• Sync Policy on a Linux Machine

    NotAnAdmin
    NotAnAdmin
    Hello all, I am trying to enforce a Peripheral Control : Device policy on a Linux Machine, so that when I plug in a USB, it allows the user to read it, but not write on it. I created the policy under Server Protection, but it is still allowing me to…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Prevent Users Installing Applications

    Onur Akcay
    Onur Akcay
    Hello, In my domain, standard domain users are not able to install a program. But there are some programs that doesnt require admin rights to be installed. I was wondering if i can block them with Sophos. I have tried application block but for that…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Real-Time Scan Exclusion Variable\WildCard Confirmation

    Yogi_Bear_79
    Yogi_Bear_79
    I want to exclude the following (example) from real-time scanning: This directory ( 26e9f183-6e80-4436-8461-a67d55c5e4b1) is randomized within the user's profile temp directory c:\Users\testuser\Temp\26e9f183-6e80-4436-8461-a67d55c5e4b1 These files…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • How do i monitor if some is trying to break the Sophos tamper?

    blueskies
    blueskies
    Scenario - Attacker has made into a system and now wants to kill \stop the AV but is tamper locked. From SIEM perspective to Monitor such events what logs can be shipped from the Event viewer? or from Sophos log directories?
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Application Control - Blocking all Wscripts but allowing one

    zulra
    zulra
    Hi All, We have application control currently set to block Microsoft WSH WScripts, and want to keep it that way. However we have a VBS script that uses Wscript that ideally we want to exclude, so it can be run on endpoints without disabling application…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Endpoint Isolated how to un-isolate or open Anydesk for RDP connection.

    Werner Smit
    Werner Smit
    Good Day, We've had some instances where either Sophos protection service or Network protection service might not start up. This cause the computer to become Isolated but we cannot un-Isolate unless we restart or use Admin rights to start the service…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Does the Server Protection (EAP) provide a security heartbeat to Sophos Central?

    alan weir
    alan weir
    I am testing the Endpoint Protection and Server Protection EAP. I have downloaded the server protection and deployed it on my home DNS server which is running on Ubuntu. It has installed successfully and is registered in Sophos Central in the Server…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Exploit mitigation or ransomware wildcards and variables and using the "$" variable

    Slappy
    Slappy
    Anybody else tried using the "$" variable to exclude a filename and not work?? Looking at the article: Exploit mitigation or ransomware wildcards and variables - Sophos Central Admin Is says this: VariableExample $ All available drives. For…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • unistall agent without tamper protection

    Amoruso Roberto
    Amoruso Roberto
    Hello i need to unistall agent but i can't disable tamper because i don't see client on my control center (i don't know the reason!) how to do? I read many post but i can't modify Sophos MCS Agent registry key (access denied, i tried to change permission…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos Central Encryption removal best practices

    Anishkumar C
    Anishkumar C
    Dear Team, Kindly share the best practices to remove Sophos encryption before expired.
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • 【server protection】Intranet servers are not allowed to access the Internet, how sophos central delivers policies and soft version updates?

    Hongbo Xia
    Hongbo Xia
    Hi team, Our customer's intranet has dozens of Windows servers. According to the requirements of the security department, the intranet servers are not allowed to access the Internet. So, I would like to know how sophos central delivers policies and…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Enterprise Application Issue - Linked to recent maintenance ??

    SimonGoode
    SimonGoode
    We use a SaaS based ticketing system, this is an enterprise application with SSO login and we use this process for many other SaaS based applications. We've an issue today whereby users are unable to login to this SaaS ticketing system resulting in a…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Mensaje de Falta ACS

    Carlos Javier Gomez Ortiz
    Carlos Javier Gomez Ortiz
    Buen día estimados, Este es el correo que tengo de contacto para solicitar su asesoramiento con las alertas que tenemos en la consola. Mi nombre es Carlos Gomez de la empresa Abastecedora Lumen S.A. de C.V. con el licenciamiento: L0006361860 Adjunto…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Device Encryption - difference between "Not encrypted" and "Unmanaged"?

    LHerzog
    LHerzog
    I wonder what the Status in the Encryption dashboard means: under which circumstances is it showing "Not encrypted" and not encrypted & "Unmanaged"? On the screenshot all have the encryption module installed, except one computer. The filter is …
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Endpoint Protection Policies didn't work

    Fabian Schäfer
    Fabian Schäfer
    Hello, unfortunately we have a little problem with the endpoints policy. So far we had blocked powershell for all users and groups via the base policy. But since we need powershell for certain scripts this way can't work for us. We tried to block…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Has anyone seen a false flag for "WIN-CAC-NET-CONNECTION-NO-CMDLINE-1.star"

    bkatw0rk
    bkatw0rk
    I'm running into an issue where sophos flags dllhost.exe as suspicious because it runs with no command line arguments. That IS suspicious, my issue is that when I dug into it, that particular process ID it flags on my end does have a command line argument…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • why do you disallow a comment for exploit mitigation exclusions?

    LHerzog
    LHerzog
    Hi, in our VoIP Client there is a ROP Detection. After searching, this is by Exploit detection engine. No I can set exclusions for a lot of things and I in all I checked, it is possible to make a comment like here: but for exploit mitigation…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos Central Peripheral Control - Purge Events?

    Chris Dalton
    Chris Dalton
    Hi, I have Central managing over 8800 active endpoints, we use Peripheral control. There are close to 24000 peripherals listed in our organisation, 2180 of which are currently allowed. I have historic data going back 4 years. To find new events…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos Enterprise Console

    Handian Sudianto
    Handian Sudianto
    Hello, Currently i will migrate our sophos enterprise console (SEC) to the sophos cloud. Anyone know here how to check license used by SEC?
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Failed to install SED64,AMSI64: 80041f00,80041f00

    IT Support36
    IT Support36
    After updating windows to the latest version which is 22H2, this error appear on certain device at the Sophos Central. The error: - "Failed to install SED64,AMSI64: 80041f00,80041f00"
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Looking at getting onboard

    Shawn Barnard
    Shawn Barnard
    Hi everyone, We are looking at getting Sophos Intercept X Advanced. Can anyone confirm if Sophos CIXA can do all the following? Monitoring of Windows clients and Instant alert if a client is compromised with a virus/malware/application vulnerability…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos Endpoint Agent XDR & Siemens WinCC V7.x

    Thomas_LSW
    Thomas_LSW
    Hi community, Sophos Central has not been approved by Siemens WinCC V7.x ! I am forced to install Sophos Endpoint Agent on such Servers anyway. What are the recommended global exclusions from Sophos for such Servers, and above all which exclusion…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos central Web filtering

    Richard Hamblin
    Richard Hamblin
    Hi everyone, I'm starting to find a few limitations in the Sophos central endpoint web filtering. Is there any way to find out if a url is in a particular web category when using sophos central? Also could sophos central report on all web browsing…
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Time to get disabling tamper protection to work

    Jo Vanattenhoven
    Jo Vanattenhoven
    Hi everyone, If we disable the tamper protection on the device itself, how long does it takes before it is actually disabled? After disabling it, we still cannot uninstall the Sophos Endpoint. Jo
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • Sophos Central Public Update Cache using FQDN

    Ahmad Almla Rashed
    Ahmad Almla Rashed
    Hi, i have many endpoints that can't update from sophos cloud (restricted network) I have installed update cache on one of my servers its internal IP let's say 10.X.X.X and the hostname is myserver.internal.local and this server also has a public static…
    • Answered
    • over 1 year ago
    • Sophos Central
    • Discussions
  • View related content from anywhere
  • More
  • Cancel
<>