What is our primary use case?
Sophos handles the security through AI-Synchronized Security AI Deep Learning/Security Heart Beat, DLP, Easy Enrollment (DEP, KME, Google Zero Touch), App management, VPN per App, iOS, Android, Windows 10 clients, and Mac. It is easy to set up, enroll users, and manage.
The Secure Workspace (GDPR Compliance / separation of corporate data from personal data) / (container with corporate apps like secure e-mail, calendar, contact persons, and corporate browser etc.) is easy to manage. It takes only a few minutes to get started. With the "instant action" and support for TeamViewer, mobile support has never been easier.
How has it helped my organization?
The central admin helps us to save resources and add more time to other projects. The administration of mobile devices has been reduced by thirty-five hours per week, and we only have to focus on deviation/alerts. Sophos handles all of the security, cleaning up automatically, and sending alerts. There is no need for awareness while Sophos is in control. We can even upload our corporate apps into the Sophos MDM/MAM/EMM/EEM.
What is most valuable?
The management and enrollment process is great, and with the asset management and instant action menu, we can easily maintain and support the users.
As a corporate manager, we now have corporate ownership of all devices and can easily distribute profiles, apps, documents, and compliance rules. The user interface is very logical and easy to work with.
The most important feature for us is that Sophos Mobile Device Management is a part of the Sophos concept of Synchronized Security / Intercept-X. It handles Firewalls, Wi-Fi, Servers, virtual servers, Unix, Linux, cloud, endpoints+EDR (PC and Mac), Web Gateway, E-mail gateway, and DLP (Data loss protection) / CryptoGuard (Military standards). It also supports integration with corporate AD, SIEM solution, with the best AV and Ransomware defender on the market. It provides Asset Management, Reporting, alerts, subscription, dashboard, a fantastic Root Cause analysis tool, Application control, Sandboxing, Patch Management, and even a Phishing module. It is even possible to design and automate Phishing campaigns for educating users.
With Easy Enrollment through "Apple" ABM/DEP, Samsung KME and Google Zero Touch which covers all smart-phone brands, we are not spending time on enrollment or setting up the smart-phones (Security, Apps, Documents, VPN, O365, Mail) or secure workbrowser.
The ROI has been calculated to more than 500% / less 12 months pay-back - AND additionally saved time on reporting and documentation by using the reporting and asset management.
What needs improvement?
We are looking forward to additional Patch Management, which has been announced for release in Q3-2020.
We would like to see graphics showing the use of each device. It would also be helpful to have a tool for designing mobile device screens, and a tool for handling which numbers the users are allowed to use.
Otherwise, we have everything we need.
For how long have I used the solution?
What do I think about the stability of the solution?
As it is running on Sophos Cloud (AWS), the performance is outstanding.
What do I think about the scalability of the solution?
Sophos MDM can handle everything from five users up to ten thousand.
How are customer service and technical support?
We have had no need for technical support as we have prepared the project. We did, however, spend some time with the vendor while setting up the firewall for App-VPN. We have no complaints.
Which solution did I use previously and why did I switch?
We did not use another solution prior to this one.
How was the initial setup?
Within thirty minutes we had the first ten users enrolled (including corporate Apple setup, corporate Knox setup, AD-integration, and Corporate TeamViewer-setup). Once you have made DEP and KME integration, the enrollment process runs automatically. As an admin, you are saving a LOT of time with no more phone setup, enrollment, etc. As all iOS devices has to be "managed" / Supervised we have made automation in all the Supervised processes and compliance rules.
What about the implementation team?
We created an internal team for understanding, implementing, and managing Sophos. This included the setup process, defining compliance rules, and deciding which apps and profiles we would use. Once we were comfortable, we started the process.
What was our ROI?
We have made a ROI calculation with all aspects of the mobile handling, administration and security which surprisingly is above 500% and a payback within the first year by (>300%). With these numbers nobody can afford NOT to invest in Sophos MDM. (Calculations are available on request).
What's my experience with pricing, setup cost, and licensing?
In Sophos, a user can have more devices (Laptop, PC, Mac, iPad, iPhone, Android, and even Chromebook), but you only have to pay for the numbers of users.
Which other solutions did I evaluate?
We have been evaluating Microsoft Intune and IBM Maas360.
What other advice do I have?
The Synchronized Security / Sophos Central provides ONE platform for management of Firewall, Wifi, Servers, Endpoints, Unified Mobile Devices (some using ONE App only and some are enrolled in Apple DEP / ABM with company specific policies (blueprints). Some have been enrolled in Samsung KNOX and we are working on the Google Zero-Touch Enrollment program+ Windows-10 / Office 365), Cloud (Azure) and AWS, Encryption and have the best anti-ransomware engine on the market (Intercept-X). Additionally you have a Threat Analysis Center from where you will have a perfect overview if the company should be under attack both from the outside and from the inside of the network. We have optimized our SD WAN (Sophos XG Firewall). By taking advantage of the Sophos cloud platform, the device asset-management and integration with the company Active Directory makes it easy to enroll all kind of users and on the same time, we have a perfect overview of all devices, where they are, who are using them and even serial numbers etc. for each device.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer: Customer, user and partner
Sophos do have GPS locator and integration with Google Maps. In the General setup under [Mobile], [Setup], [General] and [Privacy], you can switch Global locations for Smart Phones on and off as a global parameter.