Configure Sophos Endpoint Peripheral Control
Peripheral Control manages device classes such as USB storage, Bluetooth, cameras, optical drives and wireless interfaces. An overly broad block can prevent data loss, but can also affect keyboards, mobile devices, diagnostic hardware or an endpoint’s only network connection.
Rollout therefore begins with Monitor but do not block. Events show which device types are actually used. Only then is each type allowed, set to read-only or blocked.
The three operating modes
The Peripheral Control policy has three basic states:
| Mode | Effect |
|---|---|
| Disable Peripheral Control | no control through this policy |
| Monitor but do not block | record use without restricting access |
| Control access by peripheral type | enforce an action per device type |
Monitor mode is not a permanent security state, but the basis for a reliable policy. Under Reports > Events, it shows which devices were used by which user on which endpoint.
Device types and actions
Sophos distinguishes Bluetooth, camera, secure removable storage, floppy, infrared, modem, optical, removable storage, wireless and MTP/PTP devices, among others. Not every type offers the same actions. Read only is often useful for storage, while other classes can only be allowed or blocked.
Wireless has a particularly far-reaching option. In addition to Allow and Block, Block bridged can prevent a device from bridging a wireless and another network connection at the same time. Before fully blocking wireless or modem devices, an operational management connection must already exist. Otherwise the policy may cut the endpoint off from Sophos Central and the helpdesk.
According to Sophos, Block bridged does not generate alerts or events. Verify its effect with a controlled connectivity test rather than relying on the Central event list alone.
Platform behaviour differs. On macOS, Peripheral Control cannot block or control Bluetooth, and the camera is not available as a controllable device type. A policy validated on Windows must therefore not be used unchanged as evidence of macOS security.
On macOS, Wireless covers Apple AirPort devices only, not USB modems, Bluetooth tethering or smartphone tethering automatically. Peripheral Control also cannot block iPhones there, even when Removable Storage is blocked. For encrypted macOS removable storage, Read only does not work; the volume does not mount even with the correct password. If an authentication dialogue appears for a blocked encrypted medium, cancel it before removing the device because abruptly disconnecting it can cause instability.
⚠️ Secure network access first: Before blocking Wireless or Modem, create required device exceptions and test them on a pilot device. A policy must not remove the only connection through which its own correction would need to be delivered.
The Sophos class Secure Removable Storage does not automatically mean every encrypted or security-marketed USB device. Sophos maintains its own tested-device list. Even a new revision may be classified differently when hardware IDs or firmware change. Test the exact model in monitor mode before broad approval; the product name alone does not prove the classification.
Identify exceptions correctly
An exception can use Model ID or Instance ID. The choice determines its scope:
- a Model ID allows every device of the same model
- an Instance ID allows only the specific physical device
For particularly sensitive storage devices, Instance ID is narrower and usually more appropriate. For a standard approved device fleet, Model ID may be easier to administer.
If a specific exception is stricter than the general type rule, it is not used as an additional blocking mechanism. Sophos notes that a stricter single-device exception can be ignored relative to the type rule. Exceptions are used to relax a generally more restrictive type selectively.
Rollout model
After a sufficiently long observation period, assess Events by device type, user group and business process. This produces a small matrix: default action, approved models, individually approved devices and responsible team.
The first enforcing policy goes to a pilot group. A useful test includes at least one approved and one unapproved USB storage device, MTP/PTP through a mobile phone, Bluetooth, camera and the network adapters actually in use. On Windows, also test the desktop message. This message is not available identically on every platform.
MTP/PTP applies only to a physical connection. Transfers over Wi-Fi, for example through iTunes or vendor tools, are not controlled by Peripheral Control. A device can also switch between MTP/PTP and Mass Storage and then requires rules for both classes. When MTP/PTP is blocked, some smartphones can no longer charge over the USB port; this is expected behaviour and must be included in the pilot.
DVD ISO is blocked without an Event
On Windows, an Optical Drive rule also blocks mounting ISO files. A DVD ISO can be blocked without a visible Event. To obtain the virtual drive identity for an exception, briefly assign the affected test computer to a Monitor policy, mount a DVD ISO larger than 700 MB, then allow the current Optical Drive entry as a Model ID under Peripheral Exemptions. Remove the temporary Monitor policy afterwards.
If repeated mounting attempts fail with Couldn’t Mount File, orphaned Microsoft Virtual DVD-ROM entries in Device Manager may be involved. Uninstall them while hidden devices are displayed, then test the ISO again only after the exception is effective.
Forensics and operations
A Peripheral detected Alert initially means that a monitored peripheral was detected. It proves neither data loss nor successful blocking. Assess the associated Event, effective policy action and user context together.
Clean up exceptions regularly in operation. Lost USB devices, retired models and temporary project approvals must not remain indefinitely. An exception therefore has a purpose, owner and expiry date in the change system even if Sophos Central does not enforce all this metadata.
Troubleshooting
If an approved device remains blocked, first compare the actual Instance or Model ID, effective policy and parent type action. Docking stations and card readers can present several device instances. The visible product name alone is then insufficient.
If an unapproved device is not blocked, check whether the policy is still in monitor mode, whether the correct device type was selected and whether a broad Model ID exception applies. Then update the agent and generate a new Event instead of evaluating only an old entry.
Related articles
The overall pilot strategy is in Introduce Sophos Endpoint Control policies in practice. Build Sophos Central Endpoint policies correctly explains priorities and targets.