Introduce Sophos Endpoint control policies safely
Application Control, Peripheral Control, Web Control and Data Loss Prevention add operational rules to malware protection. They do not block the same things and must not be treated as interchangeable switches.
All four should be introduced by observing the existing environment, defining business rules, testing a pilot group, measuring user impact and only then enforcing blocks.
Which policy solves which problem?
| Policy | Purpose | Typical decision |
|---|---|---|
| Application Control | detect or block software that is not necessarily malicious but is unsuitable | remote tools, games, old browsers |
| Peripheral Control | control devices and removable media | read-only USB storage |
| Web Control | allow, warn or block websites by category or custom list | GenAI, streaming, malware categories |
| Data Loss Prevention | detect and restrict transfers of sensitive file content | personal or financial data |
Create these policies under My Products > Endpoint > Policies and apply them through order and target group.
Application Control
Application Control uses a Sophos-maintained list of controllable applications. Sophos recommends detection before blocking:
- select required categories and applications
- enable detection in scheduled and on-demand scans
- do not block on access yet
- wait for a complete observation period
- review events under Reports > General Logs > Events
- remove business-required applications from the controlled selection
- enable access detection and blocking in the pilot
Automatically controlling future applications that Sophos adds to a category can introduce new blocks without another policy edit. Enable it only deliberately.
Peripheral Control
Peripheral Control supports Windows and macOS, but available device types differ. Depending on the type, Allow, Read Only, Block or Block Bridged may be available.
Start with Monitor but do not block. This creates an inventory of devices actually used and allows precise exemptions by Model ID or Instance ID.
⚠️ Do not cut off network access: Blocking Wireless or Modem devices can stop a device from contacting Sophos Central. Exempt approved network adapters before enforcement, otherwise local access may be required.
Not all categories are available on macOS. Bluetooth devices are not blocked by Peripheral Control there and Camera is unavailable.
Web Control
Web Control manages categories and custom website lists. New Web profile policies add productivity and Generative AI categories and are currently available only for Windows with Sophos Endpoint 2026.1 or later.
Older and other platforms continue to use classic settings. In a mixed environment, verify which policy type each device understands.
Custom assignments are managed through Website Management and used in policies as tagged custom categories. A global website exclusion bypasses Web Control and is not the normal method for one department.
Data Loss Prevention
Endpoint DLP controls accidental file transfers. Rules define content or file attributes and an action. Policies combine one or more rules and can target users, computers and Windows servers.
Sophos supplies regional templates. They are a starting point, not a finished compliance approval. Test detection logic, language, internal data types and allowed workflows with representative files.
Actions can request user confirmation or block the transfer. Custom messages should identify the internal contact and an approved alternative process.
Performance
Content rules read file content. Large files and many sequential rules increase transfer time. File rules based on name or type are lighter. Keep DLP policies focused and test realistic file sizes.
Five rollout phases
- Scope: define platforms, groups, business process and owners.
- Observe: collect applications, peripherals, websites and data flows.
- Design: create simple rules and precise exceptions.
- Pilot: warn or block, then analyse support cases and events.
- Enforce: expand gradually and maintain the rule set.
Do not introduce several major policy changes at the same time. Otherwise, a disruption cannot be attributed reliably.
User communication
Desktop Messaging can add a custom note to several policy notifications. A good message says what was blocked and how to request a business exception.
Technical error codes without a next step increase ticket volume. The message must not reveal sensitive DLP logic or internal controls.
Detailed guides
This page deliberately remains an overarching introduction strategy. Complete configuration and troubleshooting are covered in the individual articles:
- Configure Application Control
- Configure Peripheral Control
- Configure Web Control
- Configure Data Loss Prevention
- Manage Windows Firewall with Sophos Central Endpoint