Skip to content

Sophos MDR Supported Response Actions

1. Purpose

This document lists the response actions supported by Sophos Managed Detection and Response (MDR). It is intended to be a maintained reference identifying the actions the MDR team may perform across supported endpoint, network, identity, email, and Sophos-specific control to investigate, contain, and disrupt threats across your environment.

The applicable Sophos MDR Service Description defines response modes, authorization, and broader service terms.

2. Scope

This document covers supported MDR response actions across:

  • Endpoint
  • Network
  • Identity
  • Email

Available actions depend on your deployed technologies, integrations, and configuration.

3. Supported Response Actions

3.1 Endpoint Response Actions

Endpoint response actions vary by deployment model (Sophos Sensor, Sophos Agent, or Agentless Third-Party Endpoint integrations).

Note

  • Sophos Sensor includes Sophos detection and response capabilities, but does not include Sophos endpoint protection.
  • The Sophos Agent includes Sophos endpoint protection capabilities, enabling additional protection-linked actions not available with Sophos Sensor alone.
  • Agentless Third-Party Endpoint integrations support a subset of endpoint response actions and do not support hands-on-keyboard actions.
Action Sophos Agent Sophos Sensor Agentless Third-Party Endpoint
Isolate host
Un-isolate host
Initiate antivirus scan
Block file hash
Unblock file hash
Delete file
Terminate process
Log off user sessions
Disable user accounts
Live Response actions via remote shell / terminal access
Add malicious hash to blocked items
Enable Adaptive Attack Protection
Disable Adaptive Attack Protection
Extend Adaptive Attack Protection

✔ Supported — Not supported

3.2 Network Response Actions

Sophos MDR supports the following network response actions where available through the relevant network control points:

Note

When using Sophos Firewall, these capabilities are natively available and require only configuration to enable.

  • Block IP address
  • Unblock IP address
  • Block domain
  • Unblock domain
  • Block URL
  • Unblock URL

3.3 Identity Response Actions

Sophos MDR supports the following identity response actions where available through the relevant identity platform:

  • Disable user account
  • Enable user account
  • Force password reset
  • Require reset at next login
  • Revoke active user sessions
  • Mark user as compromised
  • Dismiss user as compromised
  • Reset multi-factor authentication (MFA) factors

3.4 Email Response Actions

Sophos MDR supports the following email response actions where available through the relevant email platform or integration:

  • Block email address
  • Unblock email address
  • Disable inbox rules
  • Enable inbox rules
  • Email clawback

Note

Email clawback is available for customers using Sophos Email and/or those who have configured Sophos Email Security Management (EMS). EMS is included with every Sophos MDR and Sophos MDR Plus subscription and requires only configuration to enable - no separate connector is needed. Refer to the EMS setup instructions to get started.

4. Document Maintenance

Sophos may update this document periodically to reflect new capabilities and enhancements. The current version is the authoritative reference for supported Sophos MDR response actions.