Skip to content

Sophos Central Setup

Sophos Central provides endpoint detection and response capabilities. Once connected, Junto can monitor endpoint health, review security alerts, trigger scans, isolate compromised devices, and run Live Discover or XDR queries.

Prerequisites

  • A Sophos Central account with Partner or Organization level access
  • OAuth 2.0 credentials (Junto connects via managed OAuth)

Step 1: Connect via OAuth

  1. In Junto, go to Settings > Integrations > Sophos Central.
  2. Click Connect to start the OAuth flow.
  3. Sign in with your Sophos partner or organization account and grant the requested permissions.
  4. After authorization, you are redirected back to Junto with an active connection.

Step 2: Map Companies to Tenants

Sophos Central uses a hierarchical model: Partner > Organization > Tenant. Each MSP client is typically a separate tenant.

  1. After connecting, Junto lists available tenants from your Sophos account.
  2. Use the company mapping interface to link each Junto company to its Sophos tenant.
  3. Save mappings.

What the AI Agent Can Do

Endpoint Management

ToolDescriptionRisk Level
List EndpointsSearch endpoints by hostname, IP, serial number, or health statusLow
Get Endpoint DetailsGet full endpoint info including health, OS, user, and isolation statusLow
Scan EndpointTrigger an on-demand malware scanMedium
Isolate/Unisolate EndpointEnable or disable network isolation to contain threatsHigh
Get Isolation StatusCheck whether an endpoint is currently isolatedLow

Security Alerts

ToolDescriptionRisk Level
List AlertsList active security alerts with filtering by category or severityLow
Get Alert DetailsGet detailed information about a specific alertLow

Live Discover

ToolDescriptionRisk Level
Search QueriesSearch Live Discover query templates by name or descriptionLow
Run QueryExecute a Live Discover query against endpointsMedium
Get Query Run StatusCheck the progress of a running queryLow
Get Query ResultsRetrieve results from a completed queryLow

XDR (Extended Detection and Response)

ToolDescriptionRisk Level
Run XDR QueryExecute SQL against the Sophos XDR data lake for threat huntingHigh
Get XDR Run StatusCheck the status of an XDR queryLow
Get XDR ResultsRetrieve results from a completed XDR queryLow

Approval Policies

  • Low-risk (read-only) tools run automatically without approval.
  • Medium-risk tools (scans, Live Discover queries) require approval once per session.
  • High-risk tools (endpoint isolation, XDR queries) always require approval.

Troubleshooting

  • OAuth connection fails -- Ensure your Sophos Central account has Partner or Organization level API access.
  • No tenants listed -- Verify your account type. Partner accounts see all customer tenants; Organization accounts see only their own.
  • Endpoint not found -- Confirm the company mapping is correct.
  • Live Discover queries returning no results -- Ensure target endpoints are online with the Sophos agent running.