Configure Sophos Endpoint Web Control
Sophos Fusion (formerly Sophos Central) provides two configuration models for Endpoint Web Control. The current model uses reusable Web Filtering Profiles. Classic Web Control remains relevant for older Windows agents and macOS.
The safe workflow is to inventory target devices and agent versions, build a Web Filtering Profile, assign a small user- or device-based pilot policy, enable logging, and test one allowed, warned, and blocked request. Extend the assignment only after acceptance. Global Website Exclusions are not a substitute for targeted Site Lists or tags.
This distinction is crucial for operations. A correctly configured new policy does not affect a Mac or Windows endpoint with an older agent. Conversely, Base Policy can contain both configurations and provide a fallback.
New profile or Classic?
The current Web Profile model is intended for Windows Endpoint 2026.1 or later. Web Filtering Profiles are currently available only on Windows, not on Linux or macOS. Sophos identifies Classic primarily for macOS and Windows Endpoint 2025.2.3.8 or earlier.
A Custom Policy uses either the new profile or Classic. Base Policy can contain both parts. The agent then uses the variant suitable for its platform and version.
Before migration, inventory operating system, agent version and effective policy. Move a Custom Policy entirely to the new model only after the target supports it.
Build a Web Filtering Profile
Create a profile under Global Settings > Protection & Remediation > Web Settings > Web Filtering Profiles. The admin role needs Manage web profiles. Sophos allows up to 20 profiles per tenant. A profile can filter by categories and custom Site Lists at the same time.
Current category choices are Keep it clean, Optimal productivity, Block generative AI, Conserve bandwidth, and Business only. With Custom, set Allow, Warn, Block, or Let me specify for each group; Let me specify exposes the individual categories. Before choosing, use View Details to see what each level actually controls.
Site Lists take priority over category and file-type decisions. A list can contain domains, URLs, IP addresses, or CIDR ranges; press Enter or Tab after every item. According to Sophos, example.com and *.example.com match all domains ending in example.com, without http:// or https://. One Site List contains up to 750 entries and one profile up to 20 lists. Their top-to-bottom order determines priority.
A new profile has no automatically suitable organisational baseline. Categories, Site Lists and actions must be chosen deliberately and then used in a Web Control policy.
Create and assign the policy
- Go to My Products > Endpoint > Policies and click Add policy.
- Select Web Control as Feature and choose User or Device as Type, depending on the target. Changing assigned objects later is not a substitute for choosing the correct type.
- Enter an unambiguous name such as
WC-Pilot-Windows-Profileand assign only the pilot group on Users or Computers. - On Settings, select Web profile as policy type and choose the prepared profile. Optionally apply different profiles at different times.
- Configure Risky File Types deliberately. Recommended is the safe starting point; Allow, Warn, Block, or Let me specify require a documented business reason. You cannot add custom file types.
- Turn on Log web control events and save. Without it, Sophos only logs attempts to visit infected sites, not all block and warning attempts.
An additional custom policy contains either Web profile or Classic settings, never both. Only Base Policy can contain both configurations. If its Web Profile cannot be applied to a device, Base Policy falls back to Classic.
Use Website Management correctly
Website Management solves two other tasks: custom tags for sites and a tenant-wide category correction. Under Global Settings > Protection & Remediation > Web Settings > Website Management > Add, an entry can contain single URLs, full domains, IP addresses, CIDR ranges, or top-level domains. A domain entry includes subdomains without requiring a wildcard. Up to 5,000 tags can be created. A comment with owner and ticket number makes later reviews easier.
Website Management tags belong to the Classic Web Control workflow. The new Web Profile model controls custom destinations through Site Lists in the Web Filtering Profile instead:
- Go to Global Settings > Protection & Remediation > Web Settings > Website Management > Add, enter the destinations, select a new or existing tag under Add tags, and click Save.
- Go to My Products > Endpoint > Policies > Web Control, open a policy that uses Classic settings, and select Settings.
- Under Control sites tagged in Website Management > Add New, select the tag, set Action to Allow, Warn, or Block, then click Save in the dialog and again for the policy.
A Category override changes the Sophos category tenant-wide, but cannot allow a site classified as phishing, malware, hacking, or command-and-control. If the Sophos category is wrong, Sophos recommends a support case for reclassification. A tag groups destinations so a policy can control them selectively. A global Website Exclusion bypasses Web Control checks and has a much wider security impact. IP-based Website Management entries control browser access only, not other applications or local firewall rules.
Web-based JavaScript cryptominers are blocked through the Hacking category. This blocks the entire category, not only mining code, so test the change in a pilot policy first. If one business-justified site must remain accessible, give it a dedicated tag in Website Management and allow it selectively in the affected Web Control policy. Sophos classifies such cryptominers as parasitic malware; approval remains a documented exception, not a recommended baseline.
HTTPS and warning pages
Warnings in the new Web Profile model require HTTPS decryption. Enable SSL/TLS decryption of HTTPS websites in the effective Threat Protection policy under My Products > Endpoint > Policies. HTTPS Decryption is off by default for endpoints.
With decryption, Sophos can see full URLs and content and send samples to SophosLabs after a detection. Review privacy, internal requirements, and sensitive categories before activation. The predefined excluded categories can be turned on or off but cannot be added or removed; individual domains, IP addresses, and ranges can be added. Download scanning and risky-file checks that need decrypted content do not apply to excluded destinations. Checks that do not need decryption remain possible.
On Windows, HTTPS decryption moves the data stream from Windows Filtering Platform in the kernel to a Sophos process in user space. There it is decrypted, inspected and encrypted again. This requires CPU, memory and additional cloud queries. Older processors and slow storage can therefore lose disproportionately more throughput. If the issue affects only individual websites or remains unchanged with decryption disabled, however, this general performance cause has not been proven.
Firefox uses its own certificate store and can use its own DNS over HTTPS. On Windows, security.enterprise_roots.enabled must be true so Firefox trusts the Windows certificate store. For reliable SNI-based checking, also verify that Firefox follows managed DNS requirements.
For an internal HTTPS site with a self-signed or otherwise untrusted server certificate, the browser can point to the Sophos RSA root certificate after HTTPS decryption is enabled. This does not automatically mean the Sophos certificate is faulty: Sophos rebuilds the connection but preserves the origin server’s invalid trust status. Fix the website’s certificate chain or its trust on endpoints. A decryption exclusion deliberately accepts less control and must be narrowly scoped.
Classic Web Control
Classic provides additional security options, predefined Acceptable Use levels and Data Sharing controls. Schedules are not available in Base Policy. Where a schedule is used, it follows the endpoint’s local time.
Web Control policies can be user- or device-based. For a User policy, check the Central user mapping and locally signed-in account; for a Device policy, check computer assignment. Policy priority also determines which matching custom policy is effective. After a change, allow policy synchronization and confirm the effective policy through events rather than relying only on the intended assignment.
On macOS, Sophos Endpoint currently cannot filter or block IPv6 web traffic. A successful IPv4 test therefore does not prove the same access is controlled over IPv6.
Pilot and acceptance
A Web Control pilot checks an allowed, warned, and blocked category, a higher-priority Site List, a Website Management tag, a risky file type, an HTTPS page, and a deliberately chosen decryption exclusion. Test the browsers supported by your organisation, plus IPv4 and, where relevant, IPv6. Test scheduled policies in the endpoint’s local time.
Define rollback before expanding the pilot: record the previous assignment and profile, set abort criteria, and name the owner who will remove the custom-policy assignment or restore the previous profile. Base Policy’s automatic Classic fallback only covers devices on which the Web Profile cannot be applied; it is not a rollback for a supported device with an unsuitable configuration.
Under Reports > Events, verify which policy and action actually triggered. Expect an event for Block or Warn with the correct user or computer and planned policy. A visible browser page alone is insufficient: browser cache, Secure DNS, proxy, and QUIC can change the observed path.
For a safe functional test, use the Sophos test site sophostest.com. On Windows, C:\ProgramData\Sophos\Sophos Network Threat Protection\Logs\SophosNetFilter.log shows the URL category and action used and whether access was decrypted. On macOS, the Web Intelligence action is in /Library/Logs/Sophos Anti-Virus.log.
Without HTTPS decryption, Sophos often sees only the server name from SNI for HTTPS, not the complete path. A warning page then cannot be inserted into the encrypted content and the browser may show only a general connection error. Exact URL rules are also case-sensitive. A test with a complete HTTPS path must therefore not be interpreted like a domain-only rule.
Separate other web controls
Endpoint Web Control remains a separate product module. If DNS Protection for endpoints, Protected Browser, a proxy, or a network firewall also filters, another layer can block first. An Endpoint Allow cannot undo that block. This article therefore configures Endpoint Web Control only; during troubleshooting, inspect the events and policies of every layer actually in use separately.
Common errors
If a page is unexpectedly allowed, first check Site List priority, global Website Exclusions, Category Override and effective policy. If a warning page is missing, check HTTPS Decryption, certificate trust and browser support.
If only Firefox is affected, check its trust store and DNS over HTTPS. If only Macs are affected, also consider IPv6. A broad Website Exclusion is not a diagnostic method because it removes the controls being investigated.
If expected events are missing, first check Log web control events. Then check policy type, assignment, priority, agent version, and platform. Without logging, Sophos records only attempts to visit infected sites, so an empty event filter does not prove that the policy is ineffective.
Different handling of risky file types does not necessarily indicate a policy error. Sophos can assess known trusted sources differently from unknown sources through reputation. For encrypted downloads, this check also requires suitable HTTPS decryption. Measure its performance impact with pilot devices.
If an allowed website loads only partially, scripts, stylesheets, images or sign-in components often come from additional domains. Use the Network Threat Protection log and browser developer tools to identify each required destination instead of allowing a broad parent category.
If Web Protection must briefly be disabled to isolate the cause, use a separate policy for individual test devices with an owner, start and end time. Do not disable the Base Policy tenant-wide. Re-enable protection immediately after the comparison test and preserve the relevant events and logs.
Related articles
HTTPS Decryption is part of Sophos Endpoint Threat Protection best practices. Introduce Sophos Endpoint Control policies in practice provides the overall rollout process.