Have you created a configuration profile to whitelist the Sophos related
The kernel extensions can be found here
I tested out the restriction, and it did not work for us. I confirmed
the restriction was in place on the device, then went to the App Store,
and downloaded Snap VPN. Opened the app, and ran through its setup
without a problem. Going into Settings > ...
Have you tried unloading the daemons/agents with launchctl before
deleting them? In Terminal run sudo launchctl list to get a listing of,
and verify the daemons/agents that are running. In your script you
should be able to use something like:launchct...