Set up Sophos Server Data Collection and Investigation
The Server Data Collection and Investigation policy in Sophos Fusion (formerly Sophos Central) controls two different capabilities: Upload to the Data Lake sends server telemetry for later investigations; Allow Live Response connection to servers enables direct, privileged access to a server. The policy applies to Windows and Linux servers. Enabling uploads does not grant a Live Response session, and allowing Live Response does not provide Data Lake data.
Quick path: Check the license and an admin role with Server Protection access in your tenant. Under My Products > Server > Policies > Data Collection and Investigation, record the Base and Custom Policies, their assignments, and both switches. Assign a separate policy to a pilot group; check the effective policy and both switches on a pilot server and a sensitive server outside the pilot. Only then decide whether uploads and Live Response are enabled within the intended scope.
Establish prerequisites and scope
Before making changes, check the specific Server Protection subscription, the features available in the tenant, and the agent mode of the pilot servers. Sophos lists EDR, XDR, or MDR as a prerequisite for Live Response; a visible switch is not proof that a particular subscription or server is eligible. Check the actual license and tenant interface to determine which Data Lake queries and investigation features are available. Changing a policy cannot supply a missing license. The Sophos Fusion licensing guide provides background but does not replace checking the specific subscription.
The Base Policy initially applies to all servers not covered by a higher-priority policy. Additional policies handle groups that need different settings. For example, assign a separate Data Collection policy to a small, deliberately maintained group called SRV-Investigation-Pilot. The name is arbitrary; the actual members, assignment, and policy order are what matter. A broader policy ranked above the pilot policy can override its settings. Sophos automatically converts earlier Live Response and upload exclusions into Custom Policies with the respective feature turned off. A pilot policy alone does not limit either uploads or Live Response to the pilot: Outside the pilot, uploads may remain on by default, and with MDR, Live Response may also remain enabled by default. If only pilot servers should have these capabilities, plan and verify appropriate disabled settings in the effective policies for all other servers. Do not casually change the Base Policy: it affects every server that falls back to it. A server group also does not limit an administrator’s permission to start a session.
Changing the two policy settings requires Super Admin or an appropriate Custom Role with Manage Data Collection and Investigation settings for servers. Starting a session later requires Start Live Response sessions on servers as a separate permission; computer permissions do not automatically apply to servers. For the session role, Sophos specifies a Full or Help desk base role, Full access to Server Protection, and the server session permission. Check the actual admin role and its Server Protection access in the tenant; assigning a policy does not grant admin permissions. Granting and reviewing those permissions belongs in Administrative roles, not in a blanket Super Admin grant.
Configure the policy for the intended scope
- Under My Products > Server > Policies, open Data Collection and Investigation. Before changing anything, document the existing values of both switches, assigned groups/target servers, and order for the Base Policy and every relevant Custom Policy. Record the effective settings on a pilot server and a representative sensitive server outside the pilot group. For a separate pilot, use Add Policy if needed to create another policy of this type and assign it to the server group you have already checked. Do not change the Base Policy for a one-off test: that could affect every other server.
- Open the pilot policy and go to Settings. Set Upload to the Data Lake according to the approved data collection scope. According to Sophos, uploads are enabled by default. If the pilot servers do not behave as expected, first check which policy actually applies and whether any legacy exclusions exist.
- Enable Allow Live Response connection to servers only if an accountable incident-response process and privileged server access have been approved. According to Sophos, Live Response is enabled by default with Sophos MDR and disabled by default otherwise. Do not treat this default as the current setting or proof of licensing: check the effective policy on the target server. For sensitive servers where direct access must not be allowed, assign a separate group a policy without Live Response.
- Save the settings and inspect the active pilot policy, its priority, and its actual assignment on the pilot server. Inspect both effective switches on the server outside the pilot as well; only the intended result confirms that the pilot is properly scoped. Later edits to a shared policy also affect other groups assigned to it.
Uploads and direct investigation are not interchangeable switches. Turning off uploads limits future transmissions under the effective policy, but does not remove data already uploaded and reduces the historical visibility available for later investigations. Enabling Live Response, by contrast, grants powerful access to the running system. Document each decision separately, including its purpose, owner, and review date. Enabling uploads on many servers can cause a sudden rise in network traffic; monitor the pilot and link capacity before a broad rollout.
Verify the effect safely and understand the limits
In My Products > Server > Servers, check the pilot servers and their group membership. Under Server Groups, open the pilot group and view the enabled and applied policies on Policies; then inspect the effective policy and both switches on the named pilot server and a sensitive server outside the pilot. Group assignment alone does not prove which settings apply to an individual server.
To verify a Data Lake upload, explicitly select Data Lake Queries in Threat Analysis Center > Live Discover, not Endpoint Queries. Choose an existing predefined query with a supported operating system and a suitable data source, and keep the time range short. Data Lake queries always include all devices; the Device Selector restricts only endpoint queries and cannot narrow Data Lake queries to pilot servers. If the query returns device identifiers and timestamps, evaluate only results matching the specifically identified pilot server with an appropriate time reference after the change; tenant-wide matches or old rows do not prove that this server is uploading now. A query without a device identifier or suitable timestamps cannot verify the pilot. Zero results alone do not prove a transmission failure either: check licensing and feature availability, server status, effective policy, upload switch, schema, and time range, and involve support if necessary. A successful direct Endpoint Query may read local Event Journals and is not proof of a Data Lake upload. Do not generate a test event containing real personal data, production credentials, or artificial malware. The existing Live Discover and Data Lake guide explains the data source, retention, and safe querying.
Event Journals also reside on managed servers, but they are not the same as a Data Lake upload. To set server-side journal limits, go to Global Settings > Products and Services > Endpoint and Server > Event Journals and select the Server tab (separate from the Endpoint tab); the limits cannot be set per individual server. According to Sophos, this setting requires XDR, MDR, or MDR Plus. Reducing a limit can displace older journal data; it is not a pilot switch for a single server group. The linked Live Discover guide covers detailed journal and query diagnostics.
An active policy alone is likewise insufficient for Live Response: the license, an admin role with Server Protection access, session permission, a reachable target server, and an approved investigation purpose must all align. In an approved test, check access only on the unambiguously identified pilot server and do not run commands that change anything; then end the session. Have someone with the appropriate permissions check audit evidence as part of the incident process: the server session permission alone does not authorize downloading the detailed session log. For that, Sophos requires Super Admin or a Custom Role with Manage Live Response settings for computers and Manage Live Response settings for servers. The existing isolation and Live Response runbook explains session handling, MFA, and audit permissions. Do not apply its endpoint isolation steps to servers without checking them first.
If the pilot does not behave as planned: Stop further enablement and end any test session. Restore only the documented original values, group assignments, and pilot-policy order, then recheck the effective switches on both pilot and non-pilot servers. Do not simply delete the pilot policy if that would cause the Base Policy or another policy to enable uploads or Live Response on sensitive servers. This is an operational rollback strategy based on policy priority and separate switches, not a one-click Sophos rollback. It cannot retrieve data already sent to the Data Lake or undo actions taken in a Live Response session; address retention or deletion separately under the applicable requirements.
Under Exclusions in the server policy, there is also an Event collection exclusion: it stops event collection for Sophos Journals and the Data Lake and can impair detection and investigation. Sophos says to use this exclusion only when directed by support. It is not available under Global Exclusions and is not a substitute for a group-specific upload decision. No file or process exclusion procedure is recommended here. For a privacy or bandwidth decision, first agree on scope, permissions, retention, and the necessary investigation purpose; do not set an Event collection exclusion without instructions from support.