Skip to content
Avanet

Roll out Sophos Endpoint control policies safely

Application Control, Peripheral Control, Web Control and Data Loss Prevention (DLP) add operational rules to malware protection. However, they control different activities and are not interchangeable switches.

The safe overall approach is to choose one control, capture current usage, assign a separate pilot policy, test permitted and prohibited cases, and only then expand the scope. This keeps the cause clear if a disruption occurs.

Which policy fits the task?

PolicyControlsTypical decision
Application Controlknown applications that are not necessarily maliciousallow a remote support tool on IT devices and block it elsewhere
Peripheral Controldevice types and removable mediamake USB storage read-only and exempt one approved device
Web Controlwebsite categories, site lists and web accesswarn for streaming and block a known risk category
Data Loss Preventionfile content, name or type during transferlog, require confirmation for, or block sensitive data transfers

None of these policies replaces Threat Protection. An application allowed in Application Control is still inspected by the other protection features. DLP assesses data transfers, not whether a file contains malware.

Before the pilot: define scope and rollback

All four policy types are managed under My Products > Endpoint > Policies. For each feature, Sophos Central applies the first active policy whose user or computer scope matches. Policies of the same type are not merged. Place the pilot policy above a more general policy and assign it only to a small, clearly named group.

Record the following before enforcement:

  1. Business objective: What must be prevented, and which legitimate workflow must continue?
  2. Targets: Operating system, agent version, user or computer group, and the policy that is actually effective.
  3. Test cases: At least one permitted and one prohibited case for every configured rule or category.
  4. Success criteria: Expected action, Central event, user message, and uninterrupted access to required services.
  5. Rollback: Disable the policy or remove its assignment; for network devices, also retain local or alternative access.

Check the effective policy on the affected computer’s Policies tab. Seeing the intended configuration in the policy list does not prove that it has reached that device.

Pilot the four controls correctly

Application Control: detect before blocking

Application Control uses the Sophos-maintained catalog of controllable applications. For inventory, select the relevant categories and applications and initially enable only Detect controlled applications during scheduled and on-demand scans. After every pilot device has completed at least one scheduled scan, review Application Control events under Reports > Logs > Events.

Remove business-required applications from the controlled selection. Only then enable Detect controlled applications when users access them and Block the detected application for the pilot group. New applications added to this category by Sophos expands scope automatically later; in a blocked category it can block a newly added program without another policy edit.

Peripheral Control: protect network access

Start with Monitor but do not block (all peripherals will be allowed). Only devices discovered in this way are available for targeted exemptions. Then switch to Control access by peripheral type and add exemptions and choose Allow, Read Only, Block, or Block Bridged for Wireless, where the category supports that action.

Exemptions can be enforced by Model ID or Instance ID. Model ID covers all devices of the same model. Instance ID is usually narrower and is therefore the better starting point for one approved device.

⚠️ Never block Wireless or Modem without preparation: A block can interrupt the connection to Sophos Central. Exempt required adapters first and test an alternative access path. Otherwise, physical access may be required to restore connectivity.

Windows and macOS don’t support the same device types. Peripheral Control doesn’t block Bluetooth on macOS, and the Camera category isn’t available there. A successful Windows acceptance test therefore doesn’t automatically cover Macs.

Web Control: separate the new profile model from Classic

Sophos Central offers the new Web Filtering Profiles model and Classic Web Control. Web Filtering Profiles are intended for supported Windows endpoints from Sophos Endpoint 2026.1. Older Windows agents and macOS continue to use Classic. A mixed environment therefore needs test devices for every model actually in use.

A Web Filtering Profile can combine categories with prioritized site lists. Classic uses, among other things, custom website tags from Website Management. A global Website Exclusion bypasses Web Control more broadly and isn’t a normal substitute for a narrowly scoped policy decision.

In the pilot, test an allowed, warned and blocked category plus a targeted site-list or tag exception. Warning pages in the new profile model require HTTPS Decryption in the effective Threat Protection policy. If the warning page is missing, check certificate trust and HTTPS Decryption as well as Web Control.

Data Loss Prevention: assess detection before blocking

Endpoint DLP consists of Content Control Lists (CCLs), reusable DLP rules and the assigned policy. A Content Rule inspects file contents; a File Rule checks file name or type. SophosLabs CCLs and regional templates are a starting point, not completed compliance approval.

Run the first pilot rule with Allow file transfer. Matches appear under Reports > Endpoint & Server Protection Logs > Data Loss Prevention. Only after positive and negative tests show useful detection quality should you change to Allow transfer if user confirms or Block transfer. If several rules match, Sophos applies the strictest action.

Content Rules read file contents. Large files and many sequential rules can lengthen transfers; File Rules based on name or type aren’t affected in the same way. Include typical file sizes, real destination applications and perceived transfer duration in acceptance testing.

Rollout and acceptance testing

Introduce the four features one at a time:

  1. Capture a baseline: Inventory applications and devices, and document web requirements and sensitive data flows.
  2. Design rules: Add only justified categories, rules and exemptions; define an owner and review date.
  3. Assign a pilot: Use representative users and devices, but keep the scope small and recoverable.
  4. Test positive and negative cases: Permitted workflows must work; prohibited ones must create the expected event and action.
  5. Correct one item at a time: Change one rule or exemption, verify policy receipt and repeat the same test.
  6. Expand gradually: Add more groups only after documented acceptance and review exemptions regularly.

User messages should briefly explain what was controlled and how to request an exception internally. They must not expose sensitive DLP patterns or internal control mechanisms.

When the result doesn’t match the policy

Check in this order:

  1. Is the correct policy active, correctly assigned, and the first matching policy in the list?
  2. Does the computer’s Policies tab show that policy as effective?
  3. Do the operating system and agent version support the configured feature or model?
  4. Does the test exactly match the selected application, device identifier, website rule, DLP condition and intended transfer path?
  5. Is there a broader exemption or, for DLP, another stricter rule?
  6. Does the expected event appear? If not, correct scope and conditions instead of disabling protection globally.

Do not enforce one feature alongside several other major policy changes. Otherwise, user impact, performance and false positives cannot be attributed reliably to one cause.

Detailed guides

Frequently asked questions

Should all four control policies be enabled together?

No. Introduce and accept one feature at a time in a small pilot group. Only then make the next major policy change.

Can Peripheral Control interrupt Central communication?

Yes. Blocking required Wireless or Modem adapters without an effective exemption can make the device lose its management connection.

Is a DLP template a finished compliance rule?

No. Test the template, CCL, actions, false positives, performance and permitted business workflows with representative files and transfer paths.

Sources