This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

sophos endpoint defense software exchange 2016

hi,

since friday we have high cpu with the sophos endpoint defense software process.

windows server 2016

sophos central server core version: 2024.2.2.1

after disabling all the features the cpu is back to normal..

any ideas?



This thread was automatically locked due to age.
Parents Reply
  • it looked like, but we also activated MAPI over HTTPS, because we used RPC a long time with no issues. but we need to use MAPI for now and then AMSI kicks in..

    really interesting if anyone has some AMSI exclusions for Exchange.

    i have only w3wp.exe as mentioned earlier and the CPU is much better.

    will take a look and also use the tool to create some logs tomorrow.

Children
  • KBA-000007760 suggestions disable AMSI only for Exchange. The rest of the OS is still monitored.

    C:\PowerShell> New-SettingOverride -Name "DisablingAMSIScan" -Component Cafe -Section HttpRequestFiltering -Parameters ("Enabled=False") -Reason "Testing"

    I do not know if there is an exception within Sophos Policies.