Endpoint API update
Attackers attempt to leverage compromised, unprotected devices to pivot and infiltrate other systems on a network. You can now prevent your Sophos-managed devices from communicating with these devices by specifying the IP addresses of the compromised devices. Doing this helps stop threats from spreading to or between devices in your organization. Administrators can enter the IPv4, IPv6 or address range of compromised devices. Each entry has a default expiration period of 7 days. Once an IP address is added, all Windows and Linux endpoints and servers within the customer's environment will refuse any inbound or outbound communication attempts to that address. Please ensure you don't block addresses that are important for your business operations or security, such as critical servers.
See the API reference documentation, or the Sophos Central Admin Guide, for more information.