<?xml version="1.0" encoding="UTF-8" ?> <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/"> <channel> <title>API Reference</title><link>https://developer.sophos.com/</link><atom:link href="https://developer.sophos.com/whatsnew/rss.xml" rel="self" type="application/rss+xml" /> <language>en</language> <pubDate>Fri, 18 Sep 2026 13:45:31 -0000</pubDate> <lastBuildDate>Fri, 18 Sep 2026 13:45:31 -0000</lastBuildDate> <ttl>1440</ttl> <generator>MkDocs RSS plugin - v1.17.9</generator> <image> <url>None</url> <title>API Reference</title> <link>https://developer.sophos.com/</link> </image> <item> <title>New Fusion XDR GraphQL APIs and Classic XDR API deprecation</title> <description>Use the new Fusion XDR APIs and migrate from the Classic XDR APIs.</description> <link>https://developer.sophos.com/whatsnew/sep-18-2026-xdr-graphql-apis/</link> <pubDate>Fri, 18 Sep 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/sep-18-2026-xdr-graphql-apis/</guid> </item> <item> <title>Firewall Management API update</title> <description>&lt;p&gt;The new firewall configuration import/export APIs allow admins to export configuration from an existing firewall and import it into another firewall, or multiple firewalls, directly through APIs. This helps simplify configuration backup, migration, and reuse across firewall deployments without requiring manual configuration on each firewall.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/jul-16-2026-firewall-api-update/</link> <pubDate>Thu, 16 Jul 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jul-16-2026-firewall-api-update/</guid> </item> <item> <title>Mobile API update</title> <description>&lt;p&gt;The Mobile API now includes basic support for policies as well as settings for the automatic enrollment of the Intercept X for Mobile app. You can create and list &lt;code&gt;threatDefense&lt;/code&gt; policies for iOS and Android, and configure automatic enrollment of Intercept X for Mobile.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/jul-8-2026-mobile-api-update/</link> <pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jul-8-2026-mobile-api-update/</guid> </item> <item> <title>Endpoint Web Control Enhancements</title> <description>&lt;p&gt;Web control now includes filtering of Generative AI sites, more flexible control of specific sites, and simplified policy management. A new Web Filtering Profiles model simplifies configuration by allowing administrators to define filtering settings once and apply them consistently across multiple policies, with more granular category controls.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/jun-23-2026-web-control-enhancements/</link> <pubDate>Tue, 23 Jun 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jun-23-2026-web-control-enhancements/</guid> </item> <item> <title>Audit Events API</title> <description>&lt;p&gt;We are pleased to announce the Audit Events API, which allows you to retrieve a paginated log of administrative and system actions taken within your Sophos Central account.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/jun-09-2026-audit-events-api/</link> <pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jun-09-2026-audit-events-api/</guid> </item> <item> <title>Partner Admins API update</title> <description>&lt;p&gt;The Partner Admins API now lets you delete a partner administrator using &lt;code&gt;DELETE /partner/v1/admins/{adminId}&lt;/code&gt;.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/jun-08-2026-partner-admins-api-update/</link> <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jun-08-2026-partner-admins-api-update/</guid> </item> <item> <title>Organization Admins API</title> <description>&lt;p&gt;We are pleased to announce the Organization Admins API, which enables you to programmatically manage organization administrators and their role assignments.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/jun-03-2026-organization-admins-api/</link> <pubDate>Wed, 03 Jun 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jun-03-2026-organization-admins-api/</guid> </item> <item> <title>DNS Protection Policies &amp; Custom Domains APIs</title> <description>&lt;p&gt;We&#39;re excited to announce the general availability of two new additions to the Sophos DNS Protection API: the &lt;strong&gt;Policies API&lt;/strong&gt; and the &lt;strong&gt;Custom Domains Lists API&lt;/strong&gt;. Together with the existing Locations API, these complete the V2 management surface for DNS Protection.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/may-11-2026-dns-protection-policies-and-custom-domains-apis/</link> <pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/may-11-2026-dns-protection-policies-and-custom-domains-apis/</guid> </item> <item> <title>Device Software API</title> <description>&lt;p&gt;We have published the Device Software API. This new API allows you to assign device software to your endpoints in bulk.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/apr-07-2026-device-software-api/</link> <pubDate>Tue, 07 Apr 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/apr-07-2026-device-software-api/</guid> </item> <item> <title>Endpoint Tags API</title> <description>&lt;p&gt;We&#39;re excited to announce the general availability of the Sophos Endpoint Tags API. This new API enables you to organize and categorize your endpoints using custom key-value tags, providing greater flexibility in device management.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/mar-16-2026-tagging-api/</link> <pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/mar-16-2026-tagging-api/</guid> </item> <item> <title>Business Automation API</title> <description>&lt;p&gt;We&#39;ve published a new API that helps our distributors do business with Sophos in an easy, accurate, and efficient manner. The API includes three primary endpoints: one for retrieving all quotes associated with a distributor, one for fetching the details of a specific quote, and another for retrieving a list of partners along with their current levels.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/nov-21-2025-business-automation-api/</link> <pubDate>Fri, 21 Nov 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/nov-21-2025-business-automation-api/</guid> </item> <item> <title>DNS Protection Locations API</title> <description>&lt;p&gt;We&#39;re excited to announce the general availability of the Sophos DNS Protection Locations API. This API lets customers manage their DNS Protection Locations which can use either traditional TCP/UDP or DNS over HTTPS for applied DNS filtering and protection policies.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/oct-23-2025-dns-protection-locations-api/</link> <pubDate>Thu, 23 Oct 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/oct-23-2025-dns-protection-locations-api/</guid> </item> <item> <title>Firewall API update</title> <description>&lt;p&gt;We&#39;ve just added new operations to the Firewall Management API. The MDR threat feed APIs enable the automation of actions MDR analysts can take in Sophos Firewall to block or monitor the threat indicators. When MDR detects any suspicious IP/Domain/URI, MDR Analyst needs to apply threatFeed configuration on a firewall to protect from known IOCs. To do this, MDR shall call Central exposed ThreatFeed APIs.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/oct-10-2025-firewall-api-updated/</link> <pubDate>Fri, 10 Oct 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/oct-10-2025-firewall-api-updated/</guid> </item> <item> <title>Data Collection and Investigation API</title> <description>&lt;p&gt;We’ve introduced a new endpoint and server policy in Sophos Central called &#39;Data Collection and Investigation&#39;. This policy includes settings for enabling Data Lake Uploads and Live Response, crucial tools for threat investigation and response.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/oct-07-2025-data-collection-api/</link> <pubDate>Tue, 07 Oct 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/oct-07-2025-data-collection-api/</guid> </item> <item> <title>Endpoint API update</title> <description>&lt;h2&gt;Enhancing Threat Investigations: Memory Dump Collection in Forensic Logs {#memory-dump-collection}&lt;/h2&gt;</description> <link>https://developer.sophos.com/whatsnew/jul-24-2025-endpoint-api-updated/</link> <pubDate>Thu, 24 Jul 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/jul-24-2025-endpoint-api-updated/</guid> </item> <item> <title>Endpoint API update</title> <description>&lt;p&gt;Attackers attempt to leverage compromised, unprotected devices to pivot and infiltrate other systems on a network. You can now prevent your Sophos-managed devices from communicating with these devices by specifying the IP addresses of the compromised devices. Doing this helps stop threats from spreading to or between devices in your organization. Administrators can enter the IPv4, IPv6 or address range of compromised devices. Each entry has a default expiration period of 7 days. Once an IP address is added, all Windows and Linux endpoints and servers within the customer&#39;s environment will refuse any inbound or outbound communication attempts to that address. Please ensure you don&#39;t block addresses that are important for your business operations or security, such as critical servers.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/may-07-2025-endpoint-api-updated/</link> <pubDate>Wed, 07 May 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/may-07-2025-endpoint-api-updated/</guid> </item> <item> <title>Endpoint API update</title> <description>&lt;p&gt;We have added support for reporting as well as searching by the following new fields:&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/apr-09-2025-endpoint-api-updated/</link> <pubDate>Wed, 09 Apr 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/apr-09-2025-endpoint-api-updated/</guid> </item> <item> <title>Detections API update</title> <description>&lt;p&gt;We&#39;ve enhanced the detections and detection groups query APIs by adding additional filters to ensure consistency across all detection-related queries.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/apr-03-2025-detections-api-update/</link> <pubDate>Thu, 03 Apr 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/apr-03-2025-detections-api-update/</guid> </item> <item> <title>Endpoint API update</title> <description>&lt;p&gt;We&#39;ve updated the Sophos Endpoint API to support Forensic Log Collection. Forensic Log Collection is a new feature designed to assist customers during threat investigations. It allows customers to retrieve a variety of forensic artifacts from a device, including Sophos logs, Windows Event Logs, and other relevant operating system data. The tool offers three modes - Standard, Full, and Fast - allowing customers to customize the scope and depth of the data collected.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/mar-06-2025-endpoint-api-updated/</link> <pubDate>Thu, 06 Mar 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/mar-06-2025-endpoint-api-updated/</guid> </item> <item> <title>Mobile API update</title> <description>&lt;p&gt;We&#39;ve updated the Sophos Mobile API to support mobile device management for devices using the Sophos Mobile Control app. You can now perform additional device actions (lock, unlock, wipe, locate, unenroll, and requesting client logs). These actions require the Sophos Mobile Control app to be installed and enrolled with Sophos Mobile.&lt;/p&gt;</description> <link>https://developer.sophos.com/whatsnew/feb-06-2025-mobile-api-updates/</link> <pubDate>Thu, 06 Feb 2025 00:00:00 +0000</pubDate> <source url="https://developer.sophos.com/whatsnew/rss.xml">API Reference</source><guid isPermaLink="true">https://developer.sophos.com/whatsnew/feb-06-2025-mobile-api-updates/</guid> </item> </channel> </rss>