Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos System Protection Service

All of my virtual machines running Windows Server 2012 R2 have a security health issue related to the Sophos System Protection Service not running. The windows administrative tool Services reports the status of the service as Starting and not Running. The service can't be stopped or started since the options are greyed out. A restart of the server didn't resolve the issue.



This thread was automatically locked due to age.
Parents
  • Disabling the "Data Loss Prevention" policy from Sophos Central on affected devices followed by a reboot fixed it for me. The service is now running.

  • Hi Craig,

    Could you please explain the way you proceed to disable DLP policy?

    I tried to create a  new DLP policy for my servers getting the issue and then bypassed it. However the base policy is also applied by default.

    I'm not able to delete the DLP base policy.

    Many thanks in advance for your help,

    Best regards,

    Jérôme.

  • I suggest toggling the slider "Use rules for data transfers". 

  • Hi Kushal Lakhan,

    Thanks for your reply.

    I’m going to check this slider thing tomorrow at work.

    I also noticed that only (but all) Windows 2012R2 servers are impacted by this issue.

    Sophos System Protection Service remains on a starting status for all of them.

    Do you think Sophos will provide any patch or is there any Windows KB (even an old one) to avoid or correct this problem? 
    I hope toggling the slider will solve the issue but maybe this also could come from a Windows KB (applied or missing).

    We already control firewall permissions for Sophos flows, no connection reset occurs so i’m at my wits end.

    Many thanks again for your support,

    Best regards,

    Jérôme.

  • Thanks for following up.

    There are a few reasons this could occur. If the SXL Lookup URLs are not reachable, you'll need to ensure your white list contains all of the entries Sophos requires. There were some changes to this following the architecture changes to Sophos' Endpoint and Server products.
    - Domains and ports to allow

    If the 1920 error is returned, the following KBA advises further, though this doesn't appear to be what's happening in most cases mentioned here.
    - Error 1920 Sophos System Protection service failed to start

    If any recent updates have occurred to the system, a restart may also be necessary. 

    I'm eager to find out if the issue remains, though other users who reported similar issues haven’t reached out on this thread indicating as such.

Reply Children