Skip to content

What's New

New endpoints, fields, and fixes across the Sophos Fusion APIs, dated and in one stream. Subscribe with any feed reader through the RSS feed.

Email Management API

The Email Management API now supports S/MIME. You can configure S/MIME for a tenant and manage certificates for internal users, external users, and certificate authorities.

Firewall Management API update

The new firewall configuration import/export APIs allow admins to export configuration from an existing firewall and import it into another firewall, or multiple firewalls, directly through APIs. This helps simplify configuration backup, migration, and reuse across firewall deployments without requiring manual configuration on each firewall.

Mobile API update

The Mobile API now includes basic support for policies as well as settings for the automatic enrollment of the Intercept X for Mobile app. You can create and list threatDefense policies for iOS and Android, and configure automatic enrollment of Intercept X for Mobile.

Endpoint Web Control Enhancements

Web control now includes filtering of Generative AI sites, more flexible control of specific sites, and simplified policy management. A new Web Filtering Profiles model simplifies configuration by allowing administrators to define filtering settings once and apply them consistently across multiple policies, with more granular category controls.

Audit Events API

We are pleased to announce the Audit Events API, which allows you to retrieve a paginated log of administrative and system actions taken within your Sophos Fusion account.

Organization Admins API

We are pleased to announce the Organization Admins API, which enables you to programmatically manage organization administrators and their role assignments.

DNS Protection Policies & Custom Domains APIs

We're excited to announce the general availability of two new additions to the Sophos DNS Protection API: the Policies API and the Custom Domains Lists API. Together with the existing Locations API, these complete the V2 management surface for DNS Protection.

Endpoint Tags API

We're excited to announce the general availability of the Sophos Endpoint Tags API. This new API enables you to organize and categorize your endpoints using custom key-value tags, providing greater flexibility in device management.

Business Automation API

We've published a new API that helps our distributors do business with Sophos in an easy, accurate, and efficient manner. The API includes three primary endpoints: one for retrieving all quotes associated with a distributor, one for fetching the details of a specific quote, and another for retrieving a list of partners along with their current levels.

DNS Protection Locations API

We're excited to announce the general availability of the Sophos DNS Protection Locations API. This API lets customers manage their DNS Protection Locations which can use either traditional TCP/UDP or DNS over HTTPS for applied DNS filtering and protection policies.

Firewall API update

We've just added new operations to the Firewall Management API. The MDR threat feed APIs enable the automation of actions MDR analysts can take in Sophos Firewall to block or monitor the threat indicators. When MDR detects any suspicious IP/Domain/URI, MDR Analyst needs to apply threatFeed configuration on a firewall to protect from known IOCs. To do this, MDR shall call Central exposed ThreatFeed APIs.

Data Collection and Investigation API

We’ve introduced a new endpoint and server policy in Sophos Fusion called 'Data Collection and Investigation'. This policy includes settings for enabling Data Lake Uploads and Live Response, crucial tools for threat investigation and response.

Endpoint API update

Attackers attempt to leverage compromised, unprotected devices to pivot and infiltrate other systems on a network. You can now prevent your Sophos-managed devices from communicating with these devices by specifying the IP addresses of the compromised devices. Doing this helps stop threats from spreading to or between devices in your organization. Administrators can enter the IPv4, IPv6 or address range of compromised devices. Each entry has a default expiration period of 7 days. Once an IP address is added, all Windows and Linux endpoints and servers within the customer's environment will refuse any inbound or outbound communication attempts to that address. Please ensure you don't block addresses that are important for your business operations or security, such as critical servers.

Detections API update

We've enhanced the detections and detection groups query APIs by adding additional filters to ensure consistency across all detection-related queries.

Endpoint API update

We've updated the Sophos Endpoint API to support Forensic Log Collection. Forensic Log Collection is a new feature designed to assist customers during threat investigations. It allows customers to retrieve a variety of forensic artifacts from a device, including Sophos logs, Windows Event Logs, and other relevant operating system data. The tool offers three modes - Standard, Full, and Fast - allowing customers to customize the scope and depth of the data collected.

Mobile API update

We've updated the Sophos Mobile API to support mobile device management for devices using the Sophos Mobile Control app. You can now perform additional device actions (lock, unlock, wipe, locate, unenroll, and requesting client logs). These actions require the Sophos Mobile Control app to be installed and enrolled with Sophos Mobile.

Mobile API

We're excited to announce the general availability of the Sophos Mobile API. This API lets customers manage their devices enrolled with Sophos Mobile.

Cases API updated

We’ve added the ability to create, update, and delete self-managed cases. You can now modify fields such as case status, severity, case summary, and more.

Endpoint API updated

After careful consideration, we have removed the enabled field from the response for /endpoint/v1/settings/web-control/tls-decryption. To configure SSL/TLS decryption going forwards, the endpoint.threat-protection.web-control.tls-decryption.enabled value in the threat-protection and server-threat-protection policies can be used. See the Endpoint Policy Settings Reference for more information.

Cases API

We have added a new Cases API which enables customers to leverage their own incident management tool with the Sophos XDR platform. This API provides the ability to retrieve comprehensive details about cases including case status, severity, detections, and more. Additionally, you can identify impacted entities and analyze detections associated with the case using the MITRE ATT&CK framework. See more details in the Cases API Guide.

Detections API

We have published a new Detections API to allow our XDR customers to query for detections from endpoints, servers, and third-party integrations.

Switch & Wi-Fi Management APIs

We have published two new APIs to help manage Sophos switches and Wi-Fi access points. You can now configure MAC filtering on these devices and monitor the status of configuration tasks.

Adaptive Attack Protection API

We have added new operations to the Endpoint API that let you activate or deactivate "Adaptive Attack Protection" on a device. This setting applies more aggressive protection while investigating suspicious activity and is ideal for scenarios where fully isolating the device from the network may cause significant operational disruption to your organization. You can also extend the time that Adaptive Attack Protection is activated on a device to give you more time to complete an investigation. See the product documentation for more details about about Adaptive Attack Protection feature.

Endpoint API updated

We have added a "locked by managing account" field to the scanning exclusions section of the Endpoint API. This indicates whether or not the partner manages the exclusion.

Cloud Security API

We are pleased to announce a new API to help you manage security for your cloud resources. Cloud security covers Sophos Workload Protection and Sophos Cloud Optix. You can use this API to manage Linux runtime detection profiles for the Linux Server Protection Agent and the Sophos Linux Sensor.

Firewall Actions API

We've just added new operations to the Firewall Management API. You can now view available firmware updates and apply them to your firewalls.

Endpoint Migration API

We have just updated the Endpoint v1 API with additional routes to allow migrating endpoints from one tenant to another. Check out the details in the Endpoint Migration API guide. Over the next few days, we plan to release other major (backward compatible!) updates to the Endpoint API to manage endpoint policies and groups; keep an eye out for those. Also, we would appreciate your feedback on the community forum here.

User Activity Verification API

We've added an API for creating "attestations". Attestations are small questions with predefined answers you send to a user's mobile device. The user can easily respond to the question by clicking one of the provided answers.

XDR Query API GA

We are excited to announce that the Sophos XDR Query API is now generally available. This API allows you query the new Sophos Data Lake.

Endpoint API updates

We have made a few improvements to the Endpoint API that allow you to isolate endpoints, either one at a time or in bulk, and manage isolation exclusions. We have also added new filtering options when searching for endpoints.

Endpoint Global Settings updated

Following our second drop last month of Global Settings management using the Endpoint v1 API, we have just added support for managing Intrusion Prevention (IPS) exclusions.

Endpoint Global Settings - Part Deux

Three months ago we released our first set of APIs to manage endpoint-related global settings, specifically, allowed/blocked items, web control settings, and global tamper-protection. We now have a second set of routes available in the Endpoint API to allow you to manage some additional global settings: scanning exclusions and Exploit Mitigation settings. Read on for how to use these new APIs.