Skip to content
Avanet

Set up Sophos Managed Risk and start external scans

Sophos Managed Risk is a standalone vulnerability management service. It identifies the external attack surface based on the domains provided, checks defined external and internal assets for vulnerabilities, and delivers reports with remediation recommendations. Detecting and responding to active threats, by contrast, remains the responsibility of Sophos MDR.

The shortest path to the first assessment starts at My Products > Managed Risk > Settings > Authorized Contacts, where at least one contact is saved. Next, the external scan scope, day of the week, and time zone are set under My Products > Managed Risk > Scans > External. Before the first run, the upstream firewall also needs a narrowly scoped rule allowing the current regional scanner networks.

Check prerequisites and responsibilities

Managed Risk requires an existing Sophos MDR or Sophos MDR Plus license in the same Sophos Fusion tenant. Only then can the service be subscribed to. For setup, the Managed Risk license must be activated and My Products > Managed Risk must be visible.

Beforehand, also establish which organization-owned, publicly accessible domains, IP addresses, and networks may be scanned. At least one responsible person with Sophos Fusion administrator access is required as the primary contact. The firewall owners must also be able to allow the current scanner source networks specifically for the intended public targets and review the associated logs.

According to Sophos, the typical number of Managed Risk licenses is the sum of the existing MDR user and MDR server licenses. For internal scans, assets up to 120 percent of the Managed Risk license count may be registered; additional Managed Risk licenses are required above that level. This 120-percent limit applies to internal assets and does not change the separate external scan limits described below. It must not be used to infer a separate SKU or any pricing or contract rules.

Do not guess administrator access

The setup dialog can create a new administrator with Create new Central administrator. Only a Super Admin may perform this action. In the Managed Risk setup, Sophos lists the roles Super Admin, Admin, and Help Desk for the new contact. However, this does not provide a documented Managed Risk permission matrix for individual actions.

Therefore, use the designated administrator account for setup and first verify that Authorized Contacts, Scans > External, and the required buttons are visible with that account. If a new account must be created or a role changed, follow the complete process in Assign Sophos Fusion administrative roles correctly. After setup, access can be tested again with a less privileged operational account without assuming an undocumented minimum role.

Define the scan scope before entering it

Managed Risk separates attack surface discovery from the actual vulnerability scan:

  • Domains are used for the Attack Surface Management report. They identify external internet assets associated with the domains.
  • Public IP addresses and CIDR ranges are the targets of the weekly external vulnerability scan.

The scope must contain only assets for which the organization or MSP has obtained the necessary rights, consents, and scan permissions. This includes any required third-party permission for shared addresses, upstream providers, CDNs, and hosted services. A technically reachable target does not in itself constitute scan authorization.

The following documented limits apply to the input:

  • no more than 25 domains;
  • no more than 100 individual IP addresses or CIDR ranges;
  • no CIDR prefix smaller than /24, for example no /23 or /16;
  • no more than 1,000 external devices;
  • only registered and internet-routable domains;
  • only public targets reachable from the internet, not reserved private networks such as 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16.

example.com, example.org only illustrates the comma-separated input format for domains. Likewise, 203.0.113.25, 198.51.100.0/24 illustrates the syntax for a single address and a network. These reserved documentation values are not scan targets and must not be copied. Replace every example with approved, organization-owned, publicly routable values.

1. Save Authorized Contacts

  1. Open My Products > Managed Risk > Settings.
  2. Switch to the Authorized Contacts tab.
  3. If an administrator account is missing, have a Super Admin create it using Create new Central administrator. Otherwise, skip this step.
  4. Open the arrow next to Primary, select a Sophos Fusion administrator, and add their contact details.
  5. Add Secondary and Tertiary if required. You can select a Sophos Fusion administrator or complete the form for a new contact.
  6. Select Save.

At least Primary is required. Multiple contacts are advisable so that reports and notices do not depend on one person’s availability. After saving, verify that the intended people are displayed correctly and that the external scan settings are now available. If they are still not visible, first check whether the contacts were saved and whether the account being used can access the page.

2. Add domains, IP addresses, and networks

Important: After saving, administrators currently cannot change the external settings themselves. Request later additions, removals, or corrections to external assets and root domains through a Managed Risk case; these changes are limited to once per month. Before selecting Submit, have a second person recheck ownership, spelling, network boundaries, and approvals.

  1. Open My Products > Managed Risk > Scans.
  2. Select the External tab.
  3. Under Add Domains, enter the approved domains separated by commas and select Add. Multiple domains can be pasted together.
  4. Check the imported list for typing errors, unregistered names, and internal suffixes such as .local.
  5. Under Add IP addresses, enter the public individual addresses and CIDR ranges separated by commas and select Add.
  6. Verify that no private addresses, overly broad networks, or third-party targets are included.

If an entry is rejected, do not blindly narrow the range until the form accepts it. Instead, apply the documented limits: 25 domains, 100 IP entries or CIDR ranges, a /24 or more specific prefix, and no more than 1,000 external devices in total. Unregistered or non-publicly-routable domains and private IP ranges are not valid external targets.

3. Allow regional scanner networks in the firewall

Managed Risk performs external scans using regional Tenable Cloud Sensors. The source networks depend on the region and can change. Therefore, do not reuse a static address list from an old ticket or from this guide.

  1. Find the Welcome to Sophos Managed Risk Service email for the tenant. It states the region to use.
  2. If the email is missing, open Threat Analysis Center > Cases and find the Welcome Case. The message in the case also states the region.
  3. Open the current Tenable list of Cloud Sensors.
  4. Use only the IP ranges belonging to the region named in the welcome notice.
  5. Create or update an allowlist rule for these source ranges in the upstream firewall. Limit the destination to the public assets approved for Managed Risk and allow only the services that are already intentionally exposed there.
  6. Review the firewall logs during the first scheduled scan. Connections from the allowed regional ranges must be able to reach the intended public targets and must not be dropped by an upstream Geo-IP, IPS, WAF, or rate-limit rule.

The allowlist should enable the scanner to obtain complete information about the approved assets. It is not permission for arbitrary sources or internal targets. If no scanner connection appears in the logs, first compare the tenant region, current Cloud Sensor list, source objects, rule order, and the target path that is actually published.

4. Set Global Exclusions deliberately

Global Exclusions affect external and internal scans. An exclusion can protect a sensitive or unauthorized target, but it can also cause an intended assessment to be omitted without notice. Every entry therefore needs an identifiable owner and reason.

  1. Open My Products > Managed Risk > Settings > Global Exclusions.
  2. Select Add exclusion.
  3. Under Configure exclusion details, enter a unique name and a description containing the reason and responsibility.
  4. Under Add targets, enter IP addresses, CIDR ranges, or hostnames.
  5. Press Enter after each target entered separately. Alternatively, paste a comma-separated list.
  6. Under Add targets, select Add and review the imported targets.

A clear name might be External ERP maintenance window; the description should identify the affected service, responsible team, and reason. There is no reliable product evidence for an expiry date or automatic reactivation. Therefore, track a review date outside the product and check the exclusion whenever the scope changes.

5. Schedule and submit the weekly scan

  1. Remain under My Products > Managed Risk > Scans > External.
  2. Under Schedule weekly vulnerability scanning, select the day of the week on which the scan should begin.
  3. Set the time zone of the agreed maintenance and monitoring window.
  4. Recheck contacts, domains, IP targets, exclusions, and time zone.
  5. Select Submit.

The scan starts at approximately midnight in the selected time zone. Because scanning can disrupt services and, in some circumstances, corrupt data or cause data loss, the organization or MSP is responsible for regularly backing up all data contained in or available through devices connected to the scanned IP addresses or domains. Place the scan in a monitored change window, and choose the day so that firewall and service owners can follow the logs and any potential impact. “Approximately midnight” is not a promise of an exact start time.

Review the first results and ongoing operation

After setup, external scans run weekly. Sophos notifies the contacts when a new report is ready. A vulnerability scan checks open ports, detected services, and the operating system, among other items; Tenable plugins then test for specific vulnerabilities based on that information. In contrast, the Attack Surface Management report identifies internet assets associated with the domains provided.

Request additional on-demand scans from the Managed Risk team in advance. No more than five are available per month, and the request must provide at least one business day of lead time for scheduling and execution. Separately, Sophos may initiate an ad-hoc scan without prior approval when its security team identifies a new vulnerability with high exposure potential. Sophos determines the scope and frequency of these scans based on its assessment of the environment and vulnerability; this boundary does not authorize scanning unrelated targets.

After the first run, the firewall logs should show allowed connections from the correct regional scanner networks to the intended targets. At the same time, the registered contacts should receive notification of a new report. The expected public targets must appear in it, while deliberately excluded targets must be absent.

Compare unexpected or apparently third-party assets with domain, DNS, hosting, and ownership data before taking further action. Then assign every relevant finding to a responsible team instead of leaving it only in the report.

Managed Risk does not assess vulnerabilities at the web application or API level. A successful external scan therefore replaces neither a Web Application Security Test nor an API Security Test. Nor does an empty or short report prove that an asset has no vulnerabilities: the scan type, reachable services, operating system, and available plugins affect the result.

After 30 days, the Managed Risk team contacts the organization for a Baseline Meeting. The monitored domains and IP addresses and the initial Vulnerability and Attack Surface Management reports are discussed. Further Review Meetings at three-month intervals are documented after that. Prepare scope changes, open findings, exclusions, and questions about unexpected results for these meetings.

Troubleshoot by symptom

The following initial checks help narrow down common setup errors. If they do not resolve the problem, or if an internal scanner or authenticated scan is also affected, Managed Risk troubleshooting provides symptom-based follow-up checks and the appropriate escalation path.

External cannot be configured

Under Settings > Authorized Contacts, verify that at least Primary has been completed and saved with Save. Then check access with the designated administrator account. A Managed Risk-specific minimum role must not be inferred from a missing button.

A domain, IP address, or CIDR range is rejected

Compare the value with the input limits and check public routability. Internal domains, private addresses, a network broader than /24, or an excessive number of entries do not belong in the external scope. Also check Global Exclusions if a saved target is unexpectedly absent later.

The first scan does not reach the target

Determine the tenant region again from the welcome email or Welcome Case and compare it with the current Cloud Sensor list. Then use the logs to check firewall source objects, destination objects, rule order, and blocking security features. Do not open a blanket rule to the internet because of a single scan failure.

Saved external settings are incorrect

Do not “correct” the target by adding more exclusions. Request additions, removals, or corrections to saved external assets or root domains in a Managed Risk case; these scope changes are limited to once per month. State the affected entries and desired change in the case, but do not submit passwords, private keys, or other secrets.

The report and expectations differ

First verify that the expected asset is actually in the external scope, publicly accessible, and not globally excluded. Then bear in mind that different products, scan types, plugins, and update cycles can produce different results. Web application and API vulnerabilities are not part of this scan. Questions about scan results or reports belong in a Managed Risk case.