Set up File Integrity Monitoring for Windows Server in Sophos Fusion
File Integrity Monitoring (FIM) records changes to monitored files, folders, registry keys, and registry values on Windows servers. It does not prevent changes. To start safely, assign a dedicated FIM policy to just one pilot server, enable Use File Integrity Monitoring, add a small path owned by your application, and confirm an approved change in that server’s Events. Once enabled, Sophos already monitors critical Windows system files; custom locations extend that monitoring.
Before the pilot: scope and baseline
FIM is a server policy for Windows servers only. An older variables reference also mentions earlier Windows versions; that does not establish current support for Windows Server 2008 or for FIM on Linux. Check the pilot server’s edition, build, installed protection, and license against current Sophos support information and your contract. If the agent is not yet installed, complete the Windows server deployment first. The server must communicate with Sophos Fusion, and its effective Server Threat Protection policy must have Enable event journals turned on: according to Sophos, Server File Integrity Monitoring will not work if Event Journals are disabled there. Event Journals are not the same as the server Events checked later.
Before making changes, record the policy name, assigned servers or pilot group, current FIM status, and any existing monitored locations and exclusions. Arrange a maintenance window with the application owners. Do not change a broadly assigned Base Policy for a pilot: what seems like a local test could affect other servers. Check the assignment and effective policy on the individual server before touching a test file.
Choose locations and control noise
Start with files or registry entries whose changes genuinely need investigation: for example, a service’s configuration file rather than its rotating logs, cache, or temporary files. Here, C:\ProgramData\ExampleCorp\Service\config.ini represents a fictional, self-managed service configuration only. Replace the product, directory, and file names with a real path on the pilot server, and agree with its owner who may change it and when. Monitoring a directory such as C:\ProgramData indiscriminately creates unnecessary events and makes important changes harder to spot.
Under Custom monitoring > Add location, Type determines what is monitored:
- File: Choose a specific file when changes to that exact file matter. A specially prepared, non-production-critical configuration file is suitable for the pilot test.
- Folder: By default, Sophos monitors the folder and the files in it. To report changes to the files but not the folder itself, clear Monitor changes to the folder as well as the files. This option does not exclude files.
- Registry Key: Monitors the key, not its values. To check, for example, a value named
PilotFlagunder an application-owned key such asHKEY_LOCAL_MACHINE\SOFTWARE\ExampleCorp\Service, select Registry Value as the type and specify the value that actually exists in the dialog. This is not a real Windows or Sophos key; do not alter system keys to test FIM.
For installation-dependent file paths, the FIM policy supports its own variables, such as %programdata% for C:\ProgramData, %programfiles% for C:\Program Files, and %systemroot% for C:\Windows (example paths from the Sophos reference). One possible pilot path is %programdata%\ExampleCorp\Service\config.ini. On the target server, check what the selected variable actually resolves to and whether the file exists; the reference examples do not guarantee identical paths on every installation. Do not assume that syntax or wildcards from scan exclusions also apply to FIM.
Under Monitoring exclusions > Add exclusion, you can exclude irrelevant locations from FIM monitoring. A Folder exclusion covers the folder and its files; a Registry Key exclusion covers the key and its values. Never make an exclusion so broad that it also covers the configuration you intend to check. FIM monitoring exclusions are not malware-scanning exclusions and do not change the scope of Server Threat Protection. If events repeatedly create noise, first narrow the monitored location, then exclude only the confirmed, legitimate subset. Record the owner, reason, and review date.
Assign the policy and test safely
- Under My Products > Server > Policies, create a File Integrity Monitoring policy for the pilot (some Sophos FIM help pages show My Product in the singular). Assign it only to the pilot server or a clearly defined server group, and turn on the policy. A name such as
FIM - Windows Pilotis optional. - On the Settings tab, select Use File Integrity Monitoring. Under Custom monitoring > Add location, specify the appropriate Type and an approved location that actually exists. Select Add or Add Another, then save the policy. If needed, add a narrowly scoped location under Monitoring exclusions > Add exclusion. You can edit a list entry by selecting its path or remove it using the cross icon.
- In My Products > Server > Servers, open the pilot server and check under Policies that the expected FIM and Threat Protection policies are actually in effect. Do not rely solely on the saved configuration.
- After the policy takes effect, first perform an approved file test: change a previously backed-up, non-production test file in the monitored location, then carefully restore its original contents. Record the test time and time zone, server, path, and change approval. Writing the original contents back may itself produce another event. Do not test on production registry keys; for a registry test, use only a backed-up test value approved by the application owner.
- Under My Products > Server > Servers > [pilot server] > Events, compare the displayed period with the test time. Correlate the event by server, time, and type of change; open Details if available. View Events Report shows events by type and day. A matching event demonstrates that this change was observed; it does not establish comprehensive compliance, detection of every change, or any blocking capability. Nor does the event alone guarantee a content diff.
Expand to additional servers in small waves only after checking both the test event and normal application operation. Observe event volume across normal update and maintenance cycles; do not indiscriminately exclude known software updates.
If events are missing or too numerous
No event after the test change: First check the target server and test time, including the time zone. Then check the effective FIM policy, Use File Integrity Monitoring, the exact Type (Registry Key is not Registry Value), the resolved file path, and any overlapping Monitoring exclusions. Also check that Enable event journals is on in the effective Server Threat Protection policy and that the server is currently communicating with Fusion. Search by time range and device in the server’s Events view and, if necessary, the Events Report; a filename search in the global Events Report is not reliable for this purpose. Make a second approved pilot change only after narrowing down the cause. If you cannot establish the cause, preserve the policy state and timestamps and contact Sophos Support instead of deleting registry entries or agent files on a hunch.
Too many events: Identify the source of the changes with the application owner. If the selected folder is too broad, monitor the relevant file or a narrower location instead. Exclude only confirmed, unavoidable sublocations using Monitoring exclusions, then repeat a relevant positive test. A blanket exclusion for the entire monitored folder defeats the purpose of the test.
Rollback: Stop further policy assignments. If a pilot rule is wrong, remove the newly added location or exclusion, or restore the documented previous policy assignment. If the pilot fails overall, disable FIM in the policy assigned only to the pilot. Then check the effective state under Policies on the server and preserve the event history for investigation. Reverting the policy does not restore a file or registry value that has already changed; use the separately tested application backup or change rollback procedure for that. Do not disable existing Windows protection features or Event Journals as a supposed FIM rollback.