Sophos Endpoint network and proxy requirements
Sophos Fusion Endpoint requires outbound port 53 (DNS) and port 443 (HTTPS). On a network that denies outbound traffic by default, you must also allow the destinations relevant to the operating system and licensed features from the current Sophos “Domains and ports to allow” list. Sophos states that Sophos Firewall allows the required Fusion domains and ports by default, so this article is mainly for other firewalls and proxies.
The short path: Where the rule engine supports wildcards, allow the Sophos wildcards and the separately listed third-party hosts. Check whether *.sophos.com includes the apex domain sophos.com; if not, allow it separately. Then allow ports 53 and 443, choose the intended proxy path, and test installation, management, and updates from every relevant network. Static IP or country lists are not substitutes: Sophos uses AWS with non-static addresses and warns that regional firewall rules can override allowed destinations.
Domains to allow
For Endpoint, EDR, XDR, and MDR, Sophos documents these core wildcards:
*.sophos.com
*.sophosxl.com
*.sophosxl.net
*.sophosupd.com
*.sophosupd.net
*.hitmanpro.com
For Fusion Admin, Sophos lists fusion.sophos.com, cloud-assets.sophos.com, sophos.com, downloads.sophos.com, and login.sophos.com. Where wildcard syntax is supported, *.sophos.com already covers the subdomains, including login.sophos.com. Depending on the wildcard syntax, the apex domain sophos.com must be allowed separately. Also allow az416426.vo.msecnd.net and dc.services.visualstudio.com. If Certificate Authority destinations are not already permitted, Sophos also lists *.globalsign.com, *.globalsign.net, and *.digicert.com.
The required destinations also depend on the platform and license, for example XDR or MDR. Record the allowed destinations, operating systems, licenses, responsible person, and review date in the change. Recheck the current Sophos list against installer and network logs whenever the license, operating system, or agent changes and at least quarterly. Update the firewall and proxy together, then repeat the pilot test.
If wildcards are unavailable
Update on 9 October 2026: The Fusion Admin destinations were rechecked against the page revision dated 6 October 2026; login.sophos.com was added to the shared baseline. The September comparison mentioned below remains the historical review record, not evidence of when a product change occurred.
Without wildcards, use the following list as a starting point. It was checked on 25 September 2026 against the Sophos “Domains and ports to allow” source, last updated 14 September 2026. Check the current Sophos list before configuring the rules. These blocks cover Endpoint/EDR and the marked XDR/MDR features, but not Sophos AD Sync, for which Sophos requires wildcards. HTTPS uses port 443 and DNS uses port 53.
Check regions before allowing destinations: Do not restrict the listed MCS, RCA, and Live Terminal destinations to one region based solely on the device’s location. Installation-specific registration/API and MCS destinations must also be discovered from the respective installer (instructions below the lists). Observed AWS hosts may also need to be added. Regional blocking rules can override allowed destinations; allowing only your own country is therefore no substitute for the required domains.
Baseline for Windows, macOS, and Linux:
fusion.sophos.com
cloud-assets.sophos.com
sophos.com
downloads.sophos.com
login.sophos.com
az416426.vo.msecnd.net
dc.services.visualstudio.com
t1.sophosupd.com
sus.sophosupd.com
sdds3.sophosupd.com
sdds3.sophosupd.net
sdu-feedback.sophos.com
sophosxl.net
4.sophosxl.net
samples.sophosxl.net
cloud.sophos.com
id.sophos.com
Platform additions: Windows and macOS require sdu-auto-upload.sophosupd.com and ssp.sophos.com; Windows alone requires alert.hitmanpro.com, and macOS alone requires amazonaws.com. Windows and macOS also require these RCA upload destinations:
rca-upload-cloudstation-us-west-2.prod.hydra.sophos.com
rca-upload-cloudstation-us-east-2.prod.hydra.sophos.com
rca-upload-cloudstation-eu-west-1.prod.hydra.sophos.com
rca-upload-cloudstation-eu-central-1.prod.hydra.sophos.com
rca-upload.stn100bom.ctr.sophos.com
rca-upload.stn100yul.ctr.sophos.com
rca-upload.stn100hnd.ctr.sophos.com
rca-upload.stn100gru.ctr.sophos.com
rca-upload.stn100syd.ctr.sophos.com
MCS for all three platforms:
dzr-mcs-amzn-eu-west-1-9af7.upe.p.hmr.sophos.com
dzr-mcs-amzn-us-west-2-fa88.upe.p.hmr.sophos.com
mcs-cloudstation-eu-central-1.prod.hydra.sophos.com
mcs-cloudstation-eu-west-1.prod.hydra.sophos.com
mcs-cloudstation-us-east-2.prod.hydra.sophos.com
mcs-cloudstation-us-west-2.prod.hydra.sophos.com
mcs2-cloudstation-eu-west-1.prod.hydra.sophos.com
mcs2-cloudstation-eu-central-1.prod.hydra.sophos.com
mcs2-cloudstation-us-east-2.prod.hydra.sophos.com
mcs2-cloudstation-us-west-2.prod.hydra.sophos.com
mcs.stn100syd.ctr.sophos.com
mcs.stn100yul.ctr.sophos.com
mcs.stn100hnd.ctr.sophos.com
mcs.stn100gru.ctr.sophos.com
mcs.stn100bom.ctr.sophos.com
mcs2.stn100syd.ctr.sophos.com
mcs2.stn100yul.ctr.sophos.com
mcs2.stn100hnd.ctr.sophos.com
mcs2.stn100gru.ctr.sophos.com
mcs2.stn100bom.ctr.sophos.com
Windows and Linux additionally require the MCS push destinations:
mcs-push-server-eu-west-1.prod.hydra.sophos.com
mcs-push-server-eu-central-1.prod.hydra.sophos.com
mcs-push-server-us-west-2.prod.hydra.sophos.com
mcs-push-server-us-east-2.prod.hydra.sophos.com
mcs-push-server.stn100yul.ctr.sophos.com
mcs-push-server.stn100syd.ctr.sophos.com
mcs-push-server.stn100hnd.ctr.sophos.com
mcs-push-server.stn100gru.ctr.sophos.com
mcs-push-server.stn100bom.ctr.sophos.com
Intelix: All platforms require us.analysis.sophos.com, apac.analysis.sophos.com, au.analysis.sophos.com, and eu.analysis.sophos.com; Windows alone additionally requires analysis.sophos.com.
XDR/MDR: Only Windows and Linux devices with an XDR or MDR license require these Live Terminal destinations:
live-terminal-eu-west-1.prod.hydra.sophos.com
live-terminal-eu-central-1.prod.hydra.sophos.com
live-terminal-us-west-2.prod.hydra.sophos.com
live-terminal-us-east-2.prod.hydra.sophos.com
live-terminal.stn100yul.ctr.sophos.com
live-terminal.stn100syd.ctr.sophos.com
live-terminal.stn100hnd.ctr.sophos.com
live-terminal.stn100gru.ctr.sophos.com
live-terminal.stn100bom.ctr.sophos.com
Certificate Authorities: If not already allowed, all platforms require ocsp.globalsign.com, ocsp2.globalsign.com, crl.globalsign.com, crl.globalsign.net, ocsp.digicert.com, crl3.digicert.com, and crl4.digicert.com.
The regional registration and API destinations are installation-specific and must also be discovered:
- Windows: Open
C:\ProgramData\Sophos\CloudInstaller\Logs\SophosCloudInstaller.log, find lines beginning withOpening connection to, and allow the MCS and API domains found there (Sophos lists at least two entries). - macOS: Extract
SophosInstall.zip, openSophosInstall/Sophos Installer Components/SophosCloudConfig.plist, and allow the domain in the value followingRegistrationServerURL. - Linux: From the directory containing
SophosSetup.sh, run the installer withsudo bash -x ./SophosSetup.sh. Allow the domains shown on the+ CLOUD_URL=https://and+ MCS_URL=https://lines.
AWS hosts: Firewall or proxy logs may show reverse lookups for *.amazonaws.com. Sophos requires allowing these observed URLs as well. The explicitly listed macOS destination amazonaws.com does not allow every subdomain. Determine which AWS hosts are actually needed from the logs and review them in the change; static IP ranges do not replace this check.
When the license, platform, or agent changes, compare the current Sophos list linked above with the destinations here; do so at least quarterly as well. Record the source revision, review date, and changes in the change ticket, and update the language versions. Then rediscover the installation-specific destinations, update the firewall and proxy, and repeat the pilot test from every affected network.
Configure the proxy and understand priority
Go to Global Settings > Products and Services > Endpoint and Server > Proxy Configuration and turn on Proxy Configuration. Enter the hostname, port, and optional username and password. Alternatively, enter a PAC file URL in PAC Url, for example http://your.organization.com/pacfile.pac. Sophos cannot recover a stored proxy password, so clicking Save may overwrite an existing password.
Windows, macOS, and Linux devices use the first working configuration in this officially documented order:
- Sophos Central Message Relay
- proxy configured in Sophos Fusion (formerly Sophos Central)
- default system proxy
- Web Proxy Auto-Discovery (WPAD)
- connection without a proxy
WPAD is not supported on Linux. Because a later option can succeed as a fallback, successful communication alone does not prove that the intended proxy was used. In tightly controlled networks, deliberately restrict unwanted fallbacks and confirm the path in proxy or firewall logs.
Windows installation-time proxy parameters belong to the deployment workflow and are covered in Automate Sophos Endpoint rollout on Windows. See Sophos Endpoint updates, Cache and Message Relay for Update Cache and Message Relay.
Do not confuse TLS inspection with the allowlist
Allowing a domain and exempting it from TLS inspection are separate decisions. The Sophos pages reviewed here require the domains and CA destinations, but they do not document a blanket TLS-inspection exception for every listed wildcard. Do not copy the list unchecked into a global no-decrypt rule.
If a firewall or proxy intercepts HTTPS, the pilot must demonstrate that installation, management, and updates still work. If only the inspected path fails, first test a narrowly scoped inspection exclusion for the specific, currently documented Sophos destination involved. Limit any permanent exception to demonstrated destinations and review it whenever the owner list above changes. This avoids both claiming an unsupported blanket exception and assuming that agent communication works.
Validate communication
Test with a real pilot endpoint, not only an administrator’s browser, and repeat the test from every intended segment, VPN, and mobile network:
- DNS resolution and outbound connections on ports 53 and 443 to all required destinations are allowed.
- For rules without wildcards, installer-discovered registration and MCS destinations match the allow rules.
- The endpoint appears as managed in Sophos Fusion and receives policies.
- Updates and licensed features work over the intended path.
- Proxy or firewall logs show the expected proxy or message relay rather than an unintended fallback.
For failures, narrow the path in this order: DNS, TCP 443, proxy authentication, TLS inspection, domain allow rule, and Fusion service status. Compare repeated server errors for the exact time window with Sophos Central Status. If a matching incident is active, record its status, incident ID, and affected region in the ticket and pause local rule changes. Repeat the same pilot test after the all-clear; continue investigating the local path only if it still fails.