Policy Settings Changelog
Jun-23, 2026¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The peripheral-control and server-peripheral-control policies now both support this new setting:
| Name | Description |
|---|---|
endpoint.peripheral-control.actions.camera | Action to take on camera devices. |
The threat-protection and server-threat-protection policies now both support this new setting:
| Name | Description |
|---|---|
endpoint.threat-protection.block-security-tool-drivers.enabled | Behavior rule to block the use of any known security tool driver that could be abused to disable Sophos endpoint protection. |
The web-control and server-web-control policies now supports these new settings:
| Name | Description |
|---|---|
endpoint.web-control.web-filtering.enabled | Control access to potentially inappropriate websites. Replaces endpoint.web-control.enabled |
endpoint.web-control.web-profile.enabled | Determines whether the policy configures web control via web profiles or legacy settings. Note: When enabled, web profile settings take precedence over any legacy settings. |
endpoint.web-control.filter-by-web-profile.enabled | Determines if filtering by web profile is enabled. |
endpoint.web-control.web-profile-id | ID of the web profile (UUID format). |
endpoint.web-control.web-profile-log-web-events.enabled | Log web control events. |
endpoint.web-control.web-profile-schedules | Days of the week and hours of the day when the specified web profiles should be in effect. |
May-21, 2026¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The threat-protection and server-threat-protection policies now both support this new setting:
| Name | Description |
|---|---|
endpoint.threat-protection.block-vulnerable-drivers.enabled | Behavior rule to block the use of any known vulnerable driver that could be abused to disable Sophos endpoint protection. |
Mar-19, 2026¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The server-threat-protection policy now supports these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.linux-runtime-response-actions.enabled | Enable Linux runtime response actions. |
endpoint.threat-protection.linux-agent-quarantine.enabled | Enable Linux agent quarantine. |
Mar-02, 2026¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New policy¶
The endpoint-dns-protection policy is added, with the following settings:
| Name | Description |
|---|---|
endpoint.dns-protection.use-sophos-dns-protection | Use Sophos DNS Protection. |
endpoint.dns-protection.dns-protection-location | Location ID for Sophos DNS Protection. |
endpoint.dns-protection.domain-exclusions | List of domains for which DNS requests will continue to the DNS service configured in the system. |
endpoint.dns-protection.retry-nx-domain | Retry with system- or application-configured DNS services when DNS Protection returns NXDOMAIN. |
endpoint.dns-protection.deploy-dns-signing-cert | Automatically deploy the DNS Protection signing certificate to devices to show block pages. |
Feb-17, 2026¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The threat-protection and server-threat-protection policies now both support these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.event-journal-writes.enabled | Turn on event journal. |
endpoint.threat-protection.block-remote-attacker-communication.enabled | Block endpoint communicating with remote attacker IPs. |
Jan-22, 2026¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New policy¶
The data-collection-and-investigation and server-data-collection-and-investigation policies are added, with the following settings:
| Name | Description |
|---|---|
endpoint.data-collection-and-investigation.allow-live-response-connections | Live Response lets you connect directly to servers to investigate and remediate possible security issues. |
endpoint.data-collection-and-investigation.enable-data-lake-uploads | Manage uploads to the Data Lake from your devices. This lets you store security data in the cloud so you can query it. |
endpoint.data-collection-and-investigation.edr-exclusions | Exclusions for data collection and investigation policy. |
May-22, 2025¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The threat-protection and server-threat-protection policies now both support these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.exploit-mitigation.process-protection.access-token-protection.enabled | Prevent access token manipulation. |
endpoint.threat-protection.monitor-domain-controller.enabled | Monitor domain controller events. |
The server-threat-protection policy now supports these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.network-protection.ips.all.enabled | Prevent malicious network traffic with packet inspection. Replaces endpoint.threat-protection.network-protection.ips.enabled, which is limited to EAP devices only. |
Removed settings¶
The following settings in the threat-protection and server-threat-protection policies have been removed:
| Name | Description |
|---|---|
endpoint.threat-protection.exploit-mitigation.cpu-branch-tracing.enabled | Enable CPU branch tracing. |
endpoint.threat-protection.malware-protection.live-protection.on-demand | Use Live Protection during scheduled scans. |
Sep-20, 2024¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The threat-protection and server-threat-protection policies now both support these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.exploit-mitigation.sys-call.enabled | Prevent malicious use of syscall instructions. |
endpoint.threat-protection.exploit-mitigation.device-io-control.enabled | Monitor use of driver APIs. |
endpoint.threat-protection.block-safeboot-usage.enabled | Behavior rule to block the configuration change to boot the machine in Safe Mode, using techniques available to remote users. |
endpoint.threat-protection.protect-in-safeboot.enabled | Whether the endpoint enforces additional protection when booted into safeboot. All other existing policy will apply. |
The threat-protection policy now supports these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.network-protection.ips.all.enabled | Prevent malicious network traffic with packet inspection. Replaces endpoint.threat-protection.network-protection.ips.enabled, which is limited to EAP devices only. |
The server-threat-protection policy now supports these new settings:
| Name | Description |
|---|---|
endpoint.threat-protection.malware-protection.on-access.scan-sspl.process-termination.enabled | End malicious processes associated with a real-time threat detection. |
Oct-06, 2023¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New policy¶
The 'server-linux-runtime-detection' policy is added to support the Linux Runtime Detection features, with the following settings:
| Name | Title | Description |
|---|---|---|
endpoint.server-linux-runtime-detection.enabled | Enable runtime detection | Enable runtime detection |
endpoint.server-linux-runtime-detection.profile-id | Runtime detection profile ID | The ID of the runtime detection profile as per the /cloud-security/v1/profiles API |
endpoint.server-linux-runtime-detection.profile-version | Runtime detection profile version | The ID of the runtime detection profile as per the /cloud-security/v1/profiles API |
New settings¶
The threat-protection and server-threat-protection policies now both support these new settings:
| Name | Title | Description |
|---|---|---|
endpoint.threat-protection.exploit-mitigation.c2-interceptor.enabled | N/A | Prevent malicious beacons connecting to command-and-control servers. |
endpoint.threat-protection.exploit-mitigation.ultra-exclude.enabled | Disable exploit mitigation hooks. | Turn off exploit mitigation hooks. |
Removed settings¶
The following deprecated setting in the threat-protection and server-threat-protection policies has been removed:
| Name | Title | Description | Change |
|---|---|---|---|
endpoint.threat-protection.use-recommended-settings | Use Sophos Recommended Settings | Use Sophos Recommended Settings. | This property is no longer supported. You can get the same result by changing settings that have warnings next to them in Sophos Fusion. |
Apr-26, 2023¶
We have just updated the Endpoint Policy Settings reference with the following changes.
New settings¶
The agent-updating and server-agent-updating policies now both support these new settings:
| Name | Title | Description |
|---|---|---|
endpoint.agent-updating.software-package.windows | Set static package for Windows | Select the static software package you would like to use for the Windows devices in this policy. The default value is "recommended". |
endpoint.agent-updating.software-package.mac | Set static package for Mac | Select the static software package you would like to use for the Mac devices in this policy. The default value is "recommended". |
The threat-protection and server-threat-protection policies now both support these new settings:
| Name | Title | Description |
|---|---|---|
endpoint.threat-protection.exploit-mitigation | Enable CookieGuard | Protect browser cookies used for MFA sign-in. The default value is true. |
endpoint.threat-protection.web-control.tls-decryption.quic.enabled | Enable block QUIC network protocol access to websites | Block QUIC (Quick UDP Internet Connections) network protocol access to websites. The default and recommended value is true. |
In addition, the server-threat-protection policy now supports this new setting:
| Name | Title | Description |
|---|---|---|
endpoint.threat-protection.malware-protection.on-access.scan-sspl.enabled | Enable Scan SSPL | Scan SSPL enabled. The default value is true. |
Changes in behavior¶
| Name | Title | Description | Change |
|---|---|---|---|
endpoint.threat-protection.exploit-mitigation.all-mitigations.enabled | Enable All Exploit Mitigations | Turn on anti-ransomware protection and all exploit mitigations. | You can now use the API to change this setting. It is no longer read-only. |
endpoint.threat-protection.network-protection.connection-tracking.enabled | Enable Connection Tracking | Track network connections. | You can now use the API to change this setting. It is no longer read-only. |
endpoint.threat-protection.malware-protection.skip-trusted-installers | Skip Trusted Installers | Skip trusted installers | You can now use the API to change this setting. It is no longer read-only. |
endpoint.threat-protection.network-protection.ips.enabled | Enable IPS | Prevent malicious network traffic with packet inspection. | Previously, the recommended value for this setting was false. We no longer recommend a value. You should set it to whatever is appropriate for your environment. |
Deprecated settings¶
The following setting in the threat-protection and server-threat-protection policies has been deprecated:
| Name | Title | Description | Change |
|---|---|---|---|
endpoint.threat-protection.use-recommended-settings | Use Sophos Recommended Settings | Use Sophos Recommended Settings. | This property is no longer supported. You can get the same result by changing settings that have warnings next to them in Sophos Fusion. |