Sophos XDR User
From
Manufacturer list priceManufacturer list price from:
You save 0.00 (0%)
plus % VAT of
Gross price:
Description
Learn more about Sophos XDR User
Sophos XDR User combines workstation protection with Extended Detection and Response. It includes Sophos Endpoint and helps your IT team investigate suspicious activity, contextualise events across security products and respond to threats.
Beyond a protection-only licence, it addresses the questions behind an alert: what happened, which devices are affected and what action makes sense now? This requires the agent and intended data sources to be configured. The user licence is separate from the server licence.
Tools for your own security team
Your IT team can investigate and take action using data queries, Live Response and supported isolation actions. XDR brings together information otherwise spread across different security tools.
The product does not replace analysts. It suits teams that want to assess and handle detections themselves. If Sophos should handle this work around the clock, Sophos MDR is the corresponding managed service.
Put suspicious activity into clearer context
Detections and prioritisation help focus attention on relevant activity. Connected firewall, email, identity and other supported security sources provide additional context. Third-party integrations are included in the XDR subscription; the source product and required permissions must be available.
Sophos is expanding XDR with Secureworks technology and a new security operations interface. The interface and features available to an existing account depend on its migration status. Retention claims must therefore account for the data store in use.
Investigate files and attack paths
File and process information and graphical root cause analysis help explain a detection. Together with threat intelligence, they help assess whether a file is malicious and which other systems should be checked.
CryptoGuard and the other endpoint capabilities remain the protection foundation. XDR adds investigation and response; it guarantees neither full forensic analysis of every attack nor recovery of all data. The now-included Email Monitoring System adds email threat visibility, but monitoring does not replace blocking email protection.
The information materials explain the capabilities; older videos may show product names and interfaces that differ from the current version.
Technical specifications
Sophos Endpoint and MDR compared
Compare workstation protection: Endpoint protects devices, XDR extends investigation, and MDR adds an analyst team. MDR Plus also provides incident response for monitored systems with full Sophos XDR. Features depend on the operating system, configuration and platform migration status. The MDR columns refer to our packages including Sophos Endpoint and XDR, not sensor-only operation with another endpoint solution.
Scroll the comparison table horizontally.
| Function | ||||
|---|---|---|---|---|
| Multiple policies | ✓ | ✓ | ✓ | ✓ |
| Controlled updates | ✓ | ✓ | ✓ | ✓ |
| Application Control | ✓ | ✓ | ✓ | ✓ |
| Peripheral control | ✓ | ✓ | ✓ | ✓ |
| Web Control / category-based URL filtering | ✓ | ✓ | ✓ | ✓ |
| Download reputation (Windows) | ✓ | ✓ | ✓ | ✓ |
| Web Security | ✓ | ✓ | ✓ | ✓ |
| Deep learning malware detection | ✓ | ✓ | ✓ | ✓ |
| Anti-malware file scanning | ✓ | ✓ | ✓ | ✓ |
| Live Protection | ✓ | ✓ | ✓ | ✓ |
| Pre-execution behavioural analysis (HIPS) | ✓ | ✓ | ✓ | ✓ |
| Blocking potentially unwanted applications (PUAs) | ✓ | ✓ | ✓ | ✓ |
| Intrusion Prevention System (IPS) (Windows) | ✓ | ✓ | ✓ | ✓ |
| Data Loss Prevention (Windows) | ✓ | ✓ | ✓ | ✓ |
| Runtime behavioural analysis (HIPS) | ✓ | ✓ | ✓ | ✓ |
| Antimalware Scan Interface (AMSI) (Windows) | ✓ | ✓ | ✓ | ✓ |
| Malicious Traffic Detection (MTD) | ✓ | ✓ | ✓ | ✓ |
| Exploit Prevention (Windows) | ✓ | ✓ | ✓ | ✓ |
| Active Adversary Mitigations | ✓ | ✓ | ✓ | ✓ |
| Ransomware File Protection (CryptoGuard) | ✓ | ✓ | ✓ | ✓ |
| Disk and Boot Record Protection (WipeGuard) (Windows) | ✓ | ✓ | ✓ | ✓ |
| Man-in-the-Browser Protection (Safe Browsing) | ✓ | ✓ | ✓ | ✓ |
| Enhanced Application Lockdown (Windows) | ✓ | ✓ | ✓ | ✓ |
| Live Discover (cross-environment SQL queries for threat hunting and security compliance) | — | ✓ | ✓ | ✓ |
| SQL query library (prewritten, customisable queries) | — | ✓ | ✓ | ✓ |
| Local event data for Live Discover (storage-limited) | — | ✓ | ✓ | ✓ |
| Cross-product data sources (e.g. firewall, email) | — | ✓ | ✓ | ✓ |
| Cross-product queries | — | ✓ | ✓ | ✓ |
| Sophos Data Lake (classic, within storage limits) | — | Up to 90 days | Up to 90 days | Up to 90 days |
| Scheduled queries | — | ✓ | ✓ | ✓ |
| Graphical root cause analysis | ✓ | ✓ | ✓ | ✓ |
| Deep learning malware analysis | — | ✓ | ✓ | ✓ |
| Advanced SophosLabs threat intelligence on demand | — | ✓ | ✓ | ✓ |
| Forensic data export | — | ✓ | ✓ | ✓ |
| Automated malware removal | ✓ | ✓ | ✓ | ✓ |
| Synchronized Security Heartbeat | ✓ | ✓ | ✓ | ✓ |
| Automatic cleanup | ✓ | ✓ | ✓ | ✓ |
| Live Response (remote terminal for further analysis and response) | — | ✓ | ✓ | ✓ |
| On-demand endpoint isolation | — | ✓ | ✓ | ✓ |
| Microsoft 365 response actions with integration and authorisation | — | ✓ | ✓ | ✓ |
| 24/7 evidence-based threat hunting | — | — | ✓ | ✓ |
| Integration of supported third-party security products | — | ✓ | ✓ | ✓ |
| Security Health Checks | — | — | ✓ | ✓ |
| Activity reports | — | — | ✓ | ✓ |
| Threat intelligence for MDR investigations | — | — | ✓ | ✓ |
| Attack detection | — | — | ✓ | ✓ |
| Stopping and containing threats | — | — | ✓ | ✓ |
| Direct telephone support during incidents | — | — | ✓ | ✓ |
| Proactive threat hunting | — | — | ✓ | ✓ |
| Security configuration recommendations | — | — | ✓ | ✓ |
| Incident response and neutralisation on monitored systems with full Sophos XDR | — | — | — | ✓ |
| Incident response closure with root cause analysis and recommendations | — | — | — | ✓ |
| Dedicated contact in the incident response team | — | — | — | ✓ |
| AI investigation case summaries | — | ✓ | ✓ | ✓ |
| AI search for security investigations (depending on source and platform) | — | ✓ | ✓ | ✓ |
Avanet Services
Let us improve your security
Our services help you operate Sophos products securely and reliably. Alongside support for Sophos firewalls and the Fusion platform, you can request these services at any time:
- Setup services
- Health check
- Upgrades
- Workshops
- Migrations
- Firewall maintenance
- SLA
- Security audits
Setup services
Want professionals to set up your Sophos products? We help with commissioning and configuration for smooth operation.
Migrations
Moving from an SG Firewall (UTM) to XGS with SFOS? Our experience helps make your migration straightforward.
Health check
Configured Sophos products yourself and want a review? We check your settings and provide recommendations.
Workshops
Responsible for Sophos products in your company? We offer focused training tailored to your needs.
Information materials
Deepen your knowledge and learn more about the «Sophos Endpoint User»
Product information
- Sophos Central – Datenblatt (PDF, DE)
- Sophos Managed Detection and Response (MDR) – Datenblatt (PDF, DE)
- Sophos Managed Detection and Response (MDR) – Lösungsbroschüre (PDF, DE)
- Sophos Managed Detection and Response (MDR) – Leitfaden für den Kauf (PDF, DE)
- Sophos Breach Protection Warranty – Datenblatt (PDF, DE)
- Sophos Rapid Response – Datenblatt (PDF, DE)
- Extended Detection and Response (XDR) – Leitfaden für Einsteiger (PDF, DE)
- Sophos XDR – Licensing Guide (PDF, EN)
- Sophos XDR – Use Cases (PDF, EN)
- Sophos Network Detection and Response (NDR) – Datenblatt (PDF, DE)
- Sophos Network Detection and Response (NDR) – Kurzbeschreibung (PDF, DE)
- Sophos Endpoint Security – Leitfaden für den Kauf (PDF, DE)
- Cybersecurity System – Buyer's Guide (PDF, EN)
- Sophos Intercept X – Datenblatt (PDF, DE)
- Sophos Intercept X – Solution Brief (PDF, EN)
- Sophos Intercept X für macOS (PDF, DE)
- Sophos Intercept X Deep Learning (PDF, DE)
- FAQs zu Intercept X Essentials und Intercept X Essentials for Server (PDF, DE)
- Funktionsübersicht zu Sophos Intercept X, XDR und MTR (PDF, DE)

Education & Government
Special terms for education and government
For eligible schools, universities and government organisations, we check available special terms for the Sophos products you need.*
We clarify your organisation’s classification and provide a no-obligation quotation.
Hinweis: Availability and terms depend on the product, region and organisation classification. Not every product has a separate EDU or GOV variant.
Request special pricingTrial
Try Sophos products for free
Test available Sophos products in your own environment. Product trials offered in the console run for 30 days.
The right trial depends on the product and your account. We help clarify the features and requirements you need.
The central console brings together management and security information. Sophos is gradually introducing the name Sophos Fusion in place of Sophos Central.
The online demo provides a prepared environment for an initial look. Testing with your own devices requires registration and setup.
Buying help
Any questions about this product?
Ask before buying to make sure the selected product meets your needs.


