Skip to content
Avanet
Product gallery
Sophos Central Intercept X Advanced for Server with XDR licence box

Sophos XDR Server

Loading the current price.

Configure Fusion licence

Select the licence transaction, term, entitlement and quantity. The applicable volume price is applied automatically.

Configure product

Product ID
—
Price per licence
—
Total price
—

Current configuration options and prices are being loaded through the Commerce API.

Delivery

Free shipping from €200

Delivery time
Loaded through the Commerce API
Availability
Loaded through the Commerce API
Ship to
Loaded through the Commerce API
Payment methods:
  • Visa
  • Mastercard
  • American Express
  • PayPal
  • TWINT
  • Bitcoin
  • Bank transfer
  • Invoice
Category:
Sophos Fusion
Product ID:
sophos-xdr-server

Description

Learn more about Sophos XDR Server

Investigate and respond to attacks on servers

Sophos XDR Server combines server protection with tools for investigating and responding to threats. Alongside Sophos Endpoint, the server licence includes Extended Detection and Response: your IT team can investigate available events and correlate data from connected security products.

XDR supports your own security team; it does not include a round-the-clock MDR service. Sophos is expanding the solution with Secureworks technology. Features of the new security operations interface depend on your account’s migration status. Deployment requires supported server operating systems, a suitable agent and configured data sources.

Unauthorized File Protection replaces Server Lockdown

Unauthorized File Protection protects Windows servers against execution of program files created or modified without authorisation. It replaces Server Lockdown, whose support ends in October 2026. The existing image shows the former Lockdown configuration.

A monitoring mode helps assess the impact before enabling blocking. Policies for allowed and blocked files control exceptions. Existing Lockdown systems must be unlocked for migration; a blanket one-click block of all software installations does not describe current behaviour.

Historical Server Lockdown configuration before the transition to Unauthorized File Protection

CryptoGuard

CryptoGuard monitors Windows servers for suspicious encryption activity. On detection, Sophos can stop the process and restore affected files from copies saved by CryptoGuard. Encryption attempts from other devices against accessible shares can also be detected.

This additional protection is particularly relevant to file and application servers. It does not guarantee complete recovery and replaces neither backups nor a tested recovery plan. Available protection features differ on Linux.

Root Cause Analysis

Graphical root cause analysis shows available relationships between a detection, involved processes and files. This helps IT assess a blocked attack and plan next steps.

Its usefulness depends on the recorded data. An incident view therefore does not guarantee that every affected system or attacker action has been captured.

Exploit Protection

Exploit defence detects attack techniques that exploit vulnerabilities in applications and operating system components. Supported Windows servers gain another protection layer alongside malware checks and behavioural analysis.

The mechanisms available depend on platform and agent version. Regular updates and secure server services remain necessary.

XDR adds data queries, Live Response and supported isolation actions for investigations. Availability depends on platform, permissions and enabled data collection. The server licence adds practical tools for your IT team’s root cause analysis.

Technical specifications

Sophos server protection and MDR compared

Compare server prevention, investigation tools and managed response. Features vary between Windows and Linux. MDR Plus adds incident response on monitored systems with full Sophos XDR; cloud integrations do not replace Cloud Security Posture Management. The MDR columns refer to our packages including Sophos Endpoint and XDR, not sensor-only operation with another endpoint solution.

Scroll the comparison table horizontally.

Sophos Endpoint, XDR, MDR and MDR Plus feature comparison for servers
Function
Endpoint Server View product
Current product XDR Server Current page
MDR Server View product
Recommended MDR Plus Server View product
Multiple policies✓✓✓✓
Controlled updates✓✓✓✓
Web Security✓✓✓✓
Download reputation (Windows)✓✓✓✓
Web Control / category-based URL blocking✓✓✓✓
Peripheral control✓✓✓✓
Application Control✓✓✓✓
Unauthorized File Protection (Windows Server)✓✓✓✓
Deep learning malware detection✓✓✓✓
Anti-malware file scanning✓✓✓✓
Live Protection✓✓✓✓
Pre-execution behavioural analysis (HIPS)✓✓✓✓
Blocking potentially unwanted applications (PUAs)✓✓✓✓
Intrusion Prevention System✓✓✓✓
Data Loss Prevention (Windows)✓✓✓✓
Runtime behavioural analysis (HIPS)✓✓✓✓
Antimalware Scan Interface (AMSI) (Windows)✓✓✓✓
Malicious Traffic Detection (MTD)✓✓✓✓
Exploit Prevention (Windows)✓✓✓✓
Active Adversary Mitigations✓✓✓✓
Ransomware File Protection (CryptoGuard) (Windows Server)✓✓✓✓
Disk and Boot Record Protection (WipeGuard) (Windows)✓✓✓✓
Man-in-the-Browser Protection (Safe Browsing)✓✓✓✓
Enhanced Application Lockdown✓✓✓✓
Live Discover (cross-environment SQL queries for threat hunting and security compliance)—✓✓✓
SQL query library (prewritten, customisable queries)—✓✓✓
Suspicious event detection and prioritisation—✓✓✓
Local event data for Live Discover (storage-limited)—✓✓✓
Cross-product data sources (e.g. firewall, email)—✓✓✓
Cross-product queries—✓✓✓
Sophos Data Lake (classic, within storage limits)—Up to 90 daysUp to 90 daysUp to 90 days
Scheduled queries—✓✓✓
Graphical root cause analysis✓✓✓✓
Deep learning malware analysis—✓✓✓
Advanced SophosLabs threat intelligence on demand—✓✓✓
Forensic data export—✓✓✓
Automated malware removal✓✓✓✓
Synchronized Security Heartbeat✓✓✓✓
Automatic cleanup✓✓✓✓
Remote terminal access (remote analysis and response)—✓✓✓
On-demand server isolation—✓✓✓
Microsoft 365 response actions with integration and authorisation—✓✓✓
Endpoint protection for supported servers in AWS, Azure and Google Cloud✓✓✓✓
Synchronized Application Control (application visibility)✓✓✓✓
Threat analysis through supported cloud integrations (not CSPM)—✓✓✓
Server-specific policy management✓✓✓✓
Update cache and message relay✓✓✓✓
Automatic scan exclusions✓✓✓✓
File Integrity Monitoring (Windows Server)✓✓✓✓
24/7 evidence-based threat hunting——✓✓
Integration of supported third-party security products—✓✓✓
Security Health Checks——✓✓
Activity reports——✓✓
Threat intelligence for MDR investigations——✓✓
Attack detection——✓✓
Stopping and containing threats——✓✓
Direct telephone support during incidents——✓✓
Proactive threat hunting——✓✓
Security configuration recommendations——✓✓
Incident response and neutralisation on monitored systems with full Sophos XDR———✓
Incident response closure with root cause analysis and recommendations———✓
Dedicated contact in the incident response team———✓
AI investigation case summaries—✓✓✓
AI search for security investigations (depending on source and platform)—✓✓✓

Avanet Services

Let us improve your security

Our services help you operate Sophos products securely and reliably. Alongside support for Sophos firewalls and the Fusion platform, you can request these services at any time:

  • Setup services
  • Health check
  • Upgrades
  • Workshops
  • Migrations
  • Firewall maintenance
  • SLA
  • Security audits
Request more information

Setup services

Want professionals to set up your Sophos products? We help with commissioning and configuration for smooth operation.

Migrations

Moving from an SG Firewall (UTM) to XGS with SFOS? Our experience helps make your migration straightforward.

Health check

Configured Sophos products yourself and want a review? We check your settings and provide recommendations.

Workshops

Responsible for Sophos products in your company? We offer focused training tailored to your needs.

Education & Government

Special terms for education and government

For eligible schools, universities and government organisations, we check available special terms for the Sophos products you need.*

We clarify your organisation’s classification and provide a no-obligation quotation.

Hinweis: Availability and terms depend on the product, region and organisation classification. Not every product has a separate EDU or GOV variant.

Request special pricing

Trial

Try Sophos products for free

Test available Sophos products in your own environment. Product trials offered in the console run for 30 days.

The right trial depends on the product and your account. We help clarify the features and requirements you need.

The central console brings together management and security information. Sophos is gradually introducing the name Sophos Fusion in place of Sophos Central.

The online demo provides a prepared environment for an initial look. Testing with your own devices requires registration and setup.

Buying help

Any questions about this product?

Ask before buying to make sure the selected product meets your needs.

Ask a question