Skip to content
Avanet

Sophos Server Protection: Assign server groups and policies

For a limited rollout in Sophos Fusion (formerly Sophos Central), create a pilot group containing a test server that does not yet belong to any group under My Products > Server > Servers > Server Groups. Then assign an additional policy to the group under My Products > Server > Policies, save and prioritize it, and check which policy actually applies under My Products > Server > Servers > Server name > Policies. If the server already belongs to a group, the target policy must instead be ready before moving the server. A successful agent installation alone does not prove that the policy has been assigned.

A server group groups servers together as an assignment target. It is not a protection policy in its own right and is not the same as an Endpoint computer group. A server can belong to only one server group. This matters especially when moving a production server: selecting it for a new group removes it from its previous group and can change its effective policies across all group-dependent policy types.

Create a pilot group and check membership

For this procedure, choose a representative, non-business-critical test server that is not yet assigned to a server group. First, record the policies currently effective on that server for the relevant types and schedule a maintenance window for functional testing. Also designate a server outside the planned pilot group as a control host and record the policy currently shown for each affected type. Names such as SRV-Pilot-Web and srv-web-test-01 are examples; replace them with your own group and server names. The group name should make its scope clear, not imply a different policy effect. For a server that already belongs to a group, follow the preparatory sequence in Move an existing server safely instead.

  1. Under My Products > Server > Servers, open the Server Groups tab. The list shows the groups and their server counts.
  2. Select Add Server Group in the upper-right corner. Enter a name, such as SRV-Pilot-Web, and a short description of the pilot’s purpose.
  3. From the servers available for assignment, select only the intended test server, srv-web-test-01. Before confirming, check that it does not belong to another server group. If it is already grouped, do not select it here: doing so would remove it from its previous group. Prepare the target policies first, as described below.
  4. Create the group and open it by name. On Summary, check that srv-web-test-01 appears under Assigned Servers and that the member count is correct. To make a correction, select Edit on the left, adjust Assigned Servers and select Save.

The group alone does not activate an additional policy. The open group’s Policies tab shows which policies are enabled and applied to the group. This view provides an initial scope check, but acceptance for a specific host requires checking the server itself later.

Assign a policy to the server group

If all servers need the same settings, the Base Policy for the relevant policy type may be sufficient. Sophos provides it; it is always available and cannot be disabled or deleted. An additional policy is needed only for a justified exception, such as a narrowly scoped pilot. The Base Policy is a fallback, not a layer from which a server takes individual settings to supplement a higher-priority policy.

  1. Open My Products > Server > Policies. Before making changes, document the existing order for the affected type, including where broadly matching policies sit; on the control host outside the pilot group, record the current policy name for that same type under Servers > Server name > Policies. For the pilot, create a new policy that is not shared with other groups or servers using Add Policy and, if a dialog appears, select the server feature Threat Protection. According to Sophos, an additional policy-type selection applies only to Endpoint Protection. Do not edit an existing shared policy or reuse one as the pilot policy. Do not accidentally create a computer policy under Endpoint > Policies. The Endpoint policy fundamentals article explains the general model of order and Base Policy; its computer assignment is not the server scope.
  2. Give the additional policy a recognizable name, such as TP-SRV-Pilot-Web.
  3. In the policy details, under Servers, assign only the pilot group SRV-Pilot-Web as the target. Check every target before saving: no other server groups, individual servers or broader targets; do not select an Endpoint computer group. If the policy in question cannot be limited exclusively to the pilot group, do not proceed with this pilot using that policy. The available server-group selection may vary by policy.
  4. Under Settings, review the settings for the selected type, enable the additional policy and select Save. In the policy list, confirm that it has been saved, is active and still targets only the pilot group. Choose only settings whose effect on the pilot server you have assessed beforehand.
  5. In the list for that policy type, position the pilot policy above more general policies (by drag and drop) and check the displayed order. The Base Policy remains at the bottom. A broader match above the pilot policy would take precedence over the pilot assignment. Immediately after reordering, compare the policy of the same type on the previously recorded control host against its baseline. If it has changed, restore the original order and pilot assignment, check the control host again and stop the rollout.
  6. Reopen the group details under Server Groups > SRV-Pilot-Web > Policies. Check the name and enabled status of the policy applied there. A gray icon beside a policy indicates a security setting disabled in that policy; it does not prove that the server is using the intended protection feature.

Sophos Fusion evaluates policies from top to bottom for each feature and uses the first matching active policy. Two policies of the same type are not combined setting by setting. In this example, TP-SRV-Pilot-Web should take precedence over a general Threat Protection policy for the test server; a server outside the pilot group should retain its previous matching policy or the Base Policy. Policy order and target group therefore matter as much as the settings within the policy.

Move an existing server safely

A production server that already belongs to a group is not the server to use in the creation procedure above. Before moving it, record its current group and the effective policies shown on the server for every affected policy type. For each type that will change, also record the previous priority order and the policy applied to a control host outside the target group. Prepare new policies assigned exclusively to the target group, review their settings and targets, save them with Save, check that they are active and position them above broader matching policies. Compare the control host after reordering and before changing groups; if its policy differs from the baseline, revert the order and assignment and stop. In particular, check whether features other than Threat Protection depend on the previous group assignment; establish the target policy or an explicitly accepted fallback for each of those features in advance.

Only when the target group and its policies are ready should you assign the server to the target group through Assigned Servers, during the agreed maintenance window. This removes it from its previous group; the group change is not atomic with creating a policy afterward. Immediately afterward, compare every previously recorded policy type under the server’s Policies tab with the expected result and test the affected protection features. Compare the control host with its baseline again as well. If an unexpected policy is assigned, follow Roll back the pilot below. The exact transition time and enforcement on the host were not tested in a tenant for this article.

Validate the effective policy on the named server

Under My Products > Server > Servers (or My Environment > Computers & Servers), open srv-web-test-01 and select Policies. For the relevant Type, compare the displayed policy name with TP-SRV-Pilot-Web. Repeat for every other policy type whose assignment was intended to change. Selecting the policy name opens shared policy details; do not change anything there without considering the impact.

Acceptance criteria: The group contains exactly the intended members, its Policies view shows the intended assignment, and the expected policy appears for the checked type on the specific named server. On the previously recorded control host outside the pilot group, the policy name for every affected type must be the same before and after the change. Otherwise, restore the original order and target assignment, check again and do not roll out further. This portal check confirms the visible assignment; it does not replace functional testing of the chosen protection setting on the pilot server. Expand the scope only after both checks pass.

If the expected policy does not appear

  • Server not in the pilot group: Check the actual hostname under Server Groups > SRV-Pilot-Web > Summary > Assigned Servers. If the server has already been assigned to another group, it cannot be in the pilot group at the same time. Correct the group move deliberately, then check the server again.
  • Wrong policy type or product area: Under My Products > Server > Policies, compare the same feature shown in the server’s Type column. An Endpoint computer group or Endpoint policy is not a substitute for a server assignment.
  • Base Policy instead of pilot policy: Check that TP-SRV-Pilot-Web is active, targets the correct group and appears before any broader matching policy. The Base Policy applies if no policy above it matches. Correct the assignment and priority first; do not rush to reinstall the agent.
  • Correct name but unexpected effect: Look for gray icons indicating disabled settings in the group view; check the specific policy setting and protection status on the pilot server. If the change has not taken effect despite a correct display and matching setting, investigate the affected policy type and server status separately rather than blindly changing the policy for every group.

Roll back the pilot

You must document the original group membership (including no group), the previously effective policies for each affected type, the original policy order and the control host’s policy before making changes. If an unexpected policy is assigned, stop the rollout and restore membership deliberately:

  • Test server originally in no group: Open Server Groups > SRV-Pilot-Web > Summary > Edit > Assigned Servers, remove the test server from the pilot group and select Save. It should then belong to no server group.
  • Server originally in a group: In the original group, open Summary > Edit > Assigned Servers, add the server back and select Save. This removes it from the pilot group; verify its original membership.

Then remove the pilot policy assignment and restore every changed policy order to its recorded baseline; if pilot settings were changed, revert those too using the values documented beforehand. Do not blindly disable or delete a shared policy. On the restored server, compare the assignment for every affected type under Policies with its baseline, and do the same on the control host outside the pilot group. If they differ, do not expand the rollout; investigate the affected assignment and priority. Deleting a group leaves the servers in place; it is no substitute for this rollback or for checking the policies again.