Configure Sophos Endpoint Peripheral Control
Peripheral Control manages access to peripherals and removable media on Windows and macOS endpoints. To avoid accidentally blocking required storage or a network adapter, start deployment in monitor mode and enforce controls only after a pilot.
Quick path
- Sign in to Sophos Fusion, then create or open and activate a Peripheral Control policy under My Products > Endpoint > Policies.
- Under Settings > Manage peripherals, first select Monitor but do not block (all peripherals will be allowed).
- Inventory detected devices and prepare required exceptions.
- Switch to Control access by peripheral type and add exemptions and set the required action for each device type.
- Assign the policy to a pilot group first and test both allowed and blocked devices.
⚠️ Secure network access first: Before setting Modem or Wireless to Block, make sure exceptions for required network adapters are effective and an alternative access path exists. Otherwise, the endpoint can lose contact with Sophos Fusion and may not receive a corrected policy.
The three operating modes
Exactly these states are available under Manage peripherals:
| Mode | Effect |
|---|---|
| Disable peripheral control | Peripherals are neither monitored nor blocked. |
| Monitor but do not block (all peripherals will be allowed) | All devices remain allowed; Sophos records detected peripherals. |
| Control access by peripheral type and add exemptions | Actions are enforced by device type; selected devices can receive less restrictive access. |
If an option is locked, Sophos states that the global setting was applied by a partner or Enterprise administrator. It cannot be overridden in this tenant policy.
Device types and available actions
Not every category supports Read Only. The current Sophos Fusion policy maps the fields as follows:
- Bluetooth: Allow or Block, but on Windows only. Peripheral Control does not block or control Bluetooth devices on macOS.
- Camera: Allow or Block. This category is unavailable on macOS.
- Secure removable storage, Floppy Drive, Optical Drive, and Removable storage: Allow, Read Only, or Block.
- Infrared, Modem, and MTP/PTP: Allow or Block. MTP/PTP includes phones, tablets, cameras, and media players connected with Media Transfer Protocol or Picture Transfer Protocol.
- Wireless: Allow, Block Bridged, or Block. Block Bridged prevents two networks from being bridged and generates no block alerts or events.
A policy tested on Windows is therefore not unchanged evidence of protection on macOS. Bluetooth and Camera in particular require separate consideration during macOS acceptance testing.
Configure the policy
- Go to My Products > Endpoint > Policies and create or edit the Peripheral Control policy.
- Check that the policy is active and open Settings.
- Under Manage peripherals, select Monitor but do not block (all peripherals will be allowed) for the observation period. Changes to individual device types are not enforced in this mode.
- Assign the policy to the pilot group and connect the peripherals actually in use. Only devices detected on managed endpoints or servers by a monitor policy appear later in the selection list for new exceptions.
- After the inventory, select Control access by peripheral type and add exemptions and set the appropriate action for every listed device type.
- Save and validate on the pilot devices before adding more groups.
A meaningful pilot should include at least one removable storage device to allow and one to block, an MTP/PTP device, and the Bluetooth, camera, and network devices actually used. The exact scope depends on the environment; the important point is to test every configured category at least once for both expected access and expected denial.
Create precise exceptions
Exceptions relax the general action of a device type for selected devices. They are not a way to block one device more strictly than its category: if an exception is more restrictive than the type rule, Sophos ignores it and displays a warning icon beside it.
- Open Peripheral Exemptions > Add Exemptions.
- Select one or more previously detected devices.
- In the Policy column, choose the less restrictive access action for the exempt device.
- Set the scope in Enforce By:
- Model ID applies to all peripherals that share the same Model ID.
- Instance ID applies to devices that share the same Instance ID and is normally the narrower choice.
- Confirm with Add Exemption(s) and test the exception on the pilot endpoint.
For one approved storage device, Instance ID is usually the safer starting point. Model ID is appropriate when a fully tested device model is approved as a standard fleet. The visible product name alone is insufficient; the identifier selected under Enforce By determines the scope.
Desktop Messaging on Windows
Desktop Messaging can only be customized or switched off for Windows computers and is on by default. Custom text is added to the standard notification; leaving the text box empty still shows the standard message. If Desktop Messaging is switched off, users see no Peripheral Control notification on the endpoint.
A useful addition can state the approval process, for example: This device is not approved. Open a ticket with the device name and business purpose. This wording is an operational recommendation and must be adapted to the organization’s support process.
Validate and operate the control
After the policy update, repeat every intended case on a pilot endpoint:
- a generally allowed device remains usable;
- a storage type set to Read Only allows reading but prevents a controlled write attempt;
- a blocked type cannot be used;
- each Model ID or Instance ID exception applies only to its intended scope;
- with Block Bridged, test network bridging directly because it generates no block alerts or events;
- Windows shows the expected desktop message when Desktop Messaging is active;
- the endpoint remains reachable in Sophos Fusion.
Document exceptions in the change system with a purpose, owner, and review date, and clean them up regularly. This metadata is an operational recommendation, not a set of fields in the Sophos policy described here.
Troubleshooting
A required device remains blocked: Compare the Model ID or Instance ID actually detected, the action in Policy, the Enforce By selection, and the general type action. Also verify that the correct policy is assigned to the test device and has arrived.
An unapproved device remains allowed: Check whether Monitor but do not block (all peripherals will be allowed) is still active. Device-type changes are not enforced as blocks in this state. Then look for an overly broad Model ID exception.
The policy setting is locked: Ask the responsible partner or Enterprise administrator to check the global setting.
The endpoint is offline after a network block: If no alternative network path or effective exception exists, Sophos warns that physical access may be required to override the policy locally and restore connectivity.
Related articles
The overall pilot strategy is in Introduce Sophos Endpoint Control policies in practice. Build Sophos Fusion Endpoint policies correctly explains priorities and targets.