Skip to main content
A common use is an RMM alert that a device is offline: the agent checks the device in Sophos Central, and when Sophos still sees it online, it writes that only the RMM agent stopped.
Automatically enabled when you configure Sophos permissions in your agent workflow.

What It Does

  • Pick the client’s Sophos Central tenant from the tenants you manage
  • Find a computer or server and read whether it is online, when it was last seen, its health, IP and MAC addresses, user and isolation state
  • Read Sophos alerts, XDR detections and MDR cases, and acknowledge, clean or clear an alert
  • Isolate an endpoint or lift the isolation, scan it, check for updates and collect a forensic log
  • Read the endpoint installer links, for an RMM script that deploys Sophos
  • Read and change allowed and blocked items, exclusions and endpoint policies
  • Run Live Discover and XDR queries
  • Read Sophos Firewalls: connection, firmware and groups; upgrade firmware and manage MDR threat feed indicators
  • Search Sophos Email quarantine, release or delete a message, and claw back a delivered one
  • Find a Sophos Mobile device and sync, locate, lock or scan it
  • Read DNS Protection, web filtering and switch and Wi-Fi settings
  • Read the directory, admins and roles, your tenants, licences, usage and the account health check

How the agent checks an RMM offline alert

The agent finds the tenant for the ticket’s company, then the device by its host name, or by its MAC address when no device has that exact name or two share it. When Sophos shows the device online now, the agent writes that the device is up and only the RMM agent stopped. When Sophos does not see it either, the agent writes when Sophos last saw it. What happens to the ticket next follows your instructions.

Permission Groups

Access Profiles

Safety Controls

How to Configure

1

Connect Sophos

Save your Sophos Central API credential in the Neo Dashboard under the Security integrations category. See Connecting Sophos to Neo.
2

Configure permissions

In your agent workflow’s Integrations tab, choose an access profile or set each permission group by hand.
Start with Read Only. Checking a device after an RMM offline alert needs only reads in Sophos; the note on the ticket is written with the PSA tools.