We review products independently, but we may earn commissions if you make a purchase using affiliate links on our website. Also note that we are not antivirus software; we only provide information about some products.

Independent scan guide · Windows and macOS behavior rechecked August 5, 2026

Sophos Home Scans, Quarantine and Exclusions

A scan is the easy part. The hard part is choosing the right depth, knowing why a scheduled job was missed and refusing to restore a familiar-looking file before its publisher, source and detection context have been checked.

Fast / Full / TargetedWindows + MacVerify before restoreExclude narrowly

Quick answer: use Fast Scan for a routine system check, Full Scan after suspected infection or cleanup, and a right-click targeted scan for one download, folder or external drive. Schedule scans only when the computer will be online, awake and—on a laptop—charging. When Sophos detects something, preserve its name, path and time. Delete or clean confirmed threats; submit uncertain samples; use Allow and Restore only for a file confirmed safe. If an exception is still required, exclude the exact file or smallest folder, never a broad drive for convenience.

Choose the scan by the question you need answered

A Fast Scan asks whether common system areas and integrity points contain an obvious threat. A Full Scan asks the slower question across every folder and file. A targeted scan asks about one download, folder, volume or USB drive. A scheduled scan is not a fifth detection engine; it is a timed way to run a recurring check when the endpoint is available.

NeedBest starting scanWhy
Routine health checkFastFocuses on system integrity and likely locations
Suspected infection or post-cleanupFullInspects all folders and files
New download, folder or USBTargetedChecks the item without waiting for the whole computer
Regular household maintenanceScheduledRuns at a chosen time if the endpoint is available
Unclear detection sourceFull plus targeted follow-upChecks the system, then the exact path or external source

Do not measure scan quality only by duration or file count. A short targeted scan can be the right answer for a newly downloaded installer, while a long Full Scan can still miss encrypted archives it cannot inspect or files introduced after completion. Match the job, preserve the result and keep real-time protection enabled around it.

Real-time protection does the continuous work

Both current Windows and Mac scan articles start with the same boundary: Sophos Home’s real-time layers detect and stop threats as they try to access the computer. Manual scans are additional checks when infection is suspected, a threat was cleared, an external drive arrives or the owner needs assurance about a particular item.

That means a daily Full Scan is not a replacement for healthy real-time protection, current definitions and a protected operating system. If the shield is vulnerable, services have failed or macOS permissions are incomplete, fix that state first. A completed scan cannot compensate for an endpoint that stops inspecting files five minutes later.

The separate Sophos Home setup guide owns service and permission verification. This page assumes the correct account owns the computer and protection is green before the scan begins.

Use Fast Scan for a quick system-integrity check

On Windows, the local Scan Computer button starts a Fast Scan unless the Full option is chosen from its arrow. Sophos describes it as inspecting system files with a focus on integrity. The dashboard Scan button is also documented as a Fast Scan for Windows. It is a sensible first check after an ordinary warning or for routine maintenance.

On Mac, the default Fast Scan checks a defined set of system and user locations, including launch agents, startup items, temporary areas, Applications, Desktop, Documents and Downloads. The current Mac Fast Scan guide explicitly says it does not scan disk images, ZIP files or other archives. If the suspicious item is an archive or mounted disk image, do not treat a clean Fast result as an answer about that item.

Fast is also useful after resolving a low-confidence alert, but it should not become a ritual button pressed until the warning disappears. Read the exact detection, path and action first. A scan result without the context of what Sophos already blocked is incomplete evidence.

Use Full Scan after exposure, cleanup or an unclear detection

A Full Scan inspects all folders and files and can take substantially longer as storage grows. The official Windows scan guide and Mac Full Scan guide recommend it when infection is suspected or a threat was recently cleared.

Before starting, finish updates, connect to power, close disk-heavy work and note any external volumes. Sophos advises removing external drives from a full-system run and scanning them separately with the targeted route. That keeps the system result interpretable and avoids turning a removable archive into hours of unexpected work.

After completion, review the summary and selected computer’s activity. “No threats found” means the scan found nothing within its scope with the detection content available at that time. It does not prove every URL, password, cloud account or encrypted container is safe.

Dashboard and local scans have different strengths

A dashboard request is useful when the family administrator is away from the endpoint. Select the right computer and choose Scan. The offline reminder is static: it warns that an offline device will begin when it returns, not that Sophos has just decided the computer is offline. An online endpoint should start after a short delay and report completion under New Activity.

The local app is better when the person needs to choose Fast versus Full precisely and watch progress. A Mac local scan can run without an internet connection, although Sophos recommends connecting so current detection content is available. A dashboard-triggered Mac scan requires the internet because the command and processing involve the cloud console.

Use our dashboard and device guide when the command reaches the wrong computer, the endpoint is missing or history remains stale. Repeatedly pressing Scan is not a repair for broken account ownership.

Run Fast, Full or targeted scans on Windows 11

Double-click the Sophos Home shield in the system tray. Click Scan Computer for Fast, or use the adjacent arrow to reveal Full Scan. Keep the progress window open long enough to identify whether the job starts, advances and completes. If UAC appears during a targeted scan, verify that the action followed your own right-click on the intended item.

For one file, folder, drive or the whole PC, open File Explorer and right-click the item. Windows 11 can hide Scan with Sophos Home under Show more options; Shift-right-click can reveal the classic context menu. This is the practical route for a downloaded installer before execution and for a USB drive before browsing its contents.

Do not open the suspicious file first to see whether it “works.” Scan the unopened item, preserve its source URL and compare its publisher and digital signature. A clean targeted result is useful, but a file arriving through an unexpected message still deserves contextual skepticism.

Run Fast, Full or targeted scans on Mac

Click the Sophos Home shield in the menu bar, open the three-dot menu and choose Scan. Start the default Fast Scan, or tick Run Full Scan before starting when the whole system needs inspection. The shield animation and completion summary provide local confirmation rather than relying only on a delayed dashboard event.

For one item, Control-click or right-click it in Finder and choose Scan with Sophos Home. Depending on Finder context, the command can appear under Services. Sophos’ targeted Mac scan guide also suggests choosing Show in Enclosing Folder when the service is not visible.

Full Disk Access and the expected Sophos extensions still matter. If a scan cannot see protected locations because setup remains incomplete, changing from Fast to Full does not solve the permission boundary. Clear Action Required and restart before trusting the result.

Scan USB and external drives explicitly

Connect the drive without launching its programs, then use the right-click or Control-click scan on the drive itself. One real r/sophos USB discussion reports that the targeted route detected an EICAR test item on removable media; that is directional experience consistent with Sophos’ official targeted-scan instructions.

If the drive contains backups, virtual machines or millions of small files, expect a long run and keep normal work separate. Do not create an entire-drive exception merely because scans are slow. Decide whether the drive needs active inspection, a narrow project-folder exception or a different offline archive workflow.

Disconnect the drive before cleaning a compromised computer when it is not part of the investigation. Malware and ransomware can touch mounted removable or network storage, and a second clean machine should not browse an exposed drive until it has been scanned safely.

Scheduled scans run only when the computer is available

In Home Dashboard, select the computer, open Protection → General → Scheduled scan, enable the slider and choose a day and time. Sophos’ current Getting Started guidance adds three practical conditions: the device must be connected to the internet, awake and, for a laptop, connected to its charger.

If any condition fails, the scheduled scan does not wake the computer or immediately catch up when the lid opens. Sophos attempts it on the next scheduled day and time. This is why an old community question about sleeping devices remains useful: the owner must schedule for a period when the endpoint is genuinely on, not merely present in the house.

Check dashboard completion rather than assuming the calendar saved successfully. For a family laptop, choose a recurring plugged-in window and avoid the busiest work hour. Real-time protection is continuous; scheduling should add assurance without making the machine unpleasant to use.

Read the completion result before starting another scan

Record the scan type, start and finish time, computer, result and any detection names. A dashboard event can lag behind the local app, while a remote command can wait for an offline device. Compare both before declaring a stuck scan or launching multiple overlapping jobs.

When a result contains a detection, stop treating the job as a performance test. Open the event under New Activity or History and preserve the name, full path, time, detection class and action Sophos already took. That evidence determines whether the next step is cleanup, manual deletion, sample submission or a narrowly justified restore.

Detection type controls the available action

Sophos Home can report conventional malware, Machine Learning detections, PUAs, malicious traffic and ransomware behavior. These are not interchangeable quarantine objects. A PUA may be blocked but left for the owner to allow or delete. A Mac PUA prompt can offer Always Allow, Clean or Ignore. A Windows ML event can expose Allow and Restore under advanced options.

Ignore means the alert is cleared without excluding or deleting the PUA; Sophos says it can appear again when the program relaunches. Clean deletes the application when cleanup is possible. Always Allow opens the dashboard to create the relevant exclusion. A ransomware or malicious-traffic alert has a broader behavioral context and should not be reduced to “I recognize the executable.”

Use the visible action wording for that device and event. Do not follow a generic third-party “open quarantine and restore” article when the current Sophos event says manual cleanup or shows a feature-specific exclusion path.

Keep the item isolated until evidence supports a decision

Start with the detection as potentially malicious. Record what Sophos saw before deleting the event or moving files. Verify where the file came from, whether the publisher and signature are expected, whether its hash matches the vendor and whether other suspicious events appeared at the same time. A legitimate application name can be abused through injection or a trojanized installer.

Sophos Home detection verification, cleanup, restore and narrow exclusion decision map
Editorial decision map, not product UI: recognition is not verification, and an exception comes last.

If the file is unwanted or clearly malicious, clean or delete it and remove the source that can recreate it. If evidence conflicts, keep it isolated and submit it. Only a confirmed clean business, game or accessibility tool should move to Allow and Restore, and even then the exception should be as narrow as the software permits.

Verify a possible false positive without turning off protection

The current Sophos sample-review guide directs Home users to Intelix in Guest mode; Home credentials do not work there. Direct web submission accepts files up to 25 MB, and a larger sample can be represented by an official-vendor download link. Include the detection, source and observed behavior.

VirusTotal can add multi-engine context, but it is an indicator, not a verdict. A large group of reputable detections is strong evidence against restore; a handful can be a new threat or a false positive; zero detections can still mean a unique or zero-day sample. Do not upload confidential documents or proprietary binaries to public multi-engine services without authorization.

Sophos says Labs reviews submissions without creating a conversational support ticket and advises allowing 15 days before checking the verdict again in Intelix. Preserve the original hash so you know the later verdict refers to the same file.

Use Allow and Restore only for a confirmed safe file

For a Windows Machine Learning detection, select the affected computer, find the ML event in New Activity or History, open advanced options and use Allow and Restore under “Did we get this wrong?” Sophos says this restores the file and reports the decision for review. Some detections can offer Restore and Allow All for multiple files from one company; that broader action deserves even more caution.

The current ML restore instructions also permit temporarily disabling Machine Learning for testing, but explicitly warn that protection is reduced. Prefer an isolated test environment and a verified allow decision. If temporary disabling is unavoidable, time-box it, disconnect unneeded data and turn the layer back on immediately.

For PUAs, the owner is deciding whether the application’s advertising, bundling, privacy or user-experience behavior is acceptable—not merely whether it is a classic virus. The current PUA guide distinguishes Windows Allow and Restore from Mac Always Allow, Clean and Ignore.

Create the smallest exception that solves the verified problem

In Dashboard, select the computer and open Protection → General → Exceptions. The official scan-exception guide says files, folders, websites or applications placed there will not be checked by the relevant antivirus scanner. Folder exceptions include subfolders, so a parent directory can create a much larger blind spot than its label suggests.

On Windows, folder paths end in a backslash: C:\TrustedTool\. A specific file can use its full path, and a drive example ends in D:\. On Mac, folder and volume paths end in a slash and are case-sensitive, such as /Applications/TrustedTool.app or /Volumes/ProjectDrive/. Copy the actual path instead of improvising punctuation.

Feature-specific detections can need feature-specific exclusions. Malicious traffic, exploits, ransomware and Machine Learning do not all obey one universal list. Record why the exception exists, who approved it and when it should be reviewed. Remove it after the vendor fixes the conflict.

Mac exceptions do not bypass Full or on-demand scans

This is the most important platform difference in the current Sophos exception article: macOS exceptions apply only to on-access scanning, not Full Scan or on-demand scans. A file can therefore be allowed during ordinary access and still be detected when the owner explicitly scans its folder or the whole Mac.

Do not keep broadening the path because the Full Scan still reports it. Verify the sample and choose the appropriate action for that on-demand result. Mac paths are case-sensitive, and a missing trailing slash can change whether Sophos interprets the entry as a folder or file.

Find what recreates a repeating PUA or file

Sophos lists application updates, cloud synchronization and backup restoration as common reasons a PUA returns after the alert is cleared. Match the recreated path and timestamp to OneDrive, Dropbox, Google Drive, a software updater or a backup job. Ignoring the alert only removes the current prompt; it does not stop that source.

Pause the relevant synchronization for the exact item, verify whether the parent program is wanted and either remove it cleanly or allow the confirmed application. Do not exclude the entire sync root. That would hide unrelated files arriving from every connected device.

Troubleshoot a stuck or missing scan without disabling the suite

First decide whether the scan is actually stuck. Compare local progress with dashboard activity, allow for an offline remote command and check whether another disk-heavy task is running. Restart a supported endpoint after updates, confirm the shield is protected and retry one local Fast Scan before reinstalling anything.

Sophos’ current known-issues page documents a Mac case where right-click scanning an empty folder leaves the shield animation stuck. The workaround is to quit the Sophos Home UI through Activity Monitor; it is not evidence that the endpoint engine scanned forever. On Windows, a service failure or competing antivirus belongs to a broader health repair, not an exception.

Escalate with OS version, Sophos status, scan type, target, start time, last progress, detection name and whether the computer was online, awake and charging. Do not paste registry commands from a Central or enterprise thread into Sophos Home merely because both products use the same company name.

Sophos Home scans and exclusions FAQ

Should I run a Fast Scan or Full Scan in Sophos Home?

Use Fast Scan for a quick system-integrity check and routine follow-up. Use Full Scan after a suspected infection, after cleanup, when a detection source is unclear or before trusting a previously exposed computer. Full Scan inspects all folders and files and can take much longer. On Mac, Fast Scan skips disk images, ZIP files and other archives, so choose Full or a targeted scan when those are the concern.

Can I scan one file, folder or USB drive with Sophos Home?

Yes. On Windows, right-click the file, folder, This PC or drive and choose Scan with Sophos Home; Windows 11 may hide it under Show more options, and Shift-right-click can expose the classic menu. On Mac, Control-click or right-click the item and choose Scan with Sophos Home, sometimes under Services. Scan external drives explicitly rather than making every full scan include them.

Does the Sophos Home dashboard run a Fast or Full Scan?

Sophos currently describes the dashboard Scan button on Windows as a Fast Scan. The current Mac full-scan article describes a dashboard-triggered scan in its full-scan flow. For precise choice and visible progress, open the local Sophos Home app: Windows exposes Fast and Full from the Scan Computer control, while Mac exposes Run Full Scan as a selectable option.

Why did my scheduled Sophos Home scan not run?

The computer must be online, connected to the internet and awake at the scheduled time. Sophos also says a laptop must be connected to its charger. If it is offline, asleep or on battery, the scan is not backfilled immediately; Sophos tries again at the next scheduled day and time. Completion then appears in the Home dashboard.

Where is Sophos Home quarantine?

Sophos Home presents detections through the local notification and the selected computer’s New Activity or History view rather than one universal vault workflow. The available action depends on whether the event is malware, Machine Learning, a PUA, malicious traffic or ransomware. Preserve the detection name, path and time before choosing Clean, Delete, Ignore, Allow and Restore or an exclusion.

Is Allow and Restore safe in Sophos Home?

Only after the file is independently confirmed safe. For Windows Machine Learning and some PUA detections, Allow and Restore returns the file and creates an allow decision; it can also report the case to Sophos. Recognition, a familiar filename or one clean scanner result is not enough. Verify the official publisher, digital signature, source and hash, then use Intelix or submit a sample when uncertainty remains.

How do I report a Sophos Home false positive?

Check the file or URL with Sophos Intelix in Guest mode; Sophos Home credentials do not work there. For a formal review, use Sophos’ sample submission route and include the detection, source and observed behavior. Sophos says direct web submissions accept files up to 25 MB and advises allowing 15 days before rechecking the verdict in Intelix.

How do I add a file or folder exception?

In Home Dashboard, select the affected computer and open Protection, General, Exceptions. Enter the exact file or smallest necessary folder. Windows folder paths end in a backslash; Mac folder paths end in a slash and are case-sensitive. Folder exceptions include subfolders, so excluding a broad parent folder or entire drive creates a much larger blind spot.

Do Sophos Home exclusions work the same on Mac and Windows?

No. Sophos says Mac exceptions apply to on-access scanning only, not Full Scan or on-demand scans. Mac paths are also case-sensitive. Windows supports file, folder, type and drive examples in the normal scan-exception field, although feature-specific detections such as exploits, Machine Learning and malicious traffic can require their own narrower route.

Why does the same PUA keep returning?

The detected file may be recreated by an application update, synchronized back from OneDrive, Dropbox or Google Drive, or restored by backup software. Clearing or ignoring the alert does not remove that source. Identify what recreated the exact path, verify whether the program is wanted, then either remove it and its source or allow the confirmed application deliberately.

Bottom line: scanning ends with a decision, not a progress bar

Fast, Full, targeted and scheduled scans answer different questions. Pick the smallest scan that answers today’s question, then move to Full when exposure or cleanup makes broader coverage necessary. Keep scheduled endpoints online, awake and charging, and verify completion rather than trusting the calendar alone.

A detection is the start of triage. Preserve evidence, verify publisher and source, use Intelix or sample submission when uncertain, clean confirmed threats and restore only confirmed false positives. Exceptions come last and stay narrow. That sequence protects the computer without turning one inconvenient alert into a permanent blind spot.