All Policy Settings
This page is the reference for all settings supported in endpoint policies. You can search for text on this page using Ctrl+F (Cmd+F on macOS). You can also download this reference as a single file. Right-click on this link and select "Save Link As" or "Download Linked File".
This page was last modified on 23-Jun-2026. Please see the changelog for new settings, changes in behavior, and deprecations.
- Threat Protection
- Server Threat Protection
- Peripheral Control
- Server Peripheral Control
- Application Control
- Server Application Control
- Web Control
- Server Web Control
- Agent Updating
- Server Agent Updating
- Windows Firewall
- Server Windows Firewall
- Server Lockdown
- Server File Integrity Monitoring
- Device Encryption
- Server Linux Runtime Detection
- Data Collection and Investigation
- Server Data Collection and Investigation
- Endpoint DNS Protection
Settings for Threat Protection policies¶
Threat Protection policies have the policy type threat-protection. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.threat-protection.block-active-adversary-mitigation.enabled | Adaptive active adversary mitigation. If disabled, active adversary behaviours are reported in Detections for XDR customers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.action-on-ransomeware-detection | Action to take on ransomware detection. | String | "terminate" | "terminate", "isolate" | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.amsi-registration-protection.enabled | Prevent removal of AMSI registration. Note: This setting applies to computers running the latest version of Sophos Intercept X. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.enabled | Protect document files from ransomware (CryptoGuard). | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.side-loading-protection.enabled | Prevent side loading of insecure modules. Note: This setting only applies to endpoints you add to the New Endpoint Protection and EDR Features EAP. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.browser-cookie-protection.enabled | Protect browser cookies used for MFA sign-in. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.c2-interceptor.enabled | Prevent malicious beacons connecting to command-and-control servers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exclusions.scanning | Scanning exclusions. All items must be unique. | Array of objects | ||||||||
| with schema scanningExclusion | [] | | | | | `` | No | No | ||||
endpoint.threat-protection.exploit-mitigation.application-protection.enabled | Mitigate exploits in vulnerable applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.apc-violation-protection.enabled | Prevent APC violation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.code-cave-mitigation.enabled | Prevent code cave utilization. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.credential-theft-protection.enabled | Prevent credential theft. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.registry-credential-theft-protection.enabled | Prevent registry credential theft. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.dll-hijacking-protection.enabled | Prevent DLLs loading from untrusted folders. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.privilege-escalation-protection.enabled | Prevent privilege escalation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.access-token-protection.enabled | Prevent access token manipulation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.ultra-exclude.enabled | Turn off exploit mitigation hooks. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.process-hollowing-protection.enabled | Prevent process hollowing attacks. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.dynamic-shellcode-protection.enabled | Dynamic shellcode protection. Note: This setting applies to computers running the latest version of Sophos Intercept X. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.efs-protection.enabled | Protect from Encrypting File System attacks. Note: This setting applies to computers running the latest version of Sophos Intercept X. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.smb-protection.enabled | Protect from remotely run ransomware (only available on 64-bit systems). | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.safe-browsing.enabled | Protect critical function in web browsers (Safe Browsing). | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.sys-call.enabled | Prevent malicious use of syscall instructions. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.hardware-breakpoint-guard.enabled | Enable Hardware Breakpoint Guard. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.mbr-protection.enabled | Protect from master boot record ransomware. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.java-applications.enabled | Protect Java applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.media-applications.enabled | Protect media applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.office-applications.enabled | Protect office applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.enabled | Protect processes. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.web-browser-plugins.enabled | Protect web browser plugins. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.web-browsers.enabled | Protect web browsers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.device-io-control.enabled | Monitor use of driver APIs. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.all-mitigations.enabled | Turn on anti-ransomware protection and all exploit mitigations. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.ctf-protocol-caller-validation.enabled | Enable CTF Protocol Caller Validation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.heartbeat-protection.enabled | Enable heartbeat protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.self-isolation.enabled | Allow computers to isolate themselves on red health. Note: If a computer has red health, it will isolate itself from the network. It will still communicate with Sophos Central. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.connection-tracking.enabled | Track network connections. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.c2-detection.enabled | Detect malicious connections to command-and-control servers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exclusions.isolation | Endpoint isolation exclusions. All items must be unique. | Array of objects | ||||||||
| with schema isolationExclusion | [] | | | | | `` | No | No | ||||
endpoint.threat-protection.network-protection.ips.enabled | Prevent malicious network traffic with packet inspection - EAP devices only. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.ips.all.enabled | Prevent malicious network traffic with packet inspection - Intrusion Prevention System (IPS). | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.enabled | Protect network traffic. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.cleanup.enabled | Automatically clean up malware. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.email-protection.attachment-file-types-blocking.enabled | Block email attachment file types that are commonly associated with malware. | Boolean | false | true, false | | | | | No | Yes | ||
endpoint.threat-protection.malware-protection.amsi-protection.enabled | Enable AMSI protection with enhanced scan for script-based threats. Note: This setting applies to computers running the latest version of Core Agent. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.behavioral-detection.enabled | Detect malicious behavior. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.web-filtering.enabled | Block access to malicious websites. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.deep-learning.detection-level | Set deep learning detection level. | String | "default" | "conservative", "default" | | | | | No | Yes | ||
endpoint.threat-protection.malware-protection.desktop-messaging.enabled | Enable desktop messaging for Threat Protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.desktop-messaging.message | Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. | String | "" | | | | | `` | No | No | ||
endpoint.threat-protection.malware-protection.exclude-remote-files | Exclude remote files from scans. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.file-reputation.action | Action to take on low-reputation downloads. | String | "prompt" | "prompt", "log" | | | | | No | No | ||
endpoint.threat-protection.malware-protection.file-reputation.enabled | Detect low-reputation files. Note: Requires Live Protection to be enabled. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.file-reputation.reputation-level | Acceptable file reputation level. | String | "recommended" | "strict", "recommended" | | | | | No | No | ||
endpoint.threat-protection.malware-protection.live-protection.enabled | Use Live Protection to check the latest threat information from SophosLabs online. Note: The feature "Protect network traffic" won't work if you turn off Live Protection. The data may leave your geographic region and be shared with Sophos engineers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.deep-learning.enabled | Enable deep learning. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.hips-detection.enabled | Detect malicious behaviour (HIPS). Note: We are phasing out this feature and replacing it with Behavioral Detection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.on-access.enabled | Enable real-time scanning. Note: If you disable real-time scanning, application control won't work and detection of malicious behavior will be disabled. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.web-scanning.enabled | Scan downloads in progress. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.skip-trusted-installers | Skip trusted installers. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.days | Scheduled scan days of the week. (Sunday: 0, Monday: 1, ..., Saturday: 6). | Array of integers | [6] | | | `` | day | day | No | No | |
endpoint.threat-protection.malware-protection.scheduled-scan.enabled | Enable scheduled scan. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.scan-all-files.enabled | Allow schedule scan to scan all files. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.deep-scanning.enabled | Enable deep scanning - scans inside archive files (.zip, .cab, etc.). | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.time | Scheduled scan time. | String | "00:00" | | `hourMinute` | `hourMinute` | | `` | No | No | |||
endpoint.threat-protection.exclusions.intrusion-prevention | Intrusion prevention exclusions. All items must be unique. | Array of objects | ||||||||
| with schema intrusionPreventionExclusion | [] | | | | | `` | No | No | ||||
endpoint.threat-protection.threat-analysis.threat-case-creation.enabled | Enable Threat Graph creation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.process-memory-background-scan.enabled | Enable background process memory scanning. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.journal-hashing.exclude-remote-files.enabled | Exclude remote files from journal hashing. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.web-control.tls-decryption.enabled | Decrypt HTTPS websites using SSL/TLS. If enabled it also turns on HTTPS decryption for Web Control. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.web-control.tls-decryption.quic.enabled | Block QUIC (Quick UDP Internet Connections) network protocol access to websites. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.event-logging.enabled | Turn on event logging. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-safeboot-usage.enabled | Behavior rule to block the configuration change to boot the machine in Safe Mode, using techniques available to remote users. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.protect-in-safeboot.enabled | Whether the endpoint enforces additional protection when booted into safeboot. All other existing policy will apply. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.block-vulnerable-drivers.enabled | Behavior rule to block the use of any known vulnerable driver that could be abused to disable Sophos endpoint protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-security-tool-drivers.enabled | Behavior rule to block the use of any known security tool driver that could be abused to disable Sophos endpoint protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.monitor-domain-controller.enabled | Monitor domain controller events. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.event-journal-writes.enabled | Turn on event journal. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-remote-attacker-communication.enabled | Block endpoint communicating with remote attacker IPs. | Boolean | true | true, false | | | | | No | No |
Settings for Server Threat Protection policies¶
Server Threat Protection policies have the policy type server-threat-protection. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.threat-protection.automatic-exclusions.enabled | Automatically exclude activity by known applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-active-adversary-mitigation.enabled | Adaptive active adversary mitigation. If disabled, active adversary behaviours are reported in Detections for XDR customers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.action-on-ransomeware-detection | Action to take on ransomware detection. | String | "terminate" | "terminate", "isolate" | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.amsi-registration-protection.enabled | Prevent removal of AMSI registration. Note: This setting applies to computers running the latest version of Sophos Intercept X. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.enabled | Protect document files from ransomware (CryptoGuard). | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.side-loading-protection.enabled | Prevent side loading of insecure modules. Note: This setting only applies to endpoints you add to the New Endpoint Protection and EDR Features EAP. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.browser-cookie-protection.enabled | Protect browser cookies used for MFA sign-in. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.c2-interceptor.enabled | Prevent malicious beacons connecting to command-and-control servers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exclusions.scanning | Scanning exclusions. All items must be unique. | Array of objects | ||||||||
| with schema scanningExclusion | [] | | | | | `` | No | No | ||||
endpoint.threat-protection.exploit-mitigation.application-protection.enabled | Mitigate exploits in vulnerable applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.apc-violation-protection.enabled | Prevent APC violation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.code-cave-mitigation.enabled | Prevent code cave utilization. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.credential-theft-protection.enabled | Prevent credential theft. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.registry-credential-theft-protection.enabled | Prevent registry credential theft. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.dll-hijacking-protection.enabled | Prevent DLLs loading from untrusted folders. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.privilege-escalation-protection.enabled | Prevent privilege escalation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.access-token-protection.enabled | Prevent access token manipulation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.ultra-exclude.enabled | Turn off exploit mitigation hooks. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.process-hollowing-protection.enabled | Prevent process hollowing attacks. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.dynamic-shellcode-protection.enabled | Dynamic shellcode protection. Note: This setting applies to computers running the latest version of Sophos Intercept X. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.efs-protection.enabled | Protect from Encrypting File System attacks. Note: This setting applies to computers running the latest version of Sophos Intercept X. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.cryptoguard.smb-protection.enabled | Protect from remotely run ransomware (only available on 64-bit systems). | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.safe-browsing.enabled | Protect critical function in web browsers (Safe Browsing). | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.sys-call.enabled | Prevent malicious use of syscall instructions. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.hardware-breakpoint-guard.enabled | Enable Hardware Breakpoint Guard. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.mbr-protection.enabled | Protect from master boot record ransomware. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.java-applications.enabled | Protect Java applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.media-applications.enabled | Protect media applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.office-applications.enabled | Protect office applications. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.process-protection.enabled | Protect processes. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.web-browser-plugins.enabled | Protect web browser plugins. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.application-protection.web-browsers.enabled | Protect web browsers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.device-io-control.enabled | Monitor use of driver APIs. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.all-mitigations.enabled | Turn on anti-ransomware protection and all exploit mitigations. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exploit-mitigation.ctf-protocol-caller-validation.enabled | Enable CTF Protocol Caller Validation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.heartbeat-protection.enabled | Enable Sophos Security Heartbeat. This sends server "health" reports to Sophos XG Firewalls that are registered with your Sophos Central account. If more than one Firewall is registered, reports go to the nearest one available. If a report shows that a server might have been compromised, the Firewall can restrict its network access. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.self-isolation.enabled | Allow computers to isolate themselves on red health. Note: If a computer has red health, it will isolate itself from the network. It will still communicate with Sophos Central. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.connection-tracking.enabled | Track network connections. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.c2-detection.enabled | Detect malicious connections to command-and-control servers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.exclusions.isolation | Endpoint isolation exclusions. All items must be unique. | Array of objects | ||||||||
| with schema isolationExclusion | [] | | | | | `` | No | No | ||||
endpoint.threat-protection.network-protection.ips.all.enabled | Prevent malicious network traffic with packet inspection - Intrusion Prevention System (IPS). | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.network-protection.enabled | Protect network traffic. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.cleanup.enabled | Automatically clean up malware. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.email-protection.attachment-file-types-blocking.enabled | Block email attachment file types that are commonly associated with malware. | Boolean | false | true, false | | | | | No | Yes | ||
endpoint.threat-protection.malware-protection.amsi-protection.enabled | Enable AMSI protection with enhanced scan for script-based threats. Note: This setting applies to computers running the latest version of Core Agent. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.behavioral-detection.enabled | Detect malicious behavior. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.web-filtering.enabled | Block access to malicious websites. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.deep-learning.detection-level | Set deep learning detection level. | String | "default" | "conservative", "default" | | | | | No | Yes | ||
endpoint.threat-protection.malware-protection.desktop-messaging.enabled | Enable desktop messaging for Threat Protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.desktop-messaging.message | Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. | String | "" | | | | | `` | No | No | ||
endpoint.threat-protection.malware-protection.exclude-remote-files | Exclude remote files from scans. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.file-reputation.action | Action to take on low-reputation downloads. | String | "prompt" | "prompt", "log" | | | | | No | No | ||
endpoint.threat-protection.malware-protection.file-reputation.enabled | Detect low-reputation files. Note: Requires Live Protection to be enabled. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.file-reputation.reputation-level | Acceptable file reputation level. | String | "recommended" | "strict", "recommended" | | | | | No | No | ||
endpoint.threat-protection.malware-protection.live-protection.enabled | Use Live Protection to check the latest threat information from SophosLabs online. Note: The feature "Protect network traffic" won't work if you turn off Live Protection. The data may leave your geographic region and be shared with Sophos engineers. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.deep-learning.enabled | Enable deep learning. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.hips-detection.enabled | Detect malicious behaviour (HIPS). Note: We are phasing out this feature and replacing it with Behavioral Detection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.on-access.enabled | Enable real-time scanning. Note: If you disable real-time scanning, application control won't work and detection of malicious behavior will be disabled. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.on-access.scan-on-read.enabled | Scan on read enabled. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.on-access.scan-sspl.enabled | Scan SSPL enabled. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.on-access.scan-sspl.process-termination.enabled | End malicious processes associated with a real-time threat detection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.on-access.scan-on-write.enabled | Scan on write enabled. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.web-scanning.enabled | Scan downloads in progress. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.skip-trusted-installers | Skip trusted installers. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.days | Scheduled scan days of the week. (Sunday: 0, Monday: 1, ..., Saturday: 6). | Array of integers | [6] | | | `` | day | day | No | No | |
endpoint.threat-protection.malware-protection.scheduled-scan.enabled | Enable scheduled scan. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.deep-scanning.enabled | Enable deep scanning - scans inside archive files (.zip, .cab, etc.). | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.malware-protection.scheduled-scan.time | Scheduled scan time. | String | "00:00" | | `hourMinute` | `hourMinute` | | `` | No | No | |||
endpoint.threat-protection.exclusions.intrusion-prevention | Intrusion prevention exclusions. All items must be unique. | Array of objects | ||||||||
| with schema intrusionPreventionExclusion | [] | | | | | `` | No | No | ||||
endpoint.threat-protection.threat-analysis.threat-case-creation.enabled | Enable Threat Graph creation. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.process-memory-background-scan.enabled | Enable background process memory scanning. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.journal-hashing.exclude-remote-files.enabled | Exclude remote files from journal hashing. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.linux-runtime-detections.enabled | Enable Linux runtime detections. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.linux-runtime-response-actions.enabled | Enable Linux runtime response actions. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.linux-agent-quarantine.enabled | Enable Linux agent quarantine. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.web-control.tls-decryption.enabled | Decrypt HTTPS websites using SSL/TLS. If enabled it also turns on HTTPS decryption for Web Control. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.web-control.tls-decryption.quic.enabled | Block QUIC (Quick UDP Internet Connections) network protocol access to websites. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.event-logging.enabled | Turn on event logging. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-safeboot-usage.enabled | Behavior rule to block the configuration change to boot the machine in Safe Mode, using techniques available to remote users. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.protect-in-safeboot.enabled | Whether the endpoint enforces additional protection when booted into safeboot. All other existing policy will apply. | Boolean | false | true, false | | | | | No | No | ||
endpoint.threat-protection.block-vulnerable-drivers.enabled | Behavior rule to block the use of any known vulnerable driver that could be abused to disable Sophos endpoint protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-security-tool-drivers.enabled | Behavior rule to block the use of any known security tool driver that could be abused to disable Sophos endpoint protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.monitor-domain-controller.enabled | Monitor domain controller events. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.event-journal-writes.enabled | Turn on event journal. | Boolean | true | true, false | | | | | No | No | ||
endpoint.threat-protection.block-remote-attacker-communication.enabled | Block endpoint communicating with remote attacker IPs. | Boolean | true | true, false | | | | | No | No |
Settings for Peripheral Control policies¶
Peripheral Control policies have the policy type peripheral-control. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.peripheral-control.actions.bluetooth | Action to take on bluetooth devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.actions.camera | Action to take on camera devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.desktop-messaging.enabled | Enable desktop messaging for Peripheral Control. | Boolean | true | true, false | | | | | No | No | ||
endpoint.peripheral-control.desktop-messaging.message | Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. | String | "" | | | | | `` | No | No | ||
endpoint.peripheral-control.enabled | Control access by peripheral type. | Boolean | false | true, false | | | | | No | No | ||
endpoint.peripheral-control.actions.secure-removable-storage | Action to take on secure removable storage devices. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.exemptions | Manage peripheral exemptions, allowing or blocking specific peripherals. All items must be unique. Exemptions cannot be stricter than the settings for individual peripheral types. | Array of objects | ||||||||
| with schema peripheralControlExemption | [] | | | | | `` | No | No | ||||
endpoint.peripheral-control.actions.floppy-drive | Action to take on floppy drives. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.actions.infra-red | Action to take on infra-red devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.actions.modem | Action to take on modems. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.monitor | Monitor but do not block (all peripherals will be allowed). | Boolean | false | true, false | | | | | No | No | ||
endpoint.peripheral-control.actions.mtp-ptp | Action to take on MTP/PTP devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.actions.optical-drive | Action to take on optical drives. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.actions.removable-storage | Action to take on removable storage devices. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.actions.wireless | Action to take on wireless devices. | String | "allowed" | "allowed", "blocked", "blockBridged" | | | | | No | No |
Settings for Server Peripheral Control policies¶
Server Peripheral Control policies have the policy type server-peripheral-control. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.peripheral-control.actions.bluetooth | Action to take on bluetooth devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.actions.camera | Action to take on camera devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.desktop-messaging.enabled | Enable desktop messaging for Peripheral Control. | Boolean | true | true, false | | | | | No | No | ||
endpoint.peripheral-control.desktop-messaging.message | Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. | String | "" | | | | | `` | No | No | ||
endpoint.peripheral-control.enabled | Control access by peripheral type. | Boolean | false | true, false | | | | | No | No | ||
endpoint.peripheral-control.actions.secure-removable-storage | Action to take on secure removable storage devices. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.exemptions | Manage peripheral exemptions, allowing or blocking specific peripherals. All items must be unique. Exemptions cannot be stricter than the settings for individual peripheral types. | Array of objects | ||||||||
| with schema peripheralControlExemption | [] | | | | | `` | No | No | ||||
endpoint.peripheral-control.actions.floppy-drive | Action to take on floppy drives. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.actions.infra-red | Action to take on infra-red devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.actions.modem | Action to take on modems. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.monitor | Monitor but do not block (all peripherals will be allowed). | Boolean | false | true, false | | | | | No | No | ||
endpoint.peripheral-control.actions.mtp-ptp | Action to take on MTP/PTP devices. | String | "allowed" | "allowed", "blocked" | | | | | No | No | ||
endpoint.peripheral-control.actions.optical-drive | Action to take on optical drives. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.actions.removable-storage | Action to take on removable storage devices. | String | "allowed" | "allowed", "blocked", "readOnly" | | | | | No | No | ||
endpoint.peripheral-control.actions.wireless | Action to take on wireless devices. | String | "allowed" | "allowed", "blocked", "blockBridged" | | | | | No | No |
Settings for Application Control policies¶
Application Control policies have the policy type application-control. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.application-control.allowed-applications | Allow specific applications by name when the application category is controlled. | Array of strings | [] | | | | | `` | No | No | ||
endpoint.application-control.controlled-categories | Controlled application categories. New applications added by Sophos to these application categories will be automatically controlled. | Array of integers | [] | | | | | `` | No | No | ||
endpoint.application-control.controlled-applications | Names of applications to control. | Array of strings | [] | | | | | `` | No | No | ||
endpoint.application-control.desktop-messaging.enabled | Enable desktop messaging for Application Control. | Boolean | true | true, false | | | | | No | No | ||
endpoint.application-control.desktop-messaging.message | Configure a message to be added to the end of the standard notification. | String | "" | | | | | `` | No | No | ||
endpoint.application-control.detection.on-demand.enabled | Detect controlled applications during scheduled and on-demand scans. | Boolean | false | true, false | | | | | No | No | ||
endpoint.application-control.detection.on-access.enabled | Detect controlled applications when users access them. (You will be notified). | Boolean | false | true, false | | | | | No | No | ||
endpoint.application-control.detection.on-access.monitor | Allow/block the detected application. | Boolean | true | true, false | | | | | No | No |
Settings for Server Application Control policies¶
Server Application Control policies have the policy type server-application-control. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.application-control.allowed-applications | Allow specific applications by name when the application category is controlled. | Array of strings | [] | | | | | `` | No | No | ||
endpoint.application-control.controlled-categories | Controlled application categories. New applications added by Sophos to these application categories will be automatically controlled. | Array of integers | [] | | | | | `` | No | No | ||
endpoint.application-control.controlled-applications | Names of applications to control. | Array of strings | [] | | | | | `` | No | No | ||
endpoint.application-control.desktop-messaging.enabled | Enable desktop messaging for Application Control. | Boolean | true | true, false | | | | | No | No | ||
endpoint.application-control.desktop-messaging.message | Configure a message to be added to the end of the standard notification. | String | "" | | | | | `` | No | No | ||
endpoint.application-control.detection.on-demand.enabled | Detect controlled applications during scheduled and on-demand scans. | Boolean | false | true, false | | | | | No | No | ||
endpoint.application-control.detection.on-access.enabled | Detect controlled applications when users access them. (You will be notified). | Boolean | false | true, false | | | | | No | No | ||
endpoint.application-control.detection.on-access.monitor | Allow/block the detected application. | Boolean | true | true, false | | | | | No | No |
Settings for Web Control policies¶
Web Control policies have the policy type web-control. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.web-control.web-profile.enabled | Determines whether the policy configures web control via web profiles or legacy settings. Note: When enabled, web profile settings take precedence over any legacy settings. | Boolean | true | true, false | | | | | No | No | ||
endpoint.web-control.filter-by-web-profile.enabled | Determines if filtering by web profile is enabled. | Boolean | false | true, false | | | | | No | No | ||
endpoint.web-control.web-profile-id | ID of the web profile (UUID format). | String | "" | | | | | `` | No | No | ||
endpoint.web-control.web-profile-log-web-events.enabled | Log web control events. | Boolean | true | true, false | | | | | No | No | ||
endpoint.web-control.web-profile-schedules | Days of the week and hours of the day when the specified web profiles should be in effect. All items must be unique. | Array of objects | ||||||||
| with schema webControlWebProfilesSchedule | [] | | | | | `` | No | No | ||||
endpoint.web-control.categories.0.action | Action to take on an uncategorized website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.1.action | Action to take on an adult/sexually explicit website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.10.action | Action to take on a downloads website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.11.action | Action to take on an educational website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.12.action | Action to take on an entertainment website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.13.action | Action to take on a fashion & beauty website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.14.action | Action to take on a finance & investment website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.15.action | Action to take on a food & dining website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.16.action | Action to take on a gambling website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.17.action | Action to take on a games website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.18.action | Action to take on a government website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.19.action | Action to take on a hacking website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.2.action | Action to take on an advertisements & pop-ups related website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.20.action | Action to take on a health & medicine website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.21.action | Action to take on a hobbies & recreation website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.22.action | Action to take on a hosting site's website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.23.action | Action to take on an illegal drugs website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.24.action | Action to take on an infrastructure website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.25.action | Action to take on an intimate apparel & swimwear website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.26.action | Action to take on an intolerance & hate website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.27.action | Action to take on a job search & career development website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.28.action | Action to take on a kids' website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.29.action | Action to take on a motor vehicles website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.3.action | Action to take on an alcohol & tobacco website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.30.action | Action to take on a news website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.31.action | Action to take on a peer-to-peer website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.32.action | Action to take on a personals and dating website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.33.action | Action to take on a philanthropic & professional orgs. website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.35.action | Action to take on a photo searches website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.36.action | Action to take on a politics website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.37.action | Action to take on a proxies & translators website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.38.action | Action to take on a real-estate website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.39.action | Action to take on a reference website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.4.action | Action to take on an arts website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.40.action | Action to take on a religion website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.41.action | Action to take on a ringtones/mobile phone downloads website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.42.action | Action to take on a search engine website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.43.action | Action to take on a sex education website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.44.action | Action to take on a shopping website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.45.action | Action to take on a society & culture website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.47.action | Action to take on a sports website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.49.action | Action to take on a streaming media website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.5.action | Action to take on a blogs & forums website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.50.action | Action to take on a tasteless & offensive website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.51.action | Action to take on a travel website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.52.action | Action to take on a violence website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.53.action | Action to take on a weapons website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.54.action | Action to take on a web-based e-mail website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.6.action | Action to take on a business website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.7.action | Action to take on a chat website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.8.action | Action to take on a computing & internet related website. | String | "allow" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.categories.9.action | Action to take on a criminal activity related website. | String | "block" | "allow", "block", "warn", "inherit" | | | | | No | No | ||
endpoint.web-control.filetypes.archive-jar.action | Action to take on Java Archive (jar) files. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.doc-pdf.action | Action to take on Adobe PDF (pdf) files. | String | "allow" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-com.action | Action to take on DOS Command File (com) files. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-dll.action | Action to take on Windows Library File (dll) files. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-exe.action | Action to take on Windows Executable (exe) files. | String | "warn" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-javabytecode.action | Action to take on Java Applet (class) files. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-msi.action | Action to take on Windows Installer (msi) files. | String | "warn" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-ocx.action | Action to take on ActiveX Controls (ocx) files. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.exe-unknown.action | Action to take on unknown executables. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.filetypes.video-flv.action | Action to takeo n Adobe Flash Video (flv, swf) files. | String | "allow" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.schedule.enabled | Apply this web control policy at set times only. | Boolean | false | true, false | | | | | No | No | ||
endpoint.web-control.schedule.active-periods | Days of the week and hours of the day when this policy should be in effect. All items must be unique. | Array of objects | ||||||||
| with schema webControlSchedule | [] | | | | | `` | No | No | ||||
endpoint.web-control.tags.settings | Actions to take for sites matching tags. All items must be unique. | Array of objects | ||||||||
| with schema webControlLocalSiteTagAction | [] | | | | | `` | No | No | ||||
endpoint.web-control.web-filtering.enabled | Control access to potentially inappropriate websites. | Boolean | true | true, false | | | | | No | No | ||
endpoint.web-control.web-monitoring.enabled | Log web control events. If set to "no", only attempts to visit infected sites will be logged. Otherwise, all attempts to visit blocked sites along with warnings and proceeding through warnings will be logged and visible in reports. | String | "yes" | "yes", "no", "inherit" | | | | | No | No |
Settings for Server Web Control policies¶
Server Web Control policies have the policy type server-web-control. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.web-control.web-profile.enabled | Determines whether the policy configures web control via web profiles or legacy settings. Note: When enabled, web profile settings take precedence over any legacy settings. | Boolean | true | true, false | | | | | No | No | ||
endpoint.web-control.filter-by-web-profile.enabled | Determines if filtering by web profile is enabled. | Boolean | false | true, false | | | | | No | No | ||
endpoint.web-control.web-profile-id | ID of the web profile (UUID format). | String | "" | | | | | `` | No | No | ||
endpoint.web-control.web-profile-log-web-events.enabled | Log web control events. | Boolean | true | true, false | | | | | No | No | ||
endpoint.web-control.web-profile-schedules | Days of the week and hours of the day when the specified web profiles should be in effect. All items must be unique. | Array of objects | ||||||||
| with schema webControlWebProfilesSchedule | [] | | | | | `` | No | No | ||||
endpoint.web-control.categories.1.action | Action to take on an adult/sexually explicit website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.16.action | Action to take on a gambling website. | String | "allow" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.19.action | Action to take on a hacking website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.2.action | Action to take on an advertisements & pop-ups related website. | String | "allow" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.23.action | Action to take on an illegal drugs website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.26.action | Action to take on an intolerance & hate website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.3.action | Action to take on an alcohol & tobacco website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.37.action | Action to take on a proxies & translators website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.50.action | Action to take on a tasteless & offensive website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.52.action | Action to take on a violence website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.53.action | Action to take on a weapons website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.54.action | Action to take on a web-based e-mail website. | String | "allow" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.categories.9.action | Action to take on a criminal activity related website. | String | "block" | "allow", "block", "warn" | | | | | No | No | ||
endpoint.web-control.tags.settings | Actions to take for sites matching tags. All items must be unique. | Array of objects | ||||||||
| with schema webControlLocalSiteTagAction | [] | | | | | `` | No | No | ||||
endpoint.web-control.web-filtering.enabled | Control access to potentially inappropriate websites. | Boolean | false | true, false | | | | | No | No | ||
endpoint.web-control.web-monitoring.enabled | Log web control events. If set to "no", only attempts to visit infected sites will be logged. Otherwise, all attempts to visit blocked sites along with warnings and proceeding through warnings will be logged and visible in reports. | String | "yes" | "yes", "no", "inherit" | | | | | No | No |
Settings for Agent Updating policies¶
Agent Updating policies have the policy type agent-updating. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.agent-updating.scheduled-updates.day | Set the day of the week for scheduled updates, using 0 for Sunday, 1 for Monday, and so on. | Integer | 3 | | | `` | day | day | No | No | |
endpoint.agent-updating.scheduled-updates.enabled | Schedule updates for the time you prefer. Set the day and time when you want product updates to become available for computers. Remember: if they aren't on, they won't get the update until the next time they start. Note: This doesn't affect security updates, such as identities used to protect you against new threats. | Boolean | false | true, false | | | | | No | No | ||
endpoint.agent-updating.scheduled-updates.time | Set the time of the day (in the HH:MM time format) for scheduled updates. | String | "14:00" | | `hourMinute` | `hourMinute` | | `` | No | No | |||
endpoint.agent-updating.software-package.windows | Select the static software package you would like to use for the Windows devices in this policy. | String | "recommended" | | | | | `` | No | No | ||
endpoint.agent-updating.software-package.mac | Select the static software package you would like to use for the Mac devices in this policy. | String | "recommended" | | | | | `` | No | No | ||
endpoint.agent-updating.dont-use-update-caches.enabled | Don't use update caches. You don't usually need this setting. It's for Sophos Update Cache users with special requirements. (If you have multiple sites, you might decide it's better for computers on some sites to update directly from Sophos rather than from a cache.) By default, all computers use update caches (if you have set them up). If you use this setting, computers assigned to this policy will update directly from Sophos instead. Note: The computers will also stop using message relays. | Boolean | false | true, false | | | | | No | No |
Settings for Server Agent Updating policies¶
Server Agent Updating policies have the policy type server-agent-updating. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.agent-updating.scheduled-updates.day | Set the day of the week for scheduled updates, using 0 for Sunday, 1 for Monday, and so on. | Integer | 3 | | | `` | day | day | No | No | |
endpoint.agent-updating.scheduled-updates.enabled | Schedule updates for the time you prefer. Set the day and time when you want product updates to become available for servers. Remember: if they aren't on, they won't get the update until the next time they start. Note: This doesn't affect security updates, such as identities used to protect you against new threats. | Boolean | false | true, false | | | | | No | No | ||
endpoint.agent-updating.scheduled-updates.time | Set the time of the day (in the HH:MM time format) for scheduled updates. | String | "14:00" | | `hourMinute` | `hourMinute` | | `` | No | No | |||
endpoint.agent-updating.software-package.windows | Select the software package you would like to use for the Windows Server devices in this policy. | String | "recommended" | | | | | `` | No | No | ||
endpoint.agent-updating.software-package.sspl | Select the static software package you would like to use for the Linux Server devices in this policy. | String | "recommended" | | | | | `` | No | No | ||
endpoint.agent-updating.dont-use-update-caches.enabled | Don't use update caches. You don't usually need this setting. It's for Sophos Update Cache users with special requirements. (If you have multiple sites, you might decide it's better for servers on some sites to update directly from Sophos rather than from a cache.) By default, all servers use update caches (if you have set them up). If you use this setting, servers assigned to this policy will update directly from Sophos instead. Note: The servers will also stop using message relays. | Boolean | false | true, false | | | | | No | No |
Settings for Windows Firewall policies¶
Windows Firewall policies have the policy type windows-firewall. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.windows-firewall.profiles.domain-networks | Action for inbound connections to domain networks. | String | "allow" | "allow", "block", "blockall" | | | | | No | No | ||
endpoint.windows-firewall.monitoring-only.enabled | Monitor Only - Endpoints will report firewall status to Sophos Central. If turned off, this setting will enable the enforcement of the configured network profiles. | Boolean | true | true, false | | | | | No | No | ||
endpoint.windows-firewall.profiles.private-networks | Action for inbound connections to private networks. | String | "allow" | "allow", "block", "blockall" | | | | | No | No | ||
endpoint.windows-firewall.profiles.public-networks | Action for inbound connections to public networks. | String | "allow" | "allow", "block", "blockall" | | | | | No | No |
Settings for Server Windows Firewall policies¶
Server Windows Firewall policies have the policy type server-windows-firewall. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.windows-firewall.profiles.domain-networks | Action for inbound connections to domain networks. | String | "allow" | "allow", "block", "blockall" | | | | | No | No | ||
endpoint.windows-firewall.monitoring-only.enabled | Monitor Only - Endpoints will report firewall status to Sophos Central. If turned off, this setting will enable the enforcement of the configured network profiles. | Boolean | true | true, false | | | | | No | No | ||
endpoint.windows-firewall.profiles.private-networks | Action for inbound connections to private networks. | String | "allow" | "allow", "block", "blockall" | | | | | No | No | ||
endpoint.windows-firewall.profiles.public-networks | Action for inbound connections to public networks. | String | "allow" | "allow", "block", "blockall" | | | | | No | No |
Settings for Server Lockdown policies¶
Server Lockdown policies have the policy type server-lockdown. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.lockdown.allowed-files | Allowed files. All items must be unique. | Array of objects | ||||||||
| with schema lockdownAllowedFile | [] | | | | | `` | No | No | ||||
endpoint.lockdown.allowed-folders | Allowed folders. All items must be unique. | Array of objects | ||||||||
| with schema lockdownAllowedFolder | [] | | | | | `` | No | No | ||||
endpoint.lockdown.blocked-files | Blocked files. All items must be unique. | Array of objects | ||||||||
| with schema lockdownBlockedFile | [] | | | | | `` | No | No | ||||
endpoint.lockdown.blocked-folders | Blocked folders. All items must be unique. | Array of objects | ||||||||
| with schema lockdownBlockedFolder | [] | | | | | `` | No | No | ||||
endpoint.lockdown.dll-protection.enabled | Enable DLL protection. | Boolean | true | true, false | | | | | No | No | ||
endpoint.lockdown.diagnostics.enabled | Enable endpoint diagnostics. | Boolean | false | true, false | | | | | No | No | ||
endpoint.lockdown.excluded-files | Excluded files. All items must be unique. | Array of objects | [] | | | | | `` | No | No | ||
endpoint.lockdown.excluded-folders | Excluded folders. All items must be unique. | Array of objects | ||||||||
| with schema lockdownExcludedFolder | [] | | | | | `` | No | No | ||||
endpoint.lockdown.tamper-protection.enabled | Protect lockdown files. | Boolean | true | true, false | | | | | No | No |
Settings for Server File Integrity Monitoring policies¶
Server File Integrity Monitoring policies have the policy type server-file-integrity-monitoring. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.file-integrity-monitoring.excluded-locations | Locations you want to exclude from monitoring. All items must be unique. | Array of objects | ||||||||
| with schema fileIntegrityMonitoringLocation | [] | | | | | `` | No | No | ||||
endpoint.file-integrity-monitoring.included-locations | Additional locations you want to monitor. All items must be unique. | Array of objects | ||||||||
| with schema fileIntegrityMonitoringLocation | [] | | | | | `` | No | No | ||||
endpoint.file-integrity-monitoring.enabled | Enable File Integrity Monitoring. We monitor critical Windows system files by default. | Boolean | false | true, false | | | | | No | No |
Settings for Device Encryption policies¶
Device Encryption policies have the policy type device-encryption. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.device-encryption.enable-right-click-context-menu | Enable right-click context menu. (User is allowed to create password protected files via the context menu.). | Boolean | false | true, false | | | | | No | No | ||
endpoint.device-encryption.encrypt-non-boot-volumes | Encrypt non-boot volumes. If turned off, Device Encryption only encrypts the volume that the operating system is installed on. To keep secure, we recommend encrypting all your volumes. | Boolean | true | true, false | | | | | No | No | ||
endpoint.device-encryption.encrypt-endpoint | Encrypt all endpoints within the policy. | Boolean | false | true, false | | | | | No | No | ||
endpoint.device-encryption.encrypt-used-space-only | Encrypt used space only. | Boolean | false | true, false | | | | | No | No | ||
endpoint.device-encryption.outlook-addin.enable-attachment-prompt | Always ask how to proceed with attached files. The user can choose between password protecting the attached files or sending them unprotected. | Boolean | false | true, false | | | | | No | No | ||
endpoint.device-encryption.outlook-addin.enabled | Enable Outlook add-in. | Boolean | false | true, false | | | | | No | No | ||
endpoint.device-encryption.outlook-addin.excluded-domains | Domains excluded by Outlook add-in, for which 'Always ask' should NOT apply. Set domains separated by a comma (e.g. "mail.company.com,company.com,company.net"). No wildcards or partially specified domains are supported. | String | "" | | | | | `` | No | No | ||
endpoint.device-encryption.require-startup-authentication | Require startup authentication. | Boolean | true | | | | | `` | No | No | ||
endpoint.device-encryption.reset-authentication.frequency | Number of months after which Device Encryption should require new authentication password/PIN from users. | Integer | 0 | | | `` | months | months | No | No |
Settings for Server Linux Runtime Detection policies¶
Server Linux Runtime Detection policies have the policy type server-linux-runtime-detection. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.server-linux-runtime-detection.enabled | Runtime protection is enabled or not. | Boolean | true | true, false | | | | | No | No | ||
endpoint.server-linux-runtime-detection.profile-id | Runtime detection profile UUID. You must set both endpoint.server-linux-runtime-detection.profile-id and endpoint.server-linux-runtime-detection.profile-version to configure a profile for runtime detection. | String | "" | | | | | `` | No | No | ||
endpoint.server-linux-runtime-detection.profile-version | Runtime detection profile version. You must set both endpoint.server-linux-runtime-detection.profile-id and endpoint.server-linux-runtime-detection.profile-version to configure a profile for runtime detection. | Integer | 1 | | | | | `` | No | No |
Settings for Data Collection and Investigation policies¶
Data Collection and Investigation policies have the policy type data-collection-and-investigation. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.data-collection-and-investigation.allow-live-response-connections | Live Response lets you connect directly to computers to investigate and remediate possible security issues. | Boolean | false | true, false | | | | | No | No | ||
endpoint.data-collection-and-investigation.enable-data-lake-uploads | Manage uploads to the Data Lake from your devices. This lets you store security data in the cloud so you can query it. | Boolean | true | true, false | | | | | No | No | ||
endpoint.data-collection-and-investigation.edr-exclusions | Exclusions for data collection and investigation policy. | Array of objects | ||||||||
| with schema edrExclusion | [] | | | | | `` | No | No |
Settings for Server Data Collection and Investigation policies¶
Server Data Collection and Investigation policies have the policy type server-data-collection-and-investigation. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.data-collection-and-investigation.allow-live-response-connections | Live Response lets you connect directly to servers to investigate and remediate possible security issues. | Boolean | false | true, false | | | | | No | No | ||
endpoint.data-collection-and-investigation.enable-data-lake-uploads | Manage uploads to the Data Lake from your devices. This lets you store security data in the cloud so you can query it. | Boolean | true | true, false | | | | | No | No | ||
endpoint.data-collection-and-investigation.edr-exclusions | Exclusions for data collection and investigation policy. | Array of objects | ||||||||
| with schema edrExclusion | [] | | | | | `` | No | No |
Settings for Endpoint DNS Protection policies¶
Endpoint DNS Protection policies have the policy type endpoint-dns-protection. Supported settings are:
| Setting name | Description | Setting type | Default value | Allowed values | Default format | Allowed formats | Default unit | Allowed units | Use limited | Read only |
|---|---|---|---|---|---|---|---|---|---|---|
endpoint.dns-protection.use-sophos-dns-protection | Use Sophos DNS Protection. | Boolean | false | true, false | | | | | No | No | ||
endpoint.dns-protection.dns-protection-location | Location ID for Sophos DNS Protection. | String | "" | | | | | `` | No | No | ||
endpoint.dns-protection.domain-exclusions | List of domains for which DNS requests will continue to the DNS service configured in the system. | Array of strings | [] | | | | | `` | No | No | ||
endpoint.dns-protection.retry-nx-domain | Retry with system- or application-configured DNS services when DNS Protection returns NXDOMAIN. | Boolean | true | true, false | | | | | No | No | ||
endpoint.dns-protection.deploy-dns-signing-cert | Automatically deploy the DNS Protection signing certificate to devices to show block pages. | Boolean | true | true, false | | | | | No | No |