Handle Sophos Endpoint alerts and Account Health
A Sophos Central alert is a work item, not automatically a confirmed security incident. Alerts can result from threats, failed updates, licence issues, disrupted communication or an incorrect protection status.
Start under My Environment > Alerts. The cause is what matters. Acknowledge, Close, Resolve and Reset health status do not replace remediation.
Distinguish events, alerts and health
| Element | Meaning |
|---|---|
| Event | an individual occurrence observed on a device or platform |
| Alert | an assessed notification that requires investigation or action |
| Health State | the aggregated condition of a device |
| Threat Graph | relationships between processes, files, users and follow-on activity |
Sophos can combine repeated events into a single alert. The event count and time range show whether it is an isolated occurrence or an ongoing pattern.
Health and alerts are evaluated independently. A device with an alert can be green, and a device that is not green does not necessarily have an open alert. Do not draw a conclusion from either the colour or the alert list alone.
Triage in the right order
- Check severity, status, device and event count.
- Open the alert and record the detection name, time, user, path and action.
- Check the device condition and last activity.
- For threats, investigate the process chain, hash, signature and source.
- Check whether Sophos completed cleanup successfully.
- Isolate the device if the risk remains active.
- Resolve the cause, then review health and alerts.
High means high urgency, but Medium alerts can still indicate an attack chain or missing protection.
Understand alert actions correctly
Mark As Acknowledged
The alert disappears from the active list. The threat is not removed, and quarantine data remains available.
Mark As Resolved
Use this Windows action when the cause has already been fixed on the device. It removes the alert and clears the display in the local quarantine manager. It does not perform threat cleanup itself.
Close alert
Closing changes the workflow status. It is not a technical fix. Close an alert only after documenting the cause and validating the outcome.
Reset health status
Reset removes old warnings and resets the displayed Health State. It is not available for macOS and repairs neither malware nor damaged software. If the cause remains, the device turns amber or red again.
Continue investigating threat alerts
After triaging malware, ransomware, exploits, IPS detections, PUAs or a possible false positive, continue with the technical incident response. The complete workflow for isolation, process-chain analysis, cleanup, remote ransomware and closure criteria is described in Sophos Endpoint threat cleanup and malware remediation.
Outbreak alerts
Sophos groups a malware outbreak after 100 detections on one device within 24 hours to keep notification volume manageable. Normal detection reporting resumes only after the Outbreak Alert is marked Resolved.
First investigate the source, persistence, distribution and neighbouring devices. Marking it Resolved without removing the cause may merely make further individual alerts visible again.
Installation, compliance and restart alerts
A Failed to protect computer alert is generated when an agent that has started is still not protected after one hour. Missing or stopped Sophos services often indicate an incomplete installation or failed update. Check the supported operating system, restart status, update connectivity and installer log before reinstalling.
For Policy non-compliance, Central tries to reapply the affected policy after two hours of deviation. The alert closes automatically as soon as the device is compliant again. Manually closing it without checking the cause is therefore not useful; recurring deviations require policy, communication and agent diagnostics.
A pending restart initially generates events and then an alert after two weeks. Even with a green agent status, a device may be waiting for old drivers or components. Maintenance windows and user communication should therefore not be planned only when the alert appears.
Account Health Check
Under My Environment > Account Health Check, Sophos assesses whether devices and policies use recommended protection settings. A score below 100 produces a Medium alert after a delay. When the score returns to 100, Sophos closes this health alert automatically.
After a configuration change, the Account Health widget on a custom Canvas can continue to show the previous overall score for up to ten minutes. The individual Account Health Check pages are the authoritative source during this interval; repeatedly using Auto-Fix does not accelerate recalculation.
Fix automatically can change many settings at once. Review the pilot group, documented exception reasons and Audit Log first. Snooze postpones a Health Check but does not resolve it.
The Overall Health Score is the lowest individual check, not an average. For Threat Protection policies, Sophos deducts 10 points for each setting that is not recommended and averages multiple policies of the same type. For risky exclusions, it deducts 20 points for each detected entry.
A green Exclusion check is not a complete security approval. Sophos checks only particularly unsafe patterns. Review all exclusions regularly on their technical merits regardless of the score.
Reset on a Base Threat Protection Policy enables the recommended settings but leaves Device Isolation and SSL/TLS Decryption turned off. Both functions require a deliberate operational decision.
Health Check alerts are Medium and appear no sooner than about ten minutes after a score drops below 100. A Snooze lasts six months and temporarily closes the associated alert. Assessment continues in the background.
The Protection improvement check assesses whether Threat Graph data, Intercept X data and malware samples are submitted to Sophos. These settings improve cloud-based analysis but also concern privacy and internal approvals. Do not apply an automatic tenant-wide fix without that assessment.
The Endpoint agent mode check compares installed components with the licence. Affected devices appear as Product unassigned or Upgrade available. Fix automatically installs all licensed components on every affected computer; they can be changed selectively under Computers & Servers > Manage Software. Installation starts with the next online update and, according to Sophos, normally completes within an hour.
For Tamper Protection, the global switch must be active first. Only then can Account Health enable protection on individual computers automatically or through the Computers with tamper protection turned off device filter. Every automatic change can be checked in the Audit Log.
The download icon exports the current Account Health Check as a PDF. The report contains scores, individual checks and comments and is suitable for periodic security reviews. An exported score still does not replace the documented justification for an exclusion.
When Sophos Support is appropriate
Contact Support when cleanup repeatedly fails, the agent is damaged, a detection returns despite verified approval or a new false positive is suspected.
Before opening the case, collect the alert ID, device, time, detection name, logs, hash, signature, completed actions and desired outcome.