Endpoint Protection

Suggest, discuss, and vote on new ideas for Sophos Endpoint Protection. Comprehensive security for users and data

Endpoint Protection

Suggest, discuss, and vote on new ideas for Sophos Endpoint Protection. Comprehensive security for users and data

  • Hot ideas
  • Top ideas
  • New ideas
  • My feedback
  1. Controlled Updates in Sophos Central-I work in an environment which needs 4 levels to deploy updates. First would be the "test" group, then

    Controlled Updates in Sophos Central-I work in an environment which needs 4 levels to deploy updates. First would be the "test" group, then Dev, QA, and finally Prod. Currently Sophos only offers one group, but Enterprise environments require/demand a greater level of control over updates. Please seriously consider expanding our ability to have a more granular control set.

    3 votes
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Updating  ·  Flag idea as inappropriate…  ·  Admin →
  2. Sophos Central Patch Assessment

    We all know patch is very important in security. It would be very helpful for us if there is a patch assessment (like on the on-premise SEC) on Sophos Central Advanced.

    It should also categorized reports based on its criticality, Critical, High, Medium, or Low like the patch assement on SEC.

    5 votes
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Next Generation Endpoint  ·  Flag idea as inappropriate…  ·  Admin →
  3. File transfer block over Anydesk remote session

    Block incoming and outgoing file transfer using anydesk application during remote session.

    7 votes
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Data Leakage Prevention (DLP)  ·  Flag idea as inappropriate…  ·  Admin →
  4. central

    I been working with sophos products in our organization for close to 10 years. and this is my conclusion. who ever is designing the consoles does not design it from network admin perspective. for example, you login to the central cloud console you see alert and then you are on your own pal. you have no option to re-install the agent on the client from the console. same for policy violations alert. you have no button to force the policy. Imagine when you are responsible for near to a 1000 machine and lets say 100 of those gave you alerts.…

    2 votes
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Cloud Console  ·  Flag idea as inappropriate…  ·  Admin →
  5. Search based on TLD

    Allow searches based on the top-level domain in Threat Search.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Incident investigation  ·  Flag idea as inappropriate…  ·  Admin →
  6. web site browsing

    Having the ability to enable / capture all user browsing activity when the need arises would be helpful in troubleshooting issues where a web site appears to be blocked but its unclear of the cause along with responding to HR requests to determine if a user is accessing sites that may not be blocked but are considered risky / not meant to be accessed as a normal course of business.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Incident investigation  ·  Flag idea as inappropriate…  ·  Admin →
  7. Policy issue on IP V6

    Hello Team,

    We are facing issues with applied application policy issue in our Sophos Intercept X and Advance. We have applied the policy for blocking the Google drive and dropbox, that was working earlier but now we are not able to do the same. As i logged the request in Sophos and found that, according to them there is some issue in IP V6 because all the machines have both versions on IP. According to them in each and every system we need to manually disable the IT V6 for blocking the drives.
    I think it is a bug, kindly…

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Web Security/Control  ·  Flag idea as inappropriate…  ·  Admin →
  8. import USB exclusion

    It would be great for the Sophos Central to have a place to import the USB information (e.g., Serial number or brand) to the exclusion list. To make the migration from other brands to Sophos more easily and customers more willing to migrate to Sophos.

    2 votes
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Device Control  ·  Flag idea as inappropriate…  ·  Admin →
  9. Display private and public IP address both

    In central console, Display private and public IP address both so that administrator can understand where endpoint client is.

    5 votes
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Cloud Console  ·  Flag idea as inappropriate…  ·  Admin →
  10. Threat Search Export

    Allow for Threat Search results to be exported as excel and/or CSV for use in a pivot table.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Incident investigation  ·  Flag idea as inappropriate…  ·  Admin →
  11. Threat Search Objects Filter

    Add the ability to filter out based on the device name or allow boolean operations for username and device name.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Incident investigation  ·  Flag idea as inappropriate…  ·  Admin →
  12. Excluding cryptoguard-detections

    Cryptoguard has detected a false positive detection of a client "attacking" a server. Fortunately it is a false positive, but there's no option to exclude the thumbprint of the client attacking a server, so Cryptoguard always recognizes this as an attack. There should be an exclusion for a client false-positively "attacking" a server.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  General Endpoint  ·  Flag idea as inappropriate…  ·  Admin →
  13. Whats About OCR in Sophos DLP

    OCR (optical character recognition) Sensitive Image Recognition provides the capability to extract text from images (scanned documents, screenshots, pictures, and so on) and from PDFs, enabling you to use new or preexisting text-based detection rules on this content.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Data Leakage Prevention (DLP)  ·  Flag idea as inappropriate…  ·  Admin →
  14. Threat Search Object Limit

    I sometimes have tens of thousands of indicators of attack and compromise to run through the threat search, but I can do only 100 at a time. Increase the object limit to 500 or allow the importing of CSV's.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Incident investigation  ·  Flag idea as inappropriate…  ·  Admin →
  15. END POINT

    Hi,

    Please Provide the device Serial Number on the Dashboard, which really helps in the industry to Track the machine Immidelty.

    Also Reporting should be Improved with Large Visibility with PIE Chart & Category radio lines

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  Flag idea as inappropriate…  ·  Admin →
  16. I am unble to get details of machines where Sophos antivirus is not installed in network.

    I want to identify the machines in my network where Sophos AV is not installed. But I do not have any reports to do this, Is it possible to fetch these Details.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  General Endpoint  ·  Flag idea as inappropriate…  ·  Admin →
  17. Name doesnt match

    Today we were investigating a system that had been getting taken over by remote control. Sophos said the system was clean and RDP wasn't being used so we were baffled. Eventually, we found that there was a copy of NeSupport Client which was digitally signed and had an original file name of client32.exe, but had been renamed to wupdsvc.exe. I think it would be a good idea for Sophos to flag files that are digitally signed, but not their original name, as suspicious when doing a scan.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  General Endpoint  ·  Flag idea as inappropriate…  ·  Admin →
  18. Endpoint: "Scan with Sophos AV..." Option vs. exclusion list in Sophos Central

    We had a strange behavior of Sophos Endpoint Protection which should be solved by changing the bahavior of the "Scan with Sophos AV" option in the context menu of windows.

    What happend:
    A user had an infected word file stored on his desktop. When using the context menu function "scan file with Sophos AV" it doesn't find anything wrong or suspicious.
    This was weird because according to Virus Total this file contained Malware which was also detected by Sophos endpoint protection.
    When checking the exclusion list on Sophos Central we found an exclusion for C:\users*. This seems to prevent the…

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  General Endpoint  ·  Flag idea as inappropriate…  ·  Admin →
  19. Show communication problems with Central on Endpoint

    Hi to all,

    when there is a communication problem between Endpoint and Central, the endpoint doesn't report any problem as long as you go under Status section.
    In my company i had the case of a Windows 10 PC not showned under Central, but with no symptoms of malfunctiong from the Endpoint side,
    This is a big problem, because i could have an endpoint infected with a malware without have an alert on Central.
    From my point of view it's necessary to show an alert every X hours on the Endpoint that report this.
    Thank you.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    0 comments  ·  General Endpoint  ·  Flag idea as inappropriate…  ·  Admin →
  20. Central Login: Prioritize the different 2nd Factor Auth options

    Please make it possible, to prioritize the different 2nd Factor Auth options. I use SMS token also as TOTP. I want to use TOTP as primary variant, but Sophos uses the SMS option every time as the first option. If i want to use TOTP, i have to manually switch the login method for this one time.
    Please implement a function, that i can prioritize the different mechanisms.

    1 vote
    Sign in Sign in with Log in with your Sophos ID
    Signed in as (Sign out)

    We’ll send you updates on this idea

    1 comment  ·  Cloud Console  ·  Flag idea as inappropriate…  ·  Admin →
  • Don't see your idea?

Feedback and Knowledge Base

icon-data-protection icon-endpoint-protection icon-phish-threat icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-central icon-sophos-mobile icon-sophos-utm icon-sophos-utm icon-sophos-utm icon-web-appliance icon-xg-firewall icon-xg-firewall icon-avid-secure icon-lightbulbCreated with Sketch.