Sophos Fusion: Server Update Management for Windows and Linux
Server Update Management in Sophos Fusion (formerly Sophos Central) applies to Windows and Linux servers. Under My Products > Server > Policies, create an Update Management policy, enable it under Settings, configure Scheduled Updates if needed, and select the appropriate package separately for Windows and Linux under Select a software package. Test on a few representative servers first, then check the policy actually applied to each server under Policies.
The maintenance window controls when product updates become available. It does not block all updates: content updates for detecting new threats continue through a separate process. Conversely, time-limited software packages must not be allowed to expire unnoticed: security updates may also stop after a package expires. Put the expiration date on the change calendar.
Before making changes: Define a pilot and a recovery path
Choose Windows and Linux pilot servers that cover important applications and different time zones, but can be maintained in a controlled way if an update causes trouble. Record each server’s currently effective Update Management policy, current package, application status, and intended recovery path. Check whether the server can reach Sophos Fusion or its configured update source. Even a correctly assigned policy cannot help without a reachable update path.
For example, server-update-pilot applies only to test servers and server-update-produktiv to the remaining servers. The names are arbitrary; the actual server assignments are what matter. Schedule the local maintenance window around backups, cluster operations, and application maintenance, not just the time on the administrator’s workstation.
Configure the server policy
- Open My Products > Server > Policies. Create an Update Management policy or open the existing server policy. Do not edit the similarly named policy under Endpoint > Policies.
- Assign the intended pilot servers or appropriate server group. Place the pilot policy ahead of broader matching server policies in the policy order: the first matching policy applies to each server, or the Base policy if none matches. Under Settings, confirm that the policy is enabled. A saved but disabled policy is not a successful rollout.
- Enable Scheduled Updates if needed and choose the day of the week and time from which product updates become available. The time is local to each server: 21:00 means 21:00 on that server, not the same instant worldwide. If the server is off at that time, it receives the update only after it next starts. This setting does not promise that installation will finish at that exact minute.
- Under Select a software package, choose the appropriate package in the Windows and Linux selectors respectively. Check Details of packages before making a selection. Package selection also works without Scheduled Updates.
- Optionally set the content stage for each operating system if the tenant-wide content-timing permission is enabled; then select Save. Only an Admin or Super Admin can configure this timing. Only after the pilot is accepted should you extend your own policy assignments and product rollout to more servers; you cannot hold Sophos’s content delivery for your own approval.
Recommended updates automatically to current product features and does not expire. Fixed term support keeps a feature version for a limited period; Long term support is intended for servers that cannot be updated regularly. Both time-limited types need a replacement package in good time: an expired package may still be displayed but cannot be selected again; without a replacement, security updates may also stop. An EAP participant ignores its otherwise assigned package until the EAP ends or the device is removed from it; Special packages are available only through Sophos Support. Check which packages are actually offered in the tenant; selection may be restricted in a FedRAMP environment. The existing article on software packages and update infrastructure explains package types and shared settings; Fixed- and Long-term packages are selected in the server policy, while EAP device assignment and the addition of Special packages are handled in global settings.
Maintenance-window exception: A license change or a change to the software assigned to the server can trigger immediate installation. Treat such changes as separate changes and do not assume Scheduled Updates will hold them until the next window.
Content updates require a separate decision
Content Updates include machine-learning engines, threat definitions, and detection flags, among other things, but not a new product version. By default, Sophos controls their delivery. If the organization needs a staged rollout, Allow changes to timing of content updates must first be enabled under Global Settings > Products and Services > Endpoint and Server > Software packages. Only then select First stage, Second stage, or Last stage for Windows or Linux under Select a software package in the server policy, and save. The stages do not set a fixed time and do not replace Scheduled Updates.
For a pilot, First stage should include at least one representative server workload; the broader environment can use Second stage, and critical servers can be assigned Last stage where justified. Do not put every server in the last stage: an environment-specific problem would then appear only in your last wave. When stage controls are enabled but no stage is explicitly selected, Second stage applies. Even urgent content updates remain tied to the selected stage; Sophos can change the intervals between stages. Sophos delivers these stages; they are not started after your own pilot approval. Therefore, do not promise either a guaranteed delay of security content until the maintenance day or a fixed interval between stages.
Bypass caches only after verifying a direct path
Don’t use update caches in the Update Cache section is not an option for pausing updates. When enabled, servers assigned to this policy fetch updates directly from Sophos and also stop using Message Relays. On an isolated network, this can disrupt both updates and management communication. Enable it only for a deliberately tested exception after verifying the direct path from a pilot server. Setup, ports, and cache and relay assignments are covered in the existing article on Update Cache and Message Relay. Before choosing a host, check the current Sophos requirements for Update Caches and Message Relays: The linked existing guide still specifies 5 GB and Windows-only hosts; Sophos now requires 8 GB of free space and permits Linux hosts only when the relevant conditions are met, not for every tenant. This article does not assume general availability of Linux relays.
Verify the effective policy on each server
After Save, do not rely solely on the policy name in the policy list: My Products > Server > Servers > [Servername] > Policies shows which policies are applied to that specific server. Alternatively, go to My Environment > Computers & Servers > [Servername] > Policies. Check the Update Management policy type there and open the effective policy to compare its enabled status, target assignment, Windows or Linux package, schedule, content stage, and cache exception with the change record. Changing a policy opened from there can affect all servers assigned to it.
After the planned window, check the Sophos product version actually installed on each pilot server and whether its application works; document the time and result separately for Windows and Linux. A matching policy alone proves neither that the download finished nor that the application is working properly. Sophos Fusion also does not reliably show the exact latest content version per device; this display alone cannot establish that content has been fully validated. If you suspect a content problem, preserve the time window, affected server details, and diagnostic data for Sophos Support.
If the result differs from what you expected
- Wrong or missing update policy: Compare the server’s Policies details with the intended assignment; check that the server policy is enabled and whether another policy is effective for that server. Do not rush to change a shared policy while other servers still depend on it.
- Update before the window: Review license and software assignment changes in the change history. Then check whether the schedule was enabled at all and whether the expected policy was effective. The window is not a general safeguard against immediate product changes.
- No update after the window: Check the server’s status and local time zone, the selected package and its expiration date, and the direct or cache-based update path. Reassess a server that was off only after it starts. Narrow down the network and agent issue before changing caches.
- Unexpected content stage or content problem: First check the global permission and the setting in the Windows or Linux selector. Stages are not product versions. If there is a content problem, follow Sophos guidance to move all Update Management policies to Last stage and contact Sophos Support with details of the affected servers. This does not guarantee that delivery stops, and it does not remove content already installed.
Revert the change
First stop your own pending policy and product rollouts and restore the pilot’s previous policy assignment. Re-select the documented former package only if it is still supported and selectable; an expired package may remain visible but cannot be selected again. Otherwise, choose an available supported package and involve Sophos Support if a previous version must be restored. If only the new stage or schedule is causing problems, correct that option in the narrowly assigned pilot policy and select Save. Remove EAP participants from the EAP if necessary; changing their normal package alone does not override EAP. Then recheck the effective server policy under Policies, the installed product version, and the application.
Rolling back a policy does not automatically downgrade installed binaries. Resetting the policy does not remove an already installed product version or a faulty Content Update. If one causes a problem, preserve evidence of the application issue and installed versions, and agree on a supported recovery path with Sophos Support. For content problems, consider the stage change described above; it is not a pause button and does not undo content already delivered. Never bypass signature checks or disable protection across the board as a supposed rollback.