Configure Sophos DNS Protection for endpoints
Sophos DNS Protection is a separate product in Sophos Central. The Endpoint policy described here is its officially documented integration with Sophos Endpoint: the Endpoint agent intercepts DNS requests and forwards them to DNS Protection over HTTPS. Filtering therefore remains active away from the corporate network without manually changing the device’s DNS servers.
This integration is neither a standard Endpoint protection policy nor the same as Web Control. DNS Protection makes domain-based decisions through its own Filtering policy. Web Control uses separate Endpoint web policies. The firewall integration follows another DNS path and is covered in Sophos DNS Protection with Sophos Firewall.
Check the requirements first
The workflow currently documented by Sophos requires:
- a supported Windows endpoint; Windows Server and macOS devices cannot currently be added to this policy,
- an installed Sophos Endpoint Agent,
- access to DNS Protection in the tenant,
- HTTPS connectivity from the endpoint to DNS Protection,
- the Windows software package currently required by Sophos.
Sophos explicitly describes the package requirement as temporary. Before each rollout, check My Products > Endpoint > Policies > Update Management > Base Policy - Update Management > Settings > Select a software package to see whether FTS 2025.2.3.31.2 Required for DNS Protection Update is still required. While that instruction remains in the current Sophos documentation, select the package under Windows; Recommended may become applicable again afterwards.
Install the agent component
- Open My Products > Endpoint > Computers.
- Select the Windows computers for the pilot group.
- Select Manage Endpoint Software.
- Set DNS to Install. With a ZTNA licence, the entry is called DNS & ZTNA.
- Select Save.
Do not proceed immediately to the full estate. First verify in Central that the software assignment has reached the pilot devices and that no installation warning remains. An existing Endpoint installation alone does not prove that the DNS component has been assigned.
How a DNS request is handled
- Sophos Endpoint intercepts DNS traffic, except for explicitly excluded domains.
- All other requests are securely forwarded to DNS Protection over HTTPS.
- DNS Protection returns its responses directly to the requesting application.
- Requests for excluded domains go to the system- or application-configured DNS service.
- Optionally, the local DNS service can retry a name when DNS Protection returns
NXDOMAINbecause it cannot be resolved publicly.
Without the DNS Protection integration enabled, the local DNS service handles requests as before.
Plan the Secure DNS location and Filtering policy
DNS Protection groups devices and networks into Locations. For endpoint devices, the selected Location must use Secure DNS as its connection method. The non-editable Default location meets this requirement, or you can create a separate Secure DNS Location in DNS Protection.
A separate Location is useful when a pilot group, region or organisational unit needs different filtering. It does not replace careful selection of computers or computer groups in the Endpoint policy.
The Endpoint policy associates devices with the Location. The separate DNS Protection Filtering policy determines which domains are allowed or blocked. By default, DNS Protection blocks domains with a poor threat score or dangerous reputation even when no Filtering policy is assigned or a Domain List allows the domain. Custom category decisions must therefore not be treated as a malware bypass.
Internal domains may require two different controls:
- A Domain exclusion in the Endpoint policy sends a name that is only resolvable internally to the local DNS service.
- An allow Domain List in DNS Protection can prevent an otherwise public corporate domain from being blocked by an unsuitable category decision.
A Domain List does not replace a Domain exclusion for private DNS zones.
Create the Endpoint policy
The current, officially documented entry point is My Products > DNS Protection > Policies > Endpoint policies.
- Select Add policy.
- Add the intended computers or computer groups.
- Under Policy Active, verify that Policy is Active is turned on. It is on by default for a new policy.
- Open Settings.
- Turn on Use Sophos DNS Protection.
- Select the Default location or a custom Location that uses Secure DNS.
- Add internal domains under Domains.
- Decide whether the system- or application-configured DNS service should retry after
NXDOMAIN. - If block pages are required, configure automatic certificate deployment.
- Save and validate only with the pilot group first.
Check the effective assignment on a device. Seeing the policy in the portal is not, by itself, proof that it applies to the device.
Handle internal DNS zones safely
For internal zones such as corp.example, Active Directory zones and split-DNS namespaces, Sophos recommends explicit Domain exclusions. All subdomains of an entered domain are excluded automatically. Requests therefore go directly to the intended system- or application-configured DNS service.
Retry with system- or application-configured DNS services when DNS Protection returns NXDOMAIN is a fallback for names that cannot be resolved publicly. Sophos still recommends a maintained exclusion list for the best performance. The retry option should therefore not replace a complete inventory of internal zones.
Block pages and certificate
Automatically deploy the DNS Protection signing certificate to devices automatically installs the required root certificate on target devices. Only then can a browser show the Sophos block page for a blocked HTTPS domain without a certificate warning.
Test certificate deployment in the pilot group first, particularly for browsers with their own trust store or restrictive certificate policies. A missing block page does not prove that DNS Protection allowed the domain: Sophos states that a block returns the IP address of its block-page server instead of the destination address. Also check the policy match and DNS Protection logs.
Pilot and validation
The pilot group should cover at least:
- one allowed and one deliberately blocked public test domain,
- internal short names and FQDNs,
- office, home-working and VPN connections,
- browsers and applications with their own Secure DNS or DNS-over-HTTPS configuration,
- the block page and trust in the signing certificate,
- behaviour when the service cannot be reached or the HTTPS connection is blocked.
Success means that intended public requests appear under the expected Location and are evaluated by the expected Filtering policy, internal exclusions continue to resolve through local DNS, and pilot devices do not lose business-critical name resolution.
Evaluate logs and reports
According to Sophos, data under DNS Protection > Logs & Reports is 15 to 25 minutes behind real time. Changes to Location or policy names may take 30 minutes to four hours to appear. Allow for these delays during pilot validation.
DNS usage shows DNS requests across the network. DNS usage by source breaks them down by Location and, for Sophos Endpoint, also shows users and devices. High risk devices helps identify devices requesting risky, suspicious or insecure domains. This provides stronger evidence of the Endpoint assignment than the public IP address alone.
Saved Templates preserve the report configuration, not generated data or the selected time range. Exports have different row and column limits depending on format, and exported files are deleted after 90 days. Incident data therefore needs separate retention outside this temporary export area.
Troubleshoot common problems
The device cannot be added
Check the operating system and device type first. The current Sophos documentation only permits Windows endpoints, not Windows Server or macOS devices. Then check the Endpoint agent, DNS software component and access to DNS Protection.
Internal names do not resolve
Add the affected zone as a Domain exclusion. Then check the local DNS server, search suffix, VPN DNS settings and the policy that actually applies to the endpoint. A broad NXDOMAIN retry can help diagnosis, but does not replace a correct zone list.
The block page shows a certificate error
Verify that Automatically deploy the DNS Protection signing certificate to devices is enabled and that the pilot device trusts the root certificate. Browsers with their own trust store may need additional management.
The browser appears to bypass the policy
Browsers and applications may use their own DNS-over-HTTPS route. Check the resolver actually in use and the policy assignment first. A single browser test without this evidence is not enough to conclude that the Endpoint agent or DNS Protection has failed.
An allowed domain remains blocked
Check the threat score, reputation, category and possible CNAME targets. According to Sophos, the default security block cannot be overridden with a Domain List. Submit a demonstrably incorrect classification for recategorisation rather than creating increasingly broad allow lists.
Roll back in a controlled manner
Turn off Use Sophos DNS Protection in the affected Endpoint policy or remove the pilot devices from its assignment. On a pilot device, then verify that the system- or application-configured resolvers are used again and that both internal and public names work. Remove the deployed root certificate only afterwards through the intended managed certificate process; manual one-device cleanup is not a suitable rollback for a larger estate.