Skip to content
Avanet

Roll out Sophos Server Peripheral Control on Windows servers

Server Peripheral Control manages peripherals and removable media on Windows servers. The safe approach is to use an active policy assigned only to the pilot host: start with Monitor but do not block (all peripherals will be allowed), then review detected operational devices, define the necessary exemptions, and only then enforce Read Only or Block for individual device types. The Endpoint guide, by contrast, covers computers and their own policy under Endpoint > Policies; it does not assign a server policy. This server policy is not documented for Linux or macOS servers.

⚠️ Before blocking Modem or Wireless: If either provides the management connection, the server may lose contact with Sophos Fusion and, with it, the means to receive corrected policies. Exempt the required network devices first and have independently tested local or out-of-band access available. Sophos warns that physical access may otherwise be required to override the setting locally.

Before the pilot: identify devices and a recovery path

Choose a representative Windows server with a documented maintenance window and an administrator responsible for recovery. Inventory which USB storage devices are actually needed for backup or maintenance, and which optical media, MTP/PTP devices, and network adapters are required. On an RDS host, the decision applies to the whole server, not to individual sessions; consider the RDS operational limitations beforehand.

Before enforcing any restrictions, have a tested alternative management path and a copy of the previous policy settings or the planned pilot assignment available. Do not block backup media during a running backup or restore: confirm the read and write requirements with those responsible for backups and run the test outside a production job. These are operational safeguards, not prerequisites that Sophos checks automatically.

Monitor and assign the pilot policy

  1. In Sophos Fusion, go to My Products > Server > Policies and use Add Policy to create a Peripheral Control policy for the server pilot. Choose a recognizable name such as Server-Peripheral-Pilot; this is a name you can choose, not a Sophos default. Do not change the Base policy for an organization-wide pilot: it is the fallback for servers without a higher-priority matching policy.
  2. Activate the policy, open Settings on the policy detail page, and select Monitor but do not block (all peripherals will be allowed) under Manage peripherals. In this mode, all peripherals remain allowed even if device-type actions are set differently; detected devices are inventoried.
  3. On the policy detail page, use the assignment tab to assign only the intended pilot host, then save the changes. For example, record the assignment of Server-Peripheral-Pilot to the previously selected test server in the pilot log; the name can be changed. Under My Products > Server > Servers > [Pilothost] > Policies, check that this policy is actually applied and verify its priority relative to other server policies. Proceed with the monitor test only after this check.
  4. Connect the required devices to the pilot host under controlled conditions and check that they are detected. According to Sophos, Peripheral Exemptions > Add Exemptions lists devices detected by a monitor policy on managed computers or servers. Before creating an exemption, compare the actual device entry with the approved inventory rather than relying on a similar-sounding model name.

Manage peripherals also offers Disable peripheral control, which turns off both monitoring and blocking. This mode is therefore unsuitable for inventorying devices. An option that is locked may reflect a global setting imposed by the partner or enterprise administrator; it cannot be overridden in the local server policy.

Move from Monitor to Read Only and Block

Select Control access by peripheral type and add exemptions only after completing the inventory. This mode enforces actions by device type. Secure removable storage, Floppy Drive, Optical Drive, and Removable storage each offer Allow, Read Only, and Block. Bluetooth, Camera, Infrared, Modem, and MTP/PTP offer Allow or Block. Wireless offers Allow, Block Bridged, and Block. Block Bridged prevents network bridging but, according to Sophos, does not generate block alerts or events. MTP/PTP includes, for example, phones and cameras using the corresponding transfer protocol; this category has no Read Only option.

A limited pilot might select Removable storage: Read Only if data must be read from a test medium but must not be written to it. Select Block for this type only after confirming that no required backup or maintenance function is affected. Do not block the other types without checking them; for Wireless and Modem in particular, secure the management path first. The specific choice should follow the inventory, not a blanket server default.

For an approved device, open Peripheral Exemptions > Add Exemptions, compare the previously detected entry with the inventory, and set the desired less restrictive action in Policy. Under Enforce By, choose between Instance ID and Model ID: the exemption applies to devices with the same instance or model identifier, respectively; an Instance ID is not a guarantee that the exemption covers only one physical device. For approved operational media, the instance identifier is usually the narrower starting choice; a model exemption is justified only for a deliberately approved fleet of that model. Confirm with Add Exemption(s) and verify the exemption’s actual scope on the pilot host. An exemption cannot make a type rule stricter: Sophos ignores a stricter action for an individual device and displays a warning icon.

According to Sophos, Desktop Messaging is enabled by default. Text entered in the message field supplements the default notification; an empty field displays only the default message. If Desktop Messaging is disabled, no Peripheral Control notifications appear on the server. For the pilot, a customizable additional message such as “USB drive blocked? Contact IT operations with the hostname and time.” can explain the internal approval process; on an RDS host, desktop messages are not user-specific.

Check the effect and roll back safely

After saving the changed device-type actions and exemptions, check My Products > Server > Servers > [Pilothost] > Policies again to confirm that, as in the monitor test, exactly the expected Peripheral Control policy is applied. Editing that same policy affects all servers assigned to it, so recheck its assignment scope before every correction. Then verify the following with test data outside production jobs:

  • In Monitor mode, the connected test medium remains usable and appears as a detected device available for exemption selection.
  • Under Read Only, an existing test file can be read, while a deliberately low-risk attempt to write to the medium is prevented. Check this on the local server; do not rely solely on a desktop message.
  • Under Block, a test device without an exemption cannot be used; the explicitly exempted device works within the approved scope. Both cases are needed to detect an overly broad Model ID exemption.
  • The pilot host remains reachable and continues to communicate with Sophos Fusion. For Block Bridged, test bridging behavior separately; the absence of events is not evidence that it has no effect. For other cases, existing events under My Products > Server > Servers > [Pilothost] > Events can be checked as additional evidence; the actual access test remains decisive.

Rollback if the policy has an unintended effect: If the pilot host is still reachable, set the pilot policy under My Products > Server > Policies back to Monitor but do not block (all peripherals will be allowed) or remove its assignment to the pilot host. Then check the policy applied on the server under Policies and test access again. If the assignment is removed, the server falls back to the intended Base policy or next matching policy only if no other higher-priority server policy applies. Do not change a policy shared with production servers without considering the consequences. If the network connection has already failed, use the prepared local or out-of-band path and heed Sophos’s warning that physical access may be necessary; do not assume that a central policy correction has already been received.

If a required device remains blocked, first compare the applied policy, operating mode, device-type action, and the exemption’s Policy and Enforce By settings with the entry actually detected. If a device that should be blocked remains allowed, check for Monitor mode, an overly broad Model ID exemption, and another higher-priority policy. If the behavior cannot be explained clearly, do not expand the pilot; retain the inventory, policy state, and a reproducible test for further investigation.