Skip to content
Avanet

Configure Sophos DNS Protection for endpoints

Sophos DNS Protection is a separate product in Sophos Fusion (formerly Sophos Central). The Endpoint policy described here is its officially documented integration with Sophos Endpoint: the Endpoint agent intercepts DNS requests and forwards them to DNS Protection over HTTPS. Filtering therefore remains active away from the corporate network without manually changing the device’s DNS servers.

This integration is neither a standard Endpoint protection policy nor the same as Web Control. DNS Protection makes domain-based decisions through its own Filtering policy. Web Control uses separate Endpoint web policies. The firewall integration follows another DNS path and is covered in Sophos DNS Protection with Sophos Firewall.

Check the requirements first

The workflow currently documented by Sophos requires:

  • a Windows 10 or Windows 11 endpoint with an Intel or ARM processor; Windows Server and macOS cannot currently be added to this policy,
  • an installed Sophos Endpoint Agent,
  • access to DNS Protection in the tenant,
  • HTTPS connectivity from the endpoint to DNS Protection,
  • the current Windows > Recommended software package.

The tenant needs a Workspace Protection entitlement for DNS Protection for endpoints; usage is counted by the devices protected with DNS Protection. Xstream Protection for Sophos Firewall covers standalone DNS Protection only and does not entitle this Endpoint route. Sophos Endpoint must also be present; Workspace Protection alone does not include full Endpoint protection unless the combined bundle was purchased. Sophos Fusion licensing explains this boundary and consumption model.

Assign administrators only the DNS Protection permissions they need, following the principle of least privilege. Sophos Fusion administrative roles explains how to scope role access.

Before each rollout, open My Products > Endpoint > Policies > Update Management > Base Policy - Update Management > Settings > Select a software package, select Windows > Recommended, and verify that this package is assigned to the pilot devices. If the Endpoint Agent is not yet installed, first follow Get started with Sophos Endpoint. This package requirement applies to the managed Endpoint route described here, not to devices configured manually with DNS server addresses or a DoH template.

Install the agent component

  1. Open My Products > Endpoint > Computers.
  2. Select the Windows computers for the pilot group.
  3. Select Manage Endpoint Software.
  4. Set DNS to Install. With a ZTNA licence, the entry is called DNS & ZTNA.
  5. Select Save.

Do not proceed immediately to the full estate. First verify in Sophos Fusion that the software assignment has reached the pilot devices and that no installation warning remains. An existing Endpoint installation alone does not prove that the DNS component has been assigned.

How a DNS request is handled

  1. Sophos Endpoint intercepts DNS traffic, except for explicitly excluded domains.
  2. All other requests are securely forwarded to DNS Protection over HTTPS.
  3. DNS Protection returns its responses directly to the requesting application.
  4. Requests for excluded domains go to the system- or application-configured DNS service.
  5. Optionally, the local DNS service can retry a name when DNS Protection returns NXDOMAIN because it cannot be resolved publicly.

Without the DNS Protection integration enabled, the local DNS service handles requests as before.

Keep the operating models separate: manually connecting Windows to DNS Protection is an alternative and must not also be deployed as an apparent fallback on the same devices. Architecture, ports and bypass controls belong in the network planning guide; the central DNS route through SFOS belongs in the firewall guide. This article remains focused on the managed Endpoint route.

Choose the Secure DNS location

DNS Protection groups devices and networks into Locations. For endpoint devices, the selected Location must use Secure DNS as its connection method. The non-editable Default location meets this requirement, or you can create a separate Secure DNS Location in DNS Protection.

A separate Location is useful when a pilot group, region or organisational unit needs different filtering. It does not replace careful selection of computers or computer groups in the Endpoint policy. Follow Manage Sophos DNS Protection Locations safely when creating, changing or retiring a custom Endpoint Location, and keep Secure DNS as its connection method.

Create the Endpoint policy

The current, officially documented entry point is My Products > DNS Protection > Policies > Endpoint policies. The older My Products > Endpoint > Policies entry point remains available; for an unambiguous operating path, however, this guide uses the DNS Protection entry point. In the DNS Protection menu, the two policy types are called Endpoint policies and Filtering policies.

  1. Select Add policy.
  2. Add the intended computers or computer groups.
  3. Under Policy Active, verify that Policy is Active is turned on. It is on by default for a new policy.
  4. Open Settings.
  5. Turn on Use Sophos DNS Protection.
  6. Select the Default location or a custom Location that uses Secure DNS.
  7. Add internal domains under Domains.
  8. Decide whether the system- or application-configured DNS service should retry after NXDOMAIN.
  9. If block pages are required, configure automatic certificate deployment.
  10. Save and validate only with the pilot group first.

Check the effective assignment on a device. Seeing the policy in the portal is not, by itself, proof that it applies to the device.

Handle internal DNS zones safely

For internal zones such as corp.example, Active Directory zones and split-DNS namespaces, Sophos recommends explicit Domain exclusions. All subdomains of an entered domain are excluded automatically. Requests therefore go directly to the intended system- or application-configured DNS service.

Retry with system- or application-configured DNS services when DNS Protection returns NXDOMAIN is a fallback for names that cannot be resolved publicly. Sophos still recommends a maintained exclusion list for the best performance. The retry option should therefore not replace a complete inventory of internal zones.

Block pages and certificate

Automatically deploy the DNS Protection signing certificate to devices automatically installs the required root certificate on target devices. Only then can a browser show the Sophos block page for a blocked HTTPS domain without a certificate warning.

Test certificate deployment in the pilot group first, particularly for browsers with their own trust store or restrictive certificate policies. A missing block page does not prove that DNS Protection allowed the domain: Sophos states that a block returns the IP address of its block-page server instead of the destination address. Also check the policy match and DNS Protection logs.

Adjust filtering for the pilot if required

The Endpoint policy associates devices with the Location. The separate DNS Protection Filtering policy determines which domains are allowed or blocked. By default, DNS Protection blocks domains with a poor threat score or dangerous reputation even when no Filtering policy is assigned or a Domain List allows the domain. Custom category decisions must therefore not be treated as a malware bypass.

If a suitable Filtering policy already exists for the pilot, no further configuration is required here. Otherwise, the following optional assignment is sufficient:

  1. Under My Products > DNS Protection > Domains, use Add domain list to create a custom list if required. Use Name and Description to describe its purpose, for example Pilot – permitted business services.
  2. Under Domains, enter the required domains individually or paste them one per line, and accept each entry with Enter or Tab. A list can contain no more than 1,000 domains, and no more than 100 Domain Lists can exist in total. An entry such as example.com also covers its subdomains, whereas www.example.com does not cover the other subdomains of example.com.
  3. Under My Products > DNS Protection > Policies > Filtering policies, open the Filtering policy assigned to the Endpoint Location. DNS Protection permits no more than 50 Filtering Policies and only one policy assigned to each Location.
  4. Set category groups or individual categories to Allow, Block or Specify as appropriate. A Domain List can be explicitly allowed or blocked in the same policy.
  5. Save and verify in the pilot that the test domains appear under the expected Location with the expected Allow or Block decision.

These figures are documented maximum limits, not recommendations. Create lists and policies only when your own filtering requires them. The complete creation, assignment, pilot and rollback workflow is covered in DNS Protection Filtering policies. This article only verifies that the endpoint reaches the intended Location and therefore the intended Filtering policy.

Internal domains may require two different controls:

  • A Domain exclusion in the Endpoint policy sends a name that is only resolvable internally to the local DNS service.
  • An allow Domain List in DNS Protection can prevent an otherwise publicly resolvable corporate domain from being affected by an unsuitable category decision.

A Domain List does not replace a Domain exclusion for private DNS zones.

Pilot and validation

The pilot group should cover at least:

  • one allowed and one deliberately blocked public test domain,
  • internal short names and FQDNs,
  • office, home-working and VPN connections,
  • browsers and applications with their own Secure DNS or DNS-over-HTTPS configuration,
  • the block page and trust in the signing certificate,
  • behaviour when the service cannot be reached or the HTTPS connection is blocked.

Success means that intended public requests appear under the expected Location and are evaluated by the expected Filtering policy, internal exclusions continue to resolve through local DNS, and pilot devices do not lose business-critical name resolution.

Evaluate logs and reports

According to Sophos, data under DNS Protection > Logs & Reports is 15 to 25 minutes behind real time. Changes to Location or policy names may take 30 minutes to four hours to appear. Allow for these delays during pilot validation.

DNS usage shows DNS requests across the network. DNS usage by source breaks them down by Location and, for Sophos Endpoint, also shows users and devices. High risk devices helps identify devices requesting risky, suspicious or insecure domains. This provides stronger evidence of the Endpoint assignment than the public IP address alone.

For saved templates, export limits, retention and Live Discover, use the full DNS Protection reports and Live Discover runbook. The notes below are sufficient for immediate pilot acceptance but do not replace that reporting workflow.

To narrow the results, first select the field or column under Query, then choose the operator and enter the comparison value. Add further filters in the same way; a row is shown only when it meets every condition, so the filters are combined with AND. Then select Generate. For text values, =, != and IN are case-sensitive. The wildcard operators ~ and !~, which use *, are not case-sensitive; <, <=, > and >= apply only to numeric values.

Bar and pie charts show only the top ten categories. Use the filtered table and its export as well when you need the complete result set. Be explicit about export scope: an export of the current view applies the selected time range and active Query filters. An export for the past 90 days instead ignores the time range selected in the view and applies only the Query filters to that fixed 90-day window.

Saved Templates preserve the report configuration, not generated data or the selected time range. Exports have different row and column limits depending on format, and exported files are deleted after 90 days. Incident data therefore needs separate retention outside this temporary export area.

Check Endpoint state and package data

For a fault, separate three questions first: is the DNS software assigned, does the Endpoint policy apply to the device, and does DNS resolution behave as intended? Sophos Fusion status and Endpoint Self Help can show general Endpoint health. Sophos does not document a DNS-specific health check, local service, process, log path or error code there. A green Endpoint state therefore does not prove DNS interception; use the functional tests and DNS usage by source as the evidence.

Record the package and release

Under Global Settings > Products and Services > Endpoint and Server > Software packages, Package details and Package notes show modules and versions for a complete Endpoint package. For an incident, record the assigned Windows > Recommended package, its details, the change time and affected pilot devices. Also check the DNS Protection release notes for relevant changes and known issues.

This is not proof of a separate DNS agent version. Sophos currently publishes neither a distinct local DNS component version nor a component-specific downgrade. Do not report a Core Agent version as the DNS version. Special packages are Support fixes supplied with a token from Sophos Support; never use a third-party token or treat one as a self-selected DNS rollback.

Troubleshoot common problems

The device cannot be added

Check the operating system and device type first. The current Sophos documentation only permits Windows endpoints, not Windows Server or macOS devices. Then check the Endpoint agent, DNS software component and access to DNS Protection.

Internal names do not resolve

Add the affected zone as a Domain exclusion. Then check the local DNS server, search suffix, VPN DNS settings and the policy that actually applies to the endpoint. A broad NXDOMAIN retry can help diagnosis, but does not replace a correct zone list.

The block page shows a certificate error

Verify that Automatically deploy the DNS Protection signing certificate to devices is enabled and that the pilot device trusts the root certificate. Browsers with their own trust store may need additional management.

The browser appears to bypass the policy

Browsers and applications may use their own DNS-over-HTTPS route. Check the resolver actually in use and the policy assignment first. A single browser test without this evidence is not enough to conclude that the Endpoint agent or DNS Protection has failed.

The symptom belongs to the network or Location route

Multiple configured resolvers, a separate IPv6 DNS server, DNS hijacking by the ISP, a private Location address or a Location FQDN that no longer resolves are faults in the standalone network/Location route. They are not fixed by changing the Endpoint policy. First use DNS usage by source to determine whether the affected request comes from the Endpoint Location with a user and device. If this assignment is missing and resolution instead occurs through a network Location, continue with the DNS Protection network planning guide. Location alerts appear under My Environment > Alerts.

Manual DNS settings and the Endpoint policy apply together

Do not run manually entered Sophos resolvers or a DoH template as a fallback alongside the Endpoint policy. Domain exclusions and the NXDOMAIN retry go to the system- or application-configured DNS service; if that service points back to DNS Protection, it creates a second route that is difficult to diagnose. Follow the rollback in the Windows manual setup guide to restore DHCP or the corporate resolver, then test again.

An allowed domain remains blocked

Check the threat score, reputation, category and possible CNAME targets. According to Sophos, the default security block cannot be overridden with a Domain List. Submit a demonstrably incorrect classification for recategorisation rather than creating increasingly broad allow lists.

Escalate and collect handover data

Escalate to Sophos Support when the assignment does not arrive even though the device is online and successfully contacts the update service, reproducible DNS failures produce no matching events after the reporting delay, or several pilot devices on the same package are affected. Provide:

  • device ID, Windows version, timestamp with time zone, and the affected network connection;
  • effective Endpoint policy, Location, Filtering policy, Domain exclusions and retry setting;
  • package name, Package details, Package notes and relevant Sophos Fusion alerts;
  • test domain, expected and actual result, application and resolver used;
  • matching DNS usage by source entries, or the documented absence of an entry;
  • rollout and change times, plus relevant release-note entries.

If Sophos Fusion reports missing services, update failures or general Endpoint faults, first narrow them down with Sophos Endpoint for Windows: logs and services. A generic Endpoint action is only a DNS solution when Sophos confirms it for the case and the subsequent functional DNS test succeeds.

Roll back in a controlled manner

Turn off Use Sophos DNS Protection in the affected Endpoint policy or remove the pilot devices from its assignment. On a pilot device, then verify that the system- or application-configured resolvers are used again and that both internal and public names work.

Do not infer DNS-only repair or removal

There is no public separate repair, uninstall or local diagnostic workflow for the Endpoint DNS component. Do not restart assumed services, delete files, invent installer parameters or reinstall the Endpoint agent as a DNS repair. The safe immediate rollback remains turning off Use Sophos DNS Protection or removing devices from the policy.

Do not change the software assignment as a precaution. Its label may be DNS & ZTNA, because it can be shared with ZTNA. Before any later component change, verify ZTNA use and follow the tenant-confirmed process in Manage Sophos Endpoint Agent Mode and software. Selecting an older Endpoint package is not a proven DNS-only rollback either.

For complete decommissioning, remove the devices from the Endpoint policy and confirm the disabled state in the pilot. Do not change the DNS software component as part of the immediate rollback: Sophos documents its installation in this workflow, but not a separate removal action. It is also shared with ZTNA when named DNS & ZTNA. Plan any later software cleanup only through a Sophos Endpoint software process confirmed for the tenant, after verifying that the device does not require ZTNA.

Remove the deployed root certificate only after DNS rollback has succeeded and through the intended managed certificate process. Turning off the automatic option or removing the policy assignment does not prove that an already installed root has disappeared. Deploy the DNS Protection Root Certificate covers distribution, validation and fingerprint-specific cleanup; manual one-device cleanup is not a suitable rollback for a larger estate.

Frequently asked questions

Is DNS Protection part of Sophos Endpoint?

No. DNS Protection is a separate product in Sophos Fusion. The Endpoint policy is the documented integration through which Sophos Endpoint forwards DNS traffic to that product.

Does the Endpoint integration support macOS or Windows Server?

No. According to the current Sophos documentation, only Windows endpoints can be added; Windows Server and macOS are not currently supported.

How should internal DNS zones be handled?

Add explicit Domain exclusions so that the system- or application-configured DNS service resolves them.