Sophos Intercept X for Mobile: Check network access when updates fail
In brief: If updates or web lookups in Sophos Intercept X for Mobile (IXM) fail behind an egress filter, first record the platform, app version, management type, and failed operation. Then read existing DNS, proxy, and egress logs for the device’s actual network and compare them with the client destinations below and the time of the failure. Only after confirming a block and checking the vendor guidance applicable to that specific installation should you plan a narrowly scoped, approved pilot with a documented rollback. A DNS hit or a browser test from another computer does not prove the app can connect.
Here, network access means outbound connections from the protection app on Android or iPhone/iPad. It is neither a ZTNA access rule for internal applications nor the Network configuration of a Mobile Threat Defense policy for Wi-Fi security checks, and it is not a ready-made Sophos firewall rule. An app managed with Sophos Mobile may also need connections for management and synchronization. Checking only the app destinations can therefore miss a management problem.
Separate licensing from functionality: Sophos Mobile Device Management (MDM, formerly Central Mobile Standard) enables device management for Android, iPhone/iPad, Mac, and Windows. Sophos Mobile Threat Defense (MTD, formerly Intercept X for Mobile) enables management of IXM for Android and iPhone/iPad and of Sophos Chrome Security for ChromeOS. The combined Sophos Mobile license (formerly Central Mobile Advanced) includes both sets of features. In the affected account, use the Profile icon > Licensing to check the actual active license; also record enrollment and the effective policy. A client URL establishes neither a tenant entitlement nor enrollment or policy status.
Management/synchronization: In Sophos Fusion, open My Products > Mobile and read the region in the browser address immediately after smc-user-if-cloudstation-. Do not infer the account region from the S3 host. The region determines the following separate server destination, each using HTTPS/443 (technical guide dated September 9, 2026):
eu-central-1:smc-device-if-cloudstation-eu-central-1.prod.hydra.sophos.comeu-west-1:smc-device-if-cloudstation-eu-west-1.prod.hydra.sophos.comus-west-2:smc-device-if-cloudstation-us-west-2.prod.hydra.sophos.comus-east-2:smc-device-if-cloudstation-us-east-2.prod.hydra.sophos.com
If the region cannot be determined unambiguously or is not listed, clarify it with the account owners and Sophos Support first rather than allowing all four destinations. This mapping supplements client diagnosis; it is not a complete list of all management, push, and enrollment connections.
Check client egress for Android and iOS separately
The Android app help (June 2, 2023) and iOS app help (June 22, 2023) each list the same seven URLs for the IXM client. According to those two pages, blocking any of these destinations may impair functionality; however, they do not map individual services or specify ports, and they do not establish applicability to every later app version or management type. The Sophos Mobile technical guide (September 9, 2026) also maps these client destinations to services and ports under Android and iPhones/iPads within its Sophos Mobile network connections:
- Intercept X for Mobile:
https://sdds3.sophosupd.comandhttps://sdds3.sophosupd.net(technical guide: HTTPS/443);http://secureservices.s3.eu-central-1.amazonaws.com(HTTP/80). - Web Filtering:
https://4.sophosxl.net/lookup(HTTPS/443); investigate only if this function is actually used and applicable on the device. Do not silently turn the documented/lookuppath into permission for an entire domain. - Wi-Fi Security:
https://sslintt.sophos.com,https://sslintt.sophosupd.com, andhttps://sslintt.sophosupd.net(HTTPS/443); investigate only when the corresponding symptom occurs.
Scope: The two app help pages are platform-specific client lists from June 2023; the September 2026 technical guide describes the Sophos Mobile context, including separate management and platform connections. Agreement on the seven destinations does not establish applicability to every edition, every installed IXM version, a standalone or otherwise managed device, or every network architecture. Before making a change, compare the installed app version, licensed/active edition, management status, and function actually affected with the limits described here. If the applicable destination or port list for this environment remains unclear, do not infer permission from this article; clarify it with Sophos Support and the network team. Nor is the list a guarantee of completeness for all Mobile server, push, or enrollment connections.
The service/port mapping comes from the technical guide, not the two app help pages, and is not a ready-made firewall rule set: the source device and network, proxy, TLS inspection, and app functions actually applicable must be checked locally. In particular, both app help pages explicitly show the S3 destination with http://; do not silently rewrite it as HTTPS or infer a blanket HTTP allowance. The hostname eu-central-1 does not prove a Sophos Mobile tenant region valid for every device. Not every gateway can inspect the /lookup path: if only a host-level allowance is possible, assess the broader risk separately rather than claiming a path restriction. Do not infer a blanket TLS-inspection exception or proxy bypass from the list.
Safely narrow down a suspected network block
First check platform-specific causes unrelated to egress blocking
The following distinctions come from the Known Issues snapshot checked on October 7, 2026 (list generated on October 6, 2026). They are not universal faults or fixes for all app versions and do not justify additional host allowances. First read the browser, service status, and symptom; use the selector below to check the current version/fix status when an issue matches.
- Android – SMSECAND-4563: Web Filtering supports Chrome, Firefox, Edge, and the native browser preinstalled on older Android devices. Another browser can explain the missing filtering effect; do not apply this Android list to iOS.
- Android – SMSECAND-4568 / SMSECAND-4567: On some devices, such as Asus Zenpad 10, Android can disable the Sophos Accessibility Service required by Web Filtering during an IXM update (4568). The service can also be disabled independently of an update; IXM then asks the user to enable it again (4567). For a confirmed disabled service, 4568 describes enabling it in Android settings or restarting the device as recovery. These are changes, not read-only checks: record the status and affected function beforehand, coordinate with the device owners, and check the service and Web Filtering again afterwards. A restart interrupts device use; do not perform it as a harmless connectivity test. If the service will not remain active, involve support rather than bypassing protection features.
- ChromeOS – SMSECAND-4571: IXM Web Filtering works only in Android browser apps. The built-in Chrome browser uses Sophos Chrome Security for this, not IXM Web Filtering. Link Checker requires an installed Android browser app. Missing filtering in built-in Chrome therefore does not automatically indicate an egress failure.
- iOS – SMSECIOS-1983: Push notifications sometimes open the app with no message present. The entry attributes this to Maximum interval between Intercept X for Mobile synchronizations, which is intended to trigger synchronization. This does not prove that updates or lookups are blocked.
- iOS – SMSECIOS-2042: According to the snapshot, occasional crashes while navigating the 9.7.13 interface do not affect app functionality. A fix was planned for a later version in that dated snapshot; check the current fix status live. Do not treat a UI crash as proof of an update or lookup block.
- Android – SMSECAND-4561, during escalation: On some Android versions and devices, Gmail does not attach log/trace files to the support email. Use another email app and verify the attachments before sending; missing attachments do not prove a network block. Send only approved diagnostic data to the responsible support team.
Then examine network evidence, pilot, and rollback
- Record the baseline: Android or iOS/iPadOS, installed app version, managed with Sophos Mobile or managed differently/unmanaged, edition/license, active function and policy, time, and actual device network path (Wi-Fi, cellular, VPN/proxy). If Web Filtering is not active on the device or is inapplicable because of mode or permissions, the lack of a web-filtering effect is not evidence of an egress block. If the problem instead concerns management or synchronization, separately check the Sophos Mobile server destination mapped above to the actual account region you determined. Do not interpret the S3 destination as the tenant server.
- Observe only: Read existing DNS, proxy, and egress events for the affected device and time window on the affected network. Record the destination name, URL scheme, port, rejection reason, and specific app operation separately. A blocked request is a clue, not yet proof that this particular block caused the observed failure; a successful DNS test checks neither the HTTP(S) connection nor app functionality.
- Plan an approved pilot: Only if the observations, active function, and vendor guidance applicable to this environment align, agree on a time-limited change with the network and security owners, scoped as far as possible to the affected devices, required services, and documented destinations. Record the previous policy, test window, success criterion, and rollback in advance. No global wildcards, general HTTP opening, blanket TLS-inspection exception, or proxy bypass. If the purpose of the HTTP destination in your setup is unclear, involve Sophos or the security team first.
- Check the result and rollback: Retry the previously failing operation on the same test device and network while observing the corresponding rejections or successful connections. Only a working operation together with matching network evidence supports the hypothesis for this pilot; it does not show that all functions or versions now work. If the failure persists or unexpected connections appear, revert the pilot change using the recorded pre-change configuration, check again, and pass the findings to the responsible support team. Even a successful pilot requires separate approval before production rollout.
Known Issues selector: version-specific supplementary check only
The Sophos known issues list with product=smx is only for looking up the affected version and current issue/fix status when an Android or iOS app symptom matches. It is not a general network prerequisite, an additional egress destination list, or a substitute for the client lists or device logs. In the list view retrieved on September 28, 2026, a non-interactive fetch returned the same HTML content with and without ?product=smx; effective client-side filtering was not tested. Therefore retain the exact selector, check the product, issue, affected version, and fix status on the page, and do not infer either an exclusive server-side filter or a general IXM requirement from unfiltered HTML.
Not tested in a customer setup: The documented source lists were compared. Their applicability to the edition and app version on a specific device, the tenant permissions available, and the gateway rules actually taking effect have not been checked in a customer environment. The pilot’s effect and rollback have not been tested there either. Check these points in your own environment; comparing sources is no substitute for a device test.