Plan Sophos Central Endpoint roles and permissions
An Endpoint role must do more than display menus: it must permit precisely the intended operational and response actions.
Practical guidance for complete Sophos Central Endpoint operations: access, rollout, devices, policies, encryption, monitoring, XDR, Response and troubleshooting.
The articles follow the Endpoint lifecycle: secure Central, plan, install, group, protect, encrypt, monitor, respond and remove cleanly.
Administrator access, MFA, API automation, identity sources and synchronisation with Active Directory and Entra ID.
An Endpoint role must do more than display menus: it must permit precisely the intended operational and response actions.
The Endpoint API can manage devices, groups, policies, software and XDR data. The service principal, data region, permissions and error handling must …
Initial setup, Agent Modes, requirements, Windows and macOS installation, piloting and tenant migration.
A secure Endpoint rollout starts before the installer. Tenant, identities, licences, policy model, pilot group and operational processes must align.
This guide explains current agent modes, a pilot rollout, and the clear boundary between full Sophos protection and XDR Sensor.
Supported operating systems and agent versions change continuously. A lifecycle Runbook combines Sophos requirements, pilot groups, release notes and …
Standard and Advanced are no longer current installer options. The licence, agent mode and software scope offered in the tenant determine what is …
Install Sophos Central Endpoint on a single Mac or through MDM, grant the required macOS permissions, and resolve common installation issues.
Remove Sophos Endpoint on macOS with the built-in Removal Tool or InstallationDeployer, not by deleting the app.
The Windows installer supports controlled bulk rollout with groups, Agent Mode, proxy, Message Relay and unambiguous installation logging.
A macOS bulk rollout needs current Sophos MDM profiles, System Extensions, Full Disk Access and repeatable validation in addition to the installer.
The macOS CLI enables reproducible installations. A Mac is fully protected only after System Extensions, Network Extensions and privacy permissions …
Prepare a VDI gold image with the intended installer mode. Clones must come only from the master and need an appropriate lifecycle rule.
A green Health State is not enough. Harmless Sophos and EICAR tests confirm the protection path, policy, user notification, event and cleanup.
A tenant migration changes management and policies. Check the target tenant, licence, installer, exclusions and rollback before the first device.
Computer inventory, groups, policy assignment, installed components and inactive devices.
Learn how computers, groups, tags and software scope work together to create a reliable device inventory.
Sophos Central distinguishes people, logins and devices. A clean identity source prevents duplicate users, incorrect licences and unexpected user …
The current device view replaces the old feature dialogue. This guide explains software assignment, licensing, validation and safe switching.
Policy order, Threat Protection, Web, applications, peripherals, DLP, Windows Firewall and DNS Protection.
The first matching policy wins. This guide creates a maintainable policy model and prevents priority mistakes.
A practical Sophos Endpoint Threat Protection baseline with clear limits for exclusions and advanced settings.
Four Endpoint controls solve different problems. This guide explains their effect, platform limits and safe rollout.
Use Application Control as an inventory first. Block unwanted applications in a pilot group only after assessing the results.
Monitor peripherals first. A pilot policy then controls device types and accurately identified exceptions.
The current Windows web policy uses reusable Web Filtering Profiles. Classic remains relevant for older agents and other platforms.
Endpoint DLP combines reusable rules with a policy. Log content and files first, then require confirmation or block precisely.
The Endpoint policy monitors or controls Windows Firewall profiles. It neither replaces Sophos Firewall nor creates a central detailed rule base.
The Endpoint policy redirects DNS requests securely to Sophos. Internal namespaces and platform limits require careful planning.
Tamper Protection, global and policy exclusions, authorisations, risks and controlled validation.
Tamper Protection should be disabled only for a defined maintenance window. This guide explains the current methods and safe rollback.
Exclusions can greatly reduce protection and visibility. This guide covers selection, approval, testing and regular cleanup.
BitLocker and FileVault policies, authentication, recovery keys, Self Service, migration and decryption.
Sophos does not replace operating-system drive encryption. It centrally manages BitLocker and FileVault policies, status and recovery keys.
Sophos Central orchestrates BitLocker. TPM, authentication mode, Windows GPOs, partitioning and recovery keys remain essential to a stable rollout.
FileVault depends on more than policy. User authorisation, Secure Token, Bootstrap Token, MDM and a valid personal recovery key must align.
Troubleshoot Device Encryption using the local operating system status, CDE.log and the specific error code instead of repeatedly changing the policy.
Licences, Software Packages, Update Caches, proxies, status, Events, Reports, maintenance and lifecycle.
Update Management controls product versions, not threat intelligence. Cache and Relay save bandwidth and carry Central communication.
Endpoints need DNS and HTTPS to Sophos. Plan proxy, Message Relay and Update Cache as a clear, tested communication path.
Events remain as history, while alerts require attention. Audit Log, DLP Log and Endpoint Reports have their own time periods and limitations.
Endpoint licences are usually calculated per user. Offline devices, duplicate users and licence expiry behave differently from what the device list …
Alert emails, Account Health, device state, Event analysis and operational escalation.
Alerts and Account Health indicate where action is required. Close, Resolve, Reset, Snooze and Auto-Fix do not replace investigation of the technical …
Threat Cleanup, XDR Cases, AI Assistant, IP blocking, Device Isolation, Live Response, Forensic Snapshots and Security Heartbeat.
The correct response depends on the Detection type. Check isolation, the process chain, Cleanup status, persistence and root cause before closing.
Admin isolation and automatic isolation behave differently. This guide covers investigation, remediation and safe reconnection.
Live Endpoint queries connected devices, while Data Lake provides historical telemetry. Policy, retention and query guardrails determine reach and …
Cases group investigations and Detection Rules generate signals. Both require ownership, traceable Suppression and clear closure criteria.
Events report known actions, while detections identify suspicious activity that was not blocked. Threat Lineage and Threat Graphs provide …
AI accelerates search and summarisation, but does not replace evidence review or incident decisions. Prompts and results remain controlled working …
Central distributes IP blocks to Windows and Linux Endpoints. Document scope, expiry, exclusions and Response before a tenant-wide block.
Endpoint and Firewall remain separate products. Heartbeat reports state; Synchronized Security applies the configured network response.
Diagnostics, repair, Tamper Protection special cases, controlled removal and device cleanup.
A reproducible installation Runbook separates download, bootstrap, component installation, registration and policy sync, avoiding blind …
The current procedure uses SophosUninstall.exe, separates local removal from Central deletion and verifies the result.
Remove Sophos Endpoint despite Tamper Protection using supported recovery, password retrieval and re-registration instead of registry hacks.
Local Endpoint interface, scans, Windows logs and services, Self Help, SDU, CLI diagnostics, macOS permissions and support data.
The local Endpoint interface shows whether protection modules work, which Events occurred and which actions an administrator can perform on the …
Real-time protection and scheduled scans complement each other. This article covers selection, scheduling, performance limits, logs, and typical File …
The Intercept X CLI runs targeted or full Windows scans and provides actionable exit codes and JSON for RMM and Incident Response Runbooks.
Self Help identifies common agent problems. SDU collects the technical logs required for a sound analysis or a complete Sophos support ticket.
Not every Sophos log is relevant to every error. This reference maps a visible symptom to the right Windows log, service and next diagnostic step.