Sophos Mobile Threat Defense on iPhone and iPad: Plan an iOS Policy Safely
A Mobile Threat Defense (MTD) policy configures Sophos Intercept X for Mobile when the app is registered with Sophos Mobile. It is not an iOS/iPadOS device policy: Apple MDM settings, profiles, and device-wide management have a separate scope. An app registered with Sophos alone proves neither that a device is supervised nor that a web filter is active across the entire device. Intune MTD integration is not automatically the same policy assignment either.
⚠️ Before any change: In the device-wide MTD Web Filtering mode that Sophos Mobile documents for supervised devices, Sophos says the filter blocks all websites if the classification service at
https://4.sophosxl.net/lookupis unreachable. In that mode it also covers app connections and resources from other websites. By contrast, for the separate route on unsupervised devices, only the network traffic of the individual assigned managed app is documented as being within the filter’s scope – not every website on the device, Safari, or system apps. A wildcard entry under Blocked domains can unintentionally disable applications and system services in device-wide mode; a lone*blocks every website covered by the respective filter. Neither a broad exception nor a global block is a safe diagnostic step. First establish the scope, service reachability, an approved test group, an independent communication channel, and a rollback path.
Check licensing, edition, and platform separately first
- Sophos Mobile Threat Defense (formerly Intercept X for Mobile) licenses management of the Intercept X app; Sophos Mobile (formerly Central Mobile Advanced) includes MDM and MTD. Sophos Mobile Device Management (formerly Central Mobile Standard) alone is not evidence of MTD entitlement. Check the license and visible policy types in your own tenant rather than inferring them from a help-page heading.
- The iOS MTD configuration is intended for the Intercept X app registered with Sophos Mobile. The two official Web Filtering help editions do not explicitly contradict each other, but document the prerequisite differently: the Sophos Mobile edition explicitly restricts this configuration to supervised devices; the Threat Defense edition does not state a supervision prerequisite. That omission is not evidence of device-wide support for unsupervised devices and not authorization to assign MTD Web Filtering to them generally or claim that it works there. Until edition, license, supervision status, profile suitability, and behavior in the target tenant have been clarified, the web-filter rollout remains blocked – including for supervised devices without a verified pilot and rollback path. Separate per-app route: Sophos describes filtering individual managed apps on unsupervised devices running iOS 16 or later, or iPadOS 16.1 or later, and explicitly lists Sophos Intercept X in the managed app’s filter selector as an alternative to a policy with a “Web content filter” configuration. This establishes neither device-wide coverage nor suitability for every profile; verify this special case separately before using it.
- Device ownership (Corporate/Personal), MDM enrollment, Apple supervision, app registration, and profile installation are distinct properties. Third-party EMM has its own requirements for app configuration and, where applicable, profiles; do not reuse profiles from another edition without checking them. The iOS device profile “Web content filter” remains a different configuration from the MTD option “Web Filtering”.
Before changes and assignment
- Record the tenant license, device type, iOS/iPadOS version, supervision status, app registration, and policy assignment for a non-production-critical pilot device. Record the current policy state and an alternative communication channel that is actually reachable; do not change all devices at once.
- Before enabling device-wide Web Filtering, establish supervision and support for the intended filter profile on the pilot device, as well as the classification service’s reachability over the relevant network paths. Do not approve unsupervised devices for device-wide MTD Web Filtering; assess the documented per-app special case separately against the license, managed app, OS version, profile, and observed pilot behavior. If the edition, license, supervision, profile suitability, or reachability remains unclear, do not roll out. Do not “fix” this with a broad allowlist: its precedence can override intended blocks.
- Configure only the component needed. After assignment, check the app/profile status on the pilot device and make an approved, noncritical web request; assess expected allowed and blocked categories and documented business applications separately. A successful policy assignment alone does not demonstrate that filtering is working. No device tests were performed here.
- If an outage or erroneous block occurs, stop the change, restore the original policy or exception, or assign a previously approved alternative policy. Then recheck status, reachability, and events on the device and in Sophos Mobile. Sophos Mobile’s Uninstall policy action does not support MTD policies: update the MTD policy or assign a different one. Unlike iOS device policies, MTD policy changes synchronize when the device next connects to Sophos Mobile; verify the result on the device. Do not assume removing a profile is an invariably risk-free, immediate rollback; check MDM and app dependencies first.
Web Filtering: fail-closed behavior, exceptions, and scope
In the device-wide MTD Web Filtering mode documented for supervised devices, Web Filtering evaluates Safari, other browsers, and connections from apps. The service must be able to reach https://4.sophosxl.net/lookup; if it is unavailable, Sophos says the feature blocks all websites within the filter’s respective scope (fail-closed). The separately documented filter assignment on unsupervised devices covers only network traffic from individual managed apps; it does not imply filtering of Safari, other apps, or every website on the device. Blocked categories, malicious sites, warnings, and events need to be planned separately. Certain especially serious criminal content is always blocked when the filter is enabled; the corresponding URLs are masked in logs, events, and reports. The absence of a plaintext URL entry therefore does not disprove the block.
Filter boundary: In the documented device-wide mode, a broad blocked-domain wildcard can disrupt third-party and system apps; a lone * blocks every website in the filter scope. A broad allowlist can override intended blocks. Do not use either as a diagnostic shortcut. Assigning a filter to individual managed apps on unsupervised devices is a distinct managed-app route, not a device-wide MTD permission or per-app VPN setup instruction here. The article on iOS Web Filtering safety covers exception syntax, list precedence, filter configuration, fail-closed risks, and pilot checks.
Web Filtering events are not Network logging. Sophos Mobile can generate block/warning events for filtered websites in the device details; these events do not imply equivalent recording of URLs, connection times, and data volumes. Only for separately enabled Network logging, when Intercept X for Mobile is managed by Sophos Mobile, does the app help describe network metadata such as URLs, connection times, and amounts of data sent and received. Sophos says the organization cannot see the transmitted content through this network logging; do not assume URLs are hidden. The Network logging tile appears in the app dashboard only when the feature is enabled and explains the types of data collected. Establish purpose, access, and retention separately before enabling it.
Network and Wi-Fi security
The MTD Network configuration manages the app’s Wi-Fi security and its man-in-the-middle checks. When an attack is detected, Sophos Mobile creates an event in the device details and an alert. Once this configuration is assigned, the user can no longer change the related app settings. Configure Extra settings only at the direction of Sophos Support.
For a manual check in Intercept X for Mobile, open Dashboard > Network security > Wi-Fi Security and select Check Wi-Fi. This checks the currently connected Wi-Fi network. When Background check is enabled, Sophos says the app checks the network connection each time the device connects to Wi-Fi. This is not evidence of continuous checking; organization management and policy assignment remain authoritative for the managed app.
The types of issues displayed have different causes:
- Captive portal: A public Wi-Fi network requires a login before granting access. Redirecting traffic to the login page can trigger additional warnings.
- Content manipulation: Manipulated website content induces harmful actions. This can allow attackers, for example, to bypass authentication or delete data.
- SSL interception: A false server certificate allows a secured connection to be intercepted and sensitive data to be decrypted, even though the connection appears secure.
- SSL stripping: An HTTPS connection is downgraded to unencrypted HTTP. Using their own proxy, attackers can redirect traffic and read sensitive data while the connection still appears secure.
ARP spoofing is not detected on iOS 10.3 and later – do not claim “complete MITM protection”. An alert is a prompt to investigate, not proof of a particular cause.
Wi-Fi issues can be hidden for individual networks. Hidden Wi-Fi issues do not count toward device health. To show all hidden issues again, select Show all Wi-Fi issues on the Settings page in the Intercept X app. This restores visibility but does not fix any underlying network cause; reassess the warnings during acceptance testing.
Send the app log to Sophos Support
The app settings Log level and Send log files are under Intercept X for Mobile > Settings, not in the iOS Settings app. If Sophos Support asks, Log level lets you choose the extent of app logging. Send log files creates an email with the app log file attached; the Sophos Support address is entered by default. Before sending, check the recipient, attachment, and approval to share the log. A prefilled recipient is evidence of neither an approved nor a completed transfer. This app log file is not the same as Network logging.
Data tracking is a separate setting: Under Intercept X for Mobile > Settings > Data tracking, you can allow Sophos to collect anonymous usage data to improve the app. This statement about purpose and anonymity applies to the app usage data described there, not to all telemetry in general. Data tracking is neither sending an app log file to Sophos Support nor Network logging nor a transfer of data to the Data Lake. In particular, it does not provide any assurance that support logs, network URLs, or Data Lake data are anonymous. The Settings help does not specify a default state for Data tracking; do not assume it is enabled or disabled by default.
SMS/MMS filtering and device health
The MTD SMS Filtering configuration defines organization domains whose lookalike fake domains should be detected in SMS/MMS. Three types of variation are described: individual characters are replaced, inserted, or transposed; a prefix or suffix is added to the domain name, meaning a name component is placed before or after it; or the top-level domain, meaning the domain extension, differs. Take these variants into account when reviewing the organisation’s domains, particularly if the organisation itself uses similarly named domains or multiple domain extensions. Messages from known contacts are excluded from filtering, and subdomains of the genuine domain are not filtered for that reason alone. If a message from an unknown sender is classified as spam, that message, as well as existing and subsequent messages from the same sender, are moved to SMS Junk. iMessages are not covered.
Message Filtering checks incoming SMS/MMS for phishing URLs and must be enabled by the organization. If the Intercept X app displays Turn on Message Filtering under Settings, the local activation required by the organization is also necessary: enable Intercept X in the iOS app under Settings > Messages > Unknown & Spam > SMS Filtering. Selecting it in iOS does not replace enablement by the organization. Review domain variants and potential misclassification with the responsible business owners before assignment; check SMS Junk instead of promising delivery guarantees.
Under Device security, the app reports the model and iOS version, and a jailbreak if one is detected. Update recommendations appear when the latest available iOS version is not installed. Do not infer guaranteed freedom from compromise from the absence of a jailbreak warning.
Do not confuse iOS app permissions with Android rules: According to the platform table, the Sophos MTD compliance rule for denied Intercept X app permissions and the rule for malware scan intervals apply only to Android, not iOS. For iPhones and iPads, the Threat Defense edition instead documents, among others, the compliance rules Web Filtering turned on and the maximum Intercept X synchronization interval; device health shows a jailbreak only if the app detects it. Check the iOS activation mentioned above separately for SMS filtering, and an appropriate configuration profile for Web Filtering or Network logging; do not infer authorization for iOS malware scans or Android Accessibility access from this.
Filter profile and safe rollback
A configuration profile may be required for Web Filtering or Network logging. The organization starts the profile workflow described here by assigning a profile to the device. Depending on how it is managed, Intercept X prompts for manual installation; this does not imply that every filter mode requires a profile.
The downloaded profile must be installed within eight minutes; after that it expires and IT must assign it again.
Only if Intercept X prompts you to manually install the assigned organization profile:
- Confirm the app’s installation prompt with OK.
- Confirm the subsequent download request with Allow.
- After the download, dismiss the message with Close. The profile is not yet installed.
- Open the iOS Settings app and select Profile Downloaded.
- Tap Install and follow the displayed instructions to complete the installation.
If installation fails with Profile Installation Failed, the app help says the device does not support Web Filtering profiles: do not blindly assign them repeatedly; clarify suitability and the management route with IT. Check profile installation and active protection separately. With third-party EMM, automatic profile deployment is provided only under the separately documented prerequisites; it does not replace verification of supervision status.
Rollout prerequisites: The Sophos Mobile edition requires supervised devices for this Web Filtering configuration, while the Threat Defense edition omits that note; this provides no approval for device-wide Web Filtering on unsupervised devices. The separately documented per-app route can select Intercept X as its filter but is not blanket device approval. Edition, license, supervision, supported profiles, and per-app scope must be independently confirmed technically for the target tenant. No tests in a Sophos Mobile tenant or on iOS/iPadOS devices were performed for this article. Actual pilot acceptance and a validated rollback path are missing. Do not roll out while prerequisites remain unclear, filtering has not been verified on the intended pilot device, or the rollback path has not been validated.