> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Sophos API

> Check a device in Sophos when your RMM says it is offline, read and act on Sophos alerts, isolate and scan endpoints, manage allow and block lists, and read firewalls, email quarantine, mobile devices and licences, for each Sophos Central tenant you manage

A common use is an RMM alert that a device is offline: the agent checks the device in Sophos Central, and when Sophos still sees it online, it writes that only the RMM agent stopped.

<Info>
  Automatically enabled when you configure Sophos permissions in your agent workflow.
</Info>

## What It Does

* Pick the client's Sophos Central tenant from the tenants you manage
* Find a computer or server and read whether it is online, when it was last seen, its health, IP and MAC addresses, user and isolation state
* Read Sophos alerts, XDR detections and MDR cases, and acknowledge, clean or clear an alert
* Isolate an endpoint or lift the isolation, scan it, check for updates and collect a forensic log
* Read the endpoint installer links, for an RMM script that deploys Sophos
* Read and change allowed and blocked items, exclusions and endpoint policies
* Run Live Discover and XDR queries
* Read Sophos Firewalls: connection, firmware and groups; upgrade firmware and manage MDR threat feed indicators
* Search Sophos Email quarantine, release or delete a message, and claw back a delivered one
* Find a Sophos Mobile device and sync, locate, lock or scan it
* Read DNS Protection, web filtering and switch and Wi-Fi settings
* Read the directory, admins and roles, your tenants, licences, usage and the account health check

## How the agent checks an RMM offline alert

The agent finds the tenant for the ticket's company, then the device by its host name, or by its MAC address when no device has that exact name or two share it. When Sophos shows the device online now, the agent writes that the device is up and only the RMM agent stopped. When Sophos does not see it either, the agent writes when Sophos last saw it. What happens to the ticket next follows your instructions.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Endpoints | Disabled, Read Only, Read / Write | Computers and servers, isolation, scans, groups, tags, Tamper Protection, forensic logs |
| Endpoint Policies and Settings | Disabled, Read Only, Read / Write | Endpoint policies and global settings, cloud workload profiles |
| Allowed and Blocked Items, Exclusions | Disabled, Read Only, Read / Write | Allowed and blocked items and addresses, exclusions, local website categories |
| Alerts, Detections and Cases | Disabled, Read Only, Read / Write | Alerts and alert actions, detections, MDR cases, the SIEM feed |
| Live Discover and XDR Query | Disabled, Read Only, Read / Write | Queries on live devices and the XDR data lake |
| Firewalls | Disabled, Read Only, Read / Write | Sophos Firewalls, groups, firmware, MDR threat feed |
| Email Security | Disabled, Read Only, Read / Write | Quarantine, clawback, protected mailboxes, S/MIME |
| Mobile Devices | Disabled, Read Only, Read / Write | Sophos Mobile devices, groups, apps, policies and actions |
| DNS Protection, Web Filtering, Switches and Wi-Fi | Disabled, Read Only, Read / Write | DNS Protection, web filtering profiles and site lists, MAC filtering |
| Directory Users and Groups | Disabled, Read Only, Read / Write | The tenant's Sophos users and user groups |
| Admins, Roles and API Tokens | Disabled, Read Only, Read / Write | Admins and roles at every level, account access tokens |
| Tenants, Licences and Account Health | Disabled, Read Only, Read / Write | Your tenants, licences and usage, the account health check, the audit log |

## Access Profiles

| Profile | What runs on its own | What asks a technician |
| - | - | - |
| **Read Only** | Every read | No write is allowed |
| **Helpdesk** | Every read | Every write |
| **IT Admin** | Isolating and scanning endpoints, alert actions, email releases and clawback, mobile actions, directory changes | Policies, block lists, filtering lists, admins and account changes, and every write under Safety Controls |
| **Full Automation** | Every write except those below | Only the writes below |

## Safety Controls

| Control | Behavior |
| - | - |
| **Endpoints** | Lifting an isolation, deleting an endpoint, turning Adaptive Attack Protection off, turning Tamper Protection off and regenerating its password always ask a technician |
| **Allow lists and exclusions** | Every change to an allowed item, an exclusion (scanning, intrusion prevention, isolation, TLS decryption), an Exploit Mitigation application or a local site, taking a website category out of TLS decryption, and removing a blocked item or blocked addresses, always ask a technician |
| **Endpoint policies** | Changing assigned device software always asks a technician. So does a policy change whose settings turn a protection off, set an allow, exclusion or block list, turn on a monitor-only or skip mode, limit web control to a schedule, pick another web filtering or runtime detection profile, or lower an action or level, and a cloud runtime detection profile that turns a rule off or changes a list other than adding to a block list. Turning a policy off, assigning it or resetting it follows the group, because its devices fall back to the base policy |
| **Alerts** | Authorizing a potentially unwanted application always asks a technician |
| **Email** | A release that adds the sender to the allow list, removing a mailbox from protection and every S/MIME change always ask a technician |
| **Mobile** | A wipe, an unenroll, deleting a device, creating or deleting the Intercept X for Mobile auto-enrollment or rotating its connection code, and a device group change that sets iOS auto-enrollment always ask a technician |
| **Firewalls** | Deleting a firewall, removing MDR threat feed indicators, and turning the MDR threat feed off or to log only always ask a technician |
| **DNS Protection and web filtering** | Replacing a web filtering profile, a new profile that allows, warns or turns filtering off, and a DNS Protection policy change that allows a category or custom domains, removes a block, turns safe search or custom domains off or picks a category preset always ask a technician |
| **Access and billing** | Every admin, role and access token change, and creating or changing a tenant, its products or the default products, always ask a technician |
| **Passwords** | Neo removes every password, Tamper Protection passwords included, from what Sophos returns |
| **Installer links** | An agent with Endpoints access can read the endpoint installer links, which carry your tenant's installer token, so an RMM script can deploy Sophos |
| **Right tenant** | A call names the client's tenant; a tenant your credential does not manage is refused |
| **Refused** | Neo does not create an access token, migrate endpoints to another tenant, delete the S/MIME configuration, export or import a firewall configuration or read an export's download link, download quarantined attachments or read their download links, download S/MIME certificate files, or call the distributor-only Business Automation API |

## How to Configure

<Steps>
  <Step title="Connect Sophos">
    Save your Sophos Central API credential in the Neo Dashboard under the **Security** integrations category. See [Connecting Sophos to Neo](/integrations/sophos/connecting-to-neo).
  </Step>

  <Step title="Configure permissions">
    In your agent workflow's **Integrations** tab, choose an access profile or set each permission group by hand.
  </Step>
</Steps>

<Tip>
  Start with **Read Only**. Checking a device after an RMM offline alert needs only reads in Sophos; the note on the ticket is written with the PSA tools.
</Tip>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.