Skip to content
Avanet

Sophos Server Application Control: detect first, then block

Quick path: Under My Products > Server > Policies, create an Application Control policy for selected Windows Server machines, initially unassigned and set to Off.

  • Detect: Under Controlled Applications > Add/Edit List, choose relevant categories. Under Detection Options, enable only Detect controlled applications during scheduled and on-demand scans, then save. Only then assign the pilot servers, set the policy to On, and verify which policy actually applies.
  • Review: After a scan, compare the findings under Reports > General Logs > Events, with event type Application Control, against the server workloads.
  • Block: Only after deselecting required server applications from the controlled selection, enable Detect controlled applications when users access them and Block the detected application in a tightly scoped pilot.

Application Control enforces an operational decision about applications catalogued by Sophos that are not necessarily malicious. It is neither malware detection nor file approval through Sophos Unauthorized File Protection (SUFP). The server policy described here applies only to Windows Server, not Linux and not the endpoint policy for workstations. The endpoint procedure is therefore not a template for assigning the policy to servers.

Inventory server workloads before the first block

A block affects more than interactive administrator sessions. On each pilot system, work with the responsible application team to check services, scheduled tasks, backup and monitoring agents, remote support tools, installers, and vendor updaters. For example, a remote support tool may be needed for approved support on one application server but not on another. What matters is each server’s actual role, not a broad category name.

Record the pilot servers, responsible person, affected applications and versions, time of the next scheduled scan, maintenance window, and a working administrative access method and rollback path in advance. The Applications tab under My Products > Server > Servers > [Servername] shows installed applications as an additional inventory source; it is not the same as Application Control detection findings. Check the policy and permissions actually available in your tenant before changing a production assignment. If an option is locked, global settings controlled by the partner or enterprise administrator may be the reason.

⚠️ Do not change the shared Base policy for an initial block test: it can affect every server without a more specific policy. Do not edit an existing production policy without checking it either; a change affects all servers assigned to it.

Set up the detection phase

  1. Under My Products > Server > Policies, use Add Policy to select Application Control and name the policy something like Server-AppControl-Pilot. Create the new policy initially set to Off and with no servers assigned; do not set it to On yet. The name is your choice. Under Settings, configure detection only before assigning the policy to any server.
  2. Under Controlled Applications > Add/Edit List, open the categories relevant to the pilot. Select all applications initially adds every entry in the selected category to the list to be examined; apply the selection with Save to List. Include only categories whose impact you can assess. Sophos maintains this application list; you cannot control an application outside the catalogue by inventing a category.
  3. Under Detection Options, select only Detect controlled applications during scheduled and on-demand scans. Leave Detect controlled applications when users access them and Block the detected application off. Save and recheck the settings before assigning or enabling the policy.
  4. Only now assign the intended Windows pilot servers or their server group, and set the policy to On. Under My Products > Server > Servers > [Servername] > Policies, check on each pilot server whether the intended Application Control policy actually applies; only then wait for the test scan. When multiple policies of the same type exist, the first matching enabled policy in the policy order applies; Base remains the fallback for servers without a more specific policy. Merely saving or assigning a policy does not confirm that it is the effective policy.
  5. Scan-based detection uses the scheduled scans and file-type settings of the Threat Protection policy; wait for the pilot servers to complete an appropriate scheduled scan. Under Reports > General Logs > Events, deselect all event types except Application Control. If a selected, detectable application is found during the scan, expect an event showing the server name, application, and time; compare these details with the workload inventory. If no event appears, first check scan completion, scanned file types, the effective policy, and the event filter and time range. An empty report does not prove that no relevant applications are present, even after a scan. If, for example, a rarely used updater or a task run only during maintenance is missing, assess those workflows separately in a suitable test window before blocking. A scan finding alone proves neither active use nor that a later block will be free of side effects.

Test a limited block

  1. In Controlled Applications > Add/Edit List, deselect every application needed for business operations from the controlled selection. For the block test, choose exactly one remaining catalogue entry: its application must actually be present on the pilot server, deliberately not needed there, and agreed with the workload owner for a one-off test during the maintenance window. Deselect every other entry for this first block test too, then choose Save to List; otherwise, each additional selected entry would also be subject to the block. If there is no suitable test entry, do not enable blocking or force a block test. Do not enable the optional New applications added to this category by Sophos setting in the first block pilot: new catalogue entries and newer versions of already listed applications would otherwise be controlled automatically and blocked when blocking is enabled.
  2. Only with a vetted test entry and for the already verified pilot assignment, enable Detect controlled applications when users access them and Block the detected application under Detection Options; save the policy. This blocks access to controlled applications rather than merely reporting a scan finding. Scan-based detection alone, without access detection and the block option, does not enforce a block.
  3. On a representative pilot server, recheck the effective policy under Servers > [Servername] > Policies. During the maintenance window, try to launch only the application corresponding to the agreed, unneeded catalogue entry: the negative test is that execution is denied. Under Reports > General Logs > Events, check the associated Application Control event for that server, application, and time. If either the block or the event is absent, do not assume enforcement succeeded; check the controlled entry, version, both switches, effective policy, and event filter. Positive test: Confirm that an allowed business application deselected from the controlled selection still works, along with the affected service or scheduled job and backup/monitoring after the test. Plan the next server group only if both the block and the allowed workloads behave as intended.

According to Sophos, Desktop Messaging is enabled by default. Custom text supplements the default message; an empty field displays only the default message. For background services and tasks without an interactive user, a possible desktop message replaces neither the event nor the workload test; do not rely on visible feedback there. If a desired application is missing from the Sophos catalogue, Application Control Request at the end of the Settings tab opens a request to add it, not an immediately effective local signature.

Troubleshoot and roll back only the pilot

  • No events during detection: First check the effective policy on the affected server, its On status, scan time, and the Threat Protection scan settings. Then check the event filter and time range. Applications shows installed applications, not necessarily Application Control findings.
  • Expected block does not occur: Check whether the specific entry is selected in Controlled Applications, whether access detection and blocking are enabled, and which policy actually applies under Servers > [Servername] > Policies. Other application versions or an uncatalogued launcher are not automatically detected in the same way.
  • A required service or updater is blocked: Record the affected server, event, time, and application. In the pilot policy, remove the required entry from the controlled selection or turn off blocking for the pilot, then save. If the disruption is broader, disable the pilot policy or remove its pilot assignment; first check which other policy, especially Base, will then apply. After the update, recheck the effective policy and retest the affected service or job on the server. Do not create a global malware exception as a substitute for this Application Control correction.

This rollback reverses only your pilot decision. It is not a promise of immediate policy distribution, restart of processes already stopped, or automatic repair of interrupted jobs. If a critical workload remains disrupted, follow the internal recovery plan and escalate to the responsible support team with the event, policy assignment, and timestamps.