Sophos MDR Plus Server
From
Manufacturer list priceManufacturer list price from:
You save 0.00 (0%)
plus % VAT of
Gross price:
Description
Learn more about Sophos MDR Plus Server
Sophos MDR Plus – technology and human expertise
Sophos MDR Plus Server combines the included endpoint and XDR capabilities with a managed security service. Sophos investigates threats around the clock and supports attack response. This variant is licensed per server. Previously called MDR Complete, MDR Plus adds incident response for monitored systems running the full Sophos XDR agent.
An analyst team for servers – 24/7
The service adds a Security Operations Centre (SOC) to your IT team. Alerts receive attention outside your own working hours too. Your team remains responsible for setup, availability and tasks outside the agreed service scope.
What Sophos MDR Plus includes
MDR Plus adds incident-response assistance for confirmed incidents. This applies to monitored systems running Sophos XDR; different response limits apply to third-party-only or sensor-only systems. System recovery and on-site work are not guaranteed components of the service.
Investigate detections around the clock
The MDR team reviews relevant detections, correlates related activity and initiates the appropriate response. Alerts receive expert assessment rather than simply being forwarded.
Proactive threat hunting
Sophos searches available data for attack indicators and unusual relationships. Proactive threat hunting is included in MDR and MDR Plus and complements the investigation of incoming alerts.
Attack detection
Attackers can also use legitimate tools. Analysis combines telemetry and threat intelligence to identify suspicious behaviour in context and prioritise investigations.
Security Health Check
Sophos reviews visible security settings and flags configurations that weaken protection or data collection. Your IT team receives practical starting points for improvements.
Activity reports and case overview
Cases, investigation findings and actions remain visible in the console. Your IT team can trace decisions and completed actions. Available reports depend on your environment’s migration status.
Incident-response contact
For a confirmed incident, MDR Plus provides an incident-response contact. They coordinate with Sophos while your business remains responsible for operational crisis management.
Direct telephone support
If you suspect an attack, you can contact Sophos by telephone around the clock. Both MDR tiers include this access; MDR Plus adds extended incident response.
Bring security data together
Supported data sources give analysts additional attack context. Integrations are included in both MDR tiers and must be configured for your environment.
Improve security configuration
Recommendations help address weaknesses in visible settings. After incident response, MDR Plus also helps with root-cause analysis and measures to prevent recurring attacks.
Understand the existing environment
Device information and telemetry help establish the affected environment. Sophos Managed Risk is available separately for managed vulnerability management.
Define response permissions and responsibilities during onboarding
Before the service starts, configure reachable contacts, data sources and response permissions. The selected mode determines which actions Sophos may take; the subscribed tier determines their scope.
Notify Only
Sophos reports suspicious activity. Containment actions are not performed in this mode. For active response, Sophos recommends Collaborate or Authorize.
Collaborate
Sophos investigates the case and agrees response actions with your authorised contacts. An additional setting can permit action when your contacts cannot be reached.
Authorize
Sophos may perform agreed response actions without asking for approval each time and informs you of the actions taken. Scope and technical capabilities still depend on the tier, configuration and supported systems.
Technical specifications
Sophos server protection and MDR compared
Compare server prevention, investigation tools and managed response. Features vary between Windows and Linux. MDR Plus adds incident response on monitored systems with full Sophos XDR; cloud integrations do not replace Cloud Security Posture Management. The MDR columns refer to our packages including Sophos Endpoint and XDR, not sensor-only operation with another endpoint solution.
Scroll the comparison table horizontally.
| Function | ||||
|---|---|---|---|---|
| Multiple policies | ✓ | ✓ | ✓ | ✓ |
| Controlled updates | ✓ | ✓ | ✓ | ✓ |
| Web Security | ✓ | ✓ | ✓ | ✓ |
| Download reputation (Windows) | ✓ | ✓ | ✓ | ✓ |
| Web Control / category-based URL blocking | ✓ | ✓ | ✓ | ✓ |
| Peripheral control | ✓ | ✓ | ✓ | ✓ |
| Application Control | ✓ | ✓ | ✓ | ✓ |
| Unauthorized File Protection (Windows Server) | ✓ | ✓ | ✓ | ✓ |
| Deep learning malware detection | ✓ | ✓ | ✓ | ✓ |
| Anti-malware file scanning | ✓ | ✓ | ✓ | ✓ |
| Live Protection | ✓ | ✓ | ✓ | ✓ |
| Pre-execution behavioural analysis (HIPS) | ✓ | ✓ | ✓ | ✓ |
| Blocking potentially unwanted applications (PUAs) | ✓ | ✓ | ✓ | ✓ |
| Intrusion Prevention System | ✓ | ✓ | ✓ | ✓ |
| Data Loss Prevention (Windows) | ✓ | ✓ | ✓ | ✓ |
| Runtime behavioural analysis (HIPS) | ✓ | ✓ | ✓ | ✓ |
| Antimalware Scan Interface (AMSI) (Windows) | ✓ | ✓ | ✓ | ✓ |
| Malicious Traffic Detection (MTD) | ✓ | ✓ | ✓ | ✓ |
| Exploit Prevention (Windows) | ✓ | ✓ | ✓ | ✓ |
| Active Adversary Mitigations | ✓ | ✓ | ✓ | ✓ |
| Ransomware File Protection (CryptoGuard) (Windows Server) | ✓ | ✓ | ✓ | ✓ |
| Disk and Boot Record Protection (WipeGuard) (Windows) | ✓ | ✓ | ✓ | ✓ |
| Man-in-the-Browser Protection (Safe Browsing) | ✓ | ✓ | ✓ | ✓ |
| Enhanced Application Lockdown | ✓ | ✓ | ✓ | ✓ |
| Live Discover (cross-environment SQL queries for threat hunting and security compliance) | — | ✓ | ✓ | ✓ |
| SQL query library (prewritten, customisable queries) | — | ✓ | ✓ | ✓ |
| Suspicious event detection and prioritisation | — | ✓ | ✓ | ✓ |
| Local event data for Live Discover (storage-limited) | — | ✓ | ✓ | ✓ |
| Cross-product data sources (e.g. firewall, email) | — | ✓ | ✓ | ✓ |
| Cross-product queries | — | ✓ | ✓ | ✓ |
| Sophos Data Lake (classic, within storage limits) | — | Up to 90 days | Up to 90 days | Up to 90 days |
| Scheduled queries | — | ✓ | ✓ | ✓ |
| Graphical root cause analysis | ✓ | ✓ | ✓ | ✓ |
| Deep learning malware analysis | — | ✓ | ✓ | ✓ |
| Advanced SophosLabs threat intelligence on demand | — | ✓ | ✓ | ✓ |
| Forensic data export | — | ✓ | ✓ | ✓ |
| Automated malware removal | ✓ | ✓ | ✓ | ✓ |
| Synchronized Security Heartbeat | ✓ | ✓ | ✓ | ✓ |
| Automatic cleanup | ✓ | ✓ | ✓ | ✓ |
| Remote terminal access (remote analysis and response) | — | ✓ | ✓ | ✓ |
| On-demand server isolation | — | ✓ | ✓ | ✓ |
| Microsoft 365 response actions with integration and authorisation | — | ✓ | ✓ | ✓ |
| Endpoint protection for supported servers in AWS, Azure and Google Cloud | ✓ | ✓ | ✓ | ✓ |
| Synchronized Application Control (application visibility) | ✓ | ✓ | ✓ | ✓ |
| Threat analysis through supported cloud integrations (not CSPM) | — | ✓ | ✓ | ✓ |
| Server-specific policy management | ✓ | ✓ | ✓ | ✓ |
| Update cache and message relay | ✓ | ✓ | ✓ | ✓ |
| Automatic scan exclusions | ✓ | ✓ | ✓ | ✓ |
| File Integrity Monitoring (Windows Server) | ✓ | ✓ | ✓ | ✓ |
| 24/7 evidence-based threat hunting | — | — | ✓ | ✓ |
| Integration of supported third-party security products | — | ✓ | ✓ | ✓ |
| Security Health Checks | — | — | ✓ | ✓ |
| Activity reports | — | — | ✓ | ✓ |
| Threat intelligence for MDR investigations | — | — | ✓ | ✓ |
| Attack detection | — | — | ✓ | ✓ |
| Stopping and containing threats | — | — | ✓ | ✓ |
| Direct telephone support during incidents | — | — | ✓ | ✓ |
| Proactive threat hunting | — | — | ✓ | ✓ |
| Security configuration recommendations | — | — | ✓ | ✓ |
| Incident response and neutralisation on monitored systems with full Sophos XDR | — | — | — | ✓ |
| Incident response closure with root cause analysis and recommendations | — | — | — | ✓ |
| Dedicated contact in the incident response team | — | — | — | ✓ |
| AI investigation case summaries | — | ✓ | ✓ | ✓ |
| AI search for security investigations (depending on source and platform) | — | ✓ | ✓ | ✓ |
Avanet Services
Let us improve your security
Our services help you operate Sophos products securely and reliably. Alongside support for Sophos firewalls and the Fusion platform, you can request these services at any time:
- Setup services
- Health check
- Upgrades
- Workshops
- Migrations
- Firewall maintenance
- SLA
- Security audits
Setup services
Want professionals to set up your Sophos products? We help with commissioning and configuration for smooth operation.
Migrations
Moving from an SG Firewall (UTM) to XGS with SFOS? Our experience helps make your migration straightforward.
Health check
Configured Sophos products yourself and want a review? We check your settings and provide recommendations.
Workshops
Responsible for Sophos products in your company? We offer focused training tailored to your needs.
Information materials
Deepen your knowledge and learn more about the «Sophos Endpoint Server»
Product information
- Sophos Central – Datenblatt (PDF, DE)
- Sophos Managed Detection and Response (MDR) – Datenblatt (PDF, DE)
- Sophos Managed Detection and Response (MDR) – Leitfaden für den Kauf (PDF, DE)
- Sophos Breach Protection Warranty – Datenblatt (PDF, DE)
- Sophos Rapid Response – Datenblatt (PDF, DE)
- Extended Detection and Response (XDR) – Leitfaden für Einsteiger (PDF, DE)
- Sophos XDR – Licensing Guide (PDF, EN)
- Sophos XDR – Use Cases (PDF, EN)
- Sophos Network Detection and Response (NDR) – Datenblatt (PDF, DE)
- Sophos Network Detection and Response (NDR) – Kurzbeschreibung (PDF, DE)
- Sophos Server Protection – Leitfaden für den Kauf (PDF, DE)
- Cybersecurity System – Buyer's Guide (PDF, EN)
- Sophos Intercept X for Server – Datasheet (PDF, EN)
- Sophos Intercept X – Solution Brief (PDF, EN)
- Sophos Protection für Linux (PDF, DE)
- Sophos Intercept X Deep Learning (PDF, DE)
- FAQs zu Intercept X Essentials und Intercept X Essentials for Server (PDF, DE)
- Funktionsübersicht zu Sophos Intercept X, XDR und MTR (PDF, DE)

Education & Government
Special terms for education and government
For eligible schools, universities and government organisations, we check available special terms for the Sophos products you need.*
We clarify your organisation’s classification and provide a no-obligation quotation.
Hinweis: Availability and terms depend on the product, region and organisation classification. Not every product has a separate EDU or GOV variant.
Request special pricingTrial
Try Sophos products for free
Test available Sophos products in your own environment. Product trials offered in the console run for 30 days.
The right trial depends on the product and your account. We help clarify the features and requirements you need.
The central console brings together management and security information. Sophos is gradually introducing the name Sophos Fusion in place of Sophos Central.
The online demo provides a prepared environment for an initial look. Testing with your own devices requires registration and setup.
Buying help
Any questions about this product?
Ask before buying to make sure the selected product meets your needs.


