Sophos Intercept X for Server in an EDU Setting
Use Cases and Deployment Scope
After the initial deployment of our VMs - we push Sophos Intercept X for Server out to them. Sophos Intercept X for Server is fantastic in that you can set different policies to different OUs or Security Groups - so certain deployments can have access to more web resources or downloaded applications than others, should you need that flexibility. Sophos Intercept X for Server is fantastic as a whole, as it is cloud-based, so you can have users manage these end devices remotely without the need for an internal VPN client. Updates or changes in policies are pushed down to installed devices immediately - which is great. This provides us with the first line of defense for our devices that need an external connection to the internet.
Pros
- Applies policies based on OU or Security group - for plenty of flexibility based on the needs of the user/device.
- Receives automatic anti-virus and malware updates from Sophos without Admin intervention - to protect against the latest threats.
- Easily able to be disabled on individual machines should you need to troubleshoot an issue without completely removing the product.
- Sends out email alerts without an on-premise exchange server whenever a potential vulnerability is detected - with plenty of details of what device and where the issue is located.
Cons
- The AD Sync application can sometimes be finicky - so that application could be improved upon.
Most Important Features
- Cloud-based
- AD sync
- Email alerts (without on-site exchange server)
- Automatic AV/Malware security updates
- Easy to manage licensing
Return on Investment
- More confidence in most end-users/other techs not compromising internal systems with Sophos' proactive response to downloaded threats.
- Cost is a bit higher than other options - but with E-Rate, we can afford it for our smaller district.
- Customer support is top-notch, and responds to email inquiries incredibly quickly.
Alternatives Considered
Symantec Advanced Threat Protection
Other Software Used
Wasp Inventory, Infrascale Platform, Acronis Cyber Protect Home Office (formerly Acronis True Image)

