We have been having big issues with making sure all our computers are being managed by Sophos. Here is the problem, we currently have 393 computers that are managed by 2 SEC consoles in two different cities. Using a bit of excel vlookup of the Active Directory export vs the 'Sophos Managed Computers' list of both consoles.
It's showing as 91 that are unmanaged. These computers definitely have Sophos Endpoint Security and Control installed. We don't use Active Directory sync as we cannot seem to choose a our own country out of the domain tree. For example tree:
"Domain":
"Delegated"
GB
FR
DE
In the domain tree there are 30 other countries OUs in the delegated folder of the overall domain. When I tried to get AD to sync with Sophos it tried to basically pull in every single computer from each delegated OU!
Are you able to select the OU you want it to sync with? For example I want the Oxford SEC to sync with the GB, Delegated, Oxford OU and the Northampton SEC to sync with the GB, Delegated, Northampton OU; but obviously not every other country.
This has been an on-going problem ever since I started and the IT support team have been unable to resolve it even though I have flagged this as a major concern. Some of the managed computers are showing as disconnected even though I can ping them from the Sophos server. I really want to sort out this mess I have inherited and make sure all my computers are managed, with the correct policies applied.
In addition to this we keep getting errors about the following primary update path not being able to download updates:
Primary path = http://<AV Server IP>/sophos/CIDs/S000/SAVSCFXP/
Secondary path = \\<AV Server name>\SophosUpdate\CIDs\S000\SAVSCFXP\
Kind regards.
This thread was automatically locked due to age.