Skip to content
Avanet
Product gallery
Sophos Central Intercept X Advanced licence box

Sophos Endpoint User

Loading the current price.

Configure Fusion licence

Select the licence transaction, term, entitlement and quantity. The applicable volume price is applied automatically.

Configure product

Product ID
—
Price per licence
—
Total price
—

Current configuration options and prices are being loaded through the Commerce API.

Delivery

Free shipping from €200

Delivery time
Loaded through the Commerce API
Availability
Loaded through the Commerce API
Ship to
Loaded through the Commerce API
Payment methods:
  • Visa
  • Mastercard
  • American Express
  • PayPal
  • TWINT
  • Bitcoin
  • Bank transfer
  • Invoice
Category:
Sophos Fusion
Product ID:
sophos-endpoint-user

Description

Learn more about Sophos Endpoint User

Endpoint protection for everyday work

Sophos Endpoint User protects employees’ computers against malware, ransomware and attacks on applications. The solution was formerly called Central Intercept X Advanced. Protection policies, alerts and device status are managed centrally, giving IT visibility even across distributed workstations.

Several mechanisms complement each other: file checks, behavioural analysis and exploit defence look for malicious files and attack techniques. CryptoGuard detects suspicious file encryption, can stop the responsible process and restore affected files from its recovery copies. This reduces damage but does not replace an independent backup.

Available features depend on the operating system. Sophos Endpoint User is the user licence for workstations; servers require the corresponding server product. Sophos EDR or XDR offer more extensive investigations and manual response tools.

Exploit Prevention

An unpatched vulnerability can become an entry point for an attack. Exploit defence therefore targets common attack techniques and can block malicious actions even when the specific malware is not yet known.

It complements updates and other protection mechanisms. Vulnerabilities must still be patched; a protection feature does not guarantee coverage of every application or attack.

Root Cause Analysis

A blocked file often raises further questions: which process launched it and what happened next? Graphical root cause analysis displays available relationships and helps IT interpret a detection.

Sophos Endpoint therefore provides context for incidents. Sophos EDR and Sophos XDR go further with active threat hunting, additional data queries and response options. An analyst team working around the clock is included only with the MDR service.

Automatic cleanup

Detected malware should not remain on the device. Sophos Endpoint can automatically clean up malicious files and related traces, and highlights cases requiring IT intervention.

Cleanup does not guarantee that the entire computer returns to its original state after every attack. Confirmed compromises still require further investigation and, where necessary, recovery.

Technical specifications

Sophos Endpoint and MDR compared

Compare workstation protection: Endpoint protects devices, XDR extends investigation, and MDR adds an analyst team. MDR Plus also provides incident response for monitored systems with full Sophos XDR. Features depend on the operating system, configuration and platform migration status. The MDR columns refer to our packages including Sophos Endpoint and XDR, not sensor-only operation with another endpoint solution.

Scroll the comparison table horizontally.

Sophos Endpoint, XDR, MDR and MDR Plus feature comparison for users
Function
Current product Endpoint User Current page
XDR User View product
MDR User View product
Recommended MDR Plus User View product
Multiple policies✓✓✓✓
Controlled updates✓✓✓✓
Application Control✓✓✓✓
Peripheral control✓✓✓✓
Web Control / category-based URL filtering✓✓✓✓
Download reputation (Windows)✓✓✓✓
Web Security✓✓✓✓
Deep learning malware detection✓✓✓✓
Anti-malware file scanning✓✓✓✓
Live Protection✓✓✓✓
Pre-execution behavioural analysis (HIPS)✓✓✓✓
Blocking potentially unwanted applications (PUAs)✓✓✓✓
Intrusion Prevention System (IPS) (Windows)✓✓✓✓
Data Loss Prevention (Windows)✓✓✓✓
Runtime behavioural analysis (HIPS)✓✓✓✓
Antimalware Scan Interface (AMSI) (Windows)✓✓✓✓
Malicious Traffic Detection (MTD)✓✓✓✓
Exploit Prevention (Windows)✓✓✓✓
Active Adversary Mitigations✓✓✓✓
Ransomware File Protection (CryptoGuard)✓✓✓✓
Disk and Boot Record Protection (WipeGuard) (Windows)✓✓✓✓
Man-in-the-Browser Protection (Safe Browsing)✓✓✓✓
Enhanced Application Lockdown (Windows)✓✓✓✓
Live Discover (cross-environment SQL queries for threat hunting and security compliance)—✓✓✓
SQL query library (prewritten, customisable queries)—✓✓✓
Local event data for Live Discover (storage-limited)—✓✓✓
Cross-product data sources (e.g. firewall, email)—✓✓✓
Cross-product queries—✓✓✓
Sophos Data Lake (classic, within storage limits)—Up to 90 daysUp to 90 daysUp to 90 days
Scheduled queries—✓✓✓
Graphical root cause analysis✓✓✓✓
Deep learning malware analysis—✓✓✓
Advanced SophosLabs threat intelligence on demand—✓✓✓
Forensic data export—✓✓✓
Automated malware removal✓✓✓✓
Synchronized Security Heartbeat✓✓✓✓
Automatic cleanup✓✓✓✓
Live Response (remote terminal for further analysis and response)—✓✓✓
On-demand endpoint isolation—✓✓✓
Microsoft 365 response actions with integration and authorisation—✓✓✓
24/7 evidence-based threat hunting——✓✓
Integration of supported third-party security products—✓✓✓
Security Health Checks——✓✓
Activity reports——✓✓
Threat intelligence for MDR investigations——✓✓
Attack detection——✓✓
Stopping and containing threats——✓✓
Direct telephone support during incidents——✓✓
Proactive threat hunting——✓✓
Security configuration recommendations——✓✓
Incident response and neutralisation on monitored systems with full Sophos XDR———✓
Incident response closure with root cause analysis and recommendations———✓
Dedicated contact in the incident response team———✓
AI investigation case summaries—✓✓✓
AI search for security investigations (depending on source and platform)—✓✓✓

Avanet Services

Let us improve your security

Our services help you operate Sophos products securely and reliably. Alongside support for Sophos firewalls and the Fusion platform, you can request these services at any time:

  • Setup services
  • Health check
  • Upgrades
  • Workshops
  • Migrations
  • Firewall maintenance
  • SLA
  • Security audits
Request more information

Setup services

Want professionals to set up your Sophos products? We help with commissioning and configuration for smooth operation.

Migrations

Moving from an SG Firewall (UTM) to XGS with SFOS? Our experience helps make your migration straightforward.

Health check

Configured Sophos products yourself and want a review? We check your settings and provide recommendations.

Workshops

Responsible for Sophos products in your company? We offer focused training tailored to your needs.

Education & Government

Special terms for education and government

For eligible schools, universities and government organisations, we check available special terms for the Sophos products you need.*

We clarify your organisation’s classification and provide a no-obligation quotation.

Hinweis: Availability and terms depend on the product, region and organisation classification. Not every product has a separate EDU or GOV variant.

Request special pricing

Trial

Try Sophos products for free

Test available Sophos products in your own environment. Product trials offered in the console run for 30 days.

The right trial depends on the product and your account. We help clarify the features and requirements you need.

The central console brings together management and security information. Sophos is gradually introducing the name Sophos Fusion in place of Sophos Central.

The online demo provides a prepared environment for an initial look. Testing with your own devices requires registration and setup.

Buying help

Any questions about this product?

Ask before buying to make sure the selected product meets your needs.

Ask a question