Skip to content
Avanet

Configure Sophos Endpoint Peripheral Control

Peripheral Control manages device classes such as USB storage, Bluetooth, cameras, optical drives and wireless interfaces. An overly broad block can prevent data loss, but can also affect keyboards, mobile devices, diagnostic hardware or an endpoint’s only network connection.

Rollout therefore begins with Monitor but do not block. Events show which device types are actually used. Only then is each type allowed, set to read-only or blocked.

The three operating modes

The Peripheral Control policy has three basic states:

ModeEffect
Disable Peripheral Controlno control through this policy
Monitor but do not blockrecord use without restricting access
Control access by peripheral typeenforce an action per device type

Monitor mode is not a permanent security state, but the basis for a reliable policy. Under Reports > Events, it shows which devices were used by which user on which endpoint.

Device types and actions

Sophos distinguishes Bluetooth, camera, secure removable storage, floppy, infrared, modem, optical, removable storage, wireless and MTP/PTP devices, among others. Not every type offers the same actions. Read only is often useful for storage, while other classes can only be allowed or blocked.

Wireless has a particularly far-reaching option. In addition to Allow and Block, Block bridged can prevent a device from bridging a wireless and another network connection at the same time. Before fully blocking wireless or modem devices, an operational management connection must already exist. Otherwise the policy may cut the endpoint off from Sophos Central and the helpdesk.

According to Sophos, Block bridged does not generate alerts or events. Verify its effect with a controlled connectivity test rather than relying on the Central event list alone.

Platform behaviour differs. On macOS, Peripheral Control cannot block or control Bluetooth, and the camera is not available as a controllable device type. A policy validated on Windows must therefore not be used unchanged as evidence of macOS security.

On macOS, Wireless covers Apple AirPort devices only, not USB modems, Bluetooth tethering or smartphone tethering automatically. Peripheral Control also cannot block iPhones there, even when Removable Storage is blocked. For encrypted macOS removable storage, Read only does not work; the volume does not mount even with the correct password. If an authentication dialogue appears for a blocked encrypted medium, cancel it before removing the device because abruptly disconnecting it can cause instability.

⚠️ Secure network access first: Before blocking Wireless or Modem, create required device exceptions and test them on a pilot device. A policy must not remove the only connection through which its own correction would need to be delivered.

The Sophos class Secure Removable Storage does not automatically mean every encrypted or security-marketed USB device. Sophos maintains its own tested-device list. Even a new revision may be classified differently when hardware IDs or firmware change. Test the exact model in monitor mode before broad approval; the product name alone does not prove the classification.

Identify exceptions correctly

An exception can use Model ID or Instance ID. The choice determines its scope:

  • a Model ID allows every device of the same model
  • an Instance ID allows only the specific physical device

For particularly sensitive storage devices, Instance ID is narrower and usually more appropriate. For a standard approved device fleet, Model ID may be easier to administer.

If a specific exception is stricter than the general type rule, it is not used as an additional blocking mechanism. Sophos notes that a stricter single-device exception can be ignored relative to the type rule. Exceptions are used to relax a generally more restrictive type selectively.

Rollout model

After a sufficiently long observation period, assess Events by device type, user group and business process. This produces a small matrix: default action, approved models, individually approved devices and responsible team.

The first enforcing policy goes to a pilot group. A useful test includes at least one approved and one unapproved USB storage device, MTP/PTP through a mobile phone, Bluetooth, camera and the network adapters actually in use. On Windows, also test the desktop message. This message is not available identically on every platform.

MTP/PTP applies only to a physical connection. Transfers over Wi-Fi, for example through iTunes or vendor tools, are not controlled by Peripheral Control. A device can also switch between MTP/PTP and Mass Storage and then requires rules for both classes. When MTP/PTP is blocked, some smartphones can no longer charge over the USB port; this is expected behaviour and must be included in the pilot.

DVD ISO is blocked without an Event

On Windows, an Optical Drive rule also blocks mounting ISO files. A DVD ISO can be blocked without a visible Event. To obtain the virtual drive identity for an exception, briefly assign the affected test computer to a Monitor policy, mount a DVD ISO larger than 700 MB, then allow the current Optical Drive entry as a Model ID under Peripheral Exemptions. Remove the temporary Monitor policy afterwards.

If repeated mounting attempts fail with Couldn’t Mount File, orphaned Microsoft Virtual DVD-ROM entries in Device Manager may be involved. Uninstall them while hidden devices are displayed, then test the ISO again only after the exception is effective.

Forensics and operations

A Peripheral detected Alert initially means that a monitored peripheral was detected. It proves neither data loss nor successful blocking. Assess the associated Event, effective policy action and user context together.

Clean up exceptions regularly in operation. Lost USB devices, retired models and temporary project approvals must not remain indefinitely. An exception therefore has a purpose, owner and expiry date in the change system even if Sophos Central does not enforce all this metadata.

Troubleshooting

If an approved device remains blocked, first compare the actual Instance or Model ID, effective policy and parent type action. Docking stations and card readers can present several device instances. The visible product name alone is then insufficient.

If an unapproved device is not blocked, check whether the policy is still in monitor mode, whether the correct device type was selected and whether a broad Model ID exception applies. Then update the agent and generate a new Event instead of evaluating only an old entry.

The overall pilot strategy is in Introduce Sophos Endpoint Control policies in practice. Build Sophos Central Endpoint policies correctly explains priorities and targets.

Frequently asked questions

What is the difference between Model ID and Instance ID?

Model ID covers every device of the same model. Instance ID applies only to the specific physical device and is therefore narrower.

Can Peripheral Control interrupt the network connection?

Yes. Blocking Wireless or Modem can remove the only management connection. Test required exceptions and an alternative access path before blocking.