SOP — Subscribe to and Manage Endpoint Devices with Sophos
| Version | 1.0 |
| Date | 2026-06-22 |
| Tenant context | mptwork.com · Sophos Central console central.sophos.com |
| Product | Sophos Endpoint (powered by Intercept X), managed in Sophos Central |
| Companion SOPs | Intune device management — sop-manage-devices-intune-mptwork.md · Jamf (macOS) — sop-manage-macos-jamf-mptwork.md |
Scope note: Sophos Endpoint is an endpoint security product (next-gen AV, anti-ransomware, EDR/XDR) using a single agent across Windows, macOS, and Linux — plus optional Device Encryption (BitLocker/FileVault management) and Sophos Mobile (iOS/Android UEM). It is commonly run alongside Intune or Jamf, which handle OS configuration and app deployment, while Sophos provides the protection layer. This SOP covers subscribing and managing endpoint protection in Sophos Central.
0. Choose an edition
The same agent reports into Sophos Central; the tier decides how much detection and response you get. Pricing is partner-quoted (not public) and per user.
| Edition | What it adds |
|---|---|
| Intercept X Essentials | Core next-gen AV, deep-learning malware detection, anti-ransomware (CryptoGuard), exploit prevention |
| Intercept X Advanced | + web control, application control, peripheral/device control, DLP — full policy set |
| Intercept X Advanced with XDR | + EDR/XDR: detections, threat hunting, host isolation, Live Discover / Live Response |
| Intercept X Advanced with MDR (Essentials / Complete) | + 24/7 Sophos-managed SOC threat detection and response |
Common add-ons: Sophos Central Device Encryption (manages BitLocker/FileVault), Sophos Mobile (iOS/Android UEM), ZTNA, and Server protection. For mptwork.com this example uses Intercept X Advanced with XDR plus Device Encryption.
Part 1 — Subscribe and set up Sophos Central
- Purchase / trial: obtain licenses through a Sophos partner/reseller (or start a free trial at
sophos.com). You receive access to Sophos Central Admin. - Create the Sophos Central account for MPT Work and sign in at
https://central.sophos.com. Apply the license (license key / partner activation). - Administrators & RBAC: Global Settings → Role Management — add admins with least-privilege roles (Admin, Help Desk, Read-Only); avoid sharing the super admin.
- Enforce MFA on all Central admin logins; optionally configure federated SSO (e.g., to Microsoft Entra) for console sign-in.
- Global protection settings: enable Tamper Protection (prevents users/malware from disabling the agent) and set the update management cadence.
- Configure alert notifications (email recipients, severity) and review the Account Health Check for posture recommendations.
Part 2 — Plan device groups and policy model
- Sophos Central organizes endpoints under Devices; group them for targeted policies, e.g.
MPT-Windows-Staff,MPT-macOS-Staff,MPT-Servers. - Policies are assigned to users or device groups and evaluated by priority. Plan a base policy for all plus exceptions for servers/special cases.
- Keep default-on protection as the baseline — Sophos ships strong defaults; tune only with reason.
Part 3 — Deploy the endpoint agent
- In Sophos Central → Protect Devices, download the installer or get an installer link/email for end users.
- The single agent installs on Windows, macOS, and Linux (endpoints and servers). It removes most competing AV automatically on Windows.
- Verify check-in: devices appear under Devices in Central within minutes, showing health = green and the assigned policies applied.
Deploy by the method that fits the fleet:
| Method | Use |
|---|---|
| Manual installer | Ad hoc / small numbers |
| GPO or script | AD-domain Windows estate |
| RMM tool | MSP-managed devices |
| Intune / Jamf | Push the Sophos agent to your already-managed fleet |
| Installer link/email | User self-install (BYO or remote) |
Part 4 — Configure protection policies
Endpoint Protection → Policies. Create/assign per group:
| Policy | Configure |
|---|---|
| Threat Protection | Deep learning, real-time scanning, CryptoGuard (anti-ransomware), exploit mitigations, live protection — keep enabled by default |
| Web Control | Category-based web filtering / acceptable use |
| Application Control | Block/allow categories of apps |
| Peripheral (Device) Control | Control USB / removable media / Bluetooth |
| Data Loss Prevention | Rules for sensitive data on endpoints |
| Update Management | Update schedule and software packages |
Set exclusions sparingly and document them; over-broad exclusions weaken protection.
Part 5 — Device encryption (optional add-on)
- With Sophos Central Device Encryption, create an Encryption policy to enforce BitLocker (Windows) and FileVault (macOS).
- Recovery keys escrow to Sophos Central — help desk can retrieve them for users; verify keys are present before relying on them.
- Report on encryption status across the fleet from the Central dashboard.
If you already manage BitLocker/FileVault through Intune/Jamf, choose one system of record for encryption to avoid policy conflicts.
Part 6 — Detection and response (EDR / XDR)
With Intercept X Advanced with XDR:
- Review Threat Analysis Center → Detections and the MITRE ATT&CK-mapped activity.
- Run Live Discover queries to threat-hunt across endpoints (and other data sources in XDR).
- Take response actions: isolate a host from the network, terminate processes, and use Live Response for a remote command shell to investigate/remediate.
- Use the Threat Graph to see root cause and the full attack chain.
Part 7 — Mobile devices (optional — Sophos Mobile)
- With Sophos Mobile (UEM), enroll iOS/iPadOS and Android devices (work profile / supervised), and apply compliance, configuration, and app-management policies.
- This is a separate product from the endpoint agent — license and enroll it independently in Sophos Central. (For an existing Microsoft estate, Intune mobile management is the alternative.)
Part 8 — Monitoring, alerts, and reporting
- The Sophos Central dashboard shows fleet health, alerts, and the Account Health Check.
- Triage Alerts by severity; investigate detections in the Threat Analysis Center.
- Schedule/export reports (threat activity, policy compliance, encryption status) for stakeholders and audits.
- (Optional) forward Sophos telemetry to a SIEM (e.g., Microsoft Sentinel) via the Sophos data/API integration.
Part 9 — Managed Detection and Response (optional — Sophos MDR)
If subscribed to MDR Essentials/Complete, the Sophos SOC monitors 24/7, hunts threats, and takes response actions on your behalf. Configure your threat-response mode (Notify / Collaborate / Authorize), escalation contacts, and (Complete) confirm the incident-response lead and warranty terms.
Part 10 — Ongoing operations
| Cadence | Activity |
|---|---|
| Daily / continuous | Triage alerts and detections; isolate/respond to active threats |
| Weekly | Review Account Health Check; agent health/check-in gaps; exclusion review |
| Monthly | Policy review; encryption and compliance reporting; license/seat reconciliation |
| Quarterly | Admin/RBAC review; tamper-protection and MFA audit; test host isolation and a recovery-key retrieval |
| Annually | Renew subscription; review edition fit (XDR/MDR) against needs |
Appendix — Notes and positioning
- Sophos protects; Intune/Jamf manage. Sophos Endpoint is the security/EDR layer (and optional encryption/mobile). OS configuration, app deployment, and enrollment are typically still handled by Intune (Windows/cross-platform) or Jamf (macOS). Many orgs deploy the Sophos agent via Intune/Jamf.
- Single agent, multi-OS: one Intercept X agent covers Windows, macOS, and Linux endpoints and servers.
- Pricing is partner-quoted and per user; confirm current editions and pricing with a Sophos partner.
- Verify current steps against Sophos documentation — Sophos Central layout and feature names change periodically.