That's probably the issue. I'll test with our imaging process with disabling the Sophos services until after the join to AD is completed. We definitely need to keep Sophos on the image given the number of endpoints we have and only one SEC.
↧