Skip to content
Avanet

Enable and verify AP6 Active Threat Response safely

Active Threat Response (ATR) ingests threat-feed data through the Sophos Central API and can use it to isolate hosts identified as malicious at the access layer. For AP6, the feature only applies when the access point is registered with Sophos Fusion (formerly Sophos Central) and covered by a valid support and services license. Sophos identifies MDR, XDR, NDR, and third-party solutions as possible threat-intelligence sources, but this page doesn’t prescribe an additional license combination for this workflow.

Quick workflow: sign in at fusion.sophos.com, document the prerequisites and recovery path, enable the AP6 control under Global Settings > Protection and Remediation > Allow and Block > Network > Active Threat Response, trigger an isolation for an approved pilot device, and then verify its MAC address and AP6 status in the MDR/XDR Threat Feed.

⚠️ Operational impact: ATR overrides MAC Filtering configured on the SSIDs. An Allowed list there can’t allow a MAC address blocked by ATR. Resolve exceptions and the recovery path in the threat-feed or API process before enabling the feature.

Prerequisites and safe pre-check

  1. Confirm that the affected devices are AP6, are registered with Sophos Fusion, and have a valid support and services license. For registration and the management path, use the AP6 requirements checklist.
  2. Confirm which authorized integration or security team submits isolation decisions through the Central API. Don’t put a test MAC address into a production threat feed.
  3. Record the MAC address of an approved, disposable pilot client and its AP6 and SSID. Keep a second administrative access path that doesn’t depend on this client.
  4. Capture the current entries and status in the MDR/XDR Threat Feed. This distinguishes a new isolation entry from an existing finding after the change.
  5. Decide in advance who will reverse an incorrect isolation decision in the originating integration. The Sophos Fusion help page doesn’t document a manual release button for an individual ATR host in this view.

Enable AP6 Active Threat Response

  1. In Sophos Fusion, click the Global Settings icon.
  2. Open Protection and Remediation > Allow and Block > Network.
  3. Select Active Threat Response.
  4. In MDR/XDR Threat Feed, turn on the control next to AP6.
  5. Keep the view open and check for an error. This action only enables AP6 enforcement. A specific client becomes a target only when an isolation decision arrives through the API-based threat feed.

The control is a management action in Sophos Fusion. Its data-path effect applies to the client represented by its MAC address at the wireless access layer: ATR is intended to isolate its communications and help limit lateral movement. It doesn’t quarantine the access point itself and doesn’t replace SSID, VLAN, or other network segmentation.

Pilot and collect evidence

  1. Use the already approved threat-feed or API workflow to isolate only the recorded pilot client.
  2. Find the entry by MAC address in the MDR/XDR Threat Feed.
  3. Check the AP6 column. According to Sophos, a green check mark means the device is isolated, while a hyphen means it isn’t isolated.
  4. On the pilot client, repeat a previously documented harmless connection to an internal test destination. Failure alone isn’t proof: the MAC address and green check mark must refer to the same client.
  5. Confirm that the AP6 remains manageable. This distinguishes a client data-path effect from a general AP or management outage.

Only adopt ATR for the intended production scope when the feed entry, AP6 status, and reproducible client effect agree.

Troubleshoot methodically

The AP6 column shows a hyphen

First verify the MAC address and the correct threat-feed entry. Then confirm that the AP6 control is still on and that the responsible access point meets the documented prerequisites. Don’t expand the SSID Allowed list: it can’t override ATR isolation. If the hyphen remains, preserve the timestamp, MAC address, and integration result, then investigate the submitting API workflow.

There is a green check mark, but the expected effect is missing

Confirm that the tested client is actually using the same MAC address. Randomized or private MAC addresses can change the relationship between an inventoried address and the address currently in use. Verify this possible client state on the endpoint; Sophos doesn’t document automatic identity resolution beyond the MAC address on the ATR page. Then repeat the test on the same AP6 against the same clearly defined destination.

Enabling the feature causes an unexpected outage

Turn off the AP6 control, record the time, and repeat the previously successful client test. Preserve the threat-feed entry and its origin at the same time. An apparent exception under MAC Filtering > Allowed list isn’t a recovery path.

Reverse the change and close out

For an abort or global reversal on AP6, turn off the control next to AP6 in the same menu. Sophos explicitly documents this control as turning ATR on or off for AP6, but the documentation doesn’t promise that doing so deletes the underlying threat-feed entry. Don’t treat the finding as remediated; correct the originating integration or responsible security process separately.

Retest the pilot client and check the AP6 column in the MDR/XDR Threat Feed. Record the control-change time, MAC address, status before and after the change, and the result of the identical connection test. If the UI status and data-path effect disagree, make no further allow-list changes. Provide this evidence to Sophos Support and the API integration owner.