If a Users disables the Clients On-Access Scanning or the Sophos Service it´s not possible to enforce the Policy to the Clients. The only choice given by the WUI is the re-deploy the Agent? I´ve been missing a "enforce policy automatically" checkbox or even a Button to manually enforce the policy.