Skip to content

All Policy Settings

This page is the reference for all settings supported in endpoint policies. You can search for text on this page using Ctrl+F (Cmd+F on macOS). You can also download this reference as a single file. Right-click on this link and select "Save Link As" or "Download Linked File".

This page was last modified on 23-Jun-2026. Please see the changelog for new settings, changes in behavior, and deprecations.

Settings for Threat Protection policies

Threat Protection policies have the policy type threat-protection. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.threat-protection.block-active-adversary-mitigation.enabled Adaptive active adversary mitigation. If disabled, active adversary behaviours are reported in Detections for XDR customers. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.action-on-ransomeware-detection Action to take on ransomware detection. String "terminate" "terminate", "isolate" | | No No
endpoint.threat-protection.exploit-mitigation.amsi-registration-protection.enabled Prevent removal of AMSI registration. Note: This setting applies to computers running the latest version of Sophos Intercept X. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.enabled Protect document files from ransomware (CryptoGuard). Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.side-loading-protection.enabled Prevent side loading of insecure modules. Note: This setting only applies to endpoints you add to the New Endpoint Protection and EDR Features EAP. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.browser-cookie-protection.enabled Protect browser cookies used for MFA sign-in. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.c2-interceptor.enabled Prevent malicious beacons connecting to command-and-control servers. Boolean true true, false | | No No
endpoint.threat-protection.exclusions.scanning Scanning exclusions. All items must be unique. Array of objects
with schema scanningExclusion [] | | `` No No
endpoint.threat-protection.exploit-mitigation.application-protection.enabled Mitigate exploits in vulnerable applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.apc-violation-protection.enabled Prevent APC violation. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.code-cave-mitigation.enabled Prevent code cave utilization. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.credential-theft-protection.enabled Prevent credential theft. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.registry-credential-theft-protection.enabled Prevent registry credential theft. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.dll-hijacking-protection.enabled Prevent DLLs loading from untrusted folders. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.privilege-escalation-protection.enabled Prevent privilege escalation. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.access-token-protection.enabled Prevent access token manipulation. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.ultra-exclude.enabled Turn off exploit mitigation hooks. Boolean false true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.process-hollowing-protection.enabled Prevent process hollowing attacks. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.dynamic-shellcode-protection.enabled Dynamic shellcode protection. Note: This setting applies to computers running the latest version of Sophos Intercept X. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.efs-protection.enabled Protect from Encrypting File System attacks. Note: This setting applies to computers running the latest version of Sophos Intercept X. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.smb-protection.enabled Protect from remotely run ransomware (only available on 64-bit systems). Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.safe-browsing.enabled Protect critical function in web browsers (Safe Browsing). Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.sys-call.enabled Prevent malicious use of syscall instructions. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.hardware-breakpoint-guard.enabled Enable Hardware Breakpoint Guard. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.mbr-protection.enabled Protect from master boot record ransomware. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.java-applications.enabled Protect Java applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.media-applications.enabled Protect media applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.office-applications.enabled Protect office applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.enabled Protect processes. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.web-browser-plugins.enabled Protect web browser plugins. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.web-browsers.enabled Protect web browsers. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.device-io-control.enabled Monitor use of driver APIs. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.all-mitigations.enabled Turn on anti-ransomware protection and all exploit mitigations. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.ctf-protocol-caller-validation.enabled Enable CTF Protocol Caller Validation. Boolean true true, false | | No No
endpoint.threat-protection.heartbeat-protection.enabled Enable heartbeat protection. Boolean true true, false | | No No
endpoint.threat-protection.network-protection.self-isolation.enabled Allow computers to isolate themselves on red health. Note: If a computer has red health, it will isolate itself from the network. It will still communicate with Sophos Central. Boolean false true, false | | No No
endpoint.threat-protection.network-protection.connection-tracking.enabled Track network connections. Boolean true true, false | | No No
endpoint.threat-protection.network-protection.c2-detection.enabled Detect malicious connections to command-and-control servers. Boolean true true, false | | No No
endpoint.threat-protection.exclusions.isolation Endpoint isolation exclusions. All items must be unique. Array of objects
with schema isolationExclusion [] | | `` No No
endpoint.threat-protection.network-protection.ips.enabled Prevent malicious network traffic with packet inspection - EAP devices only. Boolean false true, false | | No No
endpoint.threat-protection.network-protection.ips.all.enabled Prevent malicious network traffic with packet inspection - Intrusion Prevention System (IPS). Boolean false true, false | | No No
endpoint.threat-protection.network-protection.enabled Protect network traffic. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.cleanup.enabled Automatically clean up malware. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.email-protection.attachment-file-types-blocking.enabled Block email attachment file types that are commonly associated with malware. Boolean false true, false | | No Yes
endpoint.threat-protection.malware-protection.amsi-protection.enabled Enable AMSI protection with enhanced scan for script-based threats. Note: This setting applies to computers running the latest version of Core Agent. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.behavioral-detection.enabled Detect malicious behavior. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.web-filtering.enabled Block access to malicious websites. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.deep-learning.detection-level Set deep learning detection level. String "default" "conservative", "default" | | No Yes
endpoint.threat-protection.malware-protection.desktop-messaging.enabled Enable desktop messaging for Threat Protection. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.desktop-messaging.message Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. String "" | | `` No No
endpoint.threat-protection.malware-protection.exclude-remote-files Exclude remote files from scans. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.file-reputation.action Action to take on low-reputation downloads. String "prompt" "prompt", "log" | | No No
endpoint.threat-protection.malware-protection.file-reputation.enabled Detect low-reputation files. Note: Requires Live Protection to be enabled. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.file-reputation.reputation-level Acceptable file reputation level. String "recommended" "strict", "recommended" | | No No
endpoint.threat-protection.malware-protection.live-protection.enabled Use Live Protection to check the latest threat information from SophosLabs online. Note: The feature "Protect network traffic" won't work if you turn off Live Protection. The data may leave your geographic region and be shared with Sophos engineers. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.deep-learning.enabled Enable deep learning. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.hips-detection.enabled Detect malicious behaviour (HIPS). Note: We are phasing out this feature and replacing it with Behavioral Detection. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.on-access.enabled Enable real-time scanning. Note: If you disable real-time scanning, application control won't work and detection of malicious behavior will be disabled. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.web-scanning.enabled Scan downloads in progress. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.skip-trusted-installers Skip trusted installers. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.days Scheduled scan days of the week. (Sunday: 0, Monday: 1, ..., Saturday: 6). Array of integers [6] | `` day day No No
endpoint.threat-protection.malware-protection.scheduled-scan.enabled Enable scheduled scan. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.scan-all-files.enabled Allow schedule scan to scan all files. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.deep-scanning.enabled Enable deep scanning - scans inside archive files (.zip, .cab, etc.). Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.time Scheduled scan time. String "00:00" | `hourMinute` | `hourMinute` | `` No No
endpoint.threat-protection.exclusions.intrusion-prevention Intrusion prevention exclusions. All items must be unique. Array of objects
with schema intrusionPreventionExclusion [] | | `` No No
endpoint.threat-protection.threat-analysis.threat-case-creation.enabled Enable Threat Graph creation. Boolean true true, false | | No No
endpoint.threat-protection.process-memory-background-scan.enabled Enable background process memory scanning. Boolean true true, false | | No No
endpoint.threat-protection.journal-hashing.exclude-remote-files.enabled Exclude remote files from journal hashing. Boolean false true, false | | No No
endpoint.threat-protection.web-control.tls-decryption.enabled Decrypt HTTPS websites using SSL/TLS. If enabled it also turns on HTTPS decryption for Web Control. Boolean false true, false | | No No
endpoint.threat-protection.web-control.tls-decryption.quic.enabled Block QUIC (Quick UDP Internet Connections) network protocol access to websites. Boolean false true, false | | No No
endpoint.threat-protection.event-logging.enabled Turn on event logging. Boolean true true, false | | No No
endpoint.threat-protection.block-safeboot-usage.enabled Behavior rule to block the configuration change to boot the machine in Safe Mode, using techniques available to remote users. Boolean true true, false | | No No
endpoint.threat-protection.protect-in-safeboot.enabled Whether the endpoint enforces additional protection when booted into safeboot. All other existing policy will apply. Boolean false true, false | | No No
endpoint.threat-protection.block-vulnerable-drivers.enabled Behavior rule to block the use of any known vulnerable driver that could be abused to disable Sophos endpoint protection. Boolean true true, false | | No No
endpoint.threat-protection.block-security-tool-drivers.enabled Behavior rule to block the use of any known security tool driver that could be abused to disable Sophos endpoint protection. Boolean true true, false | | No No
endpoint.threat-protection.monitor-domain-controller.enabled Monitor domain controller events. Boolean true true, false | | No No
endpoint.threat-protection.event-journal-writes.enabled Turn on event journal. Boolean true true, false | | No No
endpoint.threat-protection.block-remote-attacker-communication.enabled Block endpoint communicating with remote attacker IPs. Boolean true true, false | | No No

Settings for Server Threat Protection policies

Server Threat Protection policies have the policy type server-threat-protection. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.threat-protection.automatic-exclusions.enabled Automatically exclude activity by known applications. Boolean true true, false | | No No
endpoint.threat-protection.block-active-adversary-mitigation.enabled Adaptive active adversary mitigation. If disabled, active adversary behaviours are reported in Detections for XDR customers. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.action-on-ransomeware-detection Action to take on ransomware detection. String "terminate" "terminate", "isolate" | | No No
endpoint.threat-protection.exploit-mitigation.amsi-registration-protection.enabled Prevent removal of AMSI registration. Note: This setting applies to computers running the latest version of Sophos Intercept X. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.enabled Protect document files from ransomware (CryptoGuard). Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.side-loading-protection.enabled Prevent side loading of insecure modules. Note: This setting only applies to endpoints you add to the New Endpoint Protection and EDR Features EAP. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.browser-cookie-protection.enabled Protect browser cookies used for MFA sign-in. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.c2-interceptor.enabled Prevent malicious beacons connecting to command-and-control servers. Boolean true true, false | | No No
endpoint.threat-protection.exclusions.scanning Scanning exclusions. All items must be unique. Array of objects
with schema scanningExclusion [] | | `` No No
endpoint.threat-protection.exploit-mitigation.application-protection.enabled Mitigate exploits in vulnerable applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.apc-violation-protection.enabled Prevent APC violation. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.code-cave-mitigation.enabled Prevent code cave utilization. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.credential-theft-protection.enabled Prevent credential theft. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.registry-credential-theft-protection.enabled Prevent registry credential theft. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.dll-hijacking-protection.enabled Prevent DLLs loading from untrusted folders. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.privilege-escalation-protection.enabled Prevent privilege escalation. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.access-token-protection.enabled Prevent access token manipulation. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.ultra-exclude.enabled Turn off exploit mitigation hooks. Boolean false true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.process-hollowing-protection.enabled Prevent process hollowing attacks. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.dynamic-shellcode-protection.enabled Dynamic shellcode protection. Note: This setting applies to computers running the latest version of Sophos Intercept X. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.efs-protection.enabled Protect from Encrypting File System attacks. Note: This setting applies to computers running the latest version of Sophos Intercept X. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.cryptoguard.smb-protection.enabled Protect from remotely run ransomware (only available on 64-bit systems). Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.safe-browsing.enabled Protect critical function in web browsers (Safe Browsing). Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.sys-call.enabled Prevent malicious use of syscall instructions. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.hardware-breakpoint-guard.enabled Enable Hardware Breakpoint Guard. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.mbr-protection.enabled Protect from master boot record ransomware. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.java-applications.enabled Protect Java applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.media-applications.enabled Protect media applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.office-applications.enabled Protect office applications. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.process-protection.enabled Protect processes. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.web-browser-plugins.enabled Protect web browser plugins. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.application-protection.web-browsers.enabled Protect web browsers. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.device-io-control.enabled Monitor use of driver APIs. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.all-mitigations.enabled Turn on anti-ransomware protection and all exploit mitigations. Boolean true true, false | | No No
endpoint.threat-protection.exploit-mitigation.ctf-protocol-caller-validation.enabled Enable CTF Protocol Caller Validation. Boolean true true, false | | No No
endpoint.threat-protection.heartbeat-protection.enabled Enable Sophos Security Heartbeat. This sends server "health" reports to Sophos XG Firewalls that are registered with your Sophos Central account. If more than one Firewall is registered, reports go to the nearest one available. If a report shows that a server might have been compromised, the Firewall can restrict its network access. Boolean true true, false | | No No
endpoint.threat-protection.network-protection.self-isolation.enabled Allow computers to isolate themselves on red health. Note: If a computer has red health, it will isolate itself from the network. It will still communicate with Sophos Central. Boolean false true, false | | No No
endpoint.threat-protection.network-protection.connection-tracking.enabled Track network connections. Boolean true true, false | | No No
endpoint.threat-protection.network-protection.c2-detection.enabled Detect malicious connections to command-and-control servers. Boolean true true, false | | No No
endpoint.threat-protection.exclusions.isolation Endpoint isolation exclusions. All items must be unique. Array of objects
with schema isolationExclusion [] | | `` No No
endpoint.threat-protection.network-protection.ips.all.enabled Prevent malicious network traffic with packet inspection - Intrusion Prevention System (IPS). Boolean false true, false | | No No
endpoint.threat-protection.network-protection.enabled Protect network traffic. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.cleanup.enabled Automatically clean up malware. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.email-protection.attachment-file-types-blocking.enabled Block email attachment file types that are commonly associated with malware. Boolean false true, false | | No Yes
endpoint.threat-protection.malware-protection.amsi-protection.enabled Enable AMSI protection with enhanced scan for script-based threats. Note: This setting applies to computers running the latest version of Core Agent. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.behavioral-detection.enabled Detect malicious behavior. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.web-filtering.enabled Block access to malicious websites. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.deep-learning.detection-level Set deep learning detection level. String "default" "conservative", "default" | | No Yes
endpoint.threat-protection.malware-protection.desktop-messaging.enabled Enable desktop messaging for Threat Protection. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.desktop-messaging.message Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. String "" | | `` No No
endpoint.threat-protection.malware-protection.exclude-remote-files Exclude remote files from scans. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.file-reputation.action Action to take on low-reputation downloads. String "prompt" "prompt", "log" | | No No
endpoint.threat-protection.malware-protection.file-reputation.enabled Detect low-reputation files. Note: Requires Live Protection to be enabled. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.file-reputation.reputation-level Acceptable file reputation level. String "recommended" "strict", "recommended" | | No No
endpoint.threat-protection.malware-protection.live-protection.enabled Use Live Protection to check the latest threat information from SophosLabs online. Note: The feature "Protect network traffic" won't work if you turn off Live Protection. The data may leave your geographic region and be shared with Sophos engineers. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.deep-learning.enabled Enable deep learning. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.hips-detection.enabled Detect malicious behaviour (HIPS). Note: We are phasing out this feature and replacing it with Behavioral Detection. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.on-access.enabled Enable real-time scanning. Note: If you disable real-time scanning, application control won't work and detection of malicious behavior will be disabled. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.on-access.scan-on-read.enabled Scan on read enabled. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.on-access.scan-sspl.enabled Scan SSPL enabled. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.on-access.scan-sspl.process-termination.enabled End malicious processes associated with a real-time threat detection. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.on-access.scan-on-write.enabled Scan on write enabled. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.web-scanning.enabled Scan downloads in progress. Boolean true true, false | | No No
endpoint.threat-protection.malware-protection.skip-trusted-installers Skip trusted installers. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.days Scheduled scan days of the week. (Sunday: 0, Monday: 1, ..., Saturday: 6). Array of integers [6] | `` day day No No
endpoint.threat-protection.malware-protection.scheduled-scan.enabled Enable scheduled scan. Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.deep-scanning.enabled Enable deep scanning - scans inside archive files (.zip, .cab, etc.). Boolean false true, false | | No No
endpoint.threat-protection.malware-protection.scheduled-scan.time Scheduled scan time. String "00:00" | `hourMinute` | `hourMinute` | `` No No
endpoint.threat-protection.exclusions.intrusion-prevention Intrusion prevention exclusions. All items must be unique. Array of objects
with schema intrusionPreventionExclusion [] | | `` No No
endpoint.threat-protection.threat-analysis.threat-case-creation.enabled Enable Threat Graph creation. Boolean true true, false | | No No
endpoint.threat-protection.process-memory-background-scan.enabled Enable background process memory scanning. Boolean true true, false | | No No
endpoint.threat-protection.journal-hashing.exclude-remote-files.enabled Exclude remote files from journal hashing. Boolean false true, false | | No No
endpoint.threat-protection.linux-runtime-detections.enabled Enable Linux runtime detections. Boolean true true, false | | No No
endpoint.threat-protection.linux-runtime-response-actions.enabled Enable Linux runtime response actions. Boolean true true, false | | No No
endpoint.threat-protection.linux-agent-quarantine.enabled Enable Linux agent quarantine. Boolean true true, false | | No No
endpoint.threat-protection.web-control.tls-decryption.enabled Decrypt HTTPS websites using SSL/TLS. If enabled it also turns on HTTPS decryption for Web Control. Boolean false true, false | | No No
endpoint.threat-protection.web-control.tls-decryption.quic.enabled Block QUIC (Quick UDP Internet Connections) network protocol access to websites. Boolean false true, false | | No No
endpoint.threat-protection.event-logging.enabled Turn on event logging. Boolean true true, false | | No No
endpoint.threat-protection.block-safeboot-usage.enabled Behavior rule to block the configuration change to boot the machine in Safe Mode, using techniques available to remote users. Boolean true true, false | | No No
endpoint.threat-protection.protect-in-safeboot.enabled Whether the endpoint enforces additional protection when booted into safeboot. All other existing policy will apply. Boolean false true, false | | No No
endpoint.threat-protection.block-vulnerable-drivers.enabled Behavior rule to block the use of any known vulnerable driver that could be abused to disable Sophos endpoint protection. Boolean true true, false | | No No
endpoint.threat-protection.block-security-tool-drivers.enabled Behavior rule to block the use of any known security tool driver that could be abused to disable Sophos endpoint protection. Boolean true true, false | | No No
endpoint.threat-protection.monitor-domain-controller.enabled Monitor domain controller events. Boolean true true, false | | No No
endpoint.threat-protection.event-journal-writes.enabled Turn on event journal. Boolean true true, false | | No No
endpoint.threat-protection.block-remote-attacker-communication.enabled Block endpoint communicating with remote attacker IPs. Boolean true true, false | | No No

Settings for Peripheral Control policies

Peripheral Control policies have the policy type peripheral-control. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.peripheral-control.actions.bluetooth Action to take on bluetooth devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.actions.camera Action to take on camera devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.desktop-messaging.enabled Enable desktop messaging for Peripheral Control. Boolean true true, false | | No No
endpoint.peripheral-control.desktop-messaging.message Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. String "" | | `` No No
endpoint.peripheral-control.enabled Control access by peripheral type. Boolean false true, false | | No No
endpoint.peripheral-control.actions.secure-removable-storage Action to take on secure removable storage devices. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.exemptions Manage peripheral exemptions, allowing or blocking specific peripherals. All items must be unique. Exemptions cannot be stricter than the settings for individual peripheral types. Array of objects
with schema peripheralControlExemption [] | | `` No No
endpoint.peripheral-control.actions.floppy-drive Action to take on floppy drives. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.actions.infra-red Action to take on infra-red devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.actions.modem Action to take on modems. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.monitor Monitor but do not block (all peripherals will be allowed). Boolean false true, false | | No No
endpoint.peripheral-control.actions.mtp-ptp Action to take on MTP/PTP devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.actions.optical-drive Action to take on optical drives. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.actions.removable-storage Action to take on removable storage devices. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.actions.wireless Action to take on wireless devices. String "allowed" "allowed", "blocked", "blockBridged" | | No No

Settings for Server Peripheral Control policies

Server Peripheral Control policies have the policy type server-peripheral-control. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.peripheral-control.actions.bluetooth Action to take on bluetooth devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.actions.camera Action to take on camera devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.desktop-messaging.enabled Enable desktop messaging for Peripheral Control. Boolean true true, false | | No No
endpoint.peripheral-control.desktop-messaging.message Configure a message to be added to the end of the standard notification. Note: Custom messages will not be displayed for Intercept X events. String "" | | `` No No
endpoint.peripheral-control.enabled Control access by peripheral type. Boolean false true, false | | No No
endpoint.peripheral-control.actions.secure-removable-storage Action to take on secure removable storage devices. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.exemptions Manage peripheral exemptions, allowing or blocking specific peripherals. All items must be unique. Exemptions cannot be stricter than the settings for individual peripheral types. Array of objects
with schema peripheralControlExemption [] | | `` No No
endpoint.peripheral-control.actions.floppy-drive Action to take on floppy drives. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.actions.infra-red Action to take on infra-red devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.actions.modem Action to take on modems. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.monitor Monitor but do not block (all peripherals will be allowed). Boolean false true, false | | No No
endpoint.peripheral-control.actions.mtp-ptp Action to take on MTP/PTP devices. String "allowed" "allowed", "blocked" | | No No
endpoint.peripheral-control.actions.optical-drive Action to take on optical drives. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.actions.removable-storage Action to take on removable storage devices. String "allowed" "allowed", "blocked", "readOnly" | | No No
endpoint.peripheral-control.actions.wireless Action to take on wireless devices. String "allowed" "allowed", "blocked", "blockBridged" | | No No

Settings for Application Control policies

Application Control policies have the policy type application-control. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.application-control.allowed-applications Allow specific applications by name when the application category is controlled. Array of strings [] | | `` No No
endpoint.application-control.controlled-categories Controlled application categories. New applications added by Sophos to these application categories will be automatically controlled. Array of integers [] | | `` No No
endpoint.application-control.controlled-applications Names of applications to control. Array of strings [] | | `` No No
endpoint.application-control.desktop-messaging.enabled Enable desktop messaging for Application Control. Boolean true true, false | | No No
endpoint.application-control.desktop-messaging.message Configure a message to be added to the end of the standard notification. String "" | | `` No No
endpoint.application-control.detection.on-demand.enabled Detect controlled applications during scheduled and on-demand scans. Boolean false true, false | | No No
endpoint.application-control.detection.on-access.enabled Detect controlled applications when users access them. (You will be notified). Boolean false true, false | | No No
endpoint.application-control.detection.on-access.monitor Allow/block the detected application. Boolean true true, false | | No No

Settings for Server Application Control policies

Server Application Control policies have the policy type server-application-control. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.application-control.allowed-applications Allow specific applications by name when the application category is controlled. Array of strings [] | | `` No No
endpoint.application-control.controlled-categories Controlled application categories. New applications added by Sophos to these application categories will be automatically controlled. Array of integers [] | | `` No No
endpoint.application-control.controlled-applications Names of applications to control. Array of strings [] | | `` No No
endpoint.application-control.desktop-messaging.enabled Enable desktop messaging for Application Control. Boolean true true, false | | No No
endpoint.application-control.desktop-messaging.message Configure a message to be added to the end of the standard notification. String "" | | `` No No
endpoint.application-control.detection.on-demand.enabled Detect controlled applications during scheduled and on-demand scans. Boolean false true, false | | No No
endpoint.application-control.detection.on-access.enabled Detect controlled applications when users access them. (You will be notified). Boolean false true, false | | No No
endpoint.application-control.detection.on-access.monitor Allow/block the detected application. Boolean true true, false | | No No

Settings for Web Control policies

Web Control policies have the policy type web-control. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.web-control.web-profile.enabled Determines whether the policy configures web control via web profiles or legacy settings. Note: When enabled, web profile settings take precedence over any legacy settings. Boolean true true, false | | No No
endpoint.web-control.filter-by-web-profile.enabled Determines if filtering by web profile is enabled. Boolean false true, false | | No No
endpoint.web-control.web-profile-id ID of the web profile (UUID format). String "" | | `` No No
endpoint.web-control.web-profile-log-web-events.enabled Log web control events. Boolean true true, false | | No No
endpoint.web-control.web-profile-schedules Days of the week and hours of the day when the specified web profiles should be in effect. All items must be unique. Array of objects
with schema webControlWebProfilesSchedule [] | | `` No No
endpoint.web-control.categories.0.action Action to take on an uncategorized website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.1.action Action to take on an adult/sexually explicit website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.10.action Action to take on a downloads website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.11.action Action to take on an educational website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.12.action Action to take on an entertainment website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.13.action Action to take on a fashion & beauty website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.14.action Action to take on a finance & investment website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.15.action Action to take on a food & dining website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.16.action Action to take on a gambling website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.17.action Action to take on a games website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.18.action Action to take on a government website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.19.action Action to take on a hacking website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.2.action Action to take on an advertisements & pop-ups related website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.20.action Action to take on a health & medicine website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.21.action Action to take on a hobbies & recreation website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.22.action Action to take on a hosting site's website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.23.action Action to take on an illegal drugs website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.24.action Action to take on an infrastructure website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.25.action Action to take on an intimate apparel & swimwear website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.26.action Action to take on an intolerance & hate website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.27.action Action to take on a job search & career development website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.28.action Action to take on a kids' website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.29.action Action to take on a motor vehicles website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.3.action Action to take on an alcohol & tobacco website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.30.action Action to take on a news website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.31.action Action to take on a peer-to-peer website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.32.action Action to take on a personals and dating website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.33.action Action to take on a philanthropic & professional orgs. website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.35.action Action to take on a photo searches website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.36.action Action to take on a politics website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.37.action Action to take on a proxies & translators website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.38.action Action to take on a real-estate website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.39.action Action to take on a reference website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.4.action Action to take on an arts website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.40.action Action to take on a religion website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.41.action Action to take on a ringtones/mobile phone downloads website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.42.action Action to take on a search engine website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.43.action Action to take on a sex education website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.44.action Action to take on a shopping website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.45.action Action to take on a society & culture website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.47.action Action to take on a sports website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.49.action Action to take on a streaming media website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.5.action Action to take on a blogs & forums website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.50.action Action to take on a tasteless & offensive website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.51.action Action to take on a travel website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.52.action Action to take on a violence website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.53.action Action to take on a weapons website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.54.action Action to take on a web-based e-mail website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.6.action Action to take on a business website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.7.action Action to take on a chat website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.8.action Action to take on a computing & internet related website. String "allow" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.categories.9.action Action to take on a criminal activity related website. String "block" "allow", "block", "warn", "inherit" | | No No
endpoint.web-control.filetypes.archive-jar.action Action to take on Java Archive (jar) files. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.doc-pdf.action Action to take on Adobe PDF (pdf) files. String "allow" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-com.action Action to take on DOS Command File (com) files. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-dll.action Action to take on Windows Library File (dll) files. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-exe.action Action to take on Windows Executable (exe) files. String "warn" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-javabytecode.action Action to take on Java Applet (class) files. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-msi.action Action to take on Windows Installer (msi) files. String "warn" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-ocx.action Action to take on ActiveX Controls (ocx) files. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.exe-unknown.action Action to take on unknown executables. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.filetypes.video-flv.action Action to takeo n Adobe Flash Video (flv, swf) files. String "allow" "allow", "block", "warn" | | No No
endpoint.web-control.schedule.enabled Apply this web control policy at set times only. Boolean false true, false | | No No
endpoint.web-control.schedule.active-periods Days of the week and hours of the day when this policy should be in effect. All items must be unique. Array of objects
with schema webControlSchedule [] | | `` No No
endpoint.web-control.tags.settings Actions to take for sites matching tags. All items must be unique. Array of objects
with schema webControlLocalSiteTagAction [] | | `` No No
endpoint.web-control.web-filtering.enabled Control access to potentially inappropriate websites. Boolean true true, false | | No No
endpoint.web-control.web-monitoring.enabled Log web control events. If set to "no", only attempts to visit infected sites will be logged. Otherwise, all attempts to visit blocked sites along with warnings and proceeding through warnings will be logged and visible in reports. String "yes" "yes", "no", "inherit" | | No No

Settings for Server Web Control policies

Server Web Control policies have the policy type server-web-control. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.web-control.web-profile.enabled Determines whether the policy configures web control via web profiles or legacy settings. Note: When enabled, web profile settings take precedence over any legacy settings. Boolean true true, false | | No No
endpoint.web-control.filter-by-web-profile.enabled Determines if filtering by web profile is enabled. Boolean false true, false | | No No
endpoint.web-control.web-profile-id ID of the web profile (UUID format). String "" | | `` No No
endpoint.web-control.web-profile-log-web-events.enabled Log web control events. Boolean true true, false | | No No
endpoint.web-control.web-profile-schedules Days of the week and hours of the day when the specified web profiles should be in effect. All items must be unique. Array of objects
with schema webControlWebProfilesSchedule [] | | `` No No
endpoint.web-control.categories.1.action Action to take on an adult/sexually explicit website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.16.action Action to take on a gambling website. String "allow" "allow", "block", "warn" | | No No
endpoint.web-control.categories.19.action Action to take on a hacking website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.2.action Action to take on an advertisements & pop-ups related website. String "allow" "allow", "block", "warn" | | No No
endpoint.web-control.categories.23.action Action to take on an illegal drugs website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.26.action Action to take on an intolerance & hate website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.3.action Action to take on an alcohol & tobacco website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.37.action Action to take on a proxies & translators website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.50.action Action to take on a tasteless & offensive website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.52.action Action to take on a violence website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.53.action Action to take on a weapons website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.categories.54.action Action to take on a web-based e-mail website. String "allow" "allow", "block", "warn" | | No No
endpoint.web-control.categories.9.action Action to take on a criminal activity related website. String "block" "allow", "block", "warn" | | No No
endpoint.web-control.tags.settings Actions to take for sites matching tags. All items must be unique. Array of objects
with schema webControlLocalSiteTagAction [] | | `` No No
endpoint.web-control.web-filtering.enabled Control access to potentially inappropriate websites. Boolean false true, false | | No No
endpoint.web-control.web-monitoring.enabled Log web control events. If set to "no", only attempts to visit infected sites will be logged. Otherwise, all attempts to visit blocked sites along with warnings and proceeding through warnings will be logged and visible in reports. String "yes" "yes", "no", "inherit" | | No No

Settings for Agent Updating policies

Agent Updating policies have the policy type agent-updating. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.agent-updating.scheduled-updates.day Set the day of the week for scheduled updates, using 0 for Sunday, 1 for Monday, and so on. Integer 3 | `` day day No No
endpoint.agent-updating.scheduled-updates.enabled Schedule updates for the time you prefer. Set the day and time when you want product updates to become available for computers. Remember: if they aren't on, they won't get the update until the next time they start. Note: This doesn't affect security updates, such as identities used to protect you against new threats. Boolean false true, false | | No No
endpoint.agent-updating.scheduled-updates.time Set the time of the day (in the HH:MM time format) for scheduled updates. String "14:00" | `hourMinute` | `hourMinute` | `` No No
endpoint.agent-updating.software-package.windows Select the static software package you would like to use for the Windows devices in this policy. String "recommended" | | `` No No
endpoint.agent-updating.software-package.mac Select the static software package you would like to use for the Mac devices in this policy. String "recommended" | | `` No No
endpoint.agent-updating.dont-use-update-caches.enabled Don't use update caches. You don't usually need this setting. It's for Sophos Update Cache users with special requirements. (If you have multiple sites, you might decide it's better for computers on some sites to update directly from Sophos rather than from a cache.) By default, all computers use update caches (if you have set them up). If you use this setting, computers assigned to this policy will update directly from Sophos instead. Note: The computers will also stop using message relays. Boolean false true, false | | No No

Settings for Server Agent Updating policies

Server Agent Updating policies have the policy type server-agent-updating. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.agent-updating.scheduled-updates.day Set the day of the week for scheduled updates, using 0 for Sunday, 1 for Monday, and so on. Integer 3 | `` day day No No
endpoint.agent-updating.scheduled-updates.enabled Schedule updates for the time you prefer. Set the day and time when you want product updates to become available for servers. Remember: if they aren't on, they won't get the update until the next time they start. Note: This doesn't affect security updates, such as identities used to protect you against new threats. Boolean false true, false | | No No
endpoint.agent-updating.scheduled-updates.time Set the time of the day (in the HH:MM time format) for scheduled updates. String "14:00" | `hourMinute` | `hourMinute` | `` No No
endpoint.agent-updating.software-package.windows Select the software package you would like to use for the Windows Server devices in this policy. String "recommended" | | `` No No
endpoint.agent-updating.software-package.sspl Select the static software package you would like to use for the Linux Server devices in this policy. String "recommended" | | `` No No
endpoint.agent-updating.dont-use-update-caches.enabled Don't use update caches. You don't usually need this setting. It's for Sophos Update Cache users with special requirements. (If you have multiple sites, you might decide it's better for servers on some sites to update directly from Sophos rather than from a cache.) By default, all servers use update caches (if you have set them up). If you use this setting, servers assigned to this policy will update directly from Sophos instead. Note: The servers will also stop using message relays. Boolean false true, false | | No No

Settings for Windows Firewall policies

Windows Firewall policies have the policy type windows-firewall. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.windows-firewall.profiles.domain-networks Action for inbound connections to domain networks. String "allow" "allow", "block", "blockall" | | No No
endpoint.windows-firewall.monitoring-only.enabled Monitor Only - Endpoints will report firewall status to Sophos Central. If turned off, this setting will enable the enforcement of the configured network profiles. Boolean true true, false | | No No
endpoint.windows-firewall.profiles.private-networks Action for inbound connections to private networks. String "allow" "allow", "block", "blockall" | | No No
endpoint.windows-firewall.profiles.public-networks Action for inbound connections to public networks. String "allow" "allow", "block", "blockall" | | No No

Settings for Server Windows Firewall policies

Server Windows Firewall policies have the policy type server-windows-firewall. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.windows-firewall.profiles.domain-networks Action for inbound connections to domain networks. String "allow" "allow", "block", "blockall" | | No No
endpoint.windows-firewall.monitoring-only.enabled Monitor Only - Endpoints will report firewall status to Sophos Central. If turned off, this setting will enable the enforcement of the configured network profiles. Boolean true true, false | | No No
endpoint.windows-firewall.profiles.private-networks Action for inbound connections to private networks. String "allow" "allow", "block", "blockall" | | No No
endpoint.windows-firewall.profiles.public-networks Action for inbound connections to public networks. String "allow" "allow", "block", "blockall" | | No No

Settings for Server Lockdown policies

Server Lockdown policies have the policy type server-lockdown. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.lockdown.allowed-files Allowed files. All items must be unique. Array of objects
with schema lockdownAllowedFile [] | | `` No No
endpoint.lockdown.allowed-folders Allowed folders. All items must be unique. Array of objects
with schema lockdownAllowedFolder [] | | `` No No
endpoint.lockdown.blocked-files Blocked files. All items must be unique. Array of objects
with schema lockdownBlockedFile [] | | `` No No
endpoint.lockdown.blocked-folders Blocked folders. All items must be unique. Array of objects
with schema lockdownBlockedFolder [] | | `` No No
endpoint.lockdown.dll-protection.enabled Enable DLL protection. Boolean true true, false | | No No
endpoint.lockdown.diagnostics.enabled Enable endpoint diagnostics. Boolean false true, false | | No No
endpoint.lockdown.excluded-files Excluded files. All items must be unique. Array of objects [] | | `` No No
endpoint.lockdown.excluded-folders Excluded folders. All items must be unique. Array of objects
with schema lockdownExcludedFolder [] | | `` No No
endpoint.lockdown.tamper-protection.enabled Protect lockdown files. Boolean true true, false | | No No

Settings for Server File Integrity Monitoring policies

Server File Integrity Monitoring policies have the policy type server-file-integrity-monitoring. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.file-integrity-monitoring.excluded-locations Locations you want to exclude from monitoring. All items must be unique. Array of objects
with schema fileIntegrityMonitoringLocation [] | | `` No No
endpoint.file-integrity-monitoring.included-locations Additional locations you want to monitor. All items must be unique. Array of objects
with schema fileIntegrityMonitoringLocation [] | | `` No No
endpoint.file-integrity-monitoring.enabled Enable File Integrity Monitoring. We monitor critical Windows system files by default. Boolean false true, false | | No No

Settings for Device Encryption policies

Device Encryption policies have the policy type device-encryption. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.device-encryption.enable-right-click-context-menu Enable right-click context menu. (User is allowed to create password protected files via the context menu.). Boolean false true, false | | No No
endpoint.device-encryption.encrypt-non-boot-volumes Encrypt non-boot volumes. If turned off, Device Encryption only encrypts the volume that the operating system is installed on. To keep secure, we recommend encrypting all your volumes. Boolean true true, false | | No No
endpoint.device-encryption.encrypt-endpoint Encrypt all endpoints within the policy. Boolean false true, false | | No No
endpoint.device-encryption.encrypt-used-space-only Encrypt used space only. Boolean false true, false | | No No
endpoint.device-encryption.outlook-addin.enable-attachment-prompt Always ask how to proceed with attached files. The user can choose between password protecting the attached files or sending them unprotected. Boolean false true, false | | No No
endpoint.device-encryption.outlook-addin.enabled Enable Outlook add-in. Boolean false true, false | | No No
endpoint.device-encryption.outlook-addin.excluded-domains Domains excluded by Outlook add-in, for which 'Always ask' should NOT apply. Set domains separated by a comma (e.g. "mail.company.com,company.com,company.net"). No wildcards or partially specified domains are supported. String "" | | `` No No
endpoint.device-encryption.require-startup-authentication Require startup authentication. Boolean true | | `` No No
endpoint.device-encryption.reset-authentication.frequency Number of months after which Device Encryption should require new authentication password/PIN from users. Integer 0 | `` months months No No

Settings for Server Linux Runtime Detection policies

Server Linux Runtime Detection policies have the policy type server-linux-runtime-detection. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.server-linux-runtime-detection.enabled Runtime protection is enabled or not. Boolean true true, false | | No No
endpoint.server-linux-runtime-detection.profile-id Runtime detection profile UUID. You must set both endpoint.server-linux-runtime-detection.profile-id and endpoint.server-linux-runtime-detection.profile-version to configure a profile for runtime detection. String "" | | `` No No
endpoint.server-linux-runtime-detection.profile-version Runtime detection profile version. You must set both endpoint.server-linux-runtime-detection.profile-id and endpoint.server-linux-runtime-detection.profile-version to configure a profile for runtime detection. Integer 1 | | `` No No

Settings for Data Collection and Investigation policies

Data Collection and Investigation policies have the policy type data-collection-and-investigation. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.data-collection-and-investigation.allow-live-response-connections Live Response lets you connect directly to computers to investigate and remediate possible security issues. Boolean false true, false | | No No
endpoint.data-collection-and-investigation.enable-data-lake-uploads Manage uploads to the Data Lake from your devices. This lets you store security data in the cloud so you can query it. Boolean true true, false | | No No
endpoint.data-collection-and-investigation.edr-exclusions Exclusions for data collection and investigation policy. Array of objects
with schema edrExclusion [] | | `` No No

Settings for Server Data Collection and Investigation policies

Server Data Collection and Investigation policies have the policy type server-data-collection-and-investigation. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.data-collection-and-investigation.allow-live-response-connections Live Response lets you connect directly to servers to investigate and remediate possible security issues. Boolean false true, false | | No No
endpoint.data-collection-and-investigation.enable-data-lake-uploads Manage uploads to the Data Lake from your devices. This lets you store security data in the cloud so you can query it. Boolean true true, false | | No No
endpoint.data-collection-and-investigation.edr-exclusions Exclusions for data collection and investigation policy. Array of objects
with schema edrExclusion [] | | `` No No

Settings for Endpoint DNS Protection policies

Endpoint DNS Protection policies have the policy type endpoint-dns-protection. Supported settings are:

Setting name Description Setting type Default value Allowed values Default format Allowed formats Default unit Allowed units Use limited Read only
endpoint.dns-protection.use-sophos-dns-protection Use Sophos DNS Protection. Boolean false true, false | | No No
endpoint.dns-protection.dns-protection-location Location ID for Sophos DNS Protection. String "" | | `` No No
endpoint.dns-protection.domain-exclusions List of domains for which DNS requests will continue to the DNS service configured in the system. Array of strings [] | | `` No No
endpoint.dns-protection.retry-nx-domain Retry with system- or application-configured DNS services when DNS Protection returns NXDOMAIN. Boolean true true, false | | No No
endpoint.dns-protection.deploy-dns-signing-cert Automatically deploy the DNS Protection signing certificate to devices to show block pages. Boolean true true, false | | No No