Isolate Sophos Endpoint and use Live Response
During an active investigation, isolation separates an endpoint from the network while the device remains manageable from Sophos Central. Configured isolation exclusions can still allow limited communications. Live Response then opens a privileged remote shell for investigation and remediation. Both features immediately affect operations: isolation changes network traffic, while Live Response can terminate processes, restart devices, browse folders and delete files.
Safe workflow at a glance
- Match the device, user, alert and Threat Graph to the ticket or incident.
- If there is an immediate risk of spread, isolate the affected device administratively. Containment normally takes priority for ransomware, credential theft or command-and-control activity.
- Start Live Response only with the correct licence, policy, role and MFA.
- Capture state and evidence before making targeted changes.
- End the connection with End Session and retain the audit and session logs.
- Clean or block the threat, check scan and health results, then remove admin isolation.
Distinguish admin and automatic isolation
| Type | Trigger | Exit path |
|---|---|---|
| Admin isolate | An administrator isolates a suspicious device, for example from a Threat Graph | Deliberately release it after cleanup through the Threat Graph or Admin Isolated Devices |
| Device Isolation | The Threat Protection policy isolates a device because of its locally reported red health state | Resolve the cause; Sophos releases it automatically only after local health returns to green |
Automatic isolation uses the health state reported by the device. Red can indicate a detected threat, outdated software, policy non-compliance or incomplete protection. The overall status shown in Central can differ because Central considers additional factors. Automatically isolated devices do not appear in Admin Isolated Devices and cannot be released there manually.
Sophos recommends piloting Device Isolation through a Threat Protection policy applied to a representative device group. Also test the support path for devices that turn red because of protection or update faults rather than an attack. Locally cached Windows network files may remain visible during isolation; that does not prove that a network connection is active.
For the full policy logic, see Configure Sophos Central Threat Protection correctly. If an exception is essential, allow only the direction, address and port required for a specific purpose. Examples and limitations are covered in Plan Sophos Endpoint exclusions safely.
Live Response prerequisites and permissions
Live Response requires Sophos EDR, XDR or MDR. For computers, permit connections under My Products > Endpoint > Policies > Data Collection and Investigation > policy > Settings with Allow Live Response connections to computers. The base policy applies to all computers by default. Put sensitive devices in a separate group with a policy that keeps Live Response off when required. Live Response is on by default with MDR and off by default with other eligible licences.
Managing the policy and starting a session are separate rights:
- Change settings: Super Admin or a custom role with Manage Data Collection and Investigation settings for computers.
- Start a session: Super Admin or a custom role with Start Live Response sessions on computers.
- According to Sophos, the custom role needs Full or Help Desk as its base role, Full access to Endpoint Protection, and the additional setting for starting computer Live Response sessions.
- An MSP currently cannot create this custom role in a customer’s account from Sophos Central Partner.
Plan these rights according to least privilege and verify the effective assignment before an incident. Plan Sophos Central Endpoint roles and permissions explains product access and additional capabilities.
Starting Live Response normally triggers a Sophos Central MFA challenge. With federated sign-in, IdP Enforced MFA can avoid that challenge when a supported identity provider enforces MFA. The documented path is Global Settings > Access Control > Sign-in and Identity > Federated identity providers.
Isolate a device administratively
The officially documented path from a Threat Graph is:
- Open Threat Analysis Center > Threat Graphs and select the relevant graph.
- Review Summary and Suggested next steps, and confirm that the graph and device belong to the incident.
- For a high-priority graph, select Isolate this device. This action in a Threat Graph requires Sophos XDR and is not offered for a device that isolated itself automatically.
- In Central, confirm that the correct device is isolated and remains manageable.
- Record the time, operator, reason and expected impact in the ticket.
Additional matches can be isolated with Isolate device in Item Search Results. Match every affected device to the incident; broad isolation without confirmed scope can unnecessarily disrupt operations.
Administratively isolated devices are listed under Global Settings > Protection and Remediation > Allow and Block > Network > Admin Isolated Devices. Remove from Isolation is also available there later. An exception for RDP, SSH or a cleanup server deliberately expands an isolated device’s communications, so make it temporary and as narrow as possible.
Run a Live Response session safely
Before connecting
Record at least the ticket ID, device name, expected operating system, purpose, planned read-only checks, possible changes and a rollback path. Coordinate local actions with Sophos MDR or another response team so that evidence is not lost and parallel work does not interfere.
Open the session
- Open My Environment > Computers & Servers.
- Select the verified device and open its details page.
- Choose Actions > Live Response.
- Enter a precise purpose for the session.
- Use the terminal in the new browser tab. If it does not open, check the browser’s pop-up setting for Sophos Central.
The shell expects DOS, UNIX or Linux commands appropriate for the connected device. A successful connection only confirms access; it does not prove that the endpoint is clean.
Observe before changing
A defensible workflow separates observation from remediation:
- Capture the time context, signed-in users, running processes and network connections.
- Record suspicious files, paths, hashes, signatures and persistence mechanisms.
- Preserve relevant logs and artefacts and note where they are stored.
- Before each change, reconfirm the target, impact, dependencies and rollback path.
- Terminate or remove only confirmed malicious activity.
- Then rerun the central scan and review the Threat Graph, alerts and health state.
Do not experiment with commands on production systems. If a path, process or artefact is not clearly attributed, keep the endpoint isolated and escalate to Sophos Support, MDR or the incident-response team.
End and audit the session
Use End Session to close the connection deliberately. It also closes if you close or refresh the tab, navigate elsewhere in Sophos Central, or leave it inactive for 30 minutes.
Under Reports > Logs > Audit Logs, start and end entries show the administrator, target device and stated purpose. The full command record is available as a gzip file under Reports > Logs > Live Response session audit > Download session log. A custom role needs both Manage Live Response settings for computers and Manage Live Response settings for servers to retrieve it; alternatively, a Super Admin can retain the log.
For sensitive environments, also record the ticket ID, commands, retained artefacts, hashes, result and release decision.
Optionally create a Forensic Snapshot
A Forensic Snapshot captures recent device activity. Sophos automatically creates data for a Threat Graph for certain detections; you can also request a snapshot:
- Open My Environment > Computers & Servers > device > Summary.
- Select More actions > Create forensic snapshot > Create now.
- On Windows, a manually created snapshot is stored by default in:
%PROGRAMDATA%\Sophos\Endpoint Defense\Data\Forensic Snapshots\
Data stored automatically after detections is located in:
%PROGRAMDATA%\Sophos\Endpoint Defense\Data\Saved Data\
With Tamper Protection on, local access requires an elevated command prompt. Convert the snapshot to SQLite or JSON with SDR Exporter; it is not a directly readable report. Record the input file, output format and a hash you calculate for the original without treating that hash as a Sophos-generated attestation.
By default, a snapshot covers the previous two weeks. Change the period or select All log data under Global Settings > Products and Services > Endpoint and Server > Forensic Snapshots.
Upload to AWS S3
Central S3 upload is available only from Windows devices with XDR or MDR. The IAM policy documented by Sophos needs s3:ListBucket and s3:PutObject for the intended bucket. Central displays the AWS Account ID and External ID for the trust policy; a new IAM role can take up to five minutes to propagate.
Save the bucket name, optional destination directory and Role ARN under Forensic Snapshots. Sophos also recommends a restrictive bucket policy, AES-256 encryption and a lifecycle rule for incomplete multipart uploads. KMS-encrypted buckets and special characters in bucket names are not supported for this upload. Firewall rules must permit the connection to the S3 bucket.
A successful pilot does not end with a message in Central. Verify that the expected object exists under the correct bucket and prefix and is protected by your retention policy.
Clean, release and monitor
Remove admin isolation only after:
- suspicious processes and persistence have been investigated,
- malicious applications have been cleaned or blocked,
- compromised credentials have been rotated where required,
- the agent and operating system have the expected update state,
- scan, alerts, Threat Graph and health show no unexplained active threat,
- an owner and period for follow-up monitoring have been defined.
Then choose Suggested next steps > Remove from isolation in the Threat Graph, or select the device under Admin Isolated Devices and choose Remove from Isolation. On the correct device, verify that required business connections work again, Central continues to receive current data, and no new detection or isolation occurs.
Do not manually release automatic isolation. Resolve the reason for local red health. If the device remains red or is not released automatically, preserve timestamps, events and health details and escalate instead of bypassing isolation or protection with broad exclusions.
Common failures and safe next steps
- The Live Response tab does not open: Allow pop-ups for Sophos Central and deliberately start the connection again.
- The session ends unexpectedly: Check whether the tab was closed, refreshed, left, or inactive for 30 minutes. Before reconnecting, reconcile the last audit entry and changes already made.
- The device is missing from Admin Isolated Devices: Check local health and the Threat Protection policy. Automatically isolated devices are not in this list.
- Live Response cannot connect: Check policy assignment, licence, role, MFA and reachability of the Sophos management path. Keep the device isolated; do not create a broad network exception as a shortcut.
- A command or artefact is unclear: Make no mutation. End the session with a record and continue with Sophos Support, MDR or the incident-response team.
- The S3 object is missing: Check the Windows and licence prerequisites, bucket name, Role ARN, trust and IAM policies, and firewall allowance, then validate again with a pilot device.
Sources
- Sophos Central Admin: Threat Protection Policy
- Sophos Central Admin: Threat Graphs
- Sophos Central Admin: Admin Isolated Devices
- Sophos Central Admin: Set up and start Live Response
- Sophos Central Admin: Give admins access to Live Response
- Sophos Central Admin: Data Collection and Investigation policy
- Sophos Central Admin: Forensic snapshots
- Sophos Central Admin: Convert forensic snapshots
- Sophos Central Admin: Upload forensic snapshots to an AWS S3 bucket