Skip to content

Integrate Proofpoint TAP

You can integrate Proofpoint TAP with Sophos XDR so that it sends data to Sophos for analysis.

Key steps

The key steps in a Proofpoint TAP integration are as follows:

  • Generate Proofpoint TAP service credentials.
  • Configure the integration in Sophos XDR.

Requirements

The following is required for Proofpoint TAP configuration:

  • An active Proofpoint TAP account with privileges to create service credentials.

Add a Proofpoint TAP integration

To integrate Proofpoint TAP, you must first gather certain details from Proofpoint, then provide them in Sophos XDR.

Generate Proofpoint TAP service credentials

To get the Proofpoint TAP API details you need for integration, do as follows:

  1. Sign in to the TAP dashboard. See Welcome to the TAP Dashboard.
  2. Go to Settings > Connected Applications image.
  3. Click Create New Credential.
  4. Copy the Principal ID and Secret.

    The Secret is displayed only once. If you lose it, you'll have to generate new credentials.

Next, you configure an integration in Sophos XDR.

Configure the integration in Sophos XDR

To integrate Proofpoint TAP with Sophos XDR, do as follows:

  1. In Sophos Fusion, go to Security Operations > Integrations > Marketplace.
  2. Click Proofpoint TAP.

    The Proofpoint TAP page opens. You can configure integrations here and see a list of any you've already configured.

  3. In Configured integrations, click Add new.

  4. In Add an integration, do as follows:

    1. Enter a name for the integration.
    2. Enter the Service Principal and Secret obtained from Proofpoint.
  5. Click Done.

The new integration appears under Configured integrations. If its status icon is a green tick, your data should appear in the Sophos Data Lake after validation.

Additional resources

For more information on configuring Proofpoint TAP, see the following documents: