Changes
These are the new and changed help pages in this release.
New pages
- Sophos Fusion MFA Requirements
- Set up a browser-based authenticator
- Sample Submission
- License management
- Activate your license
- License expiration reminders
- Product licenses
- Endpoint licenses
- Endpoint license expiration
- Endpoint license usage and calculation FAQs
- Sophos Mobile licenses
- Firewall licenses
- Manage your firewall licenses
- Firewall license details
- Firewall reporting licenses
- Sophos Firewall OS (SFOS) licensing model
- Claim a firewall
- Claim an RMA firewall
- Transfer subscriptions between firewalls
- Download and apply an airgap license
- Frequently asked questions
- Migrate Sophos UTM licenses to Sophos Firewall
- Apply a Sophos Firewall license to an SG series UTM appliance
- Apply a virtual Sophos UTM license to a virtual Sophos Firewall
- Firewall license expiration
- Getting started with firewall licenses
- Activating firewall license keys FAQ
- Firewall license renewals, upgrades, and replacements
- Email licenses
- Email license usage calculation
- Email trial license
- Email license expiration and exceedance
- Phish Threat licenses
- AP6 series access point licenses
- AP6 support and services licensing
- Sophos Switch licenses
- Sophos Switch support and services licensing
- DNS Protection licenses
- Frequently asked questions (FAQs)
- Encryption licenses
- Encryption license expiration
- Workspace Protection licenses
- Frequently asked questions (FAQs)
- Free Trials
- Trial license banners
- AI Defense
- AI Defense setup
- AI Defense dashboard
- AI Defense activity
- AI Defense inventory
- AI Defense detections
- AI Defense reports
- AI Defense policies
- Health check alerts
- Restart required alerts
- Network Map
- Message Details
- Details
- Raw Header
- Attachments
- URLs
- Platform
- Notifications
- Configure email alerts
- Firewall Alerts Configurator
- User Activity Verification
- Directory service
- Set up synchronization with Active Directory
- Filter inactive AD users
- Active Directory synchronization FAQ
- Active Directory synchronization installation FAQ
- Device group discovery FAQ
- Purge synchronized Active Directory data
- Set up synchronization with Microsoft Entra ID
- Set up an Azure Application
- Filter users and groups
- Change Microsoft Entra ID source configuration
- Purge synchronized Microsoft Entra ID data
- Delete a Microsoft Entra ID directory source
- Migrate to Microsoft Entra ID
- Set up synchronization with Google Directory
- Disable service account key creation policy in Google Cloud
- Add another domain from the same Google account
- Troubleshoot Google Directory synchronization
- Filter users and groups
- Purge synchronized Google Directory data
- Delete a Google Directory source
- Disconnect a Google directory source from your Sophos Email
- Verify domains
- Device migration
- Early Access Program
- Co-branding
- Access Control
- Admins and Roles
- Add administrators
- Remove administrators
- Administration roles
- Compare administration roles
- Administration roles for Sophos XDR
- View a role's details
- Add a custom role
- Delete custom role
- Change roles for administrators
- Role management FAQs
- Sign-in and Identity
- Federated identity providers
- Multi-factor Authentication
- Sophos sign-in settings
- Set up Federated sign-in
- Verify a federated domain
- Use Microsoft Entra ID as an identity provider
- Use OpenID Connect as an identity provider
- Use Microsoft AD FS as an identity provider
- User access
- Send users an access email for Sophos Fusion Self Service Portal
- Add the identity provider (Entra ID/Open IDC/ADFS)
- Configure Microsoft Entra ID to allow users to sign in using UPN
- Sign-in options
- API Credentials
- Third-party access via APIs
- API Token Management
- Integration Credential Manager
- Protection and Remediation
- Allow and Block
- Global Exclusions
- Using exclusions safely
- Windows scanning exclusions
- macOS scanning exclusions
- Linux scanning exclusions
- Process exclusions (Windows)
- Website exclusions
- Exploit Mitigation and Activity Monitoring exclusions
- Detected exploits exclusions
- Ransomware Protection exclusions
- Exploit mitigation or ransomware wildcards and variables
- Files
- Allowed applications
- Blocked items
- Network
- Active Threat Response
- Admin Isolated Devices
- Block compromised IP addresses
- Inbound Allow/Block
- Import and export allow/block list
- What happens when you allow an address or domain?
- Web Settings
- Web filtering profiles
- Website Management
- SSL/TLS decryption of HTTPS websites
- Data Loss Prevention
- Data Loss Prevention Rules
- Create a Data Loss Prevention Rule
- Configure a Data Loss Prevention Rule
- Content Control Lists
- Create Custom Content Control List
- Synchronized Security
- Linux Runtime Detection Profiles
- Create a Linux Runtime Detection profile
- Advanced Linux Runtime Detection Profile configuration
- Products and Services
- Endpoint and Server
- Event Journals
- Bandwidth Usage
- Manage Update Caches and Message Relays
- Software packages
- Software packages FAQ
- Content updates FAQ
- Removal of inactive devices
- Tamper Protection
- Turn off Tamper Protection
- Proxy configuration
- Forensic snapshots
- Upload forensic snapshots to an AWS S3 bucket
- Mobile
- Protected Browser enforcement
- Set up browser enforcement using Entra ID
- Set up browser enforcement using Okta
- ZTNA Settings
- Gateway Domains
- DKIM keys
- Bounce Address Tag Validation (BATV)
- M365 Mailflow Domains
- Business Email Compromise
- Account compromise
- Impersonation protection and VIP management
- Add Internal VIPs
- Add External VIPs
- Import and export VIPs
- Delete VIPs
- Custom SMTP Routing
- Encryption
- Encryption Outlook Add-in
- Custom Branding
- Administration portal
- Message recall
- User Settings
- New Sender Settings
- S/MIME
- S/MIME email encryption setup
- Time-of-Click Block and Warn Pages
- Post-Delivery Protection
- Microsoft 365 PDP
- Google Workspace PDP
- URL Allow List
- APX Settings
- Request a backup
- Restore backup
- Download latest backup
- Schedule
- Firewall backup
- Sophos Phish Threat
- Campaign Reminders
- Training Sender Configuration
- Bounced mailboxes
- Sending domains and IPs
- Direct Delivery for M365 and Google
- Installing the Sophos Outlook add-in
- Reporting a message
- About Google permissions
- Endpoint DNS Protection policy
- Encryption Recovery Key Search
- Unauthorized File Protection Policy
- RADIUS Servers
- Configure Entra ID for AP6 authentication
- Active Threat Response
- Query wireless data using Live Discover
- Configure Windows devices to use DNS Protection with Secure DNS
- Configure Mac devices to use DNS Protection with Secure DNS
- Filtering policies
- Add a filtering policy
- Endpoint policies
- About Endpoint policy
- Configure Endpoint policy
- Protected Browser
- Dashboard
- Set up Protected Browser
- Set up users and directories
- Give Self Service Portal access
- Install Protected Browser
- Invite users to install Protected Browser
- Install Protected Browser on Windows devices
- Install Protected Browser on Mac devices
- Bulk install Protected Browser using Microsoft Intune
- Bulk install Protected Browser on Mac devices using Jamf Pro
- Protected Browser version
- Install the Protected Browser extension
- Install the extension on Mac devices manually
- Install the extension on Windows devices manually
- Bulk install the extension using Google Enterprise Core
- Bulk install the extension using Microsoft Intune
- Bulk install the extension using Jamf Pro
- Bulk install the extension using Active Directory GPO
- Integrate ZTNA and DNS Protection with Protected Browser
- Integrate DNS Protection with Protected Browser
- Integrate ZTNA with Protected Browser
- ZTNA and Protected Browser use cases
- Access RDP agentlessly via Protected Browser
- Access SSH agentlessly via Protected Browser
- Logs & Reports
- Query Protected Browser data using Live Discover
- Web policy
- Base policy
- Policies
- Configure a policy
- Policy objects
- Add a device posture
- Add an application group
- Add a site list
- Add a web category
- Troubleshooting
- How-to articles
- Safe AI use cases
- Block Generative AI apps in Protected Browser
- Block Generative AI apps in all browsers
- Allow authorized Generative AI apps with restrictions
- Allow specific actions in authorized Generative AI apps
- Prevent data leaks from SaaS apps
- Configure M365 journaling automatically
- Inbound email for Zoho Mail
- Outbound email for Zoho Mail
- Quarantined Messages
- View quarantined message details
- Search quarantined messages
- Manage quarantined messages
- Quarantined message reports
- M365 Quarantine
- Policies
- Email Security policy
- Message Authentication
- Sequence of Message Authentication
- Sender check
- End-user message settings
- Anti-malware
- Anti-spam
- Quarantine Summary Settings
- New domain/sender
- NRD Protection
- New Sender Protection
- Country of origin
- Language detection
- Impersonation protection
- URL and QR code protection
- End User Quarantine
- Outbound Disclaimer
- Data Control policy
- Add rule
- Rule type
- Financial information
- Confidential information
- Health information
- Personally identifiable information
- Attachment file types
- Content control lists
- Message attributes
- Keywords
- External senders or recipients
- Actions
- Email headers
- Calculating email attachment file sizes
- Secure Message policy
- Secure message methods
- Access your firewall's web admin console
- Backup and Recovery M365
- MDR Dashboard
- MDR Threat Hunting Dashboard
- Security posture report - Sophos MDR
- Cases in Sophos MDR
- MDR policies
- MDR Customer Penetration Testing Expectations Policy
- Sophos MDR Supported Response Actions
- Identity Risk Score
- Managed Risk critical assets
- Backup
- Active Threat Response
- Query switch data using Live Discover
- Zero Trust Network Access
- Set up Zero Trust Network Access
- Network configuration
- Requirements
- Get a certificate
- Set up directory service
- Sync users in Sophos Fusion
- Set up an identity provider
- Add a gateway
- Set up an on-premises gateway
- Set up a Sophos Cloud gateway
- Add your DNS settings
- Add policies
- Install the ZTNA agent
- Add resources
- How users access apps
- DNS flows
- ZTNA use cases
- ZTNA for guest users
- Using Microsoft Entra (Azure) B2B integration
- Requirements
- Create user groups
- Assign resources
- Add guest users
- Add guest users in bulk
- Configure a Remote Desktop Services farm with a ZTNA agent
- ZTNA and Windows Hello
- Requirements
- Set up ZTNA
- Set up Windows Hello
- Join Windows devices to Azure
- Install the ZTNA agent
- Access apps
- Control access to SaaS apps
- Use ZTNA in the office
- Use agentless and agent-based ZTNA in the office
- Troubleshooting
- Detector Explorer
- Detector types
- Account Compromise
- Brute Force
- Business Email Compromise
- Cloud Recon to Change
- Cloud Watchlist
- Domain Generation Algorithms
- Domain Watchlist
- Email Watchlist
- Hands on Keyboard
- Impossible Travel
- IP Watchlist
- Kerberoasting
- Network IDS
- Password Spray
- Penetration Test
- Portscanning and Broadscanning
- Punycode
- Quick Mail Consent (MS O365)
- Rare Program to Rare IP
- SharpHound
- Stolen User Credentials
- Suspicious DNS Activity
- Tactic Graphs™
- Taegis Watchlist
- Entity Graph
- Customization Rules FAQ
- Split and merge cases
- Automatic cases
- Templates
- CyberChef
- Transitioning to Advanced Search query language
- Saved queries
- Search history
- Schema Library
- Live Endpoint Search
- Edit or create queries
- Create query categories
- Limits on use of queries
- Quick Search
- Threat Intelligence Explorer
- Threat groups
- Threat reports
- Enrichments
- Automations Overview
- Playbooks overview
- Configured playbooks
- Playbook executions
- Playbook templates
- Playbook template versions
- Playbook schedules
- Connectors overview
- Configured connections
- Connector Library
- Connector versions
- Connector credential storage and access
- On-Premise Automation Connector
- Common Expression Language (CEL) overview
- Get started with CEL
- CEL examples
- Common supported CEL macros
- About Sophos XDR integrations
- Marketplace quick start
- Allow Sophos IPs
- Products
- Sophos
- Sophos Email
- Sophos Firewall
- Sophos NDR
- Sophos NDR on VMs
- Sophos NDR on AWS
- Sophos NDR on ESXi
- Sophos NDR on Hyper-V
- Sophos NDR on Nutanix
- Sophos NDR VM appliance size guide
- Sophos NDR on hardware
- Sophos NDR on Dell
- Sophos NDR on NUC
- Sophos NDR on OnLogic
- Sophos NDR hardware appliance size guide
- Integration appliances
- Appliance requirements
- Add appliances
- Manage appliances
- Appliance logs
- Remote assistance for appliances
- Appliance hardening
- Abnormal Inbound Email Security
- Integrate Abnormal Inbound Email Security
- Acronis Cyber Protect
- Integrate Acronis Cyber Protect
- Akamai
- Akamai App & API Protector
- Integrate Akamai App & API Protector
- Akamai Enterprise Application Access
- Integrate Akamai EAA
- Akamai Guardicore Segmentation
- Integrate Akamai Guardicore Segmentation
- Aruba ClearPass
- Integrate Aruba ClearPass
- Aryaka
- Integrate Aryaka
- Auth0
- Integrate Auth0
- Amazon Web Services (AWS)
- AWS ALB logs
- Integrate AWS ALB logs
- AWS CloudTrail
- Integrate AWS CloudTrail
- AWS CloudWatch Logs
- Integrate AWS CloudWatch Logs
- Amazon GuardDuty
- Integrate Amazon GuardDuty
- AWS VPC Flow Logs
- Integrate AWS VPC Flow Logs
- AWS WAF logs
- Integrate AWS WAF logs
- Barracuda
- Barracuda CloudGen
- Integrate Barracuda CloudGen
- Barracuda WAF
- Integrate Barracuda WAF
- BlackBerry CylanceOPTICS
- Integrate BlackBerry CylanceOPTICS
- Box
- Integrate Box
- Broadcom
- Symantec (Blue Coat) ProxySG
- Integrate Symantec ProxySG
- Broadcom Symantec Endpoint Security
- Integrate Broadcom Symantec Endpoint Security
- Broadcom (VMware) vCenter
- Integrate vCenter
- Cato Networks SASE
- Integrate Cato Networks
- Check Point
- Check Point Harmony Email Security
- Integrate Check Point Harmony Email Security
- Check Point Quantum Firewall
- Integrate Check Point Quantum Firewall
- Cisco
- Cisco ASA
- Integrate Cisco ASA
- Cisco Duo
- Integrate Cisco Duo
- Cisco FTD
- Integrate Cisco FTD
- Cisco IOS and NX-OS
- Integrate Cisco IOS and NX-OS
- Cisco Ironport
- Integrate Cisco IronPort
- Cisco ISE
- Integrate Cisco ISE
- Cisco Meraki (API)
- Integrate Cisco Meraki (API)
- Cisco Meraki (syslog)
- Integrate Cisco Meraki (syslog)
- Cisco Umbrella
- Integrate Cisco Umbrella
- Troubleshoot API data volume limits
- Claroty Continuous Threat Detection
- Integrate Claroty CTD
- Cloudflare SSE
- Integrate Cloudflare SSE
- Corelight NDR
- Integrate Corelight NDR
- CrowdStrike Falcon
- Integrate CrowdStrike Falcon
- CyberArk Privileged Threat Analytics
- Integrate CyberArk PTA
- Darktrace DETECT
- Integrate Darktrace DETECT
- Dragos Platform
- Integrate Dragos Platform
- F5 BIG-IP LTM
- Integrate F5 BIG-IP LTM
- Forcepoint
- Forcepoint Next-Generation Firewall
- Integrate Forcepoint NG Firewall
- Forcepoint Web Security
- Integrate Forcepoint Web Security
- Fortinet
- Fortinet FortiAnalyzer (API)
- Integrate Fortinet FortiAnalyzer integration (API)
- Fortinet FortiAnalyzer (syslog)
- Integrate Fortinet FortiAnalyzer (syslog)
- Fortinet FortiGate
- Integrate Fortinet FortiGate
- Fortinet FortiWeb
- Integrate Fortinet FortiWeb
- Google Cloud Platform (GCP)
- Integrate Google Cloud Platform
- Google Workspace
- Integrate Google Workspace
- Imperva
- Imperva Cloud WAF
- Integrate Imperva Cloud WAF
- Imperva WAF Gateway
- Integrate Imperva WAF Gateway
- Infoblox DNS
- Integrate Infoblox DNS
- Ivanti Connect Secure
- Integrate Ivanti Connect Secure
- Jamf
- Integrate Jamf Protect
- Juniper SRX Firewall
- Integrate Juniper SRX
- Linux servers
- Integrate Linux servers
- ManageEngine ADAudit Plus
- Integrate ManageEngine ADAudit Plus
- McAfee ePO
- Integrate McAfee ePO
- Microsoft
- Microsoft 365 and Azure data availability
- Microsoft 365
- Microsoft Graph security API alerts v2
- Integrate MS Graph security API alerts v2
- Microsoft 365 Management Activity API
- Integrate Microsoft 365 Management Activity API
- Enable Microsoft 365 response actions
- Microsoft Azure
- Microsoft Azure Activity Logs
- Integrate Microsoft Azure Activity Logs
- Microsoft Azure Application Gateway
- Integrate Azure Application Gateway
- Microsoft Azure Firewall
- Integrate Azure Firewall
- Microsoft Azure Front Door
- Integrate Azure Front Door
- Microsoft Azure Network Watcher
- Integrate Azure Network Watcher
- Microsoft Defender XDR
- Integrate Microsoft Defender XDR
- Manage Microsoft Defender XDR
- Microsoft Entra
- Microsoft Entra Activity Reports
- Integrate Microsoft Entra Activity Reports
- Microsoft Entra Risk Detection
- Integrate Microsoft Entra Identity Risk Detection
- Microsoft DHCP
- Integrate Microsoft DHCP servers
- Microsoft DNS
- Integrate Microsoft DNS servers
- Microsoft IIS
- Integrate Microsoft IIS
- Microsoft Windows Event Log
- Integrate Microsoft Windows Event Log
- Mimecast API v2
- Integrate Mimecast API v2
- NetScaler ADC
- Integrate NetScaler ADC
- Netskope SSE
- Integrate Netskope SSE
- Nozomi Guardian
- Integrate Nozomi Guardian
- Okta
- Integrate Okta
- OPNsense
- Integrate OPNsense
- Oracle Cloud Infrastructure (OCI)
- Integrate OCI
- Orca Security
- Integrate Orca Security
- Palo Alto
- Palo Alto PAN-OS
- Integrate Palo Alto PAN-OS
- Palo Alto Prisma Access
- Integrate Palo Alto Prisma Access
- pfSense
- Integrate pfSense
- Proofpoint TAP
- Integrate Proofpoint TAP
- Rubrik
- Integrate Rubrik
- Salesforce Real-Time Event Monitoring
- Integrate Salesforce Real-Time Event Monitoring
- Secutec
- Integrate Secutec SecureDNS
- SentinelOne Singularity Endpoint
- Integrate SentinelOne Singularity
- SonicWall SonicOS
- Integrate SonicWall SonicOS
- Suricata
- Integrate Suricata
- Thinkst Canary
- Integrate Thinkst Canary
- Trend Micro
- Trend Micro Deep Security
- Integrate Trend Micro Deep Security
- Trend Micro Vision One
- Integrate Trend Micro Vision One
- Ubiquiti UniFi
- Integrate Ubiquiti UniFi
- Veeam Backup & Replication
- Integrate Veeam Backup & Replication
- WatchGuard Firebox
- Integrate WatchGuard Firebox
- Zscaler ZIA
- Integrate Zscaler ZIA
- Actions
- Configuring actions
- Using actions
- Data collectors
- AWS data collector
- Azure data collector
- GCP data collector
- On-premises data collector
- Manage data collectors
- Maintenance windows for data collectors
- Troubleshooting data collectors
- Migrating from log collectors to XDR data collectors
- Custom integrations
- Microsoft Azure custom integrations
- Microsoft Azure Event Hubs
- Integrate via Microsoft Azure Event Hubs
- Microsoft Azure Storage Account
- Integrate Azure Storage Account
- HTTP Ingest
- Integrate via HTTP Ingest
- Amazon S3 custom integrations
- S3 Ingest - Customer-managed
- Integrate via customer-managed S3
- S3 Ingest - Sophos-Managed (with token)
- Integrate via Sophos-managed S3 (with token)
- S3 Ingest - Sophos-Managed (without token)
- Integrate via Sophos-managed S3 (without token)
- Configured integrations
- Configured data sources
- Integration health alerts
- Custom parsers overview
- Create custom parsers
- Manage custom parsers
- Custom parser syntax
- Add data to repeating fields
- Overriding and extending global parsers
- Supported schemas for custom parsers
- Antivirus schema
- API Call schema
- Authentication schema
- Cloud Audit schema
- DHCP schema
- DNS schema
- Email schema
- Encrypt schema
- File Modification schema
- HTTP schema
- Management Event schema
- Netflow schema
- NIDS schema
- Process schema
- Registry schema
- Third Party Alerts schema
- Utilities
- Data Exports
- CEL Explorer
- AI Expression Assistant
- Sophos Next-Gen SIEM overview
- Save AI prompts
- Use the AI workbench
- Pin AI responses
- Use "Ask AI" options
- Give feedback
- Sophos Support Assistant
Changed pages
- Getting started
- Create an account
- Activate your account and get software
- Onboarding guides
- Sophos Email onboarding
- Sophos MDR onboarding
- Install software
- Manage devices in Sophos Fusion
- Set up policies
- Automate adding users and devices
- Sophos Fusion's new look
- Sophos Help
- Manage your account
- About authentication
- Set up a passkey
- Set up an authenticator app
- Sign in to Sophos Fusion with a passkey or authenticator app
- Manage authentication methods
- Reset MFA
- Troubleshooting
- Account details
- Create an Enterprise Admin
- Supported Web Browsers
- Languages
- Licensing guide
- Renewals and license expiry
- Mobile license FAQs
- XG to XGS license transition
- High availability licensing
- Firewall license FAQs
- Phish Threat FAQs
- Free trial FAQs
- Unsupported Sophos products
- People and devices
- Users & Groups
- Users
- User Summary
- User Devices
- Import users from a CSV file
- Protect existing users
- Delete users
- Installers
- Endpoint
- Installer command-line options for Mac
- Installing Endpoint using Jamf Pro
- Security permissions on macOS
- Check security permissions on macOS
- Server
- Sophos Protection for Linux
- Create a Linux gold image
- Installer command-line options for Linux
- Sophos Protection for Linux troubleshooting
- Firewall Protection
- Domains and ports to allow
- Installer command-line options for Windows
- Create gold images and clone new devices
- Devices
- Computers and servers
- Computers
- Computer Summary
- Computer Events
- Computer Status
- Computer Policies
- Mobile devices
- Device details
- Properties
- Servers
- Server Summary
- Server Events
- Server Status
- Server Exclusions
- Server Applications
- Server Lockdown Events
- Server Policies
- Deleted and expired devices
- How to find out a file's SHA-256 hash
- Manage your products
- Dashboards
- Fusion Overview dashboard
- Create or edit a dashboard
- Manage dashboards
- Widgets for dashboards
- Policies
- About Policies
- Account Health Check
- Health check scores
- Health check reports
- Fix Endpoint agent mode
- Fix Server agent mode
- Fix endpoint or server tamper protection
- Fix global tamper protection
- Fix MDR authorized contact
- Fix automatic firewall backups
- Alerts
- Alerts for Threat Protection
- Alerts for Device Encryption
- Alerts for installation and compliance
- Firewall alerts
- Deal with ransomware
- Deal with PUAs
- Resolve PUA alerts
- Deal with malware detected by deep learning
- Stop detecting an exploit
- Stop detecting ransomware
- Deal with IPS alerts
- EDR and XDR
- Logs and Reports
- Logs
- Events
- Malware and PUA events types
- Network access event types
- Management event types
- User behavior event types
- Device encryption event types
- Malicious behavior types
- Audit Logs
- Data Loss Prevention Events Log
- Message History
- Processed report
- Message Categories
- Rejected report
- Reports
- Overview of your Sophos protection
- Computer Report
- Server Report
- Restore deleted devices and recover Tamper Protection passwords
- Attack Details
- Message Summary Report
- SophosLabs Analysis Report
- Intelix Threat Summary Report
- Time of Click Summary Report
- At Risk Users Report
- Data Control Summary Report
- Post-Delivery Summary Report
- License Usage Summary Report
- Global Settings
- Configure an identity provider
- Device isolation exclusions
- Malicious Network Traffic Prevention (IPS) (Windows) exclusions
- Set up an advanced expression
- MDR setup
- Managed Risk setup
- Convert forensic snapshots
- Identity Settings
- Data Lake uploads
- Cloud Optix
- Add VIPs
- Recognized certificate authorities
- Sophos Outlook add-in
- Upgrading the Outlook add-in
- Endpoint
- Threat Protection Policy
- Peripheral Control policy
- Application Control Policy
- Data Loss Prevention Policy
- Web Control Policy
- Update Management Policy
- Windows Firewall Policy
- Data Collection and Investigation policy
- Device Encryption administrator guide
- Migrate from SafeGuard Enterprise BitLocker
- Migrate from SafeGuard Enterprise Full Disk Encryption
- Device Encryption step by step
- TPM+PIN
- BitLocker group policy settings
- Limitations
- About decryption
- Recover Windows endpoints
- Migrate to Sophos Central Device Encryption (Mac)
- Device Encryption step by step (Mac)
- Add new FileVault users
- Recover Mac endpoints
- Unlock APFS volumes with Terminal commands
- Error: Failed to store the recovery key
- Device Encryption status (Mac)
- Encryption status
- Retrieve recovery key via Self Service Portal
- Frequently asked questions (Windows)
- Frequently asked questions (Mac)
- Server
- Server Threat Protection Policy
- Server Peripheral Control Policy
- Server Web Control Policy
- Server Lockdown Policy
- Server Data Loss Prevention Policy
- Server Update Management Policy
- Server Windows Firewall Policy
- Server Data Collection and Investigation policy
- Server Linux Runtime Detection Policy
- Wireless
- Wireless Dashboard
- Devices
- Usage insight
- Diagnostics
- Events
- Syslog
- System logs
- Support settings
- AP6 usage insight
- Access points
- Access point details
- Reset an AP6 or APX series access point
- Troubleshooting access points
- SSIDs
- Settings
- SSID advanced settings
- Create a hotspot
- Customize hotspot
- Create a voucher
- Mesh networks
- Create a mesh network
- FAQ
- Troubleshooting mesh networks
- Create a site
- Create a floorplan
- Neighborhood networks
- DNS Protection
- Dashboard
- Logs & Reports
- Locations
- Add a location
- Set up your network
- Configure Sophos Firewall to use DNS Protection
- Configure a third-party firewall to use DNS Protection
- Configure Windows Server to use DNS Protection
- Configure Windows devices to use DNS Protection
- Configure Mac devices to use DNS Protection
- Install the root certificate on Windows devices
- Install the root certificate on Mac devices
- Policies
- Domain lists
- Troubleshooting
- Email Security
- Sophos EMS (Email Monitoring System)
- Supported EMS features
- Set up Sophos EMS
- Configure Google journaling manually
- Set up Sophos Mailflow
- Rules and connectors created in M365
- Microsoft 365 email groups
- Prevent duplicate scans
- Fix conflicts with Microsoft 365 rules
- Troubleshoot Sophos Mailflow
- Troubleshoot SPF failures
- Reverse Microsoft 365 changes
- Sophos Mailflow Tamper
- Set up Sophos Gateway
- Integrate with external services
- Inbound email for Microsoft 365
- Outbound email for Microsoft 365
- Inbound email for Google Workspace
- Outbound email for Google Workspace
- Inbound email for Exchange and all other clients
- Outbound email for Exchange and other clients
- Disconnect email domain from Sophos Gateway
- Email Security Dashboard
- Email domain information
- Mailboxes
- Add mailboxes
- Add a mailbox manually
- Import mailboxes
- Delete mailboxes
- Email sending limits and privileges
- Aliases
- Distribution list owners
- DMARC Manager
- Configure DMARC Reporting
- DMARC Manager summary
- DMARC Manager portal
- Authentication checks
- How Message Authentication works
- Sophos blocked email attachments
- Using TLS connections
- Email reports
- Email Management API
- Delete Sophos Email Security domains
- Firewall Management
- Set up a new firewall with Sophos Fusion
- Enable Sophos Fusion management of Sophos Firewall
- Dashboard
- Virtual firewall trial
- Report Hub
- Report Generator
- Firewalls
- Firewall information
- Firewall groups
- Upgrade firmware for firewalls
- Transfer firewall licenses between Sophos Fusion accounts
- Add firewalls
- Add a firewall with Zero Touch
- Add a firewall with Zero Touch using a USB stick
- Zero Touch FAQ
- Manage an HA pair in Sophos Fusion
- Turn on firewall reporting
- Firewall reporting storage by firewall model
- Suspended firewalls
- Firewall reports
- Firewall reporting FAQs
- AWS Auto Scaling
- Configure AWS Auto Scaling
- Create API credentials
- Deploy the CloudFormation template
- Create a dynamic interface object
- Create a WAF rule
- Upgrade your firewalls
- SD-WAN Connection Groups
- Add IP address pools
- Create an SD-WAN connection group
- Manage an SD-WAN connection group
- SD-WAN profiles
- Tasks Queue
- Dynamic objects
- Phish Threat
- Set up Phish Threat for M365 environments
- Set up Phish Threat with Google Workspace
- User Behavior report
- Campaigns
- Create a campaign
- Campaign type
- Training
- Customize
- Auto-enrollment
- Create a campaign series
- Review & Schedule
- Campaign results
- NDR
- NDR Dashboard
- NDR Appliances
- Investigation Console
- Dashboard
- User Management
- System Details
- NDR troubleshooting
- MDR
- Classic MDR Dashboard
- MDR notifications
- MDR reports
- MDR weekly reports
- MDR monthly reports
- MDR threat hunting report
- MDR telemetry settings
- MDR threat response
- What MDR Operations team can do
- Install Sophos agent on Windows or macOS
- Install Sophos agent on Linux
- MDR Service Tiers
- MDR
- MDR Plus
- MDR investigations
- Handle active incidents
- MDR Ops team response
- Identify malware types
- TrickBot or Emotet remediation
- Malicious LNK worm remediation
- Get help from the MDR Operations team
- Get help from Product Support
- ITDR
- Identity Overview
- Risk Posture Score
- Findings
- Dark Web Intelligence
- Directory
- Identity Details
- ITDR integration guide
- ITDR frequently asked questions
- Sophos Managed Risk
- Managed Risk internal scans
- Managed Risk credentials
- Test Managed Risk credentials
- Managed Risk report history
- Allow regional IP ranges for external vulnerability scans
- Managed Risk FAQs
- Switches
- Switches
- Switch management
- VLANs
- Port settings
- Discovery
- SNMP
- Security
- Task queue
- Diagnostics
- Site management
- Stack management
- How to
- Restore a reset or replaced switch
- Zero Trust Network Access dashboard
- Reports
- Gateways
- Resources & Access
- Policies
- Identity Providers
- Mobile
- Security Operations
- Overview dashboard
- Detectors
- Endpoint Watchlists
- Detector test detections
- Detections
- Detection details
- Detection enrichment
- Events
- Event Lineage and Process Tree
- Entities
- Custom detection rules
- Detection suppression rules
- Cases
- Create and add to cases
- Work cases
- Search
- Data Lake Search
- Advanced Search query language
- Query Builder
- Schemas and logical types
- Schemas
- Automations
- Threat Analysis Center
- AI Search
- Device Exposure
- Threat Graphs
- Threat Graph analysis
- Process details
- Live Discover
- Data Lake queries
- Data Lake storage limits
- Edit or create queries
- Create query categories
- Limits on use of queries
- Set up and start Live Response
- Give admins access to Live Response
- Scheduled queries
- Cases
- Assign cases
- Detections
- Detection rules
- About MDR and XDR integrations
- Get started
- Allow Sophos IPs
- Provide your domain and IP details
- Products
- Sophos integrations
- Sophos NDR
- Generate NDR detections from the command-line interface
- Sophos NDR on ESXi or Hyper-V
- Sophos NDR on AWS
- Sophos NDR on Nutanix
- Sophos NDR on Dell hardware
- Sophos NDR on NUC hardware
- Sophos NDR on OnLogic hardware
- Sophos Cloud Optix
- Sophos Email
- Sophos Firewall
- Acronis integration
- Integrate Acronis Cyber Protect
- AppOmni integration
- Integrate AppOmni
- Armis integration
- Integrate Armis
- Aryaka integration overview
- Integrate Aryaka
- Auth0 integration overview
- Integrate Auth0 (API)
- AWS integration
- AWS CloudTrail
- Integrate an existing AWS CloudTrail
- AWS CloudTrail integration script
- AWS Security Hub
- Barracuda CloudGen integration
- Integrate Barracuda CloudGen
- CylanceOPTICS
- Broadcom - Symantec Endpoint Security
- Check Point Quantum Firewall integration
- Integrate Check Point Quantum Firewall
- Cisco integrations
- Cisco Duo integration
- Integrate Cisco Duo
- Integrate Cisco Firepower
- Integrate Cisco ISE
- Cisco Meraki API integration
- Integrate Cisco Meraki (API)
- Cisco Meraki integration (log collector)
- Integrate Cisco Meraki (Log collector)
- Integrate Cisco Umbrella
- CrowdStrike Falcon integration
- Integrate CrowdStrike Falcon
- Overview of the Darktrace DETECT integration
- Integrate Darktrace DETECT
- F5 BIG-IP ASM integration
- Integrate F5
- Forcepoint integration
- Integrate Forcepoint
- Fortinet integrations
- Fortinet FortiAnalyzer integration
- Integrate Fortinet FortiAnalyzer (API)
- Overview of the FortiAnalyzer integration (Log collector)
- Integrate Fortinet FortiAnalyzer (Log collector)
- Fortinet Fortigate integration
- Integrate Fortinet FortiGate
- Google Cloud Platform integration
- Google Workspace integration
- Integrate Google Workspace
- Jamf Protect integration
- Integrate Jamf Protect
- ManageEngine ADAudit Plus integration overview
- Integrate ManageEngine ADAudit Plus
- Microsoft 365 integrations
- Microsoft 365 Response Actions
- Microsoft Graph security API (Legacy)
- Microsoft Graph security API V2 integration
- Integrate MS Graph security API V2
- Microsoft Azure integration
- Mimecast integration
- Integrate Mimecast 2.0
- Okta integration overview
- Integrate Okta
- Create Okta credentials
- Orca Security integration overview
- Integrate Orca Security
- Integrate Ordr
- Palo Alto PAN-OS integration
- Integrate Palo Alto PAN-OS
- Proofpoint Targeted Attack Protection integration overview
- Integrate Proofpoint Targeted Attack Protection
- Rubrik integration
- Integrate Rubrik
- Secutec integration overview
- Integrate Secutec SecureDNS
- SentinelOne Singularity Endpoint integration
- Integrate SentinelOne Singularity Endpoint
- SonicWall SonicOS integration
- Integrate SonicWall SonicOS
- Thinkst Canary integration overview
- Integrate Thinkst Canary
- Trend Micro integrations
- Trend Micro Cloud App Security integration
- Integrate Trend Micro Cloud App Security
- Trend Micro Email Security integration
- Integrate Trend Micro Email Security
- Trend Micro Vision One integration
- Integrate Trend Micro Vision One
- Ubiquiti UniFi integration
- Integrate Ubiquiti UniFi
- Vectra AI integration
- Integrate Vectra AI
- Veeam Backup & Replication integration
- Integrate Veeam Backup & Replication
- WatchGuard Firebox integration
- Integrate WatchGuard Firebox
- Zscaler ZIA integration
- Integrate Zscaler ZIA
- Add integrations on AWS
- Integration appliances
- Appliance requirements
- Appliance hardening
- Deploy appliances
- Manage appliances
- Appliance logs
- Remote assistance for appliances
- Integration health alerts
- Telemetry journey
- Integrations detection pipeline
- Integration licenses
- Integration credentials
- Integrations for multiple sub-estates
- Troubleshooting integrations
- AI assistant
- Write good AI prompts
- AI features FAQs