Set up Sophos DNS Protection on Windows Server
Purpose and direct answer
When Windows Server is used as a DNS server, it can be configured to use Sophos DNS Protection as a DNS forwarder. To do this, add both DNS Protection IP addresses from Sophos Fusion to the forwarders on the Windows DNS Server.
The complete path is:
Sophos Fusion: My Products > DNS Protection > Installers > IP addresses > Copy
Then, on Windows Server, go to:
Server Manager > Tools > DNS > server > Properties > Forwarders > Edit
This guide applies to the forwarder on a Windows DNS Server. It does not configure a managed DNS Protection endpoint policy or change the DNS server addresses of individual endpoints. Location-based DNS forwarding and DNS configuration for managed endpoints are separate procedures.
Prerequisites, licensing, and roles
The following prerequisites must be met before making the change:
- Windows Server is already being used as a DNS server; the DNS Server role and the server to be changed have been clearly identified.
- The intended Traditional DNS Location exists in Sophos Fusion.
- Two DNS Protection IP addresses are displayed under My Products > DNS Protection > Installers.
- Internal and conditional zones are known and must continue to resolve locally or through their existing internal DNS paths.
- Before selecting Edit, the current state under Forwarders has been backed up or documented in a traceable manner according to the Windows DNS operating documentation.
- A tested and internally approved method is available to restore the documented initial state of the server if an error occurs.
Neither a specific license name nor a particular administrator role is defined for this procedure. Before making the change, therefore, use your own role and change documentation to verify that you are permitted to view the installer values and change the Windows DNS server properties. If either permission is missing or the correct Location cannot be clearly identified, stop here and involve the responsible Sophos Fusion or Windows DNS administrator.
⚠️ Important: Do not enter only one address. The configuration requires both DNS Protection IP addresses copied from Sophos Fusion.
Configuration with customizable example values
The example values <DNS_PROTECTION_IP_1> and <DNS_PROTECTION_IP_2> represent only the two tenant-specific addresses displayed in Sophos Fusion. Do not use public example resolvers or values from another Sophos Fusion environment.
- In Sophos Fusion, open My Products > DNS Protection > Installers.
- Next to IP addresses, click Copy. Record the copied values as
<DNS_PROTECTION_IP_1>and<DNS_PROTECTION_IP_2>for the change. - On the Windows Server, open Server Manager.
- Select Tools > DNS.
- Right-click the DNS server to be configured and open Properties.
- On the Forwarders tab, click Edit.
- Under IP address, add both DNS Protection IP addresses copied from Sophos Fusion.
- Click Apply, then OK.
Sophos documents only the user interface for this procedure, not a PowerShell command. Changes to Conditional Forwarders or to the DNS settings of network adapters and clients are not part of this procedure.
Validation and expected result
First, verify the change on the intended DNS server only:
- Reopen Server Manager > Tools > DNS > server > Properties > Forwarders.
- Confirm that both IP addresses previously copied from Sophos Fusion are listed under Forwarders.
- Test name resolution with a selected client that uses this Windows DNS Server.
- Resolve both a public name and a known name from an internal or conditional zone.
The expected result is that both Sophos addresses are saved as forwarders and that internal and conditional zones continue to resolve through their local DNS paths. This check does not verify a specific report field, a fixed processing time, or any further product behavior. If an address is missing under Forwarders, do not roll out the configuration to additional systems; check the copy-and-paste process again instead.
Troubleshooting by symptom
One or both Sophos addresses are missing
Under My Products > DNS Protection > Installers, select Copy again next to IP addresses. Then, on the exact Windows DNS Server intended for the change, open Properties > Forwarders > Edit and enter both copied values under IP address. Do not finish with Apply and OK until both values are present.
Internal or conditional names no longer resolve
Stop any further rollout immediately. Internal and conditional zones must continue to resolve locally or through their existing internal DNS paths. Creating or repairing such zones is not part of this procedure. Therefore, do not change master servers or zone values based on assumptions; instead, compare the documented pre-change state with the responsible Windows DNS administrator.
The tab or controls are unavailable
Check whether the correct DNS server has been selected and whether the session is authorized to change DNS server properties according to your administration requirements. No specific Windows or Sophos Fusion role is defined for this procedure. If access is unavailable, do not experiment with another role; involve the responsible administrator instead.
Both addresses are configured, but the expected service has not been confirmed
This procedure does not include firewall, port, report, or policy diagnostics. Therefore, do not extend the change based on unconfirmed assumptions. Document the selected Traditional DNS Location, the copied values, and the affected Windows DNS Server, and hand the issue over to the responsible DNS Protection or network administrator.
Safe rollback
This guide does not describe a universally applicable procedure for removing the IP addresses. Therefore:
- If an error occurs, stop any further rollout.
- Restore the documented initial state only by using the method that was tested and internally approved before the change.
- Then use a selected client to test public and internal name resolution again.
Without a documented initial state, do not delete addresses or enter other resolvers based on assumptions. Stop safely here and hand further recovery over to the Windows DNS administrator.
Operation and regular review
When planning changes to the Windows DNS Server or the DNS Protection Location in use, compare the current configuration with My Products > DNS Protection > Installers again. Continue to verify that both IP addresses displayed there are present under Forwarders and that internal and conditional zones remain locally resolvable.
No fixed review cycle, automatic migration, or end-of-life date is defined for this procedure. For any later change, therefore, use the then-current Sophos help and your own change approval process.
Distinction from other procedures
This guide covers only Windows Server as a DNS forwarder. Endpoint policies, individual Windows devices, macOS, Sophos Firewall, Locations, filtering policies, certificates, and reports are separate tasks. If the change affects any of these areas, use the procedure intended for that area rather than deriving steps from this forwarder guide.