Sophos Protected Browser: Create application groups and classify policy objects
Sophos Protected Browser lists Gerätestatus, Anwendungsgruppen, Standortlisten and Webkategorien as policy objects. You can find them under Meine Produkte > Protected Browser > Richtlinienobjekte; however, Sophos documents a complete creation workflow here only for application groups. For the other object types, this guide shows where you must safely stop.
Use:
- Anwendungsgruppe for related applications and supported agentless RDP and SSH applications from ZTNA-Ressourcen.
- Standortliste for agentless web applications.
- Webkategorien and Gerätestatus are other listed policy objects; Sophos does not describe a complete creation workflow for them.
Clarify prerequisites, licence and role
The Sophos product documentation specifies neither the required licence entitlement nor a particular minimum role. A visible menu path or the visible Objekt hinzufügen action does not confirm a licence entitlement either. Before making a change, therefore, have the entitlement checked by the team responsible for licensing.
Assign Sophos Fusion administration roles correctly provides general background about policy permissions and checking them with an administrator account. However, that article does not map these permissions to Protected Browser policy objects and therefore does not establish a minimum role for Objekt hinzufügen. If the role or action is unclear, stop and have the product-specific permission clarified.
ZTNA is an additional prerequisite only if an application group is to contain agentless RDP or SSH applications. For this purpose, ZTNA must already be set up, the required resources must be available in ZTNA, and ZTNA gateways deployed on ESXi, Microsoft Hyper-V or Sophos Firewall must each be running the latest version for their platform.
Create an application group
An application group is suitable when several applications are to be managed together under an internet policy.
- Open
Meine Produkte > Protected Browser > Richtlinienobjekte. - Click Objekt hinzufügen and select Anwendungsgruppe.
- Under Name, enter a name, and under Beschreibung, enter a description for the application group.
- For agentless RDP or SSH applications, expand ZTNA-Ressourcen and select the required applications.
- For other applications, expand the appropriate Anwendungskategorie and select the applications.
- An expanded category initially displays 20 applications. Mehr anzeigen displays the next 20.
- Alternatively, search for the application name in the Suche field. Then enable Nur hinzugefügte Apps anzeigen to review the selection specifically.
- Click Speichern.
Note on the documented state: According to the Sophos guide Anwendungsgruppe hinzufügen (as at 7 July 2026), the Alle derzeit in der Liste enthaltenen Apps hinzufügen option is available only for the Generative KI category. This statement describes only the state of the documentation at that time; it does not confirm that Generative KI currently appears as a category label in the live interface. If the label is missing or differs, do not use a substitute path inferred from it.
Important: In this workflow, only agentless SSH and RDP applications appear under ZTNA-Ressourcen. An agentless web application belongs in a Standortliste instead.
Site list: documented steps and stop condition
A site list is the intended object type for agentless web applications. However, Sophos does not describe a complete creation and save workflow for it.
- Open
Meine Produkte > Protected Browser > Richtlinienobjekte. - Click Objekt hinzufügen and select Standortliste.
- Complete Name and Beschreibung.
Stop at this point: Sophos describes neither further entries nor their confirmation or saving. Do not continue the site-list workflow without a current, documented continuation path.
Web category: note the documented contradiction
The Sophos guide is titled Webkategorie hinzufügen, but one step instructs you to select the Standortliste type under Objekt hinzufügen. This instruction contradicts the object type stated in the title.
Do not treat this as a safe click path and do not create another object as an experiment. Stop before selecting or saving anything and clarify the current workflow with Sophos Support. The Sophos guide does not describe a safe continuation or save path for a web-category object.
Deliberately limit device status
For device status, the selection for the Protected Browser platform contains these three options:
- Protected Browser oder Erweiterung in einem anderen Browser
- Nur Protected Browser
- Protected Browser-Erweiterung nur in einem anderen Browser
Under Endpoint-Schutz, Sophos documents the Status des Endpoint-Schutzes nicht prüfen selection. Sophos does not describe further device-status settings or a complete creation workflow.
Review the selection before saving
This is not a complete functional test. Sophos documents neither a success indication after saving nor a report or test of the policy’s effect. Review the application-group selection before saving as follows:
- Record the intended object name, object type and application selection locally.
- In the dialogue, review the selected applications using Nur hinzugefügte Apps anzeigen and, if necessary, Suche.
Stop the selection review here, before saving. This confirms only the selection in the dialogue.
Then save
Now click Speichern to complete the documented creation workflow. However, Sophos gives no success indication and describes neither a check of the persistently saved values nor the effect of a policy linked later. If there is no unambiguous result after saving, do not make further changes as a supposed test; instead, clarify the verification path with Sophos Support.
Troubleshooting by symptom
A ZTNA web application is missing from the application group
This is expected in the dialogue described: ZTNA-Ressourcen contains only agentless SSH and RDP applications. Add an agentless web application to a Standortliste; bear in mind the stop condition above for the incompletely documented workflow.
Only 20 applications are displayed
In the expanded application category, click Mehr anzeigen to display the next 20 applications. Alternatively, use Suche to find the required application.
The web-category dialogue does not match the guide
The documented Standortliste selection contradicts the title of the Sophos guide. Do not create another object as an experiment. Stop before selecting or saving anything and clarify the current UI path with Sophos Support.
Prepare changes safely
Sophos describes neither deletion nor a dependency view or restoration here. Therefore, record the intended change in a local change record before creating the object. If an existing object is to be changed, withdrawn or removed, stop before the change and clarify the current, documented workflow with Sophos Support.
Operation and recurring checks
Sophos describes no workflow here for recurring checks or measures during the operation of these policy objects. Therefore, do not use this guide as evidence for operation or decommissioning. For any further checks, you must clarify the current workflow with Sophos Support.