• ScanD not running on mac

    Sophos User1175
    Sophos User1175
    hi all, installed sophos endpoint multiple times but i get the same thing everytime, the service ScanD is not running I have disabled SIP so sophos can install unsigned drivers which has worked as before SIP was enabled it was blocking the "network…
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • remove without tamper code

    Sophos User1175
    Sophos User1175
    hi all, how would i remove sophos endpoint on a mac please without knowing the tamper code, as when i go on sophos central i cant get the macs tamper code as it hasnt registered the mac, so theres no way of finding the tamper code thanks, rob
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • INTERCEPT X DETECTIONS

    Ahmed Khalil Abidi
    Ahmed Khalil Abidi
    (Browser-Specific): Threat Protection policies only detects malwares in Firefox when accessing the eicar website but failed to detect it using Chrome. also, what is this behavior, it keeps detecting the malware, cleans it, but never kills the sophos_hips_test…
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • The way to export the all detection data to the list

    Kyohei Urano
    Kyohei Urano
    I want to make a report of detection from sophos central, but there is no such a button to export those kind of data. I need 'detection rule', 'date', 'category', 'severity' contents in this report. Someone know how to make this kind of report…
    • 2 months ago
    • Sophos Central
    • Discussions
  • ¿cuál es la diferencia entre ID de modelo e ID de instancia? al crear excepción de periféricos

    NTM
    NTM
    Buenos Día comunidad, Alguien sabe ¿cuál es la diferencia entre ID de modelo e ID de instancia? al crear excepción de periféricos . Muchas gracias.
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Veeam backups failing. Bypass RTS fixes

    Anthony Flynn
    Anthony Flynn
    Veeam B&R version 12.2.0.334 keeps failing unless I disable/override Real Time Scanning > Files. We have put in place all relevant exception rules that I can find on the Sophos support portal but I find I'm still having issues caused by the RTS. …
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Threat Protection - how to trust a file?

    Michael Wallis
    Michael Wallis
    Hi, We have a Sophos Intercept-X user that has problems running End of Month reports via Excel in a certain CRM application. He is the only user requiring this functionality. We have tracked the issue down to being a .XLL (I assume that is an Excel…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Some Questions about MAC's

    Dennis Haschke
    Dennis Haschke
    Hi, we use Sophos on MAC's and i have some questions........ * We have a group calles MACs. When we install Sophos on a MAC is it possible to auto assign to this group? * Is it possible to create scopes? E.g. that our MAC admin only can administrate…
    • 2 months ago
    • Sophos Central
    • Discussions
  • Device Encryption - Password protect files for secure sharing

    Nico00
    Nico00
    Hello, we decided to activate the file protection option in Sophos Device Encryption. What type of encryption is being used within the HTML5 Containers ? BR
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Port scan detection internal network

    @wajdiaa
    @wajdiaa
    Hi, Is there any option to detect internal network port scans from within the network or networks? Like for example using nmap or netcat or others from inside the local network, not from a wan source. I'm posting this in endpoint as well. Thanks…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Quero realizar remover o sophos endpoint em 750 deskotp nao estou conseguindo realizar pela GPO e nem via bat favor poderia me ajudar

    Walberto Denis Araujo
    Walberto Denis Araujo
    Quero realizar remover o sophos endpoint em 750 deskotp nao estou conseguindo realizar pela GPO e nem via bat favor poderia me ajudar
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Is the Zero day protection is available in Sophos end user agent?

    Firewall Monitoring
    Firewall Monitoring
    Hi all, We have the Zero day protection enabled in the firewall, however the same feature is not available in the Sophos end user agent, What will the difference if any laptop with Sophos end point connected to public network under the Sophos firewall…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • mass-release from quarantine

    FFin
    FFin
    Hi all, i've got a false-positive outbreak detected on one fileserver. There're around 100 Items in Quarantine - alerts spread over 6 pages in Events-Section in central. i went through that list multiple times but was able to release 95 elements from…
    • 2 months ago
    • Sophos Central
    • Discussions
  • Sophos updates has failed for more then one month (download error)

    Pradeep M
    Pradeep M
    Hello Team, One of my clients is using Sophos Intercept X Advanced, and they are facing an issue where changes made in the Sophos Central console are not reflecting on the employee's machine. kindly find the screenshot for your references…
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos blocking Veeam Agent on Windows 11

    Tony Graham
    Tony Graham
    I have a problem with Veeam backup agent with Sophos Endpoint Agent installed If I uninstall Sophos Endpoint I am able to backup the PC. If Sophos is installed it is blocked. I assume this is a matter of somehow unblocking the app or opening some…
    • Answered
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos affecting the Finder on Mac when connected to a Window server

    Gerald Horn
    Gerald Horn
    Has anybody seen Sophos Intercept X with XDR affecting the drawing of icons in a Finder window on a Mac when connected to a Windows server? I have Enable Real-time Scanning On but Remote files is set to Off on a Mac policy.
    • 2 months ago
    • Sophos Endpoint
    • Discussions
  • cookieguard is no longer valid

    ong! L
    ong! L
    Recently, it was found that someone frequently tried to log in to our webpage background, but failed, after several days of investigation The company found out internally that the browser data was stolen, and then found that the cookieguard module was…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Inquiry Regarding Remote Wipe Feature for Laptops

    Michael9609
    Michael9609
    Dear members I hope this email finds you well. I would like to inquire if Sophos offers any remote wipe functionality for laptops in case of loss or theft. If so, could you provide more details on how this feature works and its requirements? Thank…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • DLP to check about various external domains in an e-mail message.

    Cleber Vicentini
    Cleber Vicentini
    Hi, Anyone knows how to configure Sophos DLP, or other tool, to check fields To, CC, Bcc for existing multiple external domains? Example: TO: cccc@gmail.com;bbbbb@hotmail.com In cases when more than one external domain is fond, stop to send e-mail…
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • File control by extension

    Alves
    Alves
    Hi guys, Is it possible to block certain files when they are executed? For example, block all .EXE files when they are clicked
    • Answered
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Central Role Management

    Randy Cleveland
    Randy Cleveland
    When modifying one of our custom roles in Sophos Central for our IT Helpdesk staff, we wanted to allow one of them to do a directory sync from within "Directory Service" under the the e-mail protection settings. When I grant the custom role "Full" access…
    • 3 months ago
    • Sophos Central
    • Discussions
  • About C2_10a (T1071.001) Detected on the server

    ong! L
    ong! L
    Endpoint appears as malicious behavior, but shouldn't detecting c2 be the purview of IPS? Why is it showing malicious behavior? Or is the ips module already involved?
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Sophos Endpoint SSL/TLS Decryption - managed exclusion list

    Stefano Tortiello
    Stefano Tortiello
    Hi is there a managed exclusion List for the Endpoint SSL/TLS Decryption module? I only found the possibility to add custom URLs as exclusion. We use Sophos Firewall as well and there is the URL Group " Managed TLS exclusion list" with a bunch of…
    • Answered
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Local log write error

    ong! L
    ong! L
    The web anti-virus detection logs are written in the IPS logs at .....
    • 3 months ago
    • Sophos Endpoint
    • Discussions
  • Can we add CIXA for 20 user license and Cixa xdr for 30 user in one Sophos central portal

    DevK
    DevK
    Can we add CIXA for 20 user license and Cixa xdr for 30 user in one Sophos central portal
    • Answered
    • 3 months ago
    • Sophos Central
    • Discussions
<>