SOP — Subscribe to and Manage Endpoint Devices with Sophos

Version 1.0
Date 2026-06-22
Tenant context mptwork.com · Sophos Central console central.sophos.com
Product Sophos Endpoint (powered by Intercept X), managed in Sophos Central
Companion SOPs Intune device management — sop-manage-devices-intune-mptwork.md · Jamf (macOS) — sop-manage-macos-jamf-mptwork.md
Scope note: Sophos Endpoint is an endpoint security product (next-gen AV, anti-ransomware, EDR/XDR) using a single agent across Windows, macOS, and Linux — plus optional Device Encryption (BitLocker/FileVault management) and Sophos Mobile (iOS/Android UEM). It is commonly run alongside Intune or Jamf, which handle OS configuration and app deployment, while Sophos provides the protection layer. This SOP covers subscribing and managing endpoint protection in Sophos Central.

0. Choose an edition

The same agent reports into Sophos Central; the tier decides how much detection and response you get. Pricing is partner-quoted (not public) and per user.

Edition What it adds
Intercept X Essentials Core next-gen AV, deep-learning malware detection, anti-ransomware (CryptoGuard), exploit prevention
Intercept X Advanced + web control, application control, peripheral/device control, DLP — full policy set
Intercept X Advanced with XDR + EDR/XDR: detections, threat hunting, host isolation, Live Discover / Live Response
Intercept X Advanced with MDR (Essentials / Complete) + 24/7 Sophos-managed SOC threat detection and response

Common add-ons: Sophos Central Device Encryption (manages BitLocker/FileVault), Sophos Mobile (iOS/Android UEM), ZTNA, and Server protection. For mptwork.com this example uses Intercept X Advanced with XDR plus Device Encryption.


Part 1 — Subscribe and set up Sophos Central

  1. Purchase / trial: obtain licenses through a Sophos partner/reseller (or start a free trial at sophos.com). You receive access to Sophos Central Admin.
  2. Create the Sophos Central account for MPT Work and sign in at https://central.sophos.com. Apply the license (license key / partner activation).
  3. Administrators & RBAC: Global Settings → Role Management — add admins with least-privilege roles (Admin, Help Desk, Read-Only); avoid sharing the super admin.
  4. Enforce MFA on all Central admin logins; optionally configure federated SSO (e.g., to Microsoft Entra) for console sign-in.
  5. Global protection settings: enable Tamper Protection (prevents users/malware from disabling the agent) and set the update management cadence.
  6. Configure alert notifications (email recipients, severity) and review the Account Health Check for posture recommendations.

Part 2 — Plan device groups and policy model

  1. Sophos Central organizes endpoints under Devices; group them for targeted policies, e.g. MPT-Windows-Staff, MPT-macOS-Staff, MPT-Servers.
  2. Policies are assigned to users or device groups and evaluated by priority. Plan a base policy for all plus exceptions for servers/special cases.
  3. Keep default-on protection as the baseline — Sophos ships strong defaults; tune only with reason.

Part 3 — Deploy the endpoint agent

  1. In Sophos Central → Protect Devices, download the installer or get an installer link/email for end users.
  2. The single agent installs on Windows, macOS, and Linux (endpoints and servers). It removes most competing AV automatically on Windows.
  3. Verify check-in: devices appear under Devices in Central within minutes, showing health = green and the assigned policies applied.

Deploy by the method that fits the fleet:

Method Use
Manual installer Ad hoc / small numbers
GPO or script AD-domain Windows estate
RMM tool MSP-managed devices
Intune / Jamf Push the Sophos agent to your already-managed fleet
Installer link/email User self-install (BYO or remote)

Part 4 — Configure protection policies

Endpoint Protection → Policies. Create/assign per group:

Policy Configure
Threat Protection Deep learning, real-time scanning, CryptoGuard (anti-ransomware), exploit mitigations, live protection — keep enabled by default
Web Control Category-based web filtering / acceptable use
Application Control Block/allow categories of apps
Peripheral (Device) Control Control USB / removable media / Bluetooth
Data Loss Prevention Rules for sensitive data on endpoints
Update Management Update schedule and software packages

Set exclusions sparingly and document them; over-broad exclusions weaken protection.


Part 5 — Device encryption (optional add-on)

  1. With Sophos Central Device Encryption, create an Encryption policy to enforce BitLocker (Windows) and FileVault (macOS).
  2. Recovery keys escrow to Sophos Central — help desk can retrieve them for users; verify keys are present before relying on them.
  3. Report on encryption status across the fleet from the Central dashboard.
If you already manage BitLocker/FileVault through Intune/Jamf, choose one system of record for encryption to avoid policy conflicts.

Part 6 — Detection and response (EDR / XDR)

With Intercept X Advanced with XDR:

  1. Review Threat Analysis Center → Detections and the MITRE ATT&CK-mapped activity.
  2. Run Live Discover queries to threat-hunt across endpoints (and other data sources in XDR).
  3. Take response actions: isolate a host from the network, terminate processes, and use Live Response for a remote command shell to investigate/remediate.
  4. Use the Threat Graph to see root cause and the full attack chain.

Part 7 — Mobile devices (optional — Sophos Mobile)

  1. With Sophos Mobile (UEM), enroll iOS/iPadOS and Android devices (work profile / supervised), and apply compliance, configuration, and app-management policies.
  2. This is a separate product from the endpoint agent — license and enroll it independently in Sophos Central. (For an existing Microsoft estate, Intune mobile management is the alternative.)

Part 8 — Monitoring, alerts, and reporting

  1. The Sophos Central dashboard shows fleet health, alerts, and the Account Health Check.
  2. Triage Alerts by severity; investigate detections in the Threat Analysis Center.
  3. Schedule/export reports (threat activity, policy compliance, encryption status) for stakeholders and audits.
  4. (Optional) forward Sophos telemetry to a SIEM (e.g., Microsoft Sentinel) via the Sophos data/API integration.

Part 9 — Managed Detection and Response (optional — Sophos MDR)

If subscribed to MDR Essentials/Complete, the Sophos SOC monitors 24/7, hunts threats, and takes response actions on your behalf. Configure your threat-response mode (Notify / Collaborate / Authorize), escalation contacts, and (Complete) confirm the incident-response lead and warranty terms.


Part 10 — Ongoing operations

Cadence Activity
Daily / continuous Triage alerts and detections; isolate/respond to active threats
Weekly Review Account Health Check; agent health/check-in gaps; exclusion review
Monthly Policy review; encryption and compliance reporting; license/seat reconciliation
Quarterly Admin/RBAC review; tamper-protection and MFA audit; test host isolation and a recovery-key retrieval
Annually Renew subscription; review edition fit (XDR/MDR) against needs

Appendix — Notes and positioning

  • Sophos protects; Intune/Jamf manage. Sophos Endpoint is the security/EDR layer (and optional encryption/mobile). OS configuration, app deployment, and enrollment are typically still handled by Intune (Windows/cross-platform) or Jamf (macOS). Many orgs deploy the Sophos agent via Intune/Jamf.
  • Single agent, multi-OS: one Intercept X agent covers Windows, macOS, and Linux endpoints and servers.
  • Pricing is partner-quoted and per user; confirm current editions and pricing with a Sophos partner.
  • Verify current steps against Sophos documentation — Sophos Central layout and feature names change periodically.

Read more

SOP — Create and Manage Microsoft Azure for Enterprise

Version 1.0 Date 2026-06-22 Domain mptwork.com Model Identity rooted in the existing Microsoft Entra tenant; hierarchy of Management Groups → Subscriptions → Resource Groups → Resources Consoles Azure portal portal.azure.com · Entra admin center entra.microsoft.com Companion SOPs M365/Entra — sop-subscribe-manage-m365-mptwork.md, sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md · AWS

By admin

SOP — Create and Manage a Google Cloud (GCP) Account

Version 1.0 Date 2026-06-22 Domain mptwork.com Model GCP Organization rooted in Cloud Identity / Google Workspace for mptwork.com; hierarchy of Folders → Projects; workforce access via Google Groups, optionally federated to Microsoft Entra Companion SOPs Google Workspace — sop-subscribe-manage-google-workspace-mptwork.md · Entra auth & SSO — sop-entra-id-authentication-sso-mptwork.md · Network/IPAM — enterprise-ipam-reference-architecture.md

By admin