Skip to content
Avanet
Product gallery
Sophos Central Managed Detection and Response for Server licence box

Sophos MDR Server

Loading the current price.

Configure Fusion licence

Select the licence transaction, term, entitlement and quantity. The applicable volume price is applied automatically.

Configure product

Product ID
—
Price per licence
—
Total price
—

Current configuration options and prices are being loaded through the Commerce API.

Delivery

Free shipping from €200

Delivery time
Loaded through the Commerce API
Availability
Loaded through the Commerce API
Ship to
Loaded through the Commerce API
Payment methods:
  • Visa
  • Mastercard
  • American Express
  • PayPal
  • TWINT
  • Bitcoin
  • Bank transfer
  • Invoice
Category:
Sophos Fusion
Product ID:
sophos-mdr-server

Description

Learn more about Sophos MDR Server

Sophos MDR – technology and human expertise

Sophos MDR Server combines the included Endpoint and XDR capabilities with a managed security service. Sophos investigates threats around the clock and supports attack response. This variant is licensed per server. Sophos MDR was previously called MDR Essentials. The focus is detection and containment; your team or a separately commissioned service handles full incident response and neutralisation.

An analyst team for servers – 24/7

The service adds a Security Operations Centre (SOC) to your IT team. Alerts receive attention outside your own working hours too. Your team remains responsible for setup, availability and tasks outside the agreed service scope.

Sophos MDR capabilities

MDR reviews and prioritises detections and can carry out authorised containment actions. For full incident response beyond containment, Sophos MDR Plus provides the more comprehensive service tier.

Investigate detections around the clock

The MDR team reviews relevant detections, correlates related activity and initiates the appropriate response. Alerts receive expert assessment rather than simply being forwarded.

Attack detection

Attackers can also use legitimate tools. Analysis combines telemetry and threat intelligence to identify suspicious behaviour in context and prioritise investigations.

Security Health Check

Sophos reviews visible security settings and flags configurations that weaken protection or data collection. Your IT team receives practical starting points for improvements.

Activity reports and case overview

Cases, investigation findings and actions remain visible in the console. Your IT team can trace decisions and completed actions. Available reports depend on your environment’s migration status.

Define response permissions and responsibilities during onboarding

Before the service starts, configure reachable contacts, data sources and response permissions. The selected mode determines which actions Sophos may take; the subscribed tier determines their scope.

Notify Only

Sophos reports suspicious activity. Containment actions are not performed in this mode. For active response, Sophos recommends Collaborate or Authorize.

Collaborate

Sophos investigates the case and agrees response actions with your authorised contacts. An additional setting can permit action when your contacts cannot be reached.

Authorize

Sophos may perform agreed response actions without asking for approval each time and informs you of the actions taken. Scope and technical capabilities still depend on the tier, configuration and supported systems.

Included integrations

Supported Sophos and third-party integrations are included. This lets you incorporate existing security solutions. Source products require their own licences; available response actions depend on the integration.

Sophos XDR

The included XDR tools provide the technical foundation for detection and investigation. Analysts add their assessment; additional data sources must be configured.

Sophos Firewall

An existing, separately licensed Sophos Firewall can contribute network signals. Supported response features require the appropriate firmware, configuration and authorisation.

Sophos Endpoint

Sophos Endpoint is included in the MDR package. An existing third-party solution can remain in use through supported sensor or integration configurations. The Sophos sensor alone does not include prevention features.

Sophos Email

Sophos Email adds signals and supported response actions when email protection is separately licensed. The included Email Monitoring System analyses message copies without blocking the original emails.

Cloud security data

Supported cloud integrations supply events for threat analysis. They replace the data access formerly provided by Cloud Optix, discontinued on 30 September 2026, and must be configured. The former Cloud Security Posture Management is not included.

Data retention

In the classic Sophos Data Lake, XDR and MDR data remain available for up to 90 days within storage limits. Longer retention and the new platform have separate storage options.

Microsoft security integrations

Supported Microsoft security integrations add context, such as endpoint or identity events. Available data depend on the source product, its licence and the permissions configured.

Microsoft 365 Activity

Supported Microsoft 365 activity events help investigate suspicious activity across services. Permissions and data collection are defined during setup.

Third-party endpoint protection

MDR can be combined with supported third-party endpoint solutions. Each integration determines which data and response actions are available.

Additional integration areas

Supported third-party integrations do not require additional Integration Packs. NDR, ITDR, Managed Risk and extended data retention remain separate offerings.

Firewall integrations

Supported firewall data add network events to investigations. Connectivity depends on the vendor, software version and log forwarding.

Public cloud integrations

Cloud events broaden visibility into connected environments. Supported cloud accounts and the necessary permissions must be configured; the cloud provider may charge infrastructure costs.

Identity integrations

Supported identity services provide information on sign-ins and account risks. Sophos ITDR offers additional identity protection features as a separate add-on.

Network security integrations

Network security data add context to suspicious connections. Analysing network traffic with Sophos NDR requires a separate NDR licence.

Email integrations

Data from supported email security products help trace an attack from mailbox to device. Response options depend on the integration and permissions.

Extended data retention

Separate storage options are available for longer investigation periods. The classic one-year add-on and Next-Gen SIEM options apply to different platform capabilities. We help you choose the right option.

Technical specifications

Sophos server protection and MDR compared

Compare server prevention, investigation tools and managed response. Features vary between Windows and Linux. MDR Plus adds incident response on monitored systems with full Sophos XDR; cloud integrations do not replace Cloud Security Posture Management. The MDR columns refer to our packages including Sophos Endpoint and XDR, not sensor-only operation with another endpoint solution.

Scroll the comparison table horizontally.

Sophos Endpoint, XDR, MDR and MDR Plus feature comparison for servers
Function
Endpoint Server View product
XDR Server View product
Current product MDR Server Current page
Recommended MDR Plus Server View product
Multiple policies✓✓✓✓
Controlled updates✓✓✓✓
Web Security✓✓✓✓
Download reputation (Windows)✓✓✓✓
Web Control / category-based URL blocking✓✓✓✓
Peripheral control✓✓✓✓
Application Control✓✓✓✓
Unauthorized File Protection (Windows Server)✓✓✓✓
Deep learning malware detection✓✓✓✓
Anti-malware file scanning✓✓✓✓
Live Protection✓✓✓✓
Pre-execution behavioural analysis (HIPS)✓✓✓✓
Blocking potentially unwanted applications (PUAs)✓✓✓✓
Intrusion Prevention System✓✓✓✓
Data Loss Prevention (Windows)✓✓✓✓
Runtime behavioural analysis (HIPS)✓✓✓✓
Antimalware Scan Interface (AMSI) (Windows)✓✓✓✓
Malicious Traffic Detection (MTD)✓✓✓✓
Exploit Prevention (Windows)✓✓✓✓
Active Adversary Mitigations✓✓✓✓
Ransomware File Protection (CryptoGuard) (Windows Server)✓✓✓✓
Disk and Boot Record Protection (WipeGuard) (Windows)✓✓✓✓
Man-in-the-Browser Protection (Safe Browsing)✓✓✓✓
Enhanced Application Lockdown✓✓✓✓
Live Discover (cross-environment SQL queries for threat hunting and security compliance)—✓✓✓
SQL query library (prewritten, customisable queries)—✓✓✓
Suspicious event detection and prioritisation—✓✓✓
Local event data for Live Discover (storage-limited)—✓✓✓
Cross-product data sources (e.g. firewall, email)—✓✓✓
Cross-product queries—✓✓✓
Sophos Data Lake (classic, within storage limits)—Up to 90 daysUp to 90 daysUp to 90 days
Scheduled queries—✓✓✓
Graphical root cause analysis✓✓✓✓
Deep learning malware analysis—✓✓✓
Advanced SophosLabs threat intelligence on demand—✓✓✓
Forensic data export—✓✓✓
Automated malware removal✓✓✓✓
Synchronized Security Heartbeat✓✓✓✓
Automatic cleanup✓✓✓✓
Remote terminal access (remote analysis and response)—✓✓✓
On-demand server isolation—✓✓✓
Microsoft 365 response actions with integration and authorisation—✓✓✓
Endpoint protection for supported servers in AWS, Azure and Google Cloud✓✓✓✓
Synchronized Application Control (application visibility)✓✓✓✓
Threat analysis through supported cloud integrations (not CSPM)—✓✓✓
Server-specific policy management✓✓✓✓
Update cache and message relay✓✓✓✓
Automatic scan exclusions✓✓✓✓
File Integrity Monitoring (Windows Server)✓✓✓✓
24/7 evidence-based threat hunting——✓✓
Integration of supported third-party security products—✓✓✓
Security Health Checks——✓✓
Activity reports——✓✓
Threat intelligence for MDR investigations——✓✓
Attack detection——✓✓
Stopping and containing threats——✓✓
Direct telephone support during incidents——✓✓
Proactive threat hunting——✓✓
Security configuration recommendations——✓✓
Incident response and neutralisation on monitored systems with full Sophos XDR———✓
Incident response closure with root cause analysis and recommendations———✓
Dedicated contact in the incident response team———✓
AI investigation case summaries—✓✓✓
AI search for security investigations (depending on source and platform)—✓✓✓

Avanet Services

Let us improve your security

Our services help you operate Sophos products securely and reliably. Alongside support for Sophos firewalls and the Fusion platform, you can request these services at any time:

  • Setup services
  • Health check
  • Upgrades
  • Workshops
  • Migrations
  • Firewall maintenance
  • SLA
  • Security audits
Request more information

Setup services

Want professionals to set up your Sophos products? We help with commissioning and configuration for smooth operation.

Migrations

Moving from an SG Firewall (UTM) to XGS with SFOS? Our experience helps make your migration straightforward.

Health check

Configured Sophos products yourself and want a review? We check your settings and provide recommendations.

Workshops

Responsible for Sophos products in your company? We offer focused training tailored to your needs.

Education & Government

Special terms for education and government

For eligible schools, universities and government organisations, we check available special terms for the Sophos products you need.*

We clarify your organisation’s classification and provide a no-obligation quotation.

Hinweis: Availability and terms depend on the product, region and organisation classification. Not every product has a separate EDU or GOV variant.

Request special pricing

Trial

Try Sophos products for free

Test available Sophos products in your own environment. Product trials offered in the console run for 30 days.

The right trial depends on the product and your account. We help clarify the features and requirements you need.

The central console brings together management and security information. Sophos is gradually introducing the name Sophos Fusion in place of Sophos Central.

The online demo provides a prepared environment for an initial look. Testing with your own devices requires registration and setup.

Buying help

Any questions about this product?

Ask before buying to make sure the selected product meets your needs.

Ask a question