This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Major increase in Sophos Alerts for Policy non-compliance: Network Threat Protection

Within the past 2 weeks there has been a major increase in the amount of Sophos Alerts for Policy non-compliance: Network Threat Protection.  The generated alert only gives the following information:

  • What happened: A computer does not comply with the Sophos Central policy you applied to it.

  • Where it happened: (device name would be here, but removed for obvious reasons)

  • User associated with device: (device name would be here, but removed for obvious reasons)

  • How severe it is: Medium

  • What Sophos has done so far: We tried to reapply the policy.

  • What you need to do: Go to the computer to check that it is turned on and connected to the internet. If it is and the problem persists, re-protect the computer.

The last portion of what you need to do is not helpful at all as the device is being reported while online.  The option to reinstall Sophos on these machines is not going to work as there was literally 200 new alerts that just came in today alone(all the same exact thing).  No changes have been made on our network with the exception of having our AMP security application get updated.  

When going into Sophos Central and the Alerts Tab, this can be marked as acknowledged, but it still does not explain the reason as to why all of these alerts have appeared out of nowhere.  We typically have only a couple alerts a week, if that, and they are mostly PUAs that end up being cleaned up automatically without needing to do anything on the physical device.

Any recommendations or answers will be greatly appreciated.  A permanent resolution would be even better of course.



This thread was automatically locked due to age.
Parents
  • Hello UNLVHealthSophos,

    Looking into some of our internal release information, it appears there is a staged release for bug fixes with the IPS feature. What is likely to have occurred here is that your endpoint machines updated locally, and were out of compliance for a period of time due to the product changes that occurred. 

    The most recent release was pushed out on August 3'd. This doesn't quite explain the periodic alerts you've been receiving, though the 200 alerts received today are likely related to this release. 

    Additionally, there is a release of new IPS rules being pushed out which will be completed by August 04, 2021.

    If you wish to investigate further, I recommend checking to see if updates were completed around the time the policy compliance alerts were generated, or open a support case with our team to take a closer look.

    Kushal Lakhan 
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Hello UNLVHealthSophos,

    Looking into some of our internal release information, it appears there is a staged release for bug fixes with the IPS feature. What is likely to have occurred here is that your endpoint machines updated locally, and were out of compliance for a period of time due to the product changes that occurred. 

    The most recent release was pushed out on August 3'd. This doesn't quite explain the periodic alerts you've been receiving, though the 200 alerts received today are likely related to this release. 

    Additionally, there is a release of new IPS rules being pushed out which will be completed by August 04, 2021.

    If you wish to investigate further, I recommend checking to see if updates were completed around the time the policy compliance alerts were generated, or open a support case with our team to take a closer look.

    Kushal Lakhan 
    Community Support Engineer | Sophos Technical Support
    Sophos Support Videos | Product Documentation | @SophosSupport | Sign up for SMS Alerts
    Kushal Lakhan
    Team Lead, Global Community Support
    Connect with Sophos Support, get alerted, and be informed.
    If a post solves your question, please use the "Verify Answer" button.
    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children