Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Red Status in client but still there is a connection... Endpoint Protection | Intercept-X

Hi all,

 

I got RED STATUS for clients in dashboard.
There is a active connection still exists in the client computer even in RED STATUS.

But according to working mechanism of INTERCEPT X as shown in this video , connections are interrupted.

 

How to resolve this,
Is our protection properly maintained by Sophos ?

 

 

ps: Got licenses for Advanced Intercept-X



This thread was automatically locked due to age.
Parents
  • Hi  

    There is a policy option that allows computers to isolate themselves from the network when the computer reports a red health status. This option is available in the Threat Protection policy under Device Isolation:


    You can still manage the computer from Sophos Central when it is isolated. Please check this article for more information. 

    Shweta

    Community Support Engineer | Sophos Technical Support
    Are you a Sophos Partner? | Product Documentation@SophosSupport | Sign up for SMS Alerts
    If a post solves your question use the 'Verify Answer' link.
    The New Home of Sophos Support Videos! - Visit Sophos Techvids
  • Thanks for reply  

    According to KB Intercept X Advanced with EDR license is needed.

    With our license we can only isolate computers -not global rule- via Custom Policy.


    For the test; applied this policy to small group of computers.
    After policy apply, there are lots of computers get isolated.


    Now can not remove these isolations from admin panel as mentioned in KB.
    How to remove isolations proper way or manually.


    ps: we are Intercept X Advanced licensed. no EDR or etc.

  • Hi  

    That option is only for the computers isolated by the administrators, not for the computers isolated due to red health.

    The self-isolated computer will come out of the isolation if the health status turns Green. 

    You can also try disabling the device isolation option in the threat protection policy and check whether that device gets connected to the internet or not.

    Even when the device is isolated, it can communicate to the Sophos Central. So, the change in policy may change the policy of device isolation as well. 

    Regards,

    Jasmin
    Community Support Engineer | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

  • Thanks for reply.

    How can we remove isolation via admin panel without EDR license?

    We can not connect to isolated client via remote tools to fix the client.
    For fix there is a stop Health service and rename health database file command is given to us by Sophos Desk.

    How to make client connectable?

  • Hi  

    The option of admin isolated machines is only valid for the machines which are isolated by the Sophos Central admin from the Sophos Central, not for the machines which are auto isolated because of the policy of device isolation.

    Unfortunately, it is not possible that you can remove the isolation of the machine from Sophos Central. You can try by disabling the option of device isolation in the threat protection policy and apply to those red devices. Once the devices have been updated with the latest policy, they are chances that they may come out of the isolation.

    Regards,

    Jasmin
    Community Support Engineer | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

Reply
  • Hi  

    The option of admin isolated machines is only valid for the machines which are isolated by the Sophos Central admin from the Sophos Central, not for the machines which are auto isolated because of the policy of device isolation.

    Unfortunately, it is not possible that you can remove the isolation of the machine from Sophos Central. You can try by disabling the option of device isolation in the threat protection policy and apply to those red devices. Once the devices have been updated with the latest policy, they are chances that they may come out of the isolation.

    Regards,

    Jasmin
    Community Support Engineer | Sophos Support

    Sophos Support VideosKnowledge Base  |  @SophosSupport | Sign up for SMS Alerts |
    If a post solves your question use the 'This helped me' link

Children