Changes
These are the new and changed help pages in this release.
New pages
- Set up a browser-based authenticator
- License management
- Product licenses
- Sophos Mobile licenses
- AP6 series access point licenses
- Sophos Switch licenses
- Delete an Active Directory source
- Multi-factor Authentication
- Active Threat Response
- RADIUS Servers
- Configure Entra ID for AP6 authentication
- Active Threat Response
- Query wireless data using Live Discover
- Invite users to install Protected Browser
- Install the Protected Browser extension
- Install the extension on Mac devices manually
- Install the extension on Windows devices manually
- Bulk install the extension using Google Enterprise Core
- Bulk install the extension using Microsoft Intune
- Bulk install the extension using Jamf Pro
- Bulk install the extension using Active Directory GPO
- How-to articles
- Safe AI use cases
- Block Generative AI apps in Protected Browser
- Block Generative AI apps in all browsers
- Allow authorized Generative AI apps with restrictions
- Allow specific actions in authorized Generative AI apps
- Prevent data leaks from SaaS apps
- Configure M365 journaling automatically
- Quarantined Messages
- View quarantined message details
- Search quarantined messages
- Manage quarantined messages
- Quarantined message reports
- Policies
- Access your firewall's web admin console
- MDR policies
- MDR Customer Penetration Testing Expectations Policy
- Sophos MDR Supported Response Actions
- Identity Risk Score
- Backup
- Active Threat Response
- Query switch data using Live Discover
- Sophos Support Assistant
Changed pages
- Getting started
- Create an account
- Activate your account and get software
- Sophos Email onboarding
- Sophos MDR onboarding
- Install software
- Manage devices in Sophos Fusion
- Set up policies
- Automate adding users and devices
- Sophos Fusion's new look
- Sophos Help
- Manage your account
- About authentication
- Sophos Fusion MFA Requirements
- Set up a passkey
- Set up an authenticator app
- Sign in to Sophos Fusion with a passkey or authenticator app
- Reset MFA
- Troubleshooting
- Account details
- Create an Enterprise Admin
- Supported Web Browsers
- Languages
- Licensing guide
- Activate your license
- Renewals and license expiry
- License expiration reminders
- Endpoint licenses
- Endpoint license expiration
- Endpoint license usage and calculation FAQs
- Mobile license FAQs
- Firewall licenses
- Manage your firewall licenses
- Firewall license details
- Firewall reporting licenses
- Sophos Firewall OS (SFOS) licensing model
- Claim a firewall
- Claim an RMA firewall
- Transfer subscriptions between firewalls
- Download and apply an airgap license
- XG to XGS license transition
- Frequently asked questions
- Migrate Sophos UTM licenses to Sophos Firewall
- Apply a Sophos Firewall license to an SG series UTM appliance
- Apply a virtual Sophos UTM license to a virtual Sophos Firewall
- High availability licensing
- Firewall license expiration
- Firewall license FAQs
- Getting started with firewall licenses
- Activating firewall license keys FAQ
- Firewall license renewals, upgrades, and replacements
- Email licenses
- Email license usage calculation
- Email trial license
- Email license expiration and exceedance
- Phish Threat licenses
- Phish Threat FAQs
- AP6 support and services licensing
- Sophos Switch support and services licensing
- DNS Protection licenses
- Frequently asked questions (FAQs)
- Encryption licenses
- Encryption license expiration
- Workspace Protection licenses
- Frequently asked questions (FAQs)
- Free Trials
- Trial license banners
- Free trial FAQs
- Unsupported Sophos products
- People and devices
- Users & Groups
- Users
- User Summary
- User Devices
- Import users from a CSV file
- Protect existing users
- Delete users
- Installers
- Endpoint
- Installer command-line options for Mac
- Installing Endpoint using Jamf Pro
- Security permissions on macOS
- Server
- Sophos Protection for Linux
- Create a Linux gold image
- Installer command-line options for Linux
- Sophos Protection for Linux troubleshooting
- Firewall Protection
- Domains and ports to allow
- Installer command-line options for Windows
- Create gold images and clone new devices
- Computers and servers
- Computers
- Computer Summary
- Computer Status
- Mobile devices
- Device details
- Properties
- Scan device
- Servers
- Server Summary
- Server Status
- Server Exclusions
- Deleted and expired devices
- How to find out a file's SHA-256 hash
- Manage your products
- Dashboards
- Fusion Overview dashboard
- Create or edit a dashboard
- Manage dashboards
- Widgets for dashboards
- Policies
- About Policies
- Account Health Check
- Health check scores
- Health check alerts
- Fix Endpoint agent mode
- Fix Server agent mode
- Fix MDR authorized contact
- Alerts
- Alerts for Threat Protection
- Alerts for Device Encryption
- Alerts for installation and compliance
- Firewall alerts
- Deal with ransomware
- Deal with PUAs
- Resolve PUA alerts
- Network Map
- Threat Analysis Center
- AI Search
- Threat Graphs
- Threat Graph analysis
- Live Discover
- Data Lake queries
- Data Lake uploads
- Edit or create queries
- Create query categories
- Limits on use of queries
- Set up and start Live Response
- Give admins access to Live Response
- Scheduled queries
- Assign cases
- Detections
- Logs and Reports
- Logs
- Events
- Malware and PUA events types
- Network access event types
- Management event types
- User behavior event types
- Device encryption event types
- Malicious behavior types
- Audit Logs
- Data Loss Prevention Events Log
- Processed report
- Message Categories
- Message Details
- Details
- URLs
- Reports
- Computer Report
- Server Report
- Restore deleted devices and recover Tamper Protection passwords
- Attack Details
- SophosLabs Analysis Report
- Data Control Summary Report
- License Usage Summary Report
- Global Settings
- Configure email alerts
- User Activity Verification
- Directory service
- Set up synchronization with Active Directory
- Filter inactive AD users
- Active Directory synchronization FAQ
- Active Directory synchronization installation FAQ
- Device group discovery FAQ
- Purge synchronized Active Directory data
- Set up synchronization with Microsoft Entra ID
- Set up an Azure Application
- Filter users and groups
- Migrate to Microsoft Entra ID
- Set up synchronization with Google Directory
- Add another domain from the same Google account
- Troubleshoot Google Directory synchronization
- Filter users and groups
- Disconnect a Google directory source from your Sophos Email
- Device migration
- Co-branding
- Access Control
- Admins and Roles
- Add administrators
- Remove administrators
- Administration roles
- Compare administration roles
- Administration roles for Sophos XDR
- View a role's details
- Add a custom role
- Delete custom role
- Change roles for administrators
- Role management FAQs
- Sign-in and Identity
- Sophos sign-in settings
- Set up Federated sign-in
- Use Microsoft Entra ID as an identity provider
- Use OpenID Connect as an identity provider
- Use Microsoft AD FS as an identity provider
- User access
- Send users an access email for Sophos Fusion Self Service Portal
- Add the identity provider (Entra ID/Open IDC/ADFS)
- Configure Microsoft Entra ID to allow users to sign in using UPN
- Sign-in options
- API Credentials
- Third-party access via APIs
- API Token Management
- Integration Credential Manager
- Global Exclusions
- Linux scanning exclusions
- Admin Isolated Devices
- Block compromised IP addresses
- Inbound Allow/Block
- Import and export allow/block list
- Web filtering profiles
- Website Management
- SSL/TLS decryption of HTTPS websites
- Data Loss Prevention Rules
- Create a Data Loss Prevention Rule
- Configure a Data Loss Prevention Rule
- Content Control Lists
- Create a Linux Runtime Detection profile
- Products and Services
- MDR setup
- Managed Risk setup
- Event Journals
- Update Caches and Message Relays
- Software packages FAQ
- Content updates FAQ
- Removal of inactive devices
- Tamper Protection
- Turn off Tamper Protection
- Proxy configuration
- Forensic snapshots
- Upload forensic snapshots to an AWS S3 bucket
- Identity Settings
- Set up browser enforcement using Entra ID
- Set up browser enforcement using Okta
- ZTNA Settings
- Gateway Domains
- DKIM keys
- M365 Mailflow Domains
- Business Email Compromise
- Account compromise
- Impersonation protection and VIP management
- Add Internal VIPs
- Add External VIPs
- Import and export VIPs
- Delete VIPs
- Custom SMTP Routing
- Encryption Outlook Add-in
- Custom Branding
- User Settings
- S/MIME
- S/MIME email encryption setup
- Time-of-Click Block and Warn Pages
- Post-Delivery Protection
- Microsoft 365 PDP
- Google Workspace PDP
- URL Allow List
- APX Settings
- Request a backup
- Restore backup
- Download latest backup
- Schedule
- Firewall backup
- Direct Delivery for M365 and Google
- Installing the Sophos Outlook add-in
- About Google permissions
- Endpoint
- Threat Protection Policy
- Peripheral Control policy
- Application Control Policy
- Data Loss Prevention Policy
- Web Control Policy
- Update Management Policy
- Windows Firewall Policy
- Data Collection and Investigation policy
- Device Encryption administrator guide
- Migrate from SafeGuard Enterprise BitLocker
- Migrate from SafeGuard Enterprise Full Disk Encryption
- Device Encryption step by step
- TPM+PIN
- BitLocker group policy settings
- Limitations
- About decryption
- Recover Windows endpoints
- Migrate to Sophos Central Device Encryption (Mac)
- Device Encryption step by step (Mac)
- Add new FileVault users
- Error: Failed to store the recovery key
- Device Encryption status (Mac)
- Encryption status
- Retrieve recovery key via Self Service Portal
- Encryption Recovery Key Search
- Frequently asked questions (Windows)
- Frequently asked questions (Mac)
- Server
- Server Threat Protection Policy
- Server Peripheral Control Policy
- Server Application Control Policy
- Server Web Control Policy
- Unauthorized File Protection Policy
- Server Lockdown Policy
- Server Data Loss Prevention Policy
- Server Update Management Policy
- Server Windows Firewall Policy
- Server Data Collection and Investigation policy
- File Integrity Monitoring Policy
- Server Linux Runtime Detection Policy
- Wireless
- Wireless Dashboard
- Devices
- Diagnostics
- Events
- Syslog
- System logs
- Support settings
- AP6 usage insight
- Access points
- Access point details
- Reset an AP6 or APX series access point
- Troubleshooting access points
- SSIDs
- Settings
- SSID advanced settings
- Create a hotspot
- Customize hotspot
- Mesh networks
- Create a mesh network
- FAQ
- Troubleshooting mesh networks
- Create a site
- Create a floorplan
- Neighborhood networks
- DNS Protection
- Logs & Reports
- Locations
- Add a location
- Configure Sophos Firewall to use DNS Protection
- Configure a third-party firewall to use DNS Protection
- Configure Windows Server to use DNS Protection
- Configure Windows devices to use DNS Protection
- Configure Windows devices to use DNS Protection with Secure DNS
- Configure Mac devices to use DNS Protection
- Configure Mac devices to use DNS Protection with Secure DNS
- Install the root certificate on Windows devices
- Install the root certificate on Mac devices
- Filtering policies
- Add a filtering policy
- Configure Endpoint policy
- Domain lists
- Troubleshooting
- Protected Browser
- Set up Protected Browser
- Set up users and directories
- Give Self Service Portal access
- Install Protected Browser
- Install Protected Browser on Windows devices
- Install Protected Browser on Mac devices
- Bulk install Protected Browser using Microsoft Intune
- Bulk install Protected Browser on Mac devices using Jamf Pro
- Logs & Reports
- Query Protected Browser data using Live Discover
- Policies
- Configure a policy
- Add a device posture
- Troubleshooting
- Email Security
- Sophos EMS (Email Monitoring System)
- Set up Sophos EMS
- Configure Google journaling manually
- Set up Sophos Mailflow
- Rules and connectors created in M365
- Microsoft 365 email groups
- Fix conflicts with Microsoft 365 rules
- Troubleshoot SPF failures
- Reverse Microsoft 365 changes
- Sophos Mailflow Tamper
- Set up Sophos Gateway
- Inbound email for Microsoft 365
- Outbound email for Microsoft 365
- Inbound email for Google Workspace
- Outbound email for Google Workspace
- Inbound email for Zoho Mail
- Inbound email for Exchange and all other clients
- Outbound email for Exchange and other clients
- Email domain information
- Mailboxes
- Add a mailbox manually
- Delete mailboxes
- Aliases
- Distribution list owners
- M365 Quarantine
- DMARC Manager
- Email Security policy
- Authentication checks
- Message Authentication
- How Message Authentication works
- Sequence of Message Authentication
- Sender check
- End-user message settings
- Anti-malware
- Anti-spam
- Quarantine Summary Settings
- New domain/sender
- NRD Protection
- New Sender Protection
- Country of origin
- Language detection
- Impersonation protection
- URL and QR code protection
- End User Quarantine
- Outbound Disclaimer
- Data Control policy
- Add rule
- Rule type
- Financial information
- Confidential information
- Health information
- Personally identifiable information
- Attachment file types
- Content control lists
- Message attributes
- Keywords
- External senders or recipients
- Actions
- Email headers
- Sophos blocked email attachments
- Calculating email attachment file sizes
- Secure Message policy
- Secure message methods
- Using TLS connections
- Email reports
- Email Management API
- Delete Sophos Email Security domains
- Firewall Management
- Set up a new firewall with Sophos Fusion
- Enable Sophos Fusion management of Sophos Firewall
- Dashboard
- Virtual firewall trial
- Report Generator
- Firewalls
- Firewall information
- Firewall groups
- Upgrade firmware for firewalls
- Transfer firewall licenses between Sophos Fusion accounts
- Add firewalls
- Add a firewall with Zero Touch
- Add a firewall with Zero Touch using a USB stick
- Zero Touch FAQ
- Manage an HA pair in Sophos Fusion
- Turn on firewall reporting
- Firewall reporting storage by firewall model
- Suspended firewalls
- Firewall reports
- Firewall reporting FAQs
- AWS Auto Scaling
- Configure AWS Auto Scaling
- Create API credentials
- Deploy the CloudFormation template
- Create a dynamic interface object
- Create a WAF rule
- Upgrade your firewalls
- SD-WAN Connection Groups
- Add IP address pools
- Create an SD-WAN connection group
- Manage an SD-WAN connection group
- SD-WAN profiles
- Tasks Queue
- Dynamic objects
- Phish Threat
- User Behavior report
- Create a campaign
- Auto-enrollment
- Create a campaign series
- NDR
- NDR Dashboard
- Investigation Console
- Dashboard
- User Management
- System Details
- NDR troubleshooting
- MDR dashboard
- MDR monthly reports
- MDR threat hunting report
- Security posture report - Sophos MDR
- MDR threat response
- What MDR Operations team can do
- Install Sophos agent on Windows or macOS
- Install Sophos agent on Linux
- MDR Service Tiers
- MDR
- MDR Plus
- MDR Ops team response
- Identify malware types
- TrickBot or Emotet remediation
- Get help from the MDR Operations team
- Get help from Product Support
- ITDR
- Identity Overview
- Risk Posture Score
- Dark Web Intelligence
- Directory
- Identity Details
- ITDR integration guide
- ITDR frequently asked questions
- Sophos Managed Risk
- Managed Risk internal scans
- Managed Risk credentials
- Test Managed Risk credentials
- Allow regional IP ranges for external vulnerability scans
- Switches
- Switches
- Switch management
- VLANs
- Port settings
- Discovery
- SNMP
- Task queue
- Diagnostics
- Site management
- Stack management
- Restore a reset or replaced switch
- Set up Zero Trust Network Access
- Requirements
- Get a certificate
- Set up directory service
- Sync users in Sophos Fusion
- Set up an identity provider
- Set up an on-premises gateway
- Set up a Sophos Cloud gateway
- Add your DNS settings
- Install the ZTNA agent
- Add resources
- Requirements
- Assign resources
- Add guest users
- Add guest users in bulk
- Configure a Remote Desktop Services farm with a ZTNA agent
- Set up ZTNA
- Install the ZTNA agent
- Control access to SaaS apps
- Use agentless and agent-based ZTNA in the office
- Troubleshooting
- Reports
- Gateways
- Identity Providers
- About MDR and XDR integrations
- Get started
- Allow Sophos IPs
- Provide your domain and IP details
- Products
- Sophos integrations
- Sophos NDR
- Generate NDR detections from the command-line interface
- Sophos NDR on ESXi or Hyper-V
- Sophos NDR on AWS
- Sophos NDR on Nutanix
- Sophos NDR on Dell hardware
- Sophos NDR on NUC hardware
- Sophos NDR on OnLogic hardware
- Sophos Cloud Optix
- Sophos Email
- Sophos Firewall
- Acronis integration
- Integrate Acronis Cyber Protect
- AppOmni integration
- Integrate AppOmni
- Armis integration
- Integrate Armis
- Aryaka integration overview
- Integrate Aryaka
- Auth0 integration overview
- Integrate Auth0 (API)
- AWS integration
- AWS CloudTrail
- Integrate an existing AWS CloudTrail
- AWS CloudTrail integration script
- AWS Security Hub
- Barracuda CloudGen integration
- Integrate Barracuda CloudGen
- CylanceOPTICS
- Broadcom - Symantec Endpoint Security
- Check Point Quantum Firewall integration
- Integrate Check Point Quantum Firewall
- Cisco integrations
- Cisco Duo integration
- Integrate Cisco Duo
- Integrate Cisco Firepower
- Integrate Cisco ISE
- Cisco Meraki API integration
- Integrate Cisco Meraki (API)
- Cisco Meraki integration (log collector)
- Integrate Cisco Meraki (Log collector)
- Integrate Cisco Umbrella
- CrowdStrike Falcon integration
- Integrate CrowdStrike Falcon
- Overview of the Darktrace DETECT integration
- Integrate Darktrace DETECT
- F5 BIG-IP ASM integration
- Integrate F5
- Forcepoint integration
- Integrate Forcepoint
- Fortinet integrations
- Fortinet FortiAnalyzer integration
- Integrate Fortinet FortiAnalyzer (API)
- Overview of the FortiAnalyzer integration (Log collector)
- Integrate Fortinet FortiAnalyzer (Log collector)
- Fortinet Fortigate integration
- Integrate Fortinet FortiGate
- Google Cloud Platform integration
- Google Workspace integration
- Integrate Google Workspace
- Jamf Protect integration
- Integrate Jamf Protect
- ManageEngine ADAudit Plus integration overview
- Integrate ManageEngine ADAudit Plus
- Microsoft 365 integrations
- Microsoft 365 Management Activity
- Microsoft 365 Response Actions
- Microsoft Graph security API (Legacy)
- Microsoft Graph security API V2 integration
- Integrate MS Graph security API V2
- Microsoft Azure integration
- Mimecast integration
- Integrate Mimecast 1.0
- Integrate Mimecast 2.0
- Okta integration overview
- Integrate Okta
- Create Okta credentials
- Orca Security integration overview
- Integrate Orca Security
- Integrate Ordr
- Palo Alto PAN-OS integration
- Integrate Palo Alto PAN-OS
- Proofpoint Targeted Attack Protection integration overview
- Integrate Proofpoint Targeted Attack Protection
- Rubrik integration
- Integrate Rubrik
- Secutec integration overview
- Integrate Secutec SecureDNS
- SentinelOne Singularity Endpoint integration
- Integrate SentinelOne Singularity Endpoint
- SonicWall SonicOS integration
- Integrate SonicWall SonicOS
- Thinkst Canary integration overview
- Integrate Thinkst Canary
- Trend Micro integrations
- Trend Micro Cloud App Security integration
- Integrate Trend Micro Cloud App Security
- Trend Micro Email Security integration
- Integrate Trend Micro Email Security
- Trend Micro Vision One integration
- Integrate Trend Micro Vision One
- Ubiquiti UniFi integration
- Integrate Ubiquiti UniFi
- Vectra AI integration
- Integrate Vectra AI
- Veeam Backup & Replication integration
- Integrate Veeam Backup & Replication
- WatchGuard Firebox integration
- Integrate WatchGuard Firebox
- Zscaler ZIA integration
- Integrate Zscaler ZIA
- Add integrations on AWS
- Appliance requirements
- Appliance hardening
- Deploy appliances
- Manage appliances
- Appliance logs
- Remote assistance for appliances
- Integration health alerts
- Telemetry journey
- Integrations detection pipeline
- Integration licenses
- Integrations for multiple sub-estates
- Troubleshooting integrations
- AI assistant
- Use "Ask AI" options
- AI features FAQs