• Sophos breaking internet on Citrix servers

    Our company is using Sophos endpoint cloud for anti virus and since around March of this year we have been having a slew of issues. One particular issue is that Sophos is intermittently breaking the internet connection. Users will submit ticket saying…
  • Chromebook Recovery Utility unable to write to USB Drive

    I am having an issue trying to utilize the Chromebook Recovery Utility in Chrome. We have used this program in the past with no issue. Since the migration and install of Sophos Endpoint with Intercept X I am unable to create these USB drives. When I run…
  • Downgrade from intercept X Advanced XDR to Intercept X Advanced

    Hi, This should be fairly simple, and I am 99% certain of the answer but want to be sure. We need to change a client's license (downgrade as the subject of this post states) and I have seen in the support article that any software not included in…
  • Known issues with Sophos AV with windows 11

    Hi! I'm not sure if this is the correct place for this but I thought I would give it a shot. So I'm currently doing a research project for my college computer science class on different programs that could potentially have compatibility issues or just…
  • Sophos Endpoint - How to know the core agent version globally?

    Hello community!. I have a doubt is it possible to know the core agent version globally, for example. If I want to look de core agent version on a device, I have to go to Devices - "PC1", and in the agent summary we can look the all the components…
  • Sophos Endpoint definition update query

    Hello, We have an issue where our 3rd party monitoring tool is looking at the following folder for definition updates: C:\Program Files (x86)\Sophos\Sophos Anti-Virus From what I can see any agent that has the core update agent on version 2.20.13…
  • SSL_Error_Bad_Mac_Alert

    Hi everyone, since some weeks we and our customers are facing the issue that all of a sudden the user is not able to use google anymore. If he tries to google something he gets the error mentioned in the subject. The only solution is to close the…
  • Mail Alert do not work

    Hi, in the Report "Mailware and PUAs blocked" there are many events like this: Alert: No How can I change the event to Alert: Yes ? The frequency is settings: Best regards, Thomas
  • Monitoring daily scan log - New Architecture, New log file?

    Hello! We monitor hundreds of servers where Sophos is installed and have started to see the new architecture version rollout, triggering us to make some changes to the Windows Services we monitor. We have also noticed that the log file we check daily…
  • Log of antivirus

    Hello Could someone provide me with a log of the Sophos Antivirus? Thanks in advance
  • Outlook progressbar for copied attachments

    Hello @all, since the architecture change anounced in KB00043550 ( https://support.sophos.com/support/s/article/KB-000043550?language=en_US ) we have at most clients the behaviour, that i see a neverending progressbar from Outlook if i copy a file …
  • Problem with Anveo, a Microsoft Store App, after update Agent core to 2.20.13

    We are using Anveo as client software for our external representatives, working on our local Business Central (aka Navision) setup. Anveo is an app, downloaded from the Microsoft Store, making a connection to our database, but also having offline capabilities…
  • How to delete "Event" from Sophos Endpoint Agent? using a non-administrator account?

    Hi all, I'm using my company's laptop and running it as a non-administrator account. I am unable to access Sophos Diagnostic Utility it says "SDU is running from a non-administrator account. The tool may not be able to gather all requested information…
  • Sophos Endpoint Privacy Deactivated

    Hello, i am new to Sophos Endpoint and still try to dig my way through the settings and options. My Testclient shows me a red Alert wich means "Privacy deactivated" and "We informed your Administrator" But i didn't got informed about anything an…
  • In which customers was my endpoint installed?

    Hello dear community, I have the problem that I used a wrong installer when installing an endpoint for a customer. Unfortunately, with the large number of customers, I do not know in which customers the PC was installed. When uninstalling, the tamper…
  • Performance Loss and Central Page Usage

    Hello there! I have some questions. I wasn't sure where to open this thread (f.e Sophos Central or Intercept X Endpoint ). Please excuse me if my posting here is wrong. We recently joined Sophos. We also caught a lot of malware that our previous security…
  • Sophos Anti-Virus gone on many Windows 10 clients - but not all

    Hi all, today it seems that on a lot of Windows 10 clients the Sophos Anti-Virus service was removed however not on all. The status in Central is ok so no "service missing" message or the like. Is that due to an update? Why does it not affect all clients…
  • SDL logs for. Sophos Intercept-x for server occupying massive disk space

    Hi I am using SOPHOS Intercept-x for server with server lockdown feature and noticing that SOPHOS SDL log files keep on increasing and storing more than a year logs. Resulting no space left on the disk. Pls suggest workaround to remove these logs…
  • Bugcheck KERNEL_SECURITY_CHECK_FAILURE SSPService.exe, SophosSupport.sys

    2 of our computers got BSOD today after a Sophos product update has been installed yesterday. Both machines are EAP. The BSOD occoured about 1h after power on during a zoom video meeting session. with or before the BSOD a minidump has…
  • Next Gen Architecture Rollout

    According to this post and comments made in it, these rollouts should be complete and devices should be updated fully to the new architecture, however my entire fleet still hasn't updated. The new agent seems to be rolled out but devices still have the…
  • High CPU Usage on Windows Server while Windows Update installing

    Hello Sophos Community, my name is David Lorenz and I am a it service provider with many customers. Our customers use Windows Server 2016 and 2019 as a virtual VMware machine. They use Intercept X Advanced with XDR for Server or Intercept X Essentials…
  • Sophos Golden Image problems with Citrix

    Hi, I am having some problems with this procedure https://support.sophos.com/support/s/article/KB-000035040?language=en_US I have a Citrix MCS Catalog, my VMs are created from a VM image base. First, I install Sophos Antivirus and execute the procedure…
  • "ssl_error_bad_mac_alert" "PR_END_OF_FILE_ERROR"

    Good morning, since we enrolled Sophos Central Endpoint protection we got the Problem, that sometimes, we get these Errors as Mentioned above. PR_END_OF_FILE_ERROR ssl_error_bad_mac_alert if the User waits 5 Minutes and tries to connect the Website…
  • Credential Theft Protection

    Is the Sophos Credential Theft Protection feature considered a substitute for, or equivalent to, Windows Defender Credential Guard? I suspect not but wanted to ask. Thanks, Matt
  • Intercept X Advanced and Patch Management

    Does Intercept X Advanced have Patch Management? Can you manage 3rd party application updates?