Create a "DNS host group" definition with DNS name "all.broker.sophos.com". Add this to either packet filter (allow port 443) or transparent HTTPS proxy skiplist, if applicable.
We will make this easier in the next beta Up2Date by pre-creating this definition.
The endpoints will update patterns via simple HTTP. A transparent proxy is no problem here, but an explicit proxy will be in the way.