Skip to content
Avanet

Set up MDR and XDR integrations in Sophos Fusion

Integrations allow Sophos Fusion (formerly Sophos Central) to bring together telemetry from Sophos and third-party products in the Sophos Data Lake, or to provide targeted Response Actions in Central. The shared entry point is Threat Analysis Center > Integrations. Choosing the correct integration type is crucial: Data Ingest provides data for queries, Detections and investigations, while Response Action performs an action in the connected product. Not every product supports both directions.

Within the Endpoint onboarding path, this article completes the cross-product integration phase between protection configuration and operational acceptance.

A practical workflow is to check the licence and source system, choose the appropriate product tile and configuration in the Marketplace, establish the connection with the minimum permissions required, check it under Configured, and verify it with an expected test event. Only then should you consider the integration ready for production.

Scope: XDR, MDR and licensing

An integration does not replace an XDR or MDR licence. XDR provides analysis capabilities that allow an internal security team to investigate data in the Threat Analysis Center and Data Lake. MDR adds the managed Sophos service. The integrations available in a tenant depend on the Sophos contract, product, integration type and, where applicable, the third-party product licence.

The frequently cited claim that some integrations are free does not mean that the entire Marketplace is free. For MSP Flex, separate Integration License Packs apply to categories such as Endpoint, Network, Email and Firewall. With an XDR licence, Sophos NDR, Sophos Cloud Optix, Microsoft Graph Security and the Microsoft 365 audit appliance need no additional Integration License Pack. This rule expressly applies only to MSP Flex customers. Check what is enabled in your tenant and contract rather than assuming a blanket free entitlement.

The other platform may also require licences. Sophos’s Microsoft 365 pages conflict: the overview says Management Activity audit logs are available to all Microsoft 365 customers regardless of licensing, while the specific setup page requires Purview Audit (Standard or Premium), one of the listed user licences and enabled auditing. Apply these concrete prerequisites for setup. The Detections delivered by Graph Security V2 additionally depend on the Microsoft licence and available Defender XDR capabilities. Sophos does not specify a Microsoft licence requirement for Microsoft 365 Response Actions, but the integration requires a Microsoft 365 administrator and the Graph permissions listed below.

Integration types and required credentials

REST API

An API integration retrieves data from the vendor’s cloud service or sends a response action to it. Depending on the product, the setup assistant requests items such as a tenant or organisation ID, API URL, client ID, client secret, token or certificate. API integrations do not require a Sophos appliance.

Some integrations accept credentials directly in the assistant. Others request a reusable Integration Credential. You can tell whether a connector supports this from the option to select an existing credential or create one in its setup assistant. The Integration Credential Manager is available only for a limited subset of API integrations; its existence does not mean every secret can be reused centrally.

Log collector

With a Log Collector integration, the source system exports events by Syslog to a Sophos appliance. Its Log Collector processes the data and uploads it to the Sophos Data Lake. The appliance runs on ESXi, Hyper-V, AWS or Nutanix, or suitable Dell, NUC or OnLogic hardware. For ESXi or Hyper-V, allocate at least 4 CPUs, 16 GB RAM and 160 GB storage; supported versions start at ESXi 6.7 Update 3 with VM hardware version 11, and Hyper-V on Windows Server 2016. Sophos manages appliance operating-system and security updates; do not install another Sophos or anti-malware agent on it. Scale up for high data volumes or multiple integrations, and validate DNS, proxy, and required port and domain exclusions before approval. Configure the third-party product to send to this appliance, not to an arbitrary Syslog server.

Several integrations can use the same appliance. You must nevertheless configure the protocol, port, format and source for each product according to its integration guide. A green appliance alone does not prove that the correct event type is arriving.

Sophos products

Products such as Sophos Firewall and Sophos NDR have product-specific setup paths. Sophos NDR and Log Collector integrations require an integration appliance, but not necessarily a conventional VM. A REST API-only integration does not require an appliance. Use the affected tenant’s Marketplace as the availability check: each product tile shows the methods offered there and opens the relevant setup assistant.

Safely separate the NDR workload on a shared appliance

Only one Sophos NDR integration is permitted per appliance. The same appliance can also host multiple appliance-based third-party integrations as Log Collectors. Before making any change, expand the appliance entry under Configured > Integration Appliances and review every assigned integration. Neither the Integrations value nor a green appliance status replaces this check.

A targeted NDR restart interrupts the NDR sensor while the Log Collectors continue running. By contrast, Restart or Shutdown of the entire VM interrupts NDR and every Log Collector on that appliance. Schedule these actions within a maintenance window, document the state of every workload beforehand, and check each one separately afterward. Operate the Sophos NDR Appliance and Sensor Safely describes the procedure.

Delete in the appliance menu does not remove only one integration. Do not delete the appliance while NDR or a Log Collector is assigned to it. The menu item also does not establish that the deployed VM will be removed or that previously ingested Data Lake data will be deleted. Before decommissioning, clarify the assignments, data retention, removal of platform resources, recovery path, and final verification. Until then, leave the appliance in place.

Before setup

  1. Sign in to Sophos Fusion as an Admin or Super Admin. Sophos specifies these roles as a prerequisite for general setup.
  2. In the third-party product, check the required licence, administrator role, API capability or Syslog export.
  3. Decide whether you need Data Ingest, Response Action or both. A response integration does not automatically provide the telemetry on which an investigation depends.
  4. Where possible, create a dedicated app or service account for API access. Grant only the permissions required by the product guide and document the owner, expiry date and secret rotation path.
  5. If the third-party product requires a source IP allowlist for administrative API calls, first identify the Central region under My Environment > Installers: hover over a download link under Endpoint Protection or Server Protection and read the region from the displayed URL, for example eu-central-1. Then allow only that region’s addresses from the table below. These addresses are the sources of Sophos API calls, not outbound destinations for the integration appliance.
  6. For an integration appliance, check its own outbound network path, DNS and, where applicable, proxy against the appliance requirements.
  7. Plan a reproducible, harmless test event. A login or audit event is preferable to a real malware attempt.

Source IP addresses for API allowlisting

This table is an Avanet-maintained snapshot, checked on 14 September 2026. The Avanet Knowledge Base Operations Owner owns its freshness and reviews it monthly, and immediately after a Sophos change notice, a changed link or IP list, an allowlist change request, or an API connectivity failure that may indicate a mismatch.

At every table refresh or production allowlist decision, open the live Sophos IP list and compare the tenant’s region and complete IP set with this snapshot. If they differ, do not copy values directly into production: the owner must open a controlled change, have a second Avanet engineer verify the region mapping and diff, update all nine language versions together, test the link, then validate the affected integration with a harmless API synchronization or test event. Record approval, results and rollback instructions in the change.

Central regionIP addresses to allow
us-west-244.239.234.92, 44.236.151.222, 52.27.46.33, 3.136.113.75, 3.14.45.170
us-east-23.131.131.133, 13.59.142.27, 18.224.112.153, 3.136.113.75, 3.14.45.170
eu-west-134.246.211.14, 99.81.106.126, 52.19.250.167, 3.136.113.75, 3.14.45.170
eu-central-118.159.176.26, 18.198.100.158, 18.194.145.190, 3.136.113.75, 3.14.45.170
ca-central-13.97.4.79, 52.60.80.242, 3.99.3.86, 3.136.113.75, 3.14.45.170
ap-northeast-118.181.20.177, 54.95.61.201, 54.250.208.189, 3.136.113.75, 3.14.45.170
ap-southeast-254.79.192.43, 3.106.32.132, 52.62.157.111, 3.136.113.75, 3.14.45.170
ap-south-115.207.66.8, 65.0.211.72, 3.7.163.52, 3.136.113.75, 3.14.45.170
sa-east-1 (São Paulo)54.232.157.166, 54.207.154.36, 18.230.33.85, 3.136.113.75, 3.14.45.170
Dubai (labelled sa-east-1 in the Sophos table)51.112.210.120, 51.112.22.202, 40.172.255.38, 3.136.113.75, 3.14.45.170

Sophos currently labels both the São Paulo and Dubai rows as sa-east-1. Distinguish them by the tenant location and the IP set; never combine regions. Record the approved list in the change.

Add an integration from the Marketplace

  1. Open Threat Analysis Center > Integrations > Marketplace.
  2. Search for the vendor or product. Where similar entries exist, open the product page and check its category, product name, integration type and purpose. Cisco Meraki and Fortinet FortiAnalyzer, for example, are offered as both API and Log Collector variants.
  3. Open the required integration.
  4. Select the required type, such as Data Ingest, and click Add Configuration.
  5. Follow the Integration setup steps. For API integrations, enter the source-system details or grant OAuth consent. For Log Collector integrations, create or select an appliance and then direct the source system’s Syslog export to that appliance.
  6. If Sophos asks for internal domains and IP ranges when you add the first integration, enter only your own internal ranges. These details identify owned addresses, group related alerts and avoid third-party lookups; they are not the same as the allowlist of Sophos source addresses.
  7. Save the configuration and complete any external consent dialog. Record the integration name, source tenant, owner and next credential rotation date.
  8. Open Threat Analysis Center > Integrations > Configured. The new configuration must appear there. You can monitor or edit it later from this page. Connection Method also indicates whether to investigate the API or Log Collector path during troubleshooting.

Check operation and test the integration

A saved configuration is not proof that the integration works. Check the connection, data flow and actual content in sequence:

  1. Connection status: Open the entry under Configured, or the appliance status for an appliance-based connection. For Log Collectors, red means the integration is not working, yellow means it is working with errors, and green means events are being received and processed without visible problems.
  2. Defined test event: Generate a harmless event in the source system that the relevant API or Syslog category will definitely capture, such as an administrative change or test login. Record its time, user and source.
  3. Data Lake evidence: After the product-specific delay, search in Threat Analysis Center > Live Discover. Use the Live Discover category or query documented by the product-specific guide; if Sophos documents no such query for the connector, this general workflow must not promise a universal query-based test. The Live Discover runbook explains queries, Data Lake boundaries and result validation. Check the timestamp, tenant, user and event type. One matching record proves the connection; multiple recent records over a reasonable period demonstrate ongoing data flow.
  4. Detection boundary: Not every ingested event creates a Detection or Case. Data Ingest makes data available for analysis; Detections occur only when relevant detection logic triggers. Test ingestion in the Data Lake first rather than automatically expecting an Alert.
  5. Response Action: Use an approved test account and document its initial state. For Microsoft 365, Block user sign-in, followed by Allow user sign-in, is a suitable reversible test; Revoke all current sessions is not reversible. Also note that Entra Connect Sync may later re-enable a blocked hybrid account, the MDR response setting limits actions by Sophos analysts, and the names of individual Inbox Rules are case-sensitive for Response Actions.

Health Alerts are not an immediate test. The 24-hour period begins with the first failure message and produces a medium-severity Alert only if the failure continues without interruption. A green status or acknowledgement of the Alert resets the countdown. If the problem persists, the Alert then reappears once every 30 days.

Microsoft 365: three separate integrations

“Connect Microsoft 365” is not a single switch. The Marketplace provides separate tasks:

IntegrationDirectionResultImportant boundary
Microsoft - Office 365 Management Activity APIData IngestAudit logs in the Data Lake; Microsoft 365 audit data category in Live DiscoverMicrosoft 365 auditing must be enabled; after it is enabled, data can take up to 12 hours to appear.
Microsoft - Graph Security API V2Data IngestMicrosoft security Alerts in the Data LakeRequires access to Defender XDR capabilities; the quantity and quality of Detections depend on the Microsoft licence. The legacy API stopped working when Microsoft removed it in April 2026.
Microsoft 365 - Response ActionsResponse ActionBlock or allow user sign-in, revoke sessions and disable Inbox RulesCan be configured for only one Microsoft 365 environment; the integration does not itself ingest audit or Graph telemetry.

For Response Actions, Sophos specifies the Microsoft Graph permissions User.ManageIdentities.All, User.EnableDisableAccount.All, User.RevokeSessions.All, MailboxSettings.Readwrite and User.Read. With MDR, the selected MDR response mode still determines whether analysts may act without approval. In a hybrid Entra ID environment, Microsoft Entra Connect Sync may later re-enable a sign-in that was blocked in Central.

Example: connect Management Activity safely

  1. Make sure auditing is enabled in Microsoft 365. A Microsoft 365 administrator must authorise the connection.
  2. Open Threat Analysis Center > Integrations > Marketplace and select Microsoft - Office 365 Management Activity API.
  3. Under Data Ingest (Security Alerts), click Add Configuration.
  4. Check the auditing notice, click Save and continue, and then click Proceed under Connect to Microsoft 365.
  5. Sign in with the intended Microsoft administrator account, review the requested permissions and confirm with Accept. Finish the confirmation with Close.
  6. Check the entry in Sophos Fusion. The Microsoft 365 audit data category must appear under Live Discover > Query. Then generate a traceable audit event and find it with a provided query.

Microsoft does not guarantee a fixed time in which an individual event will appear in the audit log. A delayed record is therefore not automatically an integration error. After auditing is first enabled, data can take up to 12 hours to become visible.

For Graph Security V2, the first synchronisation occurs approximately five minutes after the data becomes available in Microsoft Defender Security Center. If the Alerts and Incidents service must first be provisioned, that Microsoft step alone can take about an hour.

Disable or remove an integration

There is no universal Disable switch for every integration type. The available actions vary by product and Connection Method, so do not rely on a universal control:

  1. Open Threat Analysis Center > Integrations > Configured, select the configuration and record its status, name, source tenant, appliance and credential.
  2. For an API integration, first stop ingestion in a controlled manner or use a Disable or Delete action if the specific product page provides one. Then revoke OAuth consent or disable the dedicated app or token in the source system. For Response Actions, this prevents further actions from Central.
  3. For a Log Collector integration, remove the Syslog destination from the source system. Do not delete a shared Sophos appliance while other integrations use it.
  4. Remove the configuration in Central only when retention, audit and change requirements are satisfied. Removing a configuration does not guarantee deletion of Data Lake data that has already been ingested; clarify retention and deletion in advance against the Data Lake and compliance requirements that apply to the tenant.
  5. Verify that no new events arrive and that no unexpected Response Actions remain possible. Then remove any secrets, certificates, service accounts and allowlist entries that are no longer needed.

For a short maintenance interruption to a Log Collector integration, stop the Syslog export without deleting a shared appliance. For API and Response integrations, lock a credential as a maintenance pause only if reactivation of the same configuration has been verified beforehand; otherwise use only the connector’s available Disable, Delete or Reconnect path. A locked or expired credential is not a universal rollback and causes synchronisation errors.

Troubleshoot common failures systematically

API integration does not synchronise

Open Configured, check the Connection Method and read the specific error. Resolve Invalid credentials, insufficient permission and expired credentials in the third-party product first: check IDs, secrets, token lifetimes, certificates and API permissions. Network not reachable and invalid domain also require DNS, proxy, firewall and service-status checks. With request throttling, the provider has limited the API; repeatedly saving immediately may worsen the problem. For Microsoft, HTTP 401 means invalid authentication; 429 and 509 indicate throttling.

Log Collector remains red or yellow

Red means not working; yellow means working with errors. Check VM resources, network and DNS, outbound connectivity, and the Syslog path from the source system to the appliance. no events received since last container restart indicates that no Syslog events have arrived since the container started. no received events in last 10 mins may indicate an interrupted export or simply a source that sends infrequently. If uploads fail, the appliance buffers data on disk. If uploading remains blocked and storage fills, older data may be discarded.

Microsoft 365 supplies no data

For Management Activity, Microsoft 365 auditing must be enabled, and Enabled for users to sign-in? = Yes must be set under Office 365 Management APIs. Allow for the startup time of up to 12 hours after enabling auditing. For Graph Security V2, check Defender XDR access, consent, provisioning of the Alerts service and the available Microsoft licence. The old Graph Security API is no longer a fallback.

No Health Alert despite an outage

First check that this is a Data Ingest integration and that the failure has continued for 24 hours without interruption since the first error message. An intervening green status or acknowledgement of the Alert resets the countdown. By default, all Central administrators receive the email; custom Notification Rules can change this distribution.

Security and operational rules

  • Use dedicated apps and secrets instead of personal administrator accounts.
  • Grant only the API permissions required by the specific integration. Response integrations inherently require write permissions and warrant stricter approval than ingestion-only connections.
  • Do not store secrets in tickets, screenshots or KB articles. Record the owner and expiry date in password or secret management.
  • Plan credential rotation before expiry. Sophos reports expired credentials as synchronisation errors.
  • Allow Sophos IP addresses only where the provider requires a source allowlist, and use the list for the actual Central region.
  • Enable health notifications for a responsible team. When creating a Custom Notification Rule, remember that doing so disables the default delivery of all email Alerts to all administrators, so you must recreate any required rules separately.
  • Document each integration’s data source, purpose, data classification, retention, permissions, test, owner and removal path.

Acceptance criteria

Setup is complete only when the integration appears under Configured with the expected method, a defined test event can be found in the intended destination, its timestamp and source tenant are correct, and an owner accepts responsibility for credential rotation and Health Alerts. For Response Actions, acceptance also requires an approved test that returns to the initial state. Record unavoidable delays, such as Microsoft 365 auditing latency, in the operations log.

Frequently asked questions

Does every integration send data to the Sophos Data Lake?

No. Data Ingest sends data to the Data Lake. Response Action enables an action in the third-party product. Some products offer only one type; others have separate configurations for both directions.

Are third-party integrations free with XDR?

Not in every case. For MSP Flex, Sophos lists specific Sophos XDR category integrations that can be used with XDR without an additional Integration License Pack. Other categories require the appropriate packs under Flex. Third-party licences may also be required.

Why can I see data but no Detection?

Ingestion and detection are separate stages. A Data Ingest connector can write events correctly to the Data Lake without every event producing a Sophos Detection or Case. Check the raw data flow first with the intended Live Discover query.

Can I use the same appliance for multiple Syslog integrations?

Yes. Sophos allows multiple third-party integrations and Sophos NDR on the same appliance. Each source must still be configured with the correct connection and format details.

Why is the Microsoft 365 Response integration not enough?

It provides actions but does not automatically ingest audit data or Defender Alerts. Add Microsoft 365 Management Activity and Microsoft Graph Security API V2 so that Detections and investigation context are available.

Does removing an integration delete historical Data Lake data?

Removal does not guarantee immediate deletion of data already ingested. Treat removal as stopping future data flow, and clarify retention or deletion obligations separately before committing to a deletion deadline.