Configure Sophos Endpoint Web Control
Sophos Central provides two configuration models for Endpoint Web Control. The current model uses reusable Web Filtering Profiles. Classic Web Control remains relevant for older Windows agents and platforms that do not support the new profile model.
This distinction is crucial for operations. A correctly configured new policy does not affect a Mac or Windows endpoint with an older agent. Conversely, Base Policy can contain both configurations and provide a fallback.
New profile or Classic?
The current Web Profile model is intended for Windows Endpoint 2026.1 or later. Web Filtering Profiles are currently available only on Windows. macOS and Linux continue to use supported Classic settings.
A Custom Policy uses either the new profile or Classic. Base Policy can contain both parts. The agent then uses the variant suitable for its platform and version.
Before migration, inventory operating system, agent version and effective policy. Move a Custom Policy entirely to the new model only after the target supports it.
Build a Web Filtering Profile
Create a profile under Global Settings > Protection & Remediation > Web Settings > Web Filtering Profiles. Sophos allows up to 20 profiles per tenant. A profile can filter by categories and custom Site Lists.
Preconfigured category levels include Keep it clean, Gentle guidance, Conserve bandwidth and Business only. Let me specify sets Allow, Warn or Block per category.
Site Lists take priority over category decisions. A list can contain domains, URLs, IP addresses or CIDR ranges. One Site List contains up to 750 entries and one profile up to 20 lists. Their order in the profile determines priority.
A new profile has no automatically suitable organisational baseline. Categories, Site Lists and actions must be chosen deliberately and then used in a Web Control policy.
Use Website Management correctly
Website Management solves two other tasks: custom tags for sites and a tenant-wide category correction. A domain entry includes subdomains without requiring a wildcard. Up to 5,000 tags can be created.
A Category Override cannot allow a page classified by Sophos as Malware, Phishing, Hacking or Command-and-Control. If the Sophos category is wrong, reclassification through Sophos is cleaner. A Website Exclusion bypasses Web Control checks and has a much wider security impact.
Web-based JavaScript cryptominers are blocked through the Hacking category. This blocks the entire category, not only miners. If a business application requires miner-like JavaScript, first establish the exact URL and business need; any approval is narrow and documented rather than allowing Hacking globally.
HTTPS and warning pages
Warnings in the new Web Profile model require HTTPS decryption, which is enabled in the effective Threat Protection policy. HTTPS Decryption is off by default for endpoints.
With decryption, Sophos can see full URLs and content and send samples to SophosLabs after a detection. Privacy, internal requirements and sensitive categories are therefore reviewed before activation. Global HTTPS exclusions protect specific categories and sites from decryption. Checks requiring decrypted content do not apply to excluded destinations.
On Windows, HTTPS decryption moves the data stream from Windows Filtering Platform in the kernel to a Sophos process in user space. There it is decrypted, inspected and encrypted again. This requires CPU, memory and additional cloud queries. Older processors and slow storage can therefore lose disproportionately more throughput. If the issue affects only individual websites or remains unchanged with decryption disabled, however, this general performance cause has not been proven.
Firefox uses its own certificate store and can use its own DNS over HTTPS. On Windows, security.enterprise_roots.enabled must be true so Firefox trusts the Windows certificate store. For reliable SNI-based checking, also verify that Firefox follows managed DNS requirements.
For an internal HTTPS site with a self-signed or otherwise untrusted server certificate, the browser can show a different certificate error after HTTPS decryption is enabled. The permanent fix is a trusted server certificate and complete chain. Disabling decryption or adding a broad Website Exclusion only hides the trust problem and weakens inspection.
Classic Web Control
Classic provides additional security options, predefined Acceptable Use levels and Data Sharing controls. Schedules are not available in Base Policy. Where a schedule is used, it follows the endpoint’s local time.
Endpoint Web Control is user-based. After a user change, the new user policy can take about five minutes. During this transition, the previous user’s policy may still apply. Therefore check computer state, Central user mapping and the locally signed-in account together.
On macOS, Sophos Endpoint currently cannot filter or block IPv6 web traffic. A successful IPv4 test therefore does not prove the same access is controlled over IPv6.
Pilot and acceptance
A Web Control pilot checks an allowed, warned and blocked category, a higher-priority Site List, an HTTPS page and a global exclusion. It also tests Chrome, Edge and Firefox, plus IPv4 and, where relevant, IPv6.
Under Reports > Events, verify which policy and action actually triggered. A visible browser page alone is insufficient: browser cache, Secure DNS, proxy and QUIC can change the observed path.
For a safe functional test, use the Sophos test site sophostest.com. On Windows, C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\SophosNetFilter.log shows the URL category and action used and whether access was decrypted. On macOS, the Web Intelligence action is in /Library/Logs/Sophos Anti-Virus.log.
Without HTTPS decryption, Sophos often sees only the server name from SNI for HTTPS, not the complete path. A warning page then cannot be inserted into the encrypted content and the browser may show only a general connection error. Exact URL rules are also case-sensitive. A test with a complete HTTPS path must therefore not be interpreted like a domain-only rule.
Interpret multiple Sophos web controls correctly
Endpoint Web Control remains a separate product module. If DNS Protection for endpoints, Protected Browser or a network firewall also filters, the first block determines access. The displayed block page can nevertheless come from a later control: DNS Protection, for example, redirects to a block-page server whose browser request can then also be blocked by Endpoint Web Control.
In simplified terms, Sophos checks DNS Protection first, then Endpoint Web Control, Protected Browser and finally network or firewall filtering. A later Allow cannot undo an earlier block. Different block pages therefore prove neither that an earlier layer was inactive nor that the Endpoint policy alone caused the issue. Troubleshooting must examine the Events and policies of every layer actually in use separately.
Common errors
If a page is unexpectedly allowed, first check Site List priority, global Website Exclusions, Category Override and effective policy. If a warning page is missing, check HTTPS Decryption, certificate trust and browser support.
If only Firefox is affected, check its trust store and DNS over HTTPS. If only Macs are affected, also consider IPv6. A broad Website Exclusion is not a diagnostic method because it removes the controls being investigated.
Different handling of risky file types does not necessarily indicate a policy error. Sophos can assess known trusted sources differently from unknown sources through reputation. For encrypted downloads, this check also requires suitable HTTPS decryption. Measure its performance impact with pilot devices.
If an allowed website loads only partially, scripts, stylesheets, images or sign-in components often come from additional domains. Use the Network Threat Protection log and browser developer tools to identify each required destination instead of allowing a broad parent category.
If Web Protection must briefly be disabled to isolate the cause, use a separate policy for individual test devices with an owner, start and end time. Do not disable the Base Policy tenant-wide. Re-enable protection immediately after the comparison test and preserve the relevant events and logs.
Related articles
HTTPS Decryption is part of Sophos Endpoint Threat Protection best practices. Introduce Sophos Endpoint Control policies in practice provides the overall rollout process.