Skip to content
Avanet

Operate Sophos Switch Active Threat Response safely

Active Threat Response (ATR) uses Sophos Switches at the access layer to isolate hosts identified as malicious. The detection decision does not come from the switch: Sophos MDR, XDR, NDR, or an authorized third-party solution supplies threat-feed data through the Sophos Fusion API. The switch enforces the resulting response for wired, wireless, managed, and unmanaged hosts.

Quick procedure: Verify switch registration, licensing, and responsibilities; under Global Settings > Protection and Remediation > Allow and Block > Network > Active Threat Response, enable the control next to Switch; trigger an approved pilot case through the existing API or threat-feed process; then check the MAC address and Switch status in the MDR/XDR Threat Feed.

Distinguish Switch isolation, Firewall ATR, and NDR

The similar product names refer to different functions:

  • Switch ATR is an API-driven response path. It isolates a host identified by its MAC address at the access layer to help limit lateral movement. It does not isolate the switch itself.
  • Firewall ATR operates in the Sophos Firewall data path and has its own configuration, indicators, and evidence. Isolation shown in the Switch column does not prove firewall blocking; conversely, a firewall match does not prove switch isolation. The firewall workflow is described in Sophos Firewall Threat Feeds.
  • NDR can provide threat intelligence to ATR. It is therefore one possible detection source, not the Switch enforcement mechanism itself. Enabling the Switch control activates neither an NDR sensor nor NDR analysis on the switch.

Endpoint isolation and Security Heartbeat are also separate control paths. In particular, ATR can cover hosts without Sophos Endpoint. Sophos Security Heartbeat and Synchronized Security explains how Heartbeat and endpoint responses differ. For a conceptual overview with use cases, see Active Threat Response for Sophos Switches and Access Points.

Prerequisites, licenses, and roles

Check the following before enabling ATR:

  1. Management: Every affected Sophos Switch is registered to and managed in the correct Sophos Fusion tenant. Verify registration and the management path with Register Sophos Switch in Sophos Fusion.
  2. License: Every switch that will use ATR has a valid Sophos Switch Support and Services subscription. A locally managed or unlicensed switch does not meet this ATR prerequisite. See Sophos Fusion licensing (formerly Sophos Central) for the general licensing boundary.
  3. Integration: Identify the authorized MDR, XDR, NDR, or third-party integration that submits the isolation decision. Registering a switch alone does not create threat-feed entries.
  4. Responsibility and recovery path: A security owner confirms the finding and decides whether to isolate or release the host. Before activation, the API integration operator confirms whether—and by what supported procedure—the specific integration can correct, remove, or release an isolation decision, and owns the escalation if no such procedure has been verified. A network administrator checks switch association, status, and the effect on the data path.
  5. Authorization: The account used for the change can read and modify the global ATR setting in the correct tenant. The two underlying Sophos pages do not specify a particular role name. If the control is absent, check the tenant, license, and assigned Fusion permissions rather than guessing a role or granting blanket privileges.
  6. Pilot: Record the MAC address, port, test destination, and normal connectivity state of a nonessential pilot client. Administrative access must not depend on this client or on the same path being tested. Start the pilot only after the owner and the supported, integration-specific recovery path from item 4 have been verified.

Understand the data and response path

Validate the process in five stages:

  1. An MDR/XDR analyst, a network administrator, or an authorized external API integration identifies a host as malicious.
  2. The Sophos Fusion API receives the threat-feed data.
  3. The entry appears in the MDR/XDR Threat Feed, which lists isolated hosts across all Sophos Switches and AP6 Access Points managed in Fusion.
  4. When the Switch control is enabled, Sophos Switch enforces host isolation at the access layer.
  5. The Switch column shows the response state: a green check mark means the device is isolated; a hyphen means it is not isolated.

The name MDR/XDR Threat Feed does not limit possible sources to MDR and XDR. Sophos also names NDR and third-party solutions. At the same time, the status view does not prove which product generated the original finding. Trace that origin in the incident and in the integration that submitted it.

Enable Active Threat Response

  1. In Sophos Fusion, open the Global Settings icon.
  2. Select Protection and Remediation > Allow and Block > Network.
  3. Open Active Threat Response.
  4. In the MDR/XDR Threat Feed section, enable the control next to Switch.
  5. Confirm that the interface shows the enabled state without an error.
  6. Do not start a broad production test. First, have only the approved pilot client isolated through the already approved threat-feed or API workflow.

Perform step 4 only after verifying the supported correction, removal, or release mechanism for the integration that actually submits the data, as well as its operator. Otherwise, stop activation and escalate to the integration operator or Sophos Support. Step 4 enables enforcement only on Sophos Switches. Without an isolation decision from the feed, it does not preemptively block any host. AP6 has a separate control on the same page; changing it is outside the scope of this Switch runbook. For the wireless path, use the separate runbook Enable and verify AP6 Active Threat Response safely.

Validate the pilot and isolation

  1. Before triggering the action, recheck the tenant, pilot MAC address, and normal connectivity test.
  2. Target only this pilot client through the approved feed or API process. Do not enter an unrelated or production MAC address as a test indicator.
  3. In the MDR/XDR Threat Feed, find the entry by its full MAC address.
  4. Check the status in the Switch column. A green check mark is expected for the isolated host.
  5. On the pilot client, repeat the same harmless internal connectivity test used before the change. Failure alone is not sufficient evidence: the MAC address, feed entry, and green check mark must all refer to the same host.
  6. At the same time, verify that the switch remains manageable in Sophos Fusion. This distinguishes the intended client isolation from a general switch, uplink, or management outage.
  7. Record the time, tenant, MAC address, submitting integration, status before and after the test, and the result of the identical connectivity test.

The pilot succeeds only when the feed entry, Switch status, and reproducible effect on the client agree. The test proves enforcement for this host at this time; it does not automatically establish the quality of all future detections.

Resolve false positives and unexpected states

Green check mark for the wrong or a legitimate host

  1. Do not create a broad exception in VLAN, port, or firewall rules. It does not correct the ATR entry and may open additional communication paths.
  2. Preserve the full MAC address, time, Switch status, affected port, and origin of the feed entry.
  3. On the endpoint, or through a reliable inventory source, verify that the MAC address currently in use really belongs to the expected host. A similar device name is not sufficient.
  4. Have the security owner reassess the finding. Only if a supported correction, removal, or release mechanism has been verified for the originating integration may its operator perform the confirmed procedure. Otherwise, escalate the preserved data to the integration operator or Sophos Support; do not assume that a targeted release is available.
  5. After a confirmed integration action, recheck the same MAC address in the MDR/XDR Threat Feed and repeat the same connectivity test. Only a hyphen in the Switch column together with the expected restored connection confirms that the host is no longer isolated through the switch. Continue investigating and escalate any discrepancy.

The Sophos pages used for this runbook document neither a manual release button for an individual Switch host in the ATR view nor a general API endpoint for removal. This runbook therefore does not invent a click path or API call. If no targeted recovery path has been verified for the specific integration, escalate the preserved data. For an urgent broad rollback, the Switch control is the option documented in this view; it operates at tenant level and is not an individual release.

A hyphen appears in the Switch column

According to Sophos, a hyphen means that the host is not isolated through Sophos Switch. Check, in this order:

  1. the correct MAC address and feed entry;
  2. that the Switch control is enabled;
  3. registration and a valid Support and Services license for the affected switch;
  4. the correct tenant and the client’s actual port;
  5. the result and timestamp from the submitting API integration.

If the status remains unchanged, do not submit a second, differently formatted MAC address on speculation. Preserve the status, timestamps, and integration result, and involve the API owner or Sophos Support.

Green check mark, but the host can still communicate

First make sure the test is being run on the device currently using that same MAC address. Then repeat the test on the same port and use exactly the same pre-recorded internal test. A single reachable destination proves neither complete isolation nor its complete absence if the test path or destination changed between the before and after tests. If the MAC address, status, and test still disagree, do not add network rules as a supposed fix; escalate the discrepancy with timestamps.

Release safely and roll back globally

Release starts with a security decision: the incident owner confirms remediation or a false positive. The feed operator may modify the isolation decision only through the previously verified mechanism supported by that integration. Without this evidence, escalate to the integration operator or Sophos Support instead of claiming a targeted release. After every confirmed action, check the Switch status and repeat the original connectivity test. A restored connection while the green check remains, or a hyphen while the connection remains blocked, is not a clean resolution and requires further investigation.

For an urgent stop or broad tenant-level rollback:

  1. Preserve the current feed entry, MAC address, and time.
  2. Under Global Settings > Protection and Remediation > Allow and Block > Network > Active Threat Response, disable the control next to Switch.
  3. Recheck the pilot client’s status in the Switch column and repeat the identical connectivity test.
  4. Correct the originating integration separately. Disabling the Switch control is not documented as deleting the underlying threat-feed entry.
  5. Re-enable ATR only after clarifying the source, target MAC address, responsibility, and recovery path. Then validate again with a single approved pilot client.

This rollback globally disables Switch enforcement and may therefore also lift legitimate isolations on other managed Sophos Switches. Do not use it as a convenient individual release. If the UI status and data-path effect do not agree after disabling the control, make no untargeted additional changes; instead, send the tenant, MAC address, timestamps, status screenshots, and integration result to Sophos Support and the API integration operator.