• Custom Query Intermittent Results

    Lee Fellows
    Lee Fellows
    We have created a custom query to allow us to find specific file names and path on any system within our tenant. SELECT file, path FROM sophos_file_journal WHERE file LIKE '$$Filename$$'; This is very temperamental, as it will sometimes return a result…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Controlled application blocked: Microsoft Powershell

    Simeon Lewis
    Simeon Lewis
    I've seen a few posts already about this but nothing in recent years. I've turned on Application policy to try an prevent misuse of PowerShell and other tools. However its raised a large number of regular (hourly) alerts on most of the endpoints. Suggests…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Device Encryption - difference between "Not encrypted" and "Unmanaged"?

    LHerzog
    LHerzog
    I wonder what the Status in the Encryption dashboard means: under which circumstances is it showing "Not encrypted" and not encrypted & "Unmanaged"? On the screenshot all have the encryption module installed, except one computer. The filter is …
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Endpoint Protection Policies didn't work

    Fabian Schäfer
    Fabian Schäfer
    Hello, unfortunately we have a little problem with the endpoints policy. So far we had blocked powershell for all users and groups via the base policy. But since we need powershell for certain scripts this way can't work for us. We tried to block…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Intercept X Web control - Web Threats Blocked

    Jonas Stadler
    Jonas Stadler
    Hello everyone, yesterday I saw for the first time an entry at "Web Threats Blocked". It shows me that a "High Risk" website was blocked. But sadly in this overview is not date and no information what website exactly was blocked. Is there an option…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Sophos me esta bloqueando una pagina que indica Mal/HTMLGen-A

    Agustin Ibarra
    Agustin Ibarra
    Sophos no deja entrar a mis usuario a una pagina de gobierno ( egob.finanzas.cdmx.gob.mx/.../a ) porque una aplicación que usa la categoriza como "Mal/HTMLGen-A". Ya puse la pagina en una whitelist y nada.
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Threat Analysis Center / Detections: "Vulnerability SRP path rules missing" caused by MDR checks

    LHerzog
    LHerzog
    The detections section in Threat Analysis Center is filling with many of these events caused by MDR checks. SRP seems to be related to Microsoft Software Restriction Policies. What is the intension of this check? "COMPLIANCE-SRP-DISALLOWED-PATHS…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Access of Bluetooth

    Shubham Taur
    Shubham Taur
    I would like a setting from Sophos central to have block Bluetooth but only connect Bluetooth headphones which only transmits 2-way (in and out) audio but no data or file sharing. It is Possible or not...? If it possible then please guide me...!
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Peripheral List

    jmwork
    jmwork
    Hallo, gibt es eine Möglichkeit eine Liste der Peripheral des jeweiligen Central Accounts zu erhalten um zu sehen, wann welche Peripheral zuletzt benutzt wurde, bzw. welche gar nicht mehr genutzt wurde? Der Peripheral Report zeigt leider nur die letzte…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • SSL Decryption Issues

    TomHilton
    TomHilton
    Is anyone else noticing issues with SSL inspection recently? we've just had the new core agent 2023.1.0.73 deployed on our estate and seeing a vast amount of websites being blocked 'the encryption used by this server hosting the URL is insecure' downgrading…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • disabling tamper protection via cmd

    Sophos User1175
    Sophos User1175
    hi all, is there a way of disabling tamper protection via cmd ie once i have the number via sophos central can i make a cmd bat script and disable it thanks, rob
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central Peripheral Control - Purge Events?

    Chris Dalton
    Chris Dalton
    Hi, I have Central managing over 8800 active endpoints, we use Peripheral control. There are close to 24000 peripherals listed in our organisation, 2180 of which are currently allowed. I have historic data going back 4 years. To find new events…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos central Web filtering

    Richard Hamblin
    Richard Hamblin
    Hi everyone, I'm starting to find a few limitations in the Sophos central endpoint web filtering. Is there any way to find out if a url is in a particular web category when using sophos central? Also could sophos central report on all web browsing…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Time to get disabling tamper protection to work

    Jo Vanattenhoven
    Jo Vanattenhoven
    Hi everyone, If we disable the tamper protection on the device itself, how long does it takes before it is actually disabled? After disabling it, we still cannot uninstall the Sophos Endpoint. Jo
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Internal Local Hardisk & Network storage service block

    Anishkumar C
    Anishkumar C
    Hi team, Is there any option to control (Block) Network storage services(NAS). And to block users using local Hardisk to store the data(Only store the data in MicrosoftOndrive) - To block internal harddisk. kindly help me to achieve above things.…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Need help in building OS Query for Finding SHA1 andSHA256

    Jenil Sadrani
    Jenil Sadrani
    Hello All, I have been trying to create custom queries in Sophos Central for finding IoCs (SHA1 and SHA256). Can you please help me build query for the same? Regards, Jenil
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Sophos XDR Technical Demo (23 minutes)

    Andrzej Kozlowski
    Andrzej Kozlowski
    I upgraded my subs to XDR and looked to following video: https://vimeo.com/519661823 Unfortunately I do not see tables mentioned there like: Data Lake hydration queries query result List all EP and XG FW Tables Windows programs Inventory search…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Scheduled query - recommendation

    Andrzej Kozlowski
    Andrzej Kozlowski
    I have mixed Mac and Windows environment. So far I scheduled weekly two queries: Pending macOS updates Data Lake Pending Windows updates Data Lake Do you have any other recommendation what makes sense to run using the schedule ?
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Detections Many Level 4 messages

    Andrzej Kozlowski
    Andrzej Kozlowski
    Hello, Just upgraded my license to XDR and now under detections I see many level 4 warnings like: SRP path rules missing. Secure boot supported but not enabled. DEP is not Admin Opt-out or Always-on. Applications with special compatibility…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint Web whatsapp blocked

    Muhammad Abdullah Siddiqui
    Muhammad Abdullah Siddiqui
    Hi, Endpoint is blocking Web. WhatsApp on a single user although all users seem to be running it fine and I have added an exception of web.whatsApp in chats categories and called it in Policies settings. Web WhatsApp page loads correctly but after…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Blocking Drive Services

    Onur Akcay
    Onur Akcay
    Hello, i want to block drive services (google drive, yandex, cloud etc.) I've already blocked them on my firewall but when user connects to another network, user can still use drive services. Is there any way to prevent user to use drive services…
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central - Web control policy violators

    Anishkumar C
    Anishkumar C
    Hi team, Help us to get report in Web control policy violators with username and categories. Is it possible?
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • SOPHOS DEVICE ENCRYPTION WITH OFFICE DOCUMENTS

    Tanda Rich
    Tanda Rich
    Translator Hi, i want to join a script.py to my Sophos Central in Device Encrytion , it will automatically detect a type of my office document (Public, secret and confidential) and make the encryption with it.
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Bloquear uso de impresora por red

    Wilson Echeverry
    Wilson Echeverry
    Hola comunidad, Tengo la siguiente duda: ¿Es posible que desde Sophos central se bloquee el servicio de impresión por red? Gracias por su ayuda.
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
  • Peripheral Control

    Kevin Fourie
    Kevin Fourie
    Hi We have Sophos Central in our environment. Peripheral Control is enabled everything works as it should however we are unable to update create or delete files on our peripheral devices. Is there perhaps a setting that we could change to help solve…
    • Answered
    • over 1 year ago
    • Sophos Endpoint
    • Discussions
<>