Add Sophos XDR as a posture provider

Available on: Enterprise

Firezone syncs endpoint inventory from Sophos Central to evaluate endpoint health, threat status, disk encryption, and recent activity. Sophos posture fields apply to Windows, macOS, and Linux, with narrower support for some checks.

Before you begin

Complete the shared prerequisites. You need access to administer your Sophos Central tenant and an endpoint with a reporting Sophos agent.

The connection requires tenant API credentials that can call GET /endpoint/v1/endpoints. Partner and organization credentials are not supported, because they do not belong to a single tenant.

Prepare the API credentials

  1. In Sophos Central, open Global Settings → Access Control → API Credentials.
  2. Select Add Credential and enter a name, such as Firezone.
  3. Select the Service Principal Read-Only role.
  4. Copy the Client ID and Client Secret. Sophos shows the secret only once.

Firezone reads endpoint inventory and does not require write permissions. Sophos API credentials expire without an alert and cannot be renewed. Record the expiry so you can create and add new credentials before the old ones stop working.

Add the provider

  1. In Firezone, open Settings → Device Posture → Add posture provider and select Sophos XDR.
  2. Enter a Name, the Client ID, and the Client Secret.
  3. Select Verify Now. Firezone asks Sophos which tenant the credentials belong to and which regional API host serves it. After Verified appears, the Tenant ID is shown. Select Create.
  4. Request Sync Now from the provider's actions menu and wait for Last Synced to update.
  5. Open your test device's Posture tab and confirm its Sophos record appears with the expected serial number and health.

Firezone matches Sophos endpoints by hardware serial. Use Device Trust to attest that serial and enable Require attestation on the Policy. A matching hostname or MAC address alone does not associate a Sophos record with a Firezone Client.

Sophos documentation states that only Mac endpoints report a serial number. In practice, Windows and most Linux endpoints report one too. An endpoint that reports no serial syncs to Firezone but matches no Client.

Use Sophos evidence in Policies

Follow the Policy setup steps to select the simplified checks you need.

CheckSophos evidence
Disk encryptionEndpoint reports an overall encryption status of encrypted.
Endpoint protection activeEndpoint reports a services health of good.
No active threatsEndpoint reports a threats health of good.
Recently seenEndpoint was seen within seven days.
OS up to dateFirezone evaluates the reported macOS release. This field does not apply to Windows or Linux.

For an explicit requirement that tamper protection is on for every matched Sophos record, use the JSON tab.

{
  "field": "sophos.tamper_protection_enabled",
  "op": "is",
  "value": true,
  "rows": "all"
}

See the Sophos attribute reference for overall health, isolation, lockdown, assigned products, and other fields.

Troubleshooting

If verification fails, check that the client ID and secret are correct and have not expired. If Firezone reports partner or organization credentials, create new API credentials inside the tenant itself.

If an endpoint syncs but does not match a Client, inspect its reported serial and compare it with the Firezone device identity. A missing or different serial prevents a match even when the endpoint is otherwise healthy.

If a device was reinstalled, Sophos can keep its old endpoint record next to the new one, with the same serial. Firezone uses only the most recently seen of these records. Remove the old endpoint in Sophos Central to keep the inventory clean.

If a check fails, inspect the endpoint's health, encryption, and last seen values in the Posture tab. Resolve the state in Sophos, let the agent report it, and request Sync Now in Firezone.

To rotate the credentials, edit the provider, paste the new client ID and secret, select Verify Now, and Save. Confirm that inventory sync succeeds before deleting the previous credentials in Sophos Central.


Need help? See all support options.