Deploy Sophos Managed Risk Appliance and Set Up Internal Scans
Internal Managed Risk scans require a virtual vulnerability-scanning appliance. The safe process is to check the prerequisites, create a scanner under My Products > Managed Risk > Scans > Internal, deploy the correct image once, wait for the Connected status, and run a Discovery Scan first. Configure the weekly Vulnerability Scan only after the discovery report shows the expected inventory.
Requirements before deployment
Authorized contacts and the external scans must already be set up. Without these two steps, the internal scanning path cannot be configured. In addition, you need:
- a supported VMware-ESXi or Microsoft Hyper-V host;
- a management network from which the appliance reaches Sophos and its update sources;
- routing and firewall rules from the appliance to all intended internal destinations;
- enough Managed Risk licenses for the planned asset inventory;
- a secure password vault for the appliance credentials, which are displayed only once;
- a maintenance window of up to 30 minutes for initial start, restart and plugin loading.
Managed Risk uses this appliance to assess hosts and services. It is not a web-application or API vulnerability assessment. Do not confuse the appliance with a Sophos NDR appliance: this process does not configure traffic mirroring, SPAN, ERSPAN, SYSLOG, or an NDR integration.
Checking virtualization and resources
For VMware, ESXi 6.7 Update 3 or later and VM hardware version 11 or later are required. VMware Cloud deployments are not supported. In an EVC cluster, the EVC mode must correspond to at least a Skylake CPU; VM hardware version 11 remains the minimum there as well.
For Hyper-V, version 6.0.6001.18016 (Windows Server 2016) or later is required. Processor Compatibility Mode is not supported.
The appliance requires at least:
- 4 CPUs
- 16 GB RAM
- 160 GB Storage.
The VMware OVA is preconfigured with these minimum values. They also apply to Hyper-V; the supplied script asks for the number of CPUs and amount of memory during deployment.
The CPU generation is also a strict requirement. Sophos lists Intel Skylake, Kaby Lake, Coffee Lake, Coffee Lake Refresh, Cascade Lake, Comet Lake, Cannon Lake, Ice Lake, Rocket Lake, Alder Lake, and Raptor Lake. For AMD, it lists Naples, Great Horned Owl, Rome, Milan, and Genoa. What matters is the effective CPU microarchitecture visible to the VM; the hypervisor host’s model name alone is not sufficient.
Before downloading, compare the installed hypervisor build with the manufacturer’s current release information. For ESXi, the vSphere client shows the build under Hosts and Clusters after you select the host. The Broadcom mapping of build numbers to versions helps identify it. A build above Sophos’s minimum version is not necessarily fully patched. For Hyper-V, check the version and patch level using the approved Windows Server inventory; the obsolete external version link cited in older documents is not a reliable source.
Allow outgoing connections
The appliance must be able to boot and download updates. For a firewall with wildcard support, Sophos lists the following outbound destinations for the shared appliance platform:
| Destination | Port and protocol | Purpose |
|---|---|---|
*.sophos.com | TCP 443 | Communication with Sophos Fusion |
*.amazonaws.com | TCP 443 | Image and content retrieval |
*.ntp.org | UDP 123 | Time synchronization |
sophossecops.jfrog.io | TCP 443 | Package and Update Source |
yum.oracle.com | TCP 443 | Optional package source |
yum.oracle.com is optional; if the destination is unreachable, the appliance uses the Sophos-JFrog mirror. If the firewall does not support wildcards, use the current explicit destination list from Managed Risk appliance requirements > Port and Domain exclusions. This list contains regional and cloud-specific names and must not be copied from old project documentation.
The shared appliance documentation also lists TCP 22 for *.sophos.com in the wildcard view. In the explicit destination list, however, that port is assigned to ndr.apu.sophos.com and therefore belongs to the NDR portion of the shared platform. Do not allow TCP 22 for the Managed Risk process described here.
The rule applies only to outbound traffic from the appliance’s management network. This process requires no inbound Internet access. According to Sophos, a Sophos Firewall allows the required destinations by default; nevertheless, verify the rule and web-filter path that actually apply.
Create a scanner in Sophos Fusion
- Open My Products > Managed Risk > Scans and select the Internal tab.
- Click Add scanner.
- Enter a unique name and description, for example
MR-Scanner-ZurichandInternal networks at the Zurich site. - Under Virtual Platform, select either VMware or Hyper-V. The selection must match the image that you will deploy on the hypervisor.
- Select the IP configuration:
- DHCP obtains the address automatically. For this option, configure a DHCP reservation so that rules, routing, and support documents do not point to the wrong address after a lease change.
- Manual uses the static network settings intended for the management network. Take the values from your own IP plan; do not use example addresses without verifying them.
- Select Save.
- Immediately copy the displayed appliance credentials to an approved password vault and restrict access to the responsible administrators. The window shows these credentials only once. Do not put them in a ticket, chat log, or scan description.
- Select Close. The new scanner initially appears with Waiting for Deployment.
- In the scanner row, open the three-dot menu under Action. Download appears when the image is ready. If this takes more than a few minutes, use the button at the top right to refresh the page, then download the image.
The image must match the selected platform. For VMware, the one-time use of the OVA described below also applies.
Deploy the appliance
VMware ESXi
The OVA generated in Sophos Fusion can only be used once. If you need a new VM or must start again after a failed deployment, generate a new OVA in Sophos Fusion. Do not deploy an old OVA file again.
- On the ESXi host, open Virtual Machines > Create/Register VM.
- Under Select creation type, select Deploy a virtual machine from an OVF or OVA file.
- Set a unique VM name and select the OVA file you just downloaded.
- Under Select storage, select the intended datastore. Sophos specifies Standard as the storage type.
- Assign the interfaces under Deployment options. The common appliance image also requires fields that Managed Risk does not use:
- For SPAN1 and SPAN2, select any Port Group as the required placeholder and disconnect both adapters in the VM settings after deployment.
- For SYSLOG, select the same Port Group as for MGMT as the required placeholder.
- For MGMT select the Port Group of the management network. Only this interface is used for vulnerability scans and communication with Sophos.
- When using DHCP, check that the VM can obtain an address in the MGMT Port Group and that the reservation is already active.
- For Disk Provisioning, select Thin and activate Power on automatically.
- Skip Additional settings and complete deployment with Finish.
- Wait for the VM to appear in the list, disconnect SPAN1 and SPAN2 in the VM settings, and turn on the VM if it has not already started.
The placeholder assignments only satisfy the required fields in the shared deployment dialog. They do not configure traffic capture, SYSLOG, or an NDR integration.
Microsoft Hyper-V
The Hyper-V download package is a ZIP archive containing virtual disks, seed.iso, and the supplied PowerShell script. You do not need custom commands or modified script paths.
- Unpack the ZIP archive into a local work folder.
- In the unpacked folder, start the file nessus-scanner with Run with PowerShell.
- If Security Warning appears, confirm that the package downloaded from Sophos Fusion may run by selecting Open.
- Enter a unique name for the VM.
- If the script shows the new folder at the default virtual drive location, use
Cto confirm its creation. - Specify at least
4processors and16GB memory. - From the numbered list, select the vSwitch for the management interface. This vSwitch must reach the intended scan targets and Sophos; with DHCP, address assignment must also work through it.
- For the required placeholder field SYSLOG, specify the same vSwitch as for the management interface.
- Select any vSwitches for the required placeholder fields of the traffic capture interfaces and disconnect these adapters after deployment in the VM settings.
- Continue until the Installation Completed Successfully message appears, then press any key to exit the script.
- In Hyper-V Manager, verify the new VM and its resources, disconnect the unneeded capture adapters, and turn on the VM.
For Managed Risk, the management interface alone is the scan and communication path. The remaining prompts come from the shared appliance script; the required placeholders do not activate NDR, capture, or SYSLOG functionality.
Check connection and initial start
On first startup, the VM checks its connection to the selected Port Groups or vSwitches and to the Internet, then restarts. This process can take up to 30 minutes. Sophos Fusion then shows plugin-loading progress in the status.
Under My Products > Managed Risk > Scans > Internal, hover over Status to see the progress. After a successful deployment, the scanner passes through these states:
- Downloaded
- Waiting for appliance
- Loading plugins
- Connected
Only Connected is the success criterion for the next step. If the status stops earlier, first check the platform version, CPU compatibility, resources, management IP, default gateway, DNS, time synchronization, and outbound firewall rules. Do not repeatedly recreate the VM while the cause is unknown; with ESXi, doing so would also require a new single-use OVA.
Discovery Scan first
A Discovery Scan determines which internal assets the appliance sees in the selected target range. It is the inventory check performed before the more in-depth Vulnerability Scan.
- Open My Products > Managed Risk > Scans > Internal.
- Select Create discovery scan.
- On Create Discovery Scan under Select scanner select the connected scanner.
- Enter a name and description under Configure scan details, for example
Discovery-Zurich-ServersandInventory of production server networks. - Under Add scan targets, enter IP addresses, CIDR networks, or hostnames and select Add for each. Submit individual entries with Enter; alternatively, paste a comma-separated list.
- Under Schedule the weekly scan, select the weekday, time, and correct time zone. If you do not select another time, the scan runs at midnight in the selected time zone.
After execution, the report appears under Managed Risk > Report History. Compare the discovered IP addresses and hostnames with the CMDB, IPAM, or an approved asset list. If expected systems are missing, correct the routing, firewall rules, and selected target range before scheduling a Vulnerability Scan.
Setting up a Vulnerability Scan
- Open My Products > Managed Risk > Scans > Internal.
- Select Create vulnerability scan.
- On Create Vulnerability Scan, select the connected scanner under Select scanner.
- Under Configure scan details, enter a unique name and description.
- Under Scan type choose between Unauthenticated and Authenticated:
- Unauthenticated does not use credentials and simulates the view of an attacker without an account. As a result, fewer vulnerabilities are often detected.
- Authenticated uses authorized credentials to examine the target system in greater depth. This scan type typically finds more vulnerabilities. The target systems and dedicated scan credentials must be prepared first.
- For Authenticated, select no more than ten previously verified credentials under Select credentials. Create opens the form for adding new credentials. The guide Managed Risk credentials for authenticated scans explains how to prepare, store, and verify the accounts. Do not record credentials in the name, description, or support evidence.
- Under Add scan targets, add the IP addresses, CIDR networks, or hostnames previously verified with the Discovery Scan.
- Under Schedule the weekly scan, select the correct time zone and a time outside resource-intensive business operations and backup windows.
- Select Save at the top right.
The scan then runs weekly. Its report appears under Managed Risk > Report History after completion. A successful run does not mean that every CVE has been tested: Managed Risk uses Tenable plugins, and which plugins run depends on factors such as the operating system, open ports, and scan type. The Tenable Plugin Database shows the available coverage, while Newest Plugins shows the latest additions. This information provides neither a guarantee that all CVEs are covered nor a fixed update time for a specific vulnerability.
Size the scope safely
The number of internal assets must not exceed 120 percent of the number of Managed Risk licenses. With 100 Managed Risk licenses, you can scan no more than 120 internal assets. More assets require additional Managed Risk licenses. The actual number of assets counts, not the number of target entries or scans.
CIDR networks with a /16 or shorter prefix contain many addresses and can cause timeouts. Divide these ranges into smaller, operationally related networks and scan them on different days or at different times. A single large range does not automatically provide better coverage; instead, it makes runtime planning and troubleshooting more difficult.
You can scan targets in other VLANs. However, Sophos requires full bidirectional access on all ports and protocols between the appliance and the target VLANs. Check the stateful firewall rules, routing, and return path together. A successful ping alone does not prove this connectivity.
Exclusions defined under Managed Risk > Settings > Global Exclusions affect both internal and external scans. Before investigating a missing asset, check whether its IP address, hostname, or CIDR range is globally excluded. A broad exclusion can remove a technically reachable host from the scan entirely.
Changes and decommissioning
Request changes to a scheduled internal Discovery Scan or Vulnerability Scan through a Managed Risk service request. Under Threat Analysis Center > Cases > Create case, create a case that includes the scan name and requested change.
Do not shut down or delete the appliance or its VM to stop a scan. There is no documented deletion procedure for complete decommissioning. Follow Decommission Managed Risk in a controlled manner for the safe procedure and the conditions that require you to stop.
Support access
For an appliance issue, you can grant Sophos Product Support time-limited remote access. The appliance must be online:
- Under My Products > Managed Risk > Scans > Internal, open the three-dot menu for the affected scanner and select Remote Assistance.
- In the Remote Assistance dialog, turn on the Enable option.
- Select the checkbox to acknowledge the Sophos Group Privacy Notice, then select Save.
- Wait for the appliance to provide an Access ID. Send this ID to Sophos Product Support only through the agreed support channel.
- After completion, switch Enable off again in the same dialog. Without manual intervention, remote assistance ends automatically after seven days.
Remote Assistance is intended for product and appliance faults. If the scanner remains offline or a scan is incomplete, Troubleshoot Managed Risk scans and appliances provides safe preliminary checks. Report a product fault to Sophos Product Support; Open a support ticket with Sophos describes the general contact options. Questions about scan results or Managed Risk services belong in a Managed Risk case, while an active security incident remains an MDR matter. Do not send passwords, private keys, or the one-time appliance credentials in any of these cases.