Skip to content

Policy Settings Changelog

Jun-23, 2026

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The peripheral-control and server-peripheral-control policies now both support this new setting:

Name Description
endpoint.peripheral-control.actions.camera Action to take on camera devices.

The threat-protection and server-threat-protection policies now both support this new setting:

Name Description
endpoint.threat-protection.block-security-tool-drivers.enabled Behavior rule to block the use of any known security tool driver that could be abused to disable Sophos endpoint protection.

The web-control and server-web-control policies now supports these new settings:

Name Description
endpoint.web-control.web-filtering.enabled Control access to potentially inappropriate websites. Replaces endpoint.web-control.enabled
endpoint.web-control.web-profile.enabled Determines whether the policy configures web control via web profiles or legacy settings. Note: When enabled, web profile settings take precedence over any legacy settings.
endpoint.web-control.filter-by-web-profile.enabled Determines if filtering by web profile is enabled.
endpoint.web-control.web-profile-id ID of the web profile (UUID format).
endpoint.web-control.web-profile-log-web-events.enabled Log web control events.
endpoint.web-control.web-profile-schedules Days of the week and hours of the day when the specified web profiles should be in effect.

May-21, 2026

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The threat-protection and server-threat-protection policies now both support this new setting:

Name Description
endpoint.threat-protection.block-vulnerable-drivers.enabled Behavior rule to block the use of any known vulnerable driver that could be abused to disable Sophos endpoint protection.

Mar-19, 2026

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The server-threat-protection policy now supports these new settings:

Name Description
endpoint.threat-protection.linux-runtime-response-actions.enabled Enable Linux runtime response actions.
endpoint.threat-protection.linux-agent-quarantine.enabled Enable Linux agent quarantine.

Mar-02, 2026

We have just updated the Endpoint Policy Settings reference with the following changes.

New policy

The endpoint-dns-protection policy is added, with the following settings:

Name Description
endpoint.dns-protection.use-sophos-dns-protection Use Sophos DNS Protection.
endpoint.dns-protection.dns-protection-location Location ID for Sophos DNS Protection.
endpoint.dns-protection.domain-exclusions List of domains for which DNS requests will continue to the DNS service configured in the system.
endpoint.dns-protection.retry-nx-domain Retry with system- or application-configured DNS services when DNS Protection returns NXDOMAIN.
endpoint.dns-protection.deploy-dns-signing-cert Automatically deploy the DNS Protection signing certificate to devices to show block pages.

Feb-17, 2026

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The threat-protection and server-threat-protection policies now both support these new settings:

Name Description
endpoint.threat-protection.event-journal-writes.enabled Turn on event journal.
endpoint.threat-protection.block-remote-attacker-communication.enabled Block endpoint communicating with remote attacker IPs.

Jan-22, 2026

We have just updated the Endpoint Policy Settings reference with the following changes.

New policy

The data-collection-and-investigation and server-data-collection-and-investigation policies are added, with the following settings:

Name Description
endpoint.data-collection-and-investigation.allow-live-response-connections Live Response lets you connect directly to servers to investigate and remediate possible security issues.
endpoint.data-collection-and-investigation.enable-data-lake-uploads Manage uploads to the Data Lake from your devices. This lets you store security data in the cloud so you can query it.
endpoint.data-collection-and-investigation.edr-exclusions Exclusions for data collection and investigation policy.

May-22, 2025

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The threat-protection and server-threat-protection policies now both support these new settings:

Name Description
endpoint.threat-protection.exploit-mitigation.process-protection.access-token-protection.enabled Prevent access token manipulation.
endpoint.threat-protection.monitor-domain-controller.enabled Monitor domain controller events.

The server-threat-protection policy now supports these new settings:

Name Description
endpoint.threat-protection.network-protection.ips.all.enabled Prevent malicious network traffic with packet inspection. Replaces endpoint.threat-protection.network-protection.ips.enabled, which is limited to EAP devices only.

Removed settings

The following settings in the threat-protection and server-threat-protection policies have been removed:

Name Description
endpoint.threat-protection.exploit-mitigation.cpu-branch-tracing.enabled Enable CPU branch tracing.
endpoint.threat-protection.malware-protection.live-protection.on-demand Use Live Protection during scheduled scans.

Sep-20, 2024

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The threat-protection and server-threat-protection policies now both support these new settings:

Name Description
endpoint.threat-protection.exploit-mitigation.sys-call.enabled Prevent malicious use of syscall instructions.
endpoint.threat-protection.exploit-mitigation.device-io-control.enabled Monitor use of driver APIs.
endpoint.threat-protection.block-safeboot-usage.enabled Behavior rule to block the configuration change to boot the machine in Safe Mode, using techniques available to remote users.
endpoint.threat-protection.protect-in-safeboot.enabled Whether the endpoint enforces additional protection when booted into safeboot. All other existing policy will apply.

The threat-protection policy now supports these new settings:

Name Description
endpoint.threat-protection.network-protection.ips.all.enabled Prevent malicious network traffic with packet inspection. Replaces endpoint.threat-protection.network-protection.ips.enabled, which is limited to EAP devices only.

The server-threat-protection policy now supports these new settings:

Name Description
endpoint.threat-protection.malware-protection.on-access.scan-sspl.process-termination.enabled End malicious processes associated with a real-time threat detection.

Oct-06, 2023

We have just updated the Endpoint Policy Settings reference with the following changes.

New policy

The 'server-linux-runtime-detection' policy is added to support the Linux Runtime Detection features, with the following settings:

Name Title Description
endpoint.server-linux-runtime-detection.enabled Enable runtime detection Enable runtime detection
endpoint.server-linux-runtime-detection.profile-id Runtime detection profile ID The ID of the runtime detection profile as per the /cloud-security/v1/profiles API
endpoint.server-linux-runtime-detection.profile-version Runtime detection profile version The ID of the runtime detection profile as per the /cloud-security/v1/profiles API

New settings

The threat-protection and server-threat-protection policies now both support these new settings:

Name Title Description
endpoint.threat-protection.exploit-mitigation.c2-interceptor.enabled N/A Prevent malicious beacons connecting to command-and-control servers.
endpoint.threat-protection.exploit-mitigation.ultra-exclude.enabled Disable exploit mitigation hooks. Turn off exploit mitigation hooks.

Removed settings

The following deprecated setting in the threat-protection and server-threat-protection policies has been removed:

Name Title Description Change
endpoint.threat-protection.use-recommended-settings Use Sophos Recommended Settings Use Sophos Recommended Settings. This property is no longer supported. You can get the same result by changing settings that have warnings next to them in Sophos Fusion.

Apr-26, 2023

We have just updated the Endpoint Policy Settings reference with the following changes.

New settings

The agent-updating and server-agent-updating policies now both support these new settings:

Name Title Description
endpoint.agent-updating.software-package.windows Set static package for Windows Select the static software package you would like to use for the Windows devices in this policy. The default value is "recommended".
endpoint.agent-updating.software-package.mac Set static package for Mac Select the static software package you would like to use for the Mac devices in this policy. The default value is "recommended".

The threat-protection and server-threat-protection policies now both support these new settings:

Name Title Description
endpoint.threat-protection.exploit-mitigation Enable CookieGuard Protect browser cookies used for MFA sign-in. The default value is true.
endpoint.threat-protection.web-control.tls-decryption.quic.enabled Enable block QUIC network protocol access to websites Block QUIC (Quick UDP Internet Connections) network protocol access to websites. The default and recommended value is true.

In addition, the server-threat-protection policy now supports this new setting:

Name Title Description
endpoint.threat-protection.malware-protection.on-access.scan-sspl.enabled Enable Scan SSPL Scan SSPL enabled. The default value is true.

Changes in behavior

Name Title Description Change
endpoint.threat-protection.exploit-mitigation.all-mitigations.enabled Enable All Exploit Mitigations Turn on anti-ransomware protection and all exploit mitigations. You can now use the API to change this setting. It is no longer read-only.
endpoint.threat-protection.network-protection.connection-tracking.enabled Enable Connection Tracking Track network connections. You can now use the API to change this setting. It is no longer read-only.
endpoint.threat-protection.malware-protection.skip-trusted-installers Skip Trusted Installers Skip trusted installers You can now use the API to change this setting. It is no longer read-only.
endpoint.threat-protection.network-protection.ips.enabled Enable IPS Prevent malicious network traffic with packet inspection. Previously, the recommended value for this setting was false. We no longer recommend a value. You should set it to whatever is appropriate for your environment.

Deprecated settings

The following setting in the threat-protection and server-threat-protection policies has been deprecated:

Name Title Description Change
endpoint.threat-protection.use-recommended-settings Use Sophos Recommended Settings Use Sophos Recommended Settings. This property is no longer supported. You can get the same result by changing settings that have warnings next to them in Sophos Fusion.