Sophos Firewall: SATC with Sophos Server Protection Step by Step Guide


Sophos Authentication for Thin client (SATC) with Sophos Server Protection enables Sophos Firewall to authenticate users accessing a server or remote desktop.SATC is included with Sophos Server Protection in Sophos Central. It's part of Sophos Central Server Core Agent and is available with any Server Protection license in Sophos Central. Currently, SATC with Sophos Server Protection only supports Windows Remote Desktop Services.You must download the Windows Server installer from Sophos Central. The installers that you can download would depend on the licenses you have. 

Sophos Firewall controls those authenticated users using a session-based approach via an identity-based firewall rule providing more granular access controls per user group. 

What To Do

Follow the steps below to set up new SATC client integration with Sophos Server Protection: 

  1. In Sophos Central, select your username on the top right side and then select Early Access Program. Find "New Server Protection Features" in the Early Access Program and select join. 

  2. Once you have gone through the join process, there will be a join device option in the bottom right corner. Select this and add the terminal server.  

  3. Add the eligible devices: 

  4. Once this is done, it may take some time to apply to the terminal server. When writing this article, the versions shown in the screenshot below are the latest *versions supporting SATC.

    *NOTE: Version may differ in the upcoming days cause of the regular updates, so that is fine.

  5. You can validate by checking the SophosNetFilter.exe service running from the task manager > Details:

  6. Turn off tamper protection for server protection. Note the current settings before you turn off tamper protection, as you need to change these back once SATC is activated. 

  7. Ensure IPS is turned on in the server's threat protection policy. This setting is on by default. For more information, refer the screenshot below: 
    Path On Sophos Central: Server Protection > Policies > Threat Protection > Settings > Server Protection default settings > Runtime Protection. 

  8. Set up SATC with Sophos Server Protection.

  9. On the server, open a command-line console/Power Shell. Add new parameter Satc PendDuration Ms in SATC, run the following command to turn on SatcPendDurationMs parameter  
    command: - reg add "HKLM\Software\Sophos\Sophos Network Threat Protection\Application" /v SatcPendDurationMs /t REG_DWORD /d 300 

    NOTE: We are updating the pend duration only when there is network latency.

  10. Please ensure to reboot the Terminal Server once changes are applied. 

  11. Lastly, check the windows registry to confirm the changes under: HKLM\Software\Sophos\Sophos Network Threat Protection\Application  

If you face any issues or need further assistance with this, kindly reach out to our Sophos Support team -

Note Update
[edited by: Vivek Jagad at 11:59 AM (GMT -7) on 28 Jul 2022]

Top Replies

Parents Reply Children
  • Yup that's true it is still in early access programs. You can log a service request if you are having troubles with it. And support can help you investigate further to narrow down the situation.

    Thanks & Regards,

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved

    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.

  • Thank you for the reply...

    I have tried to provide access to Sophos support it took me a month case to escalate to the Global Support team, they have tried to provide me support many times, i have also spent around 10+ hours with for the remote support to diagnose the issue but, not done.. finally i have to uninstall the Sophos server protection, as it was high on server resources.

    Sophos as already discontinued the old SATC client, and the new solution is provided in full of bugs... what exactly does Sophos expect from the customers, to provide them with our production servers for their own research and developments?

    It is almost 1+ year Sophos has announced end of support or OLD SATC and new solution still in BETA...

    Looking forward to get some ETA announcement for the final and proper solution...

  • Hey ,

    The 2022.2.x version of the Server agent moves the SATC functionality out of IPS and into the Core product.

    We are due to release that to IT next week and start the Server release towards the end of July. 

    Thanks & Regards,

    Vivek Jagad | Technical Account Manager 3 | Cyber Security Evolved

    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.