• Data Loss Prevention Policies - How to configure alerts to not generate a new alert for the same event in specified amount of time

    Ugo Marzola
    Ugo Marzola
    Hello everyone, I have configured DLP policies for one of our clients, they work as expected. There is just one remark our client gave us : Sometimes if a user does the same action repeateadly, generating alerts every time he does that action, that…
    • Answered
    • 1 month ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central Detections

    admin_idl
    admin_idl
    Hello, We have a Sophos Central account with about 150 computers and 25 servers. XDR is used. The licences have currently been active for about 8 days, but no detections have been displayed so far. Could it be that nothing has been detected so far and…
    • 1 month ago
    • Sophos Central
    • Discussions
  • Is Sophos CPU history recorded in Data Lake?

    PK1
    PK1
    Is Sophos CPU history recorded in Data Lake?
    • 1 month ago
    • Sophos Endpoint
    • Discussions
  • Protected devices/users

    Josefina Frutos
    Josefina Frutos
    Hi! I wanted to know if there is a way to download the list of users and the serial numbers of the computers assigned to them. From what I've seen in the reports section, it doesn't allow modifying the columns. Do you know if it's possible to download…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Need command to identify BitLocker is managed by Sophos Encryption on the PC itself

    ArtL
    ArtL
    I have identified a problem with Sophos Encryption, and I need to do a validation before bringing it up with Support as an issue. I can run a powershell command (as seen below) to find the encryption status however it doesn't tell me that it was Sophos…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Application Control Policy Not Working

    ptho
    ptho
    Hi Sophos, I can't get the Application Control policy to block Proxy / VPN Tools. I've tried to edit the Base Policy as well as create a new policy and neither seem to work. See the attached image. I have tried selecting all VPN / Proxt Tool objects…
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint causing network to disconnect when transitioning from wired / wireless

    OtherUTMGuy
    OtherUTMGuy
    Sophos Endpoint running reliably in our environment for 5-ish years. There is a message / cache server on-prem that supports our clients, and we've had no major issues. All Dell Latitude / OptiPlex equipment. In this specific example, I'm using a Latitude…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • ¿cuál es la diferencia entre ID de modelo e ID de instancia? al crear excepción de periféricos

    NTM
    NTM
    Buenos Día comunidad, Alguien sabe ¿cuál es la diferencia entre ID de modelo e ID de instancia? al crear excepción de periféricos . Muchas gracias.
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Device Encryption - Password protect files for secure sharing

    Nico00
    Nico00
    Hello, we decided to activate the file protection option in Sophos Device Encryption. What type of encryption is being used within the HTML5 Containers ? BR
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • DLP to check about various external domains in an e-mail message.

    Cleber Vicentini
    Cleber Vicentini
    Hi, Anyone knows how to configure Sophos DLP, or other tool, to check fields To, CC, Bcc for existing multiple external domains? Example: TO: cccc@gmail.com;bbbbb@hotmail.com In cases when more than one external domain is fond, stop to send e-mail…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint SSL/TLS Decryption - managed exclusion list

    Stefano Tortiello
    Stefano Tortiello
    Hi is there a managed exclusion List for the Endpoint SSL/TLS Decryption module? I only found the possibility to add custom URLs as exclusion. We use Sophos Firewall as well and there is the URL Group " Managed TLS exclusion list" with a bunch of…
    • Answered
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • RE: Blocking Controlled Items Prompts for Problems

    ong! L
    ong! L
    One more question, how to customize the tamper protection password?
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central + YARA

    Mansoor Ahmad
    Mansoor Ahmad
    As residents of Saudi Arabia, SAMA provides us with YARA rules for threat detection. How can we effectively create and implement our own query within Sophos Central to scan for these YARA rules? What are the best practices and challenges associated…
    • 3 months ago
    • Sophos Central
    • Discussions
  • Sophos Application Control and Installing Intune Management Extension

    Monkster
    Monkster
    Hi, We've recently moved to a hybrid setup for our Windows devices (local active and Intune). Many devices have successfully fully setup but most have not. They are registered with Intune and show compliance, however we have found that those not working…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Improvement suggestion for Peripheral Control - Add note/remark

    Rafael Sardinha
    Rafael Sardinha
    Hello, I would like to suggest an improvement to the Peripheral Control Policy by adding a note/comment field where we can enter a text justifying the exception. I have “old” exceptions for USB sticks/disks that I can't remember what/who they were…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Finding where the domain users group added to the remote desktop users local group

    Nandha
    Nandha
    Hi, Is there any osquery to get all the domain-joined machines where the "Domain Users" group is added to the "Remote Desktop Users" local group?
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Web Control - decontrol whole category for a user

    Thomas_LSW
    Thomas_LSW
    Hello community, How can I decontrol a specified category for a user or user group ? Best regards, Thomas
    • Answered
    • 4 months ago
    • Sophos Central
    • Discussions
  • Separate Admin DLP email alerts

    Mark Northcott1
    Mark Northcott1
    We have a situation that's causing some annoyance with both our IT Engineers and our Information Governance staff, and its all to do with the DLP alerts to Admins when a user may be breaking our policies. I've looked at the Custom Rules for Admin email…
    • 4 months ago
    • Sophos Central
    • Discussions
  • Blocking USB storage devices with endpoint protection?

    Lothar Kruse
    Lothar Kruse
    Hello, I am currently using Sophos Endpoint Protection Intercept X Advanced in the company network. Is it possible with Endpoint Protection to block USB interfaces for storage media such as USB sticks or external hard drives? So that only approved USB…
    • 4 months ago
    • Sophos Endpoint
    • Discussions
  • Remove Endpoint Client without password

    Lothar Kruse
    Lothar Kruse
    Hello, I have a Windows 11 Pro Client that has a Sophos Endpoint Protection Client installed. But in Sophos Central the client is not listed any more. When I start an update on the client manually, there comes an error. I can´t find any way to…
    • 4 months ago
    • Sophos Endpoint
    • Discussions
  • How to manually disable Tamper Protection

    Jeff Pascone
    Jeff Pascone
    Hi, I have read through these forums and also some FAQ's and everything I have tried hasn't worked. The SOPHOS administrator has been unable to recover the key, so this problem has been dumped in my lap. Does anybody have a method they have successfully…
    • 4 months ago
    • Sophos Endpoint
    • Discussions
  • How can I search for a MD5 Hash with Sophos EndPoint

    Hans_Dampf
    Hans_Dampf
    I have a hash like: 6ea2c9276c122222222222f9ae2 i want to search on the clients for this hash. is there a posibility to search with Sophos EP?
    • 5 months ago
    • Sophos Endpoint
    • Discussions
  • TLD block in Sopho Central

    Damian Kowalik
    Damian Kowalik
    Hello there, I am trying to block TLDs in Sophos Central using Website Management—Add Website Customisation, and instead of putting many domains with a malicious top domain, I would like to be able to block this particular domain. What should I…
    • 5 months ago
    • Sophos Central
    • Discussions
  • Sophs Central control

    Nyein Chan Zaw
    Nyein Chan Zaw
    Hi all, I have installed Sophos EP in client and it's possible to control "no internet access and only the website that allow from Sophos Central" ? or can block all http and https from Sophos Central ?
    • 5 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos DLP Inside file Content Blocking

    Shashank Khamkar
    Shashank Khamkar
    Dear Team, Can we block a content in a file such as adhar card number sent in a file or so.
    • 5 months ago
    • Sophos Endpoint
    • Discussions
>