Licensing Sophos Server Protection: Servers, VMs, RDS, and XDR Sensor
Plan Sophos Server Protection against the server product ordered and the servers protected. VMs and RDS are not blanket exemptions; XDR Sensor …
Guides to protecting Windows and Linux servers in Sophos Fusion (formerly Sophos Central): check licensing and platform support before rollout, group servers deliberately, pilot policies, and verify their effect on each server. Not every feature is available on both operating systems; available features and entitlements depend on the specific agent, tenant, and contract.
Start by checking licensing and platform support, then move through server groups and pilot policies to updates, integrity monitoring, and investigation. This overview shows the guides assigned here, not every Sophos feature or every task in a server's lifecycle.
Check server entitlements and supported platforms, plan cloud guest VMs, and prepare a controlled rollout.
Plan Sophos Server Protection against the server product ordered and the servers protected. VMs and RDS are not blanket exemptions; XDR Sensor …
A Server-owned workflow for individual installation and software deployment with full protection or XDR Sensor, including clear stop and rollback …
Protect Linux servers manually, by script or from a gold image with Sophos Protection for Linux, and validate their registration in Sophos Fusion.
Check Windows Server generations, resources and legacy restrictions, as well as SPL platforms, before an installation or update wave.
A practical guide to Sophos Server Protection on RDS and Citrix multi-user hosts, with support checks, a pilot, and a rollback path.
A controlled guest-agent rollout for cloud servers: choose a protection mode and network path, verify VM identities, and reconcile terminated …
Create pilot groups, prioritize policies, and verify the effective assignment on each server.
A pilot group limits the scope; the first matching server policy wins. Check the actual assignment on the server's Policies tab.
Pilot Threat Protection and Windows-specific policies for peripherals, applications, Unauthorized File Protection, and Web Control.
Configure a server protection policy for small pilot groups, distinguish Windows and Linux capabilities, and verify its actual effect on each server.
Monitor Windows server peripherals first, then exempt required devices and test Read Only or Block on the pilot host.
A dedicated server policy first detects controllable applications. Only after reviewing server workloads do you selectively block them in a small …
Monitor a small number of Windows servers first, allow legitimate executions selectively, and enable Block only after reviewing the events.
Document the existing Lockdown estate, test unlocked servers with a cloned Monitor policy, and move groups to Block only after repeated reviews of …
Create a Web Control policy for one Windows server, verify its effective assignment and resolve unexpected blocks without global exclusions.
Introduce Linux Runtime Detection as an additional detection capability, with its own policy and verified prerequisites.
Roll out RTD for Sophos Protection for Linux to a small server group, review detections, and narrow down false positives.
Plan server updates in a controlled way and review File Integrity Monitoring specifically on Windows servers.
The server policy controls product updates and package selection by operating system. Content updates follow a separate, optionally staged process; a …
Pilot FIM on a few Windows servers, limit monitored paths and registry values, confirm changes in server Events, and roll back if the policy generates …
Control Data Lake uploads and Live Response for servers separately, and verify that each is effectively enabled.
The server policy controls uploads and Live Response separately. A pilot limits their scope only if effective settings outside the pilot group are …
Decommission Windows and Linux servers in a controlled way and check their protection status after removal.
Remove SPL from Linux servers with its built-in uninstaller, handle empty cgroup directories safely and verify the protection state.
A safe runbook for completely removing Sophos Server Protection from supported Windows servers.
Before installing, check the specific server license coverage and supported platform. Then choose a small pilot: a server policy assigned only to the pilot group limits its scope. The group alone does not replace checking policy targets and priority or verifying which policy is actually applied to the server. The XDR Sensor does not provide malware protection; verify its XDR entitlement and separate third-party protection before deployment.
The installation guides for Windows Server, Sophos Protection for Linux, and RDS terminal servers are linked directly here. For controlled decommissioning, there are separate guides to Windows server uninstallation and Linux uninstallation.
Server policies are managed under My Products > Server > Policies. The articles listed here distinguish between platforms and tasks: Server Threat Protection covers Windows and Linux, while Server Web Control, Application Control, Peripheral Control, Unauthorized File Protection, and File Integrity Monitoring, for example, are described in their respective guides for Windows servers. Linux Runtime Detection requires an appropriate Linux server configuration and separately verified entitlement. A policy’s presence in the portal does not establish that it is effective on every host or that a license entitlement exists.
When piloting a change, check the effective policy under My Products > Server > Servers > Servername > Policies and the protection status on the affected server. If the change has no effect, first compare the platform, agent mode, group membership, and priority of the relevant policy before relaxing protection features globally.