Skip to content
Avanet

Configure Sophos Endpoint Data Loss Prevention

Sophos Data Loss Prevention (DLP) monitors and restricts the transfer of files containing sensitive data. Content Control Lists (CCLs) describe data to protect, while DLP rules connect conditions to an action. Rules are assigned through separate Data Loss Prevention policies: under Endpoint for computers and under Server for Windows servers.

Important: DLP for computers and Windows servers isn’t the same as Data Control in Sophos Email. The products use separate policies and reporting. This article covers DLP for computers and Windows servers, not Sophos Email.

Quick path for a safe pilot

  1. Under Global Settings > Protection & Remediation > Data Loss Prevention > Content Control Lists, select an existing SophosLabs CCL or create a custom CCL.
  2. Under Global Settings > Protection & Remediation > Data Loss Prevention > Rules, create a Content Rule or File Rule and initially select Allow file transfer.
  3. For computers, under My Products > Endpoint > Policies, create a Data Loss Prevention policy, turn on Use rules for data transfers, add the rule, and assign the policy to a small pilot group. For Windows servers, use the separate Server policy path instead.
  4. Test an allowed and a prohibited business case using the actual file type and transfer route.
  5. Review the matches under Reports > Endpoint & Server Protection Logs > Data Loss Prevention. Only move to user confirmation or blocking when match quality is sufficient.

This separates detection from enforcement, so an imprecise first draft doesn’t interrupt legitimate workflows.

Choose a Content Rule or File Rule

A Content Rule checks file contents against one or more CCLs. SophosLabs provides definitions for common financial and personally identifiable data, such as credit card numbers, postal addresses, social security numbers, and email addresses. A custom CCL is suitable for organization-specific terms or patterns.

A File Rule decides by full file name or file type. It is suitable when the file category itself needs protection, for example database files at a defined transfer destination. A full file name includes its extension; use Sophos-supported wildcards to match multiple names or extensions.

A rule only matches when all its required conditions are met. If a file matches several rules with different actions, Sophos enforces the strictest action:

ActionSuitable rollout phase
Allow file transfervalidate detection and the Event baseline
Allow transfer if user confirmslet users confirm justified exceptions
Block transferprevent clearly defined and tested transfers

Block transfer takes priority over Allow transfer if user confirms, which in turn takes priority over Allow file transfer. Troubleshooting must therefore consider every rule in the effective policy.

Prepare Content Control Lists

Use existing SophosLabs CCLs

The Content Control Lists page can be filtered by region, source, and type. SophosLabs CCLs can’t be edited. The detail view shows what a definition detects. Sophos can independently update the file types included in DLP, so an old test matrix isn’t a permanent commitment for every file type.

The Recommended filter shows CCLs suggested for the selected region. Deprecated identifies obsolete definitions. Policies containing a deprecated CCL remain active, but Sophos states that functionality may be reduced over time. Migrate these definitions methodically to a current alternative and test them again.

Create a custom CCL

Under Content Control Lists > Add Custom Content Control List, enter a name, description, and optional filter tags. Then select one appropriate matching method:

  • Any of these terms matches when any entered term occurs.
  • All of these terms requires every entered term.
  • Exactly this phrase searches for the exact phrase without case sensitivity.
  • Advanced Setup uses an Advanced Expression.

A name such as Finance_Project_Terms can be reused, but the actual terms must come from your own protection requirements. It is safer to validate a few justified terms with positive and negative sample files than to import a long, untested word list.

Custom CCLs can later be edited, exported, cloned, or deleted. A clone is useful when a tested definition needs a controlled variation for another use case.

Use Advanced Expressions only with a test corpus

Advanced Expressions use Perl 5 regular expressions. Under Advanced Setup, configure Trigger score, Expression, Score, and Max count. Sophos requires Score to match Trigger score; Max count limits how often an expression contributes to the overall score. Adding expressions expands the CCL’s scope.

Sophos Support doesn’t assist with creating or debugging custom regular-expression DLP rules and directs customers to Sophos Professional Services. A custom expression therefore needs a versioned test set with expected matches and non-matches. Without that evidence, keep the rule at Allow file transfer during the pilot.

Create and configure the DLP rule

  1. Under Global Settings > Protection & Remediation > Data Loss Prevention > Rules, click Create New Rule.
  2. Select New Content Rule or New File Rule, then enter an unambiguous name and description.
  3. Optionally turn on Send me email alerts. According to Sophos, this email doesn’t create an additional alert in Sophos Fusion.
  4. For a File Rule, choose file name or file type. For a Content Rule, all predefined condition types are required.
  5. If necessary, configure file-name or file-type exclusions. They apply only to this rule and aren’t general malware exclusions.
  6. Initially select Allow file transfer; choose a stricter action later after match quality is approved.
  7. Complete the conditions with Next: Rule Configuration.

Sophos notes that some features might not yet be available to all customers. If an option described here is missing, verify the tenant’s rollout status first rather than assuming a different UI path.

For a Content Rule, select the CCLs under File Contains and set the required number of matches for each selection. A lower value triggers sooner; a higher one allows more occurrences before the rule matches. Determine the right value from the protection requirement and test cases, not a universal default.

For a File Rule, choose monitored types under File types or enter full names, including the extension, under File names. Then select the destinations relevant to the business case under Destination is. Configure exclusions separately by file type or full file name.

Microsoft Office files need realistic tests: Sophos checks CCLs not only in visible document text but also in metadata such as titles, tags, and comments, as well as headers, footers, footnotes, and embedded Excel charts. DLP can’t check signature data for CCL matches.

Create and assign the policy

Create a Data Loss Prevention policy under My Products > Endpoint > Policies. On the Settings tab, Use rules for data transfers must be turned on.

Sophos offers two routes:

  • Create from Template adds a predefined rule after you select a region and template. Add more rules with Add.
  • Create Custom Policy starts without a template. Use Add to select an existing rule or create a new one.

The DLP rules and CCLs can be shared, but the Server policy is managed separately under Server. Use a clearly scoped pilot group for the rollout. Build Sophos Fusion Endpoint policies correctly explains the general targeting and priority model.

Under Messages For End Users, confirmation and block messages can be turned on or off and supplemented with custom text. Each message can contain no more than 100 characters. If the text field is blank, Sophos shows the standard notification. A concise addition should identify the purpose and responsible team without copying sensitive data into the message.

Assign and verify Windows servers separately

According to Sophos, the Server Data Loss Prevention policy is available only for Windows servers. Assigning an Endpoint policy does not establish that servers are protected:

  1. Under My Products > Server > Policies, create a Data Loss Prevention policy, turn on Use rules for data transfers on the Settings tab, and add the required shared DLP rules. CCLs and rules remain defined under Global Settings > Protection & Remediation > Data Loss Prevention.
  2. Assign and enable the policy specifically for the intended Windows servers or a clearly scoped server group. If several policies apply, the highest-priority applicable policy takes effect; otherwise the Base Policy applies. Settings from multiple policies are not combined.
  3. Under My Products > Server > Servers, open the pilot server and check Policies for the DLP policy actually applied, including enabled transfer rules and settings. Group assignment alone is not sufficient. Then run the shared pilot tests with transfers from the Windows server and perform the Event and action checks. Without access to the tenant and a test server, actual enforcement remains unverified.

Validate performance and the pilot deliberately

Content Rules inspect the entire file content, so inspection time increases with file size. File Rules only check names or types and aren’t affected by file size in the same way. Sophos checks rules sequentially for each file, so a larger number of rules also increases the work required.

The pilot therefore includes more than an artificial match file. For every destination needed in production, test at least one allowed and one prohibited business case with the actual file type, application, and normal transfer route. Record the result, user message, and perceived transfer time. Introduce Sophos Endpoint Control policies in practice describes the shared approach for control policies.

Review DLP Events

Under Reports > Endpoint & Server Protection Logs > Data Loss Prevention, the Event Log shows date and time, user, device, rule name, rule action, file name, and destination type. You can search by user, device, or rule and filter by rule name and file type. The selected period can cover no more than 90 days; CSV and PDF exports are limited to 5,000 Events per export.

An endpoint computer can send no more than 50 Data Control Events per hour to Sophos Fusion. All Events are also logged locally on the computer. During a high-volume incident, a flattening Sophos Fusion report therefore doesn’t prove that no further Events occurred.

Validate three outcomes separately before approval:

  1. The intended rule appears in the Event Log with the correct file name and destination type.
  2. The action matches the effective, strictest rule.
  3. Confirmation or block notification and the optional email behave as configured.

Troubleshoot without a premature exclusion

No Event appears: Check the effective policy and assignment, Use rules for data transfers, rule conditions, full file name and extension, file type, selected CCL, match count, and destination. Then repeat the same test with a known positive file.

Too many files match: For Content Rules, first check terms, expression, and match count against negative samples. For File Rules, narrow the names, wildcards, and type selection. A broad file exclusion would reduce control for every matching transfer in that rule.

The expected action isn’t enforced: Look for other matching rules in the same policy. As soon as a stricter rule matches, it wins regardless of the milder action in the rule you first inspected.

The rollout noticeably slows file transfers: Compare the number of rules, file sizes, and especially Content Rules in the pilot. Make one change at a time and measure the same test set again so cause and effect remain attributable.

Frequently asked questions

Is Endpoint DLP the same as Sophos Email Data Control?

No. They are separate features with their own policies and reporting. This article covers DLP for managed endpoints and Windows servers.

What happens when several DLP rules match the same file?

Sophos enforces the strictest action: blocking before user confirmation, and user confirmation before an allowed transfer.

Can I edit a SophosLabs CCL?

No. SophosLabs CCLs can be filtered and inspected, but not edited. Create a custom CCL for your own requirements, or clone a suitable custom CCL.