Manage Windows Firewall with Sophos Central Endpoint
The Windows Firewall Policy in Sophos Central Endpoint manages the host firewall built into Windows. It has nothing to do with a Sophos Firewall appliance, its firewall rules or Central Firewall Management.
Sophos Central can monitor the state of Windows Firewall and other firewalls registered with Windows. In configuration mode, the policy sets the basic action for Domain, Private and Public profiles. Detailed exceptions remain Windows rules, GPOs or the responsibility of the deployed management system.
Three operating modes
| Mode | Meaning |
|---|---|
| Disabled | Sophos removes the Endpoint firewall component and stops monitoring |
| Monitor Only | Sophos reports the state without changing profiles |
| Monitor and Configure Network Profiles | Sophos monitors and applies the selected profile actions |
Monitor Only is the default and the correct starting point for existing GPO or MDM management. Switching directly to Configure can combine local rules, Group Policy and third-party products into an unexpected result.
Actions per network profile
Domain, Private and Public offer three basic actions:
- Block all: blocks profile network traffic without local exceptions.
- Block with exceptions: blocks by default but honours local Windows Firewall exceptions.
- Allow all: allows profile traffic.
For production clients, Block with exceptions is usually the only sensible enforcing baseline. Allow all largely removes the host firewall’s effect. Block all can interrupt management, authentication, printing, file storage and support access.
Windows, GPO and third-party products
The effective Windows Firewall configuration does not come from Sophos Central alone. Group Policy, local rules and other Windows-registered firewalls can affect it. Before migration, identify who currently owns the rule base.
When Sophos Central configures the profiles, the policy prevents changes to Windows Firewall through Windows Security Center. This is intentional but may change the previous helpdesk process. Detailed rules remain managed in the organisationally designated system.
Product boundary: This article covers only local Windows Firewall on an endpoint. Network firewall rules, NAT, VPN, Web Application Firewall and Sophos Firewall policies do not belong in this configuration.
If Sophos detects that Windows Group Policy manages the firewall, it does not apply the Sophos Central configuration. This prevents competing management, but the monitoring status continues to be reported.
Check My Environment > Computers & Servers > device > Summary > Windows Firewall. If Windows Group Policy shows Yes, a Configure policy not taking effect is expected and is not an MCS error.
Roll out safely
A new policy starts with Monitor Only. The pilot includes devices using Domain, Private and Public profiles plus a home-office client. Existing GPOs and local exceptions are then documented.
When switching to Monitor and Configure Network Profiles, control one profile first. Acceptance checks Central communication, DNS, DHCP, Active Directory, software distribution, Remote Support, printing and critical client-server connections.
Keep a fallback available, such as a higher-priority pilot policy or tested alternative management access. An endpoint whose Public profile blocks everything cannot reliably be repaired solely over that same network path.
Monitor another firewall
If another host firewall is registered with Windows Security Center, Sophos can monitor its state. This does not mean Sophos Central can configure its rule base. Green status confirms only the protection state reported by Windows, not the quality of all rules.
Troubleshooting
For unexpectedly blocked traffic, first check the active Windows network profile, effective Sophos policy and Windows Firewall rules. Then inspect GPO Resultant Set and registered security products. An apparent Sophos rule may actually come from a domain GPO.
If a user can no longer change Windows Firewall in Security Center, this is expected in Configure mode. If local change is required, adjust the operating model rather than manipulating the Endpoint agent.
If Central reports the wrong state, check Windows Security Center, service status and Events. A restart may be necessary after component changes. Do not “repair” the policy with a broad Threat Protection exclusion.
Installation ends with Could not set firewall auditing information
Older versions could fail with EnableFirewallAuditing: Error 0x80004005 and MSI error 1603. Sophos fixed the original defect in Endpoint Firewall 10.8.12.1. Use a current installer before attempting registry or auditing changes.
If it persists, record installer version, GPO and third-party firewall. Change the registry only for a current documented Sophos case with backup and Tamper Protection override; an old workaround is not a general repair.
Related articles
Build Sophos Central Endpoint policies correctly explains policy assignment. Agent network access and proxy requirements are covered separately.