• Malicious Behaviour (PrivGuard) detected

    Ingo Buyny
    Ingo Buyny
    Hello, i use gsudo.exe with Windows Terminal to start CMD or Powershell with administrative rights but since i use Sophos Endpoint it shuts down the Terminal app every time the gsudo process opens a new tab. The Error message is "Malicious Behaviour…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • SafeGuard user certificates are expiring

    Chris Carson
    Chris Carson
    As the title says, our user certificates are coming up on expiration date soon. Mine personally has already expired (my MSO is another user). 1) If we do not use file encryption, is there a consequence of certificates expiring? 2) I looked at auto…
    • over 2 years ago
    • Encryption
    • Discussions
  • Required users in SafeGuard console?

    Chris Carson
    Chris Carson
    We do not use File Encryption. We basically image a computer, login to the Safeguard credential provider (or to domain, then login to the Safeguard prompt) which prompts encryption. Then we disable the credential provider and the auth prompt using the…
    • Answered
    • over 2 years ago
    • Encryption
    • Discussions
  • CloseDisc.exe Utility

    PootieTang
    PootieTang
    Greetings all, Can anybody tell me if it's possible to specify the drive letter to target when using the closedisc.exe utility? Not having any luck using closedisc.exe D: or even /? Thanks, Pootie
    • Answered
    • over 2 years ago
    • On-Premise Endpoint
    • Sophos Endpoint Software
  • How to delete "Event" from Sophos Endpoint Agent? using a non-administrator account?

    Chris L
    Chris L
    Hi all, I'm using my company's laptop and running it as a non-administrator account. I am unable to access Sophos Diagnostic Utility it says "SDU is running from a non-administrator account. The tool may not be able to gather all requested information…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • PDF Viewing via Edge and Chrome is freezing since Sophos

    SGICT
    SGICT
    We're rolling out Sophos Central Endpoint Advanced to a firm that use to have Panda 360. The migration is going fine but have several machines with the same problem. That is if Adobe Reader is not installed OR is not the default program to open PDFs,…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint Privacy Deactivated

    Ingo Buyny
    Ingo Buyny
    Hello, i am new to Sophos Endpoint and still try to dig my way through the settings and options. My Testclient shows me a red Alert wich means "Privacy deactivated" and "We informed your Administrator" But i didn't got informed about anything an…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Windows Server 2019: Network Setup Service constantly restarting. disabling Network Threat Protection fixes it

    LHerzog
    LHerzog
    Today I noticed on our Windows Servers 2019 with Intercept X that the Windows Service "Network Setup Service" is constantly restarting. It runs for 3 seconds, then stops. Starting again after a second or a few seconds. This is happening all day long…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • In which customers was my endpoint installed?

    Ardit Latifaj
    Ardit Latifaj
    Hello dear community, I have the problem that I used a wrong installer when installing an endpoint for a customer. Unfortunately, with the large number of customers, I do not know in which customers the PC was installed. When uninstalling, the tamper…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Remove System Extension off of Macs using Jamf Pro

    Joey Byboth
    Joey Byboth
    Hi, I know this is a known issue but I'd thought I'd reach out anyway. I need to remove Sophos off of a lot of Mac computers, including the system extensions. (They seem to be causing performance issues). I cannot ask users to disable SIP and run a bunch…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Performance Loss and Central Page Usage

    optimum
    optimum
    Hello there! I have some questions. I wasn't sure where to open this thread (f.e Sophos Central or Intercept X Endpoint ). Please excuse me if my posting here is wrong. We recently joined Sophos. We also caught a lot of malware that our previous security…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Anti-Virus gone on many Windows 10 clients - but not all

    astiadmin
    astiadmin
    Hi all, today it seems that on a lot of Windows 10 clients the Sophos Anti-Virus service was removed however not on all. The status in Central is ok so no "service missing" message or the like. Is that due to an update? Why does it not affect all clients…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • SDL logs for. Sophos Intercept-x for server occupying massive disk space

    Alok Gupta
    Alok Gupta
    Hi I am using SOPHOS Intercept-x for server with server lockdown feature and noticing that SOPHOS SDL log files keep on increasing and storing more than a year logs. Resulting no space left on the disk. Pls suggest workaround to remove these logs…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Querying a Registry path, parsing it in CASE...not working.

    Andrew Short1
    Andrew Short1
    Trying to create a Live Query to assess the state of the Windows Firewall via the registry. I started with the "View registry Section" query and modified it to the following. The initial case statement ALWAYS produces the results "Error", even though…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Bugcheck KERNEL_SECURITY_CHECK_FAILURE SSPService.exe, SophosSupport.sys

    LHerzog
    LHerzog
    2 of our computers got BSOD today after a Sophos product update has been installed yesterday. Both machines are EAP. The BSOD occoured about 1h after power on during a zoom video meeting session. with or before the BSOD a minidump has…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • AD Sync tool is deleting a groupmembership in Sophos Central

    Alexander Schmidt2
    Alexander Schmidt2
    when I run the AD sync a specific server in Sophos Central is moved from AD group to no group. However, the group is available in Central and I can manually move the server back there. But a sync deletes this assignment again. In AD, the server can be…
    • Answered
    • over 2 years ago
    • Community Chat
    • Discussions
  • Hitman Pro Alert Cannot be Installed

    Frederic Jiang
    Frederic Jiang
    Hi, I am running Windows 10 Home 64bit 21H2. I am trying to install Hitman Pro Alert using the file downloaded from the official web page. It is version 3.8.19.923. However, when I run the .exe file, and then click on Install, a message pops up…
    • Answered
    • over 2 years ago
    • Community Chat
    • Discussions
  • Protecting endpoints from SEC fails with error 0000002e on some clients

    Ulli Conrad
    Ulli Conrad
    Hi all, while most clients in my branch can be protected from the SEC without any problems it fails on a couple of clients. All are installed from the same image with same GPOs. Searched for solutions and tried suggestions for this error but none…
    • over 2 years ago
    • On-Premise Endpoint
    • Sophos Enterprise Console
  • Next Gen Architecture Rollout

    NetGuy
    NetGuy
    According to this post and comments made in it, these rollouts should be complete and devices should be updated fully to the new architecture, however my entire fleet still hasn't updated. The new agent seems to be rolled out but devices still have the…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • High CPU Usage on Windows Server while Windows Update installing

    David Lorenz
    David Lorenz
    Hello Sophos Community, my name is David Lorenz and I am a it service provider with many customers. Our customers use Windows Server 2016 and 2019 as a virtual VMware machine. They use Intercept X Advanced with XDR for Server or Intercept X Essentials…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Golden Image problems with Citrix

    Alejandro Hernandez
    Alejandro Hernandez
    Hi, I am having some problems with this procedure https://support.sophos.com/support/s/article/KB-000035040?language=en_US I have a Citrix MCS Catalog, my VMs are created from a VM image base. First, I install Sophos Antivirus and execute the procedure…
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint Web Control and IPv6

    RyzenShine
    RyzenShine
    What's the status on a solution for this? I am thinking we're going to have to move in a different direction for our mobile devices since this has been a known issue for years with no solution in sight. IPv6 is very common now and lack of support is making…
    • Answered
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • ReRegister Sophos Endpoint Protection Silently

    Kyle McLaughlin
    Kyle McLaughlin
    can I execute --registeronly with the --silent command so the end user doesn't see the change? I have managed to get tamper protection turned off
    • over 2 years ago
    • Sophos Central
    • Discussions
  • Sophos Intercept X and Encryption (Bitlocker) Windows 11

    RyanHosiassohn
    RyanHosiassohn
    Hey All, I was wondering has anyone has any issues with having this installed on Windows 11 ? I installed it and the Encryption policy never seems to ask for a password, I can see there is a TPM but doesnt ask for a password to be set for bootup.
    • over 2 years ago
    • Sophos Endpoint
    • Discussions
  • Sophos SafeGuard Management export Inventory

    M-ameen Ahmed Ahmed
    M-ameen Ahmed Ahmed
    how to export inventory with the following information in Sophos SafeGuard Management Center? : Computer name, features (module name), user name
    • over 2 years ago
    • Encryption
    • Discussions
<>