real-time antimalware apps and says to verify Defender and Windows Firewall after removing another security suite.
Can I reinstall Sophos Home after removing it?
Yes. Sophos says no new license key is needed after the initial activation. Complete the supported uninstall, restart, remove any conflicting third-party antivirus, sign in to my.sophos.com, choose Add Device and Install, and download a fresh installer. Verify the device record and protection state rather than reusing an old installer or cleanup script.
Finish when the handoff is proven, not when the icon disappears
For Windows, the best path is Installed apps, restart, Windows Security and dashboard verification. SophosZap comes only after a documented failure and requires two passes separated by restarts. For Mac, use Remove Sophos Home, restart and verify; recover the current signed remover or fresh Home-only script if the normal path is broken. Trash, app cleaners and broad deletion commands are not the supported first line.
The product-family check prevents the most serious mistake. Sophos Home does not ask for a distinct Tamper Protection password. A managed work or school agent belongs to its administrator, and a Home guide should not be used to bypass it. The billing check prevents the expensive mistake: local removal does not turn off renewal.
Once the agent is absent, the dashboard is correct and one protection provider is healthy, stop cleaning. That is a complete uninstall. Preserve the removal log only if a support or reinstall problem remains, and move the next computer through the same controlled sequence.