Safely introduce Sophos Server Web Control on Windows
Server Web Control controls access to website categories and custom website lists on Windows servers. The safe starting point is an additional policy for one representative server: inventory operational access, make a narrowly scoped category decision, enable event logging and extend the policy to other servers only after a functional test. The Endpoint policy under My Products > Endpoint does not assign a Server Web Control policy to a server.
Prerequisites and choice of policy type
The server must appear in the correct Sophos Fusion tenant under My Products > Server > Servers and have a protection mode licensed for the intended Web Control function. Check the licence and the components actually installed in the tenant first; a visible policy screen alone does not establish entitlement or an effective agent feature. Do not assume Web Control will work with an XDR Sensor that has no malware protection. Before changing the policy, document with the application owner which server roles, browser connections or service connections could be affected. A web filter on a server does not replace rules in a proxy, DNS protection or network firewall.
Sophos offers Classic settings and Web profile. Base Policy initially has Classic enabled with recommended settings and Web profile disabled. Each additional policy contains only one of the two types. A Web Filtering Profile is a reusable collection of categories and Site Lists available on Windows; it is not deployed automatically. The shared setup of Web Filtering Profiles and Site Lists is explained in the existing Endpoint article; its Endpoint policy path does not apply to servers. Sophos specifies “Sophos Endpoint 2026.1 or later” for Web Profile policies in one place, but does not establish a corresponding server agent version. This Endpoint version is therefore not treated here as a server minimum: before assigning a Web Profile in production, check support for the specific server agent in the tenant. If support is unclear, start with Classic on a pilot server.
Choose a non-critical business category and a harmless test URL for the pilot. Check its actual Sophos category beforehand with SophosLabs Intelix: the Site category lookup button is available in the Web Filtering Profile editor under Filter by category (Global Settings > Protection & Remediation > Web Settings > Web Filtering Profiles). Test only if the category matches; do not guess how Sophos categorises the URL. This lookup does not require assigning a profile to the server. Inventory required server URLs and automated downloads before deciding to Block. For a reproducible HTTPS pilot, start with Block and check browser access over a test path confirmed not to use QUIC: according to Sophos, QUIC can bypass website checking for some sites. Check the test browser’s QUIC transport before accepting the result and, if necessary, use a verified non-QUIC path for that browser only. Block QUIC browser connections in the effective Server Threat Protection policy is off by default; do not enable this Threat Protection policy setting without review just for the pilot. Use Warn as a visible HTTPS warning test only after HTTPS decryption has been approved in the effective Server Threat Protection policy and is effective for the test URL. Without that prerequisite, do not use a visible warning as an acceptance criterion; defer the warning test. Do not enable decryption casually: it can expose full URLs and personal content. Review privacy, certificates and affected services separately. The linked Endpoint article provides background in its “HTTPS and warning pages” section; its Endpoint switch is not a server instruction.
Create a small server policy
- Under My Products > Server > Policies, click Add policy, select Web Control as Feature and enter a recognisable name such as
WC-Server-Pilot. The name is arbitrary but should indicate scope and purpose. - On Servers, move the single pilot server from Available Servers to Assigned Servers. Do not accidentally select the entire server group.
- On Settings, turn on Web Control. For a pilot without confirmed Web Profile support, choose Classic settings. Under Filter website by category, initially set Block for the verified test category; test Warn only when the HTTPS prerequisites above are met. Allow does not test blocking. Do not tighten other categories without reviewing them.
- Enable Log web control events and save the policy. Without this option, Sophos says only attempts to visit infected websites are logged, not ordinary block and warning attempts. Then confirm that the new policy is active and that a higher-priority matching Web Control policy does not override it for the pilot.
Option for required destinations in Classic: Under Global Settings > Protection & Remediation > Web Settings > Website Management > Add, assign the specific required destination a new or existing tag and save it. Check where else an existing tag is used first; otherwise choose a dedicated pilot tag. Then, under My Products > Server > Policies > Web Control > [Pilot-Policy] > Settings > Control sites tagged in Website Management > Add New, select the tag and the justified Action. Click Save in the dialogue and then save the policy. Retest the destination and affected services on the pilot server. This is a targeted Classic policy rule, not a global Website Exclusion or an Endpoint policy step.
If the specific server supports Web profile, choose Web profile instead and assign a profile that has already been created. Use Apply different profiles at different times with a verified schedule only if the business requires it. Risky File Types are a separate decision: review Recommended and View More before changing the setting. Allow for every risky type is not a harmless default. The profile may also be used in other policies: check which other devices and servers a change to it would affect first. An additional policy cannot contain Classic settings and Web profile at the same time; Base Policy can contain both and fall back to Classic when profile settings are not applicable. That is not a guaranteed rollback path for an incorrectly chosen additional policy.
Verify the effect and narrow down faults
Before the change, check access from the pilot server to the verified test URL and to a required update, login or management destination; record the destinations, identified category and expected action. Before acceptance, make sure the test URL is not covered by a Website Exclusion for threat checking and, for Web profile, not covered by a higher-priority Site List; for Classic, also check existing Website Management tag rules for the destination. After policy synchronisation, confirm the expected Web Control policy name under My Products > Server > Servers > [Pilotserver] > Policies. Access the test URL again from the pilot server over the previously verified non-QUIC path and look under Events on that same server for a Block event at the time of the test. Expected result: the page is blocked, the event matches the test request and required access still works. For the separate, approved HTTPS Warn test, verify both the visible warning and the warning event; a logged warning event alone does not confirm that a warning page appeared. Defer this part of acceptance without approved and effective decryption. The Policies view alone does not prove that filtering works; a missing event when logging is off does not prove that filtering is ineffective.
- Wrong policy: Check the assigned server, whether the policy is active and policy order; the server detail page shows the policy actually applied. Do not use the Endpoint computer tab as evidence.
- Expected category is not blocked or Block event is missing: Check whether the test browser fetched the URL over QUIC rather than the verified non-QUIC path; QUIC can bypass checking for some sites. Then check the identified Sophos category, profile support for the specific server and the selected Classic or profile variant. For a profile, check its Site Lists: they take precedence over category decisions. In Classic, also check matching Website Management tags. According to Sophos, websites excluded from threat checking in Threat Protection are not subject to these Web Control settings.
- Warning is missing or a required page does not load: First check the effective Server Threat Protection policy, approved HTTPS decryption for the test URL, certificate trust and possible upstream proxy or firewall blocks. If neither a warning page nor a warning event appears, also check logging, category and effective Web Control policy; do not accept a visible HTTPS warning test without effective decryption. Do not create a global Website Exclusion as a quick fix. If a server application is affected, identify the exact destinations it needs and test a narrowly scoped policy change separately.
Abort and rollback: Before the pilot, record the previous policy name, the affected server assignment and the chosen category actions. If there is a disruption, do not assign any more servers. Remove the pilot server from Assigned Servers in the additional policy or disable the pilot policy, then check the policy now effective under Policies on the server. Retest affected services and the access checked before the pilot. Changing a profile or Base Policy is not a low-risk rollback because other devices may be affected.