Sophos MDR Supported Response Actions
1. Purpose
This document lists the response actions supported by Sophos Managed Detection and Response (MDR). It is intended to be a maintained reference identifying the actions the MDR team may perform across supported endpoint, network, identity, email, and Sophos-specific control to investigate, contain, and disrupt threats across your environment.
The applicable Sophos MDR Service Description defines response modes, authorization, and broader service terms.
2. Scope
This document covers supported MDR response actions across:
- Endpoint
- Network
- Identity
Available actions depend on your deployed technologies, integrations, and configuration.
3. Supported Response Actions
3.1 Endpoint Response Actions
Endpoint response actions vary by deployment model (Sophos Sensor, Sophos Agent, or Agentless Third-Party Endpoint integrations).
Note
- Sophos Sensor includes Sophos detection and response capabilities, but does not include Sophos endpoint protection.
- The Sophos Agent includes Sophos endpoint protection capabilities, enabling additional protection-linked actions not available with Sophos Sensor alone.
- Agentless Third-Party Endpoint integrations support a subset of endpoint response actions and do not support hands-on-keyboard actions.
| Action | Sophos Agent | Sophos Sensor | Agentless Third-Party Endpoint |
|---|---|---|---|
| Isolate host | ✔ | ✔ | ✔ |
| Un-isolate host | ✔ | ✔ | ✔ |
| Initiate antivirus scan | ✔ | ✔ | — |
| Block file hash | ✔ | ✔ | — |
| Unblock file hash | ✔ | ✔ | — |
| Delete file | ✔ | ✔ | — |
| Terminate process | ✔ | ✔ | — |
| Log off user sessions | ✔ | ✔ | — |
| Disable user accounts | ✔ | ✔ | — |
| Live Response actions via remote shell / terminal access | ✔ | ✔ | — |
| Add malicious hash to blocked items | ✔ | — | — |
| Enable Adaptive Attack Protection | ✔ | — | — |
| Disable Adaptive Attack Protection | ✔ | — | — |
| Extend Adaptive Attack Protection | ✔ | — | — |
✔ Supported — Not supported
3.2 Network Response Actions
Sophos MDR supports the following network response actions where available through the relevant network control points:
Note
When using Sophos Firewall, these capabilities are natively available and require only configuration to enable.
- Block IP address
- Unblock IP address
- Block domain
- Unblock domain
- Block URL
- Unblock URL
3.3 Identity Response Actions
Sophos MDR supports the following identity response actions where available through the relevant identity platform:
- Disable user account
- Enable user account
- Force password reset
- Require reset at next login
- Revoke active user sessions
- Mark user as compromised
- Dismiss user as compromised
- Reset multi-factor authentication (MFA) factors
3.4 Email Response Actions
Sophos MDR supports the following email response actions where available through the relevant email platform or integration:
- Block email address
- Unblock email address
- Disable inbox rules
- Enable inbox rules
- Email clawback
Note
Email clawback is available for customers using Sophos Email and/or those who have configured Sophos Email Security Management (EMS). EMS is included with every Sophos MDR and Sophos MDR Plus subscription and requires only configuration to enable - no separate connector is needed. Refer to the EMS setup instructions to get started.
4. Document Maintenance
Sophos may update this document periodically to reflect new capabilities and enhancements. The current version is the authoritative reference for supported Sophos MDR response actions.