Email Management API
The Email Management API now supports S/MIME. You can configure S/MIME for a tenant and manage certificates for internal users, external users, and certificate authorities.
New endpoints, fields, and fixes across the Sophos Fusion APIs, dated and in one stream. Subscribe with any feed reader through the RSS feed.
The Email Management API now supports S/MIME. You can configure S/MIME for a tenant and manage certificates for internal users, external users, and certificate authorities.
Date: 2026-09-18 API: Fusion XDR APIs
We added five GraphQL APIs to Fusion XDR. Use GraphQL for all new Fusion XDR integrations and write workflows.
The new firewall configuration import/export APIs allow admins to export configuration from an existing firewall and import it into another firewall, or multiple firewalls, directly through APIs. This helps simplify configuration backup, migration, and reuse across firewall deployments without requiring manual configuration on each firewall.
The Mobile API now includes basic support for policies as well as settings for the automatic enrollment of the Intercept X for Mobile app. You can create and list threatDefense policies for iOS and Android, and configure automatic enrollment of Intercept X for Mobile.
Web control now includes filtering of Generative AI sites, more flexible control of specific sites, and simplified policy management. A new Web Filtering Profiles model simplifies configuration by allowing administrators to define filtering settings once and apply them consistently across multiple policies, with more granular category controls.
We are pleased to announce the Audit Events API, which allows you to retrieve a paginated log of administrative and system actions taken within your Sophos Fusion account.
The Partner Admins API now lets you delete a partner administrator using DELETE /partner/v1/admins/{adminId}.
We are pleased to announce the Organization Admins API, which enables you to programmatically manage organization administrators and their role assignments.
We're excited to announce the general availability of two new additions to the Sophos DNS Protection API: the Policies API and the Custom Domains Lists API. Together with the existing Locations API, these complete the V2 management surface for DNS Protection.
We have published the Device Software API. This new API allows you to assign device software to your endpoints in bulk.
We're excited to announce the general availability of the Sophos Endpoint Tags API. This new API enables you to organize and categorize your endpoints using custom key-value tags, providing greater flexibility in device management.
We've published a new API that helps our distributors do business with Sophos in an easy, accurate, and efficient manner. The API includes three primary endpoints: one for retrieving all quotes associated with a distributor, one for fetching the details of a specific quote, and another for retrieving a list of partners along with their current levels.
We're excited to announce the general availability of the Sophos DNS Protection Locations API. This API lets customers manage their DNS Protection Locations which can use either traditional TCP/UDP or DNS over HTTPS for applied DNS filtering and protection policies.
We've just added new operations to the Firewall Management API. The MDR threat feed APIs enable the automation of actions MDR analysts can take in Sophos Firewall to block or monitor the threat indicators. When MDR detects any suspicious IP/Domain/URI, MDR Analyst needs to apply threatFeed configuration on a firewall to protect from known IOCs. To do this, MDR shall call Central exposed ThreatFeed APIs.
We’ve introduced a new endpoint and server policy in Sophos Fusion called 'Data Collection and Investigation'. This policy includes settings for enabling Data Lake Uploads and Live Response, crucial tools for threat investigation and response.
Attackers attempt to leverage compromised, unprotected devices to pivot and infiltrate other systems on a network. You can now prevent your Sophos-managed devices from communicating with these devices by specifying the IP addresses of the compromised devices. Doing this helps stop threats from spreading to or between devices in your organization. Administrators can enter the IPv4, IPv6 or address range of compromised devices. Each entry has a default expiration period of 7 days. Once an IP address is added, all Windows and Linux endpoints and servers within the customer's environment will refuse any inbound or outbound communication attempts to that address. Please ensure you don't block addresses that are important for your business operations or security, such as critical servers.
We have added support for reporting as well as searching by the following new fields:
We've enhanced the detections and detection groups query APIs by adding additional filters to ensure consistency across all detection-related queries.
We've updated the Sophos Endpoint API to support Forensic Log Collection. Forensic Log Collection is a new feature designed to assist customers during threat investigations. It allows customers to retrieve a variety of forensic artifacts from a device, including Sophos logs, Windows Event Logs, and other relevant operating system data. The tool offers three modes - Standard, Full, and Fast - allowing customers to customize the scope and depth of the data collected.
We've updated the Sophos Mobile API to support mobile device management for devices using the Sophos Mobile Control app. You can now perform additional device actions (lock, unlock, wipe, locate, unenroll, and requesting client logs). These actions require the Sophos Mobile Control app to be installed and enrolled with Sophos Mobile.
We're excited to announce the general availability of the Sophos Mobile API. This API lets customers manage their devices enrolled with Sophos Mobile.
We have updated the Email Management API to allow mailbox management in Sophos Email. Using this API, you can create, read, search, update, and delete mailboxes in Sophos Email. See the Email Mailbox Management API Guide for more details.
We’ve added the ability to create, update, and delete self-managed cases. You can now modify fields such as case status, severity, case summary, and more.
After careful consideration, we have removed the enabled field from the response for /endpoint/v1/settings/web-control/tls-decryption. To configure SSL/TLS decryption going forwards, the endpoint.threat-protection.web-control.tls-decryption.enabled value in the threat-protection and server-threat-protection policies can be used. See the Endpoint Policy Settings Reference for more information.
We have published a licensing API which allows you to view license details for MSP accounts.
We have added a new Cases API which enables customers to leverage their own incident management tool with the Sophos XDR platform. This API provides the ability to retrieve comprehensive details about cases including case status, severity, detections, and more. Additionally, you can identify impacted entities and analyze detections associated with the case using the MITRE ATT&CK framework. See more details in the Cases API Guide.
We have published a new Detections API to allow our XDR customers to query for detections from endpoints, servers, and third-party integrations.
We have published two new APIs to help manage Sophos switches and Wi-Fi access points. You can now configure MAC filtering on these devices and monitor the status of configuration tasks.
We have now added the Account Health Check Historical Scores API, giving the ability to fetch historical scores for your account, to see how your scores have changed over time.
We have added new operations to the Endpoint API that let you activate or deactivate "Adaptive Attack Protection" on a device. This setting applies more aggressive protection while investigating suspicious activity and is ideal for scenarios where fully isolating the device from the network may cause significant operational disruption to your organization. You can also extend the time that Adaptive Attack Protection is activated on a device to give you more time to complete an investigation. See the product documentation for more details about about Adaptive Attack Protection feature.
We have added a "locked by managing account" field to the scanning exclusions section of the Endpoint API. This indicates whether or not the partner manages the exclusion.
We have added functionality to the Endpoint API that allows you to delete multiple devices at once.
We have now added the Account Health Check Regional Scores API, giving the ability to fetch scores for other organizations in your region so you can see how your scores compare.
We are pleased to announce a new API to help you manage security for your cloud resources. Cloud security covers Sophos Workload Protection and Sophos Cloud Optix. You can use this API to manage Linux runtime detection profiles for the Linux Server Protection Agent and the Sophos Linux Sensor.
We have updated the Email Management API to allow clawing back messages in Sophos Email. For more details, see the Email Clawback API guide.
We have updated the Account Health Check API to show a score for each of your checks. These reflect whether your devices or policies are using recommended, secure settings.
We recently added the Account Health Check Snooze API to allow you to document that you've decided to defer fixing health issues identified by Account Health Check API.
We have updated the Account Health Check API to allow requesting a selection of health checks:
We've just added new operations to the Firewall Management API. You can now view available firmware updates and apply them to your firewalls.
We have added a new Account Health Check API, which allows you to get the Account Health Check results for your account.
We have updated the Endpoint v1 API with new functionality to manage groups of endpoints as well as endpoint policies. We have added two extensive guides to these new APIs:
We are excited to present a new API for managing settings associated with your Sophos account! For now, this API allows you to manage access tokens that you can use to install the Sophos Linux Sensor (SLS).
We have just updated the Endpoint v1 API with additional routes to allow migrating endpoints from one tenant to another. Check out the details in the Endpoint Migration API guide. Over the next few days, we plan to release other major (backward compatible!) updates to the Endpoint API to manage endpoint policies and groups; keep an eye out for those. Also, we would appreciate your feedback on the community forum here.
We've added an API for creating "attestations". Attestations are small questions with predefined answers you send to a user's mobile device. The user can easily respond to the question by clicking one of the provided answers.
We have just added an API route to the Endpoint API to help you automate the deployment of the Sophos Endpoint agent.
We are pleased to announce a few major additions to our Partner API.
We are excited to announce that the Sophos XDR Query API is now generally available. This API allows you query the new Sophos Data Lake.
We have made a few improvements to the Endpoint API that allow you to isolate endpoints, either one at a time or in bulk, and manage isolation exclusions. We have also added new filtering options when searching for endpoints.
We are pleased to announce that the Live Discover API is now available. You can now run EDR queries against online endpoints and see the query results being returned in real-time.
Following our second drop last month of Global Settings management using the Endpoint v1 API, we have just added support for managing Intrusion Prevention (IPS) exclusions.
Three months ago we released our first set of APIs to manage endpoint-related global settings, specifically, allowed/blocked items, web control settings, and global tamper-protection. We now have a second set of routes available in the Endpoint API to allow you to manage some additional global settings: scanning exclusions and Exploit Mitigation settings. Read on for how to use these new APIs.