Deploy Sophos Fusion Endpoint systematically
This guide connects the tenant, identities, licences, policies, pilot and operational acceptance without repeating the linked detailed runbooks.
Practical guidance for Sophos Fusion Endpoint operations: access, rollout, devices, protection policies, monitoring, XDR, Response and troubleshooting. Central management of BitLocker and FileVault has its own Sophos Device Encryption category.
The articles guide you through the lifecycle: get oriented, secure Fusion, plan, install, group, protect, monitor, respond and remove cleanly.
Initial setup, Agent Modes, requirements, Windows and macOS installation, Linux Server Protection, piloting and tenant migration.
This guide connects the tenant, identities, licences, policies, pilot and operational acceptance without repeating the linked detailed runbooks.
This guide explains current agent modes, a pilot rollout, and the clear boundary between full Sophos protection and XDR Sensor.
Supported operating systems and agent versions change continuously. A lifecycle Runbook combines Sophos requirements, pilot groups, release notes and …
Standard and Advanced are no longer current installer options. The licence, agent mode and software scope offered in the tenant determine what is …
Install Sophos Fusion Endpoint on a single Mac, select components, grant macOS permissions, and accept the device into service.
An evidence-based Windows rollout with SophosSetup.exe, secure parameters, representative waves and clear stop criteria.
A reliable Jamf deployment assigns the matching Sophos MDM profile first, then runs the current tenant installer and validates macOS permissions.
The macOS CLI enables reproducible installations. A Mac is fully protected only after System Extensions, Network Extensions and privacy permissions …
Prepare a VDI gold image with the intended installer mode. Clones must come only from the master and need an appropriate lifecycle rule.
A green Health State is not enough. Harmless Sophos and EICAR tests confirm the protection path, policy, user notification, event and cleanup.
The primary method is API-based Device Migration with a Receiving Job and Sending Job. --registeronly remains a separate Windows re-registration …
Administrator access, MFA, API automation, identity sources and synchronisation with Active Directory and Entra ID.
An Endpoint role must do more than display menus: it must permit precisely the intended operational and response actions.
The Endpoint API manages a tenant's endpoint and server resources. The correct regional host, least privilege and complete error handling are …
Computer inventory, groups, policy assignment, installed components and inactive devices.
Learn how computers, groups, tags and software scope work together to create a reliable device inventory.
Sophos Fusion separates users, detected logins and protected devices. This guide explains safe mapping and distinguishes Endpoint identities from …
This lifecycle separates the new device, local removal, and the Fusion record so that protection remains in place and stale objects are removed only …
The device view controls agent mode and additional components. This guide explains assignment, shared product rows, validation and safe removal.
Policy order, Threat Protection, Web, applications, peripherals, DLP, Windows Firewall and DNS Protection.
Sophos Fusion applies the first matching policy for each feature. Keep assignment, scope and priority transparent.
A practical Sophos Endpoint Threat Protection baseline with clear limits for exclusions and advanced settings.
Four Endpoint controls solve different problems. This guide connects policy choice, pilot plan, acceptance testing and a safe rollback path.
Use Application Control as an inventory first. Block unwanted applications in a pilot group only after assessing the results.
Monitor peripherals first. A pilot policy then controls device types and accurately identified exceptions.
The current Windows web policy uses reusable Web Filtering Profiles. Classic remains relevant for older Windows agents and macOS.
Endpoint DLP connects Content Control Lists and reusable rules with a policy. A pilot provides the evidence needed for targeted confirmation or …
The Endpoint policy monitors or controls Windows Firewall profiles. It neither replaces Sophos Firewall nor creates a central detailed rule base.
The DNS Protection Endpoint policy forwards DNS requests from supported Windows devices to DNS Protection over HTTPS. Xstream alone does not cover …
Tamper Protection, global and policy exclusions, authorisations, risks and controlled validation.
Tamper Protection should be disabled only for a defined maintenance window. This guide explains the current methods and safe rollback.
Exclusions reduce protection and visibility. This guide explains global exclusions, policy scope, Windows, macOS and Linux syntax, and secure …
Licences, Software Packages, Update Caches, proxies, status, Events, Reports, maintenance and lifecycle.
Update Management controls product versions, not threat intelligence. Cache and Relay save bandwidth and carry Sophos Fusion communication.
Sophos Endpoint needs DNS and HTTPS to current Sophos destinations. Plan and validate wildcards, proxy use, and TLS inspection deliberately.
Events provide the technical history. Computer Report and Hero Report answer different operational questions and must be interpreted separately.
Endpoint licences are usually calculated per user. User assignment, activity, licence type and the exact licence status determine the result.
Alert emails, Account Health, device state, Event analysis and operational escalation.
An alert is an investigation task. Establish cause and impact before remediation, validation, and any workflow status change.
Threat Cleanup, XDR Cases, AI Assistant, IP blocking, Device Isolation, Live Response, Forensic Snapshots and Security Heartbeat.
Cleanup is a technical remediation process: preserve evidence, determine scope, perform supported Sophos actions, validate the result, and only then …
Admin isolation and automatic isolation have different triggers and exit paths. This runbook covers safe containment through release.
Live Endpoint queries connected devices, while Data Lake provides historical telemetry. Policy, retention and query guardrails determine reach and …
Cases group XDR investigations. Detection Rules suppress defined matches and therefore require narrow conditions, validation and a review date.
Detections show suspicious activity that was not blocked. Threat Lineage and Threat Graphs provide context for triage and evidence-based response …
AI Assistant and AI Search are Sophos XDR tools. They accelerate investigations but do not replace raw-data validation or human response decisions.
The global Central list blocks specified IP destinations on managed Windows and Linux devices. It is not a firewall rule and has no group scope.
Security Heartbeat supplies device health. Firewall rules, endpoint rejection, and Active Threat Response are separate response paths.
Diagnostics, repair, Tamper Protection special cases, controlled removal and device cleanup.
A symptom-first runbook for failed Sophos Fusion Endpoint installations on Windows, without invented exit codes or repair commands.
A symptom-first runbook for blocked installers, Folder Insecurity, missing Sophos Fusion registration, red permissions and update failures on a Mac.
The current procedure uses SophosUninstall.exe, separates local removal from deletion in Sophos Fusion and verifies the result.
Remove Sophos Endpoint despite Tamper Protection using supported recovery, password retrieval and re-registration instead of registry hacks.
Sophos Endpoint is removed from macOS using the official Removal Tool or InstallationDeployer. Fusion deletion and MDM cleanup are separate steps.
Local Endpoint interface, scans, Windows logs and services, Self Help, SDU, CLI diagnostics, macOS permissions and support data.
The local Endpoint interface shows whether protection modules work, which Events occurred and which actions an administrator can perform on the …
A practical guide to Scheduled Scanning, the Fusion scan action, pilot rollout, validation, and safe symptom-led troubleshooting.
The Intercept X CLI runs targeted or full Windows scans and provides actionable exit codes and JSON for RMM and Incident Response Runbooks.
Self Help identifies common agent problems. SDU collects the technical logs required for a sound analysis or a complete Sophos support ticket.
Not every Sophos log is relevant to every error. This reference maps a visible symptom to the right Windows log, service and next diagnostic step.