Sophos Protected Browser: overview and dashboard
Protected Browser enforces web policies directly in the browser session. Its dashboard shows setup status, active users, risky access attempts and, …
Workspace Protection brings together four distinct security capabilities for hybrid workplaces. This overview explains the product boundaries and licensing model and directs you to the relevant guide.
Choose a product area, then select the guide for your specific administration task. Make changes by following the guide for the affected product.
Deploy the browser, control policies and SaaS access, analyse usage, and troubleshoot issues.
Protected Browser enforces web policies directly in the browser session. Its dashboard shows setup status, active users, risky access attempts and, …
Protected Browser can be deployed manually, by email invitation, Microsoft Intune or Jamf Pro. This guide combines rollout with version checks, …
This guide covers the Sophos Central download, manual and central browser-extension deployment, validation, and safe manual removal on Windows and …
Protected Browser requires users in Sophos Central, the appropriate sign-in method and SSP access. This guide covers everything from the identity …
This guide covers the documented application-group workflow and shows which steps are documented for other policy objects and where you must stop.
The first active policy whose conditions match completely takes precedence. This guide shows how to introduce conditions, file protection, and data …
This guide shows how to use Entra ID or Okta to permit access to selected SaaS applications only through Sophos Protected Browser.
Protected Browser has no shared integration screen for DNS Protection and ZTNA. DNS is delivered through the endpoint policy; ZTNA must first be fully …
Protected Browser provides RDP and SSH sessions without a ZTNA agent. This guide covers prerequisites, policies, resources, access control, testing …
Safe AI Controls combine application groups and web policies in Protected Browser. You can also use DNS Protection for endpoints to block unauthorised …
Reports answer recurring operational questions; Live Discover exposes the Protected Browser schema for detailed investigations.
A symptom-based runbook for failed RDP/SSH resources, ZTNA connectivity, sign-in and changed SSH host keys.
Plan and operate identities, gateways, applications, agents, and agentless access.
Zero Trust is not a product, but an access concept. ZTNA applies it in practice: identity, device, context and application decide access.
This runbook covers the complete Sophos ZTNA setup in a reliable order—from the access model through validation, troubleshooting and offboarding.
A runbook covering prerequisites, certificates, DNS, networking, deployment, validation, troubleshooting and the lifecycle of a Sophos ZTNA Gateway.
Let's Encrypt wildcard certificates cover multiple hostnames under one domain. DNS-01, renewal, DNS access, and operational limits are crucial.
Sophos ZTNA can provide Windows devices with multiple domain controllers through the tunnel. This guide explains resources, SRV control, testing, and …
The ZTNA Agent is deployed through the tenant-specific Sophos Endpoint installer or Manage software. This guide covers prerequisites, acceptance …
Agent status, resource, user assignment, DNS, ZTNA reports, and a controlled comparison test show where access is failing.
Enable DNS Protection on managed endpoints and distinguish it from standalone network DNS operation.
The DNS Protection Endpoint policy forwards DNS requests from supported Windows devices to DNS Protection over HTTPS. Xstream alone does not cover …
Configure monitor-only journaling, investigate findings, and connect Microsoft 365 or Google Workspace.
This overview explains what Sophos EMS monitors, what it deliberately does not enforce, and how to safely plan deployment, validation, and a later …
This runbook covers the enabled EMS mode, mailboxes, domain, and provider-specific journaling through Quick Test, Message History, troubleshooting, …
Sophos automatically creates the application and journal rule and, if necessary, configures the NDR mailbox. This runbook covers consent, validation, …
This runbook covers the manual Google Workspace configuration for Sophos EMS, including configuration options, validation, troubleshooting, and a safe …
Sophos EMS applies policies for assessment only. This guide covers the appropriate configuration, controlled validation, and troubleshooting of …
Practical runbook for EMS reporting boundaries, Microsoft-365 connection, manual clawback, post-delivery quarantine and handover to detections and …
Sophos Workspace Protection is not a fifth security engine. It is the combined offering for exactly four distinct capabilities that protect users, applications, and data:
Workspace Protection became available with these four capabilities on 16 March 2026. The Protected Browser extension followed in July 2026; in the same month, Endpoint DNS and DNS filtering policy management were combined for Workspace Protection customers. Protected Browser remains one component of the suite and is not the name of the entire family.
| Task | Start here |
|---|---|
| Plan and deploy Protected Browser and check it in the dashboard | Protected Browser overview |
| Configure ZTNA with identity, a gateway, and applications | Set up Sophos ZTNA |
| Use DNS Protection on managed endpoints | Endpoint DNS Protection |
| Understand and configure Email Monitoring System | Email Monitoring System |
| Operate DNS for locations, networks, manually managed devices, or Xstream | Standalone DNS Protection overview |
You can find Endpoint DNS tasks in this hub. For DNS tasks involving networks, locations, manually managed devices, Xstream, filters, certificates, and reporting, use the separate DNS Protection hub. Email Monitoring System is a monitor-only offering; full gateway, mail flow, and post-delivery procedures belong to Sophos Email.
Workspace Protection is available with the term-based Standalone Workspace Protection licence and through MSP Flex. The standalone licence does not include a Sophos Endpoint licence; Endpoint is licensed separately. Sophos Endpoint Plus Workspace Protection adds the same four Workspace Protection products to Sophos Endpoint.
Activation and management take place in Sophos Fusion under Profile icon > Licensing. The individual usage metrics are:
The required number of Workspace Protection licences—the applicable bundle quantity—is the highest user or device usage among the included products. The metrics are not added together. If the quantity differs from what you expect, check the highest individual 30-day usage first.
A 30-day trial licence is available. After it expires, the Workspace Protection products disappear from Sophos Fusion, but their configuration is retained and reappears after renewal. Licence expiry is therefore neither a controlled offboarding method nor a substitute for the documented removal of a component.
For ZTNA, the same licence covers on-premises and Sophos Cloud Gateway modes as well as agent-based and agentless access. Sophos Cloud Gateway has an average bandwidth limit of 15 GB per user per month.
Start with a limited pilot group. Check Profile icon > Licensing and record the licence option, highest measured usage, and expiry date. Then go only to the guide for the affected product and validate the expected browser, access, DNS, or monitoring result there.
If a product is missing despite the expected licence, do not change or delete configuration based on assumptions. Check the licence status and highest 30-day usage, then refer the case to licensing or product support. This hub does not provide a shared rollback procedure for all four components. Roll back or remove each component only by following its product-specific guide.