What are the key advantages of Sophos Central Intercept X Advanced for Server Corporate?
Central management – All servers managed from one cloud console.
Ransomware rollback – CryptoGuard reverses malicious encryption on protected servers.
Mixed platforms – One agent covers Windows and Linux servers.
File monitoring – Alerts on tampering with critical Windows files.
Server hardening – Blocks unauthorised executables launched by untrusted processes.
Important note – EDR and XDR need a higher edition.
Sophos Central console – Cloud management for all protected servers and policies.
CryptoGuard anti-ransomware – Detects malicious encryption and rolls affected files back.
Deep learning detection – Identifies unknown malware on servers without signature updates.
Exploit prevention – Blocks the techniques used in fileless and zero-day attacks.
File integrity monitoring – Reports unauthorised changes to critical Windows Server files.
Important – EDR and XDR are not included in this edition.
Sophos Central Intercept X Advanced for Server is server workload protection for Windows and Linux, managed entirely from the Sophos Central cloud console, with no on-premises management server to run. It succeeded Central Server Protection, which Sophos withdrew from new sales in July 2021, and Corporate identifies the commercial customer variant as distinct from the education and government variants of the same product.
One agent, mixed estates – Same agent for on-premises, virtual and cloud servers.
Automatic application exclusions – Avoids false positives on Exchange and SQL Server.
Root cause analysis – Threat Cases show how an incident reached the server.
Unauthorized File Protection – Hardens Windows Servers against untrusted executables without downtime.
Policy granularity – Multiple policies and controlled updates, unlike the Essentials edition.
Regional data residency – Your Central account stays in one chosen data region.
The deciding factor is not headcount but whether anyone is watching the console. This edition prevents and records; it does not hunt. A company with one part-time IT generalist gets full value from it, while a company that has been told by an auditor or an insurer to demonstrate detection and response on servers will need the XDR edition or the MDR service on top.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rarely | By sector | By sector |
| NIS 2 in the European Union | ✕ | By sector | By sector |
| Security questionnaire from large customers | Sometimes | ✓ | ✓ |
| Searchable detection and response on servers | Rarely | ✓ | ✓ |
| This product fits | ✓ | With XDR | With MDR |
The reporting obligation in the revised Information Security Act has applied since 1 April 2025, and it affects operators of critical infrastructure rather than every company: energy and water supply, hospitals, transport, telecommunications, financial services, cloud and data centre providers, and cantonal and communal administrations, with exemptions for organisations below the sector thresholds. Affected organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, and may complete the report within a further 14 days. This product supports that deadline in one specific way: Threat Cases reconstruct how an incident reached the server, which is the substance of what the initial report has to describe. What it does not do is help you notice the attack across an estate in the first place, because cross-server querying, retained telemetry and remote response sit in the XDR edition or in the Sophos MDR service, and there is no case management or export format built around the BACS reporting form. Server events are held in the Sophos Central region chosen when the account was created, which for Swiss buyers is in practice Germany or Ireland, as Sophos operates no Swiss region. This is general product information and not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No software product makes an organisation NIS 2 compliant, because the directive addresses governance, processes and evidence rather than tooling. NIS 2 requires risk analysis and information security policies, incident handling, business continuity including backup and crisis management, supply chain security, security in acquisition and maintenance including vulnerability handling, procedures for assessing whether the measures work, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. Against that list, this product contributes to incident handling at the server layer and to the technical protection measures: malware and exploit prevention, ransomware rollback, file integrity monitoring, and application, peripheral and web control on Windows Servers. It does not cover backup and recovery, vulnerability and patch management, encryption, multi-factor authentication or staff training, and it generates none of the policy documentation an assessor will ask to see. The retained, searchable event history that supports the incident-handling and effectiveness-assessment measures belongs to the XDR edition, not to this one.
Partly, and it is worth knowing exactly where the line falls before you commit to an answer sheet. It lets you answer yes to centrally managed anti-malware on servers, signatureless detection of unknown malware, exploit and ransomware protection with automatic file rollback, application allowlisting on Windows Servers through Unauthorized File Protection, file integrity monitoring on critical Windows Server files, removable media control, and a named data processing region for the management platform. It does not let you answer yes to endpoint detection and response, retained security telemetry with a defined retention period, remote forensic access to a compromised host, host isolation during an incident, SIEM or syslog export of security events, backup and restore, patch management, disk encryption, or 24/7 monitoring. Where those gaps are the blocker, moving up within the same family is usually cheaper and far less work than adding a second vendor: the XDR edition adds the query, retention, remote response and isolation answers, and Sophos MDR adds the round-the-clock monitoring answer, both on the same agent and the same console you already operate. Backup, patching and encryption are genuinely outside this product family's server edition and need separate products regardless of which tier you choose.
The single most decisive difference is policy freedom: Essentials for Server confines you to the base policy, so every server is configured identically, while Advanced for Server allows multiple policies and controlled updates, which is what you need the moment a domain controller, a file server and a database server require different exclusions and different update windows. Both editions share the same protection core, including deep learning detection, exploit prevention and CryptoGuard rollback, so the gap is about management and forensic depth rather than raw blocking power. Advanced additionally brings file integrity monitoring, Unauthorized File Protection, the control policies, and Threat Cases for root cause analysis. Neither edition includes detection and response; the third column below shows what the XDR edition adds, and it is the column most buyers end up comparing against.
| Capability | Essentials for Server | Advanced for Server | Advanced with XDR |
|---|---|---|---|
| Deep learning, exploit prevention, CryptoGuard | ✓ | ✓ | ✓ |
| Multiple policies and controlled updates | ✕ | ✓ | ✓ |
| File integrity monitoring | ✕ | Windows only | Windows only |
| Unauthorized File Protection | ✕ | Windows only | Windows only |
| Application, peripheral and web control | ✕ | ✓ | ✓ |
| Threat Cases (root cause analysis) | ✕ | ✓ | ✓ |
| Live Discover queries and Data Lake storage | ✕ | ✕ | ✓ |
| Live Response and server isolation | ✕ | ✕ | ✓ |
| Linux runtime and container detections | ✕ | ✕ | ✓ |
The most time-sensitive point is Server Lockdown: Sophos has deprecated the feature and set its end of support for October 2026, replacing it with Unauthorized File Protection, which ships in the same agent and adds a monitor-only mode before you enforce blocking. Existing allowed and blocked file entries carry over, but if your allowlisting runbook still says lock down the server, that runbook needs rewriting before the deadline. The second point is platform asymmetry: file integrity monitoring, Unauthorized File Protection, and the application, peripheral and web control policies apply to Windows Servers, so a Linux estate gets the protection core but not the control layer, and Linux offers two deployment options that cannot be run side by side on the same host. Third, the Sophos Central data region is fixed when the account is created and cannot be moved afterwards, and there is no Swiss region, which matters if a contract requires data residency in Switzerland rather than in the European Union. Finally, the follow-up purchases this edition most often triggers are detection and response, which means the XDR edition, and backup, patch management, disk encryption and mailbox protection, which are separate products entirely.
The agent applies automatic scanning exclusions for common business server applications, including Exchange and SQL Server, so the usual false positives and repeated rescanning of database and mail store files do not need to be configured by hand. You can still add your own exclusions in the policy for line-of-business applications Sophos does not recognise.
Yes. One console and one licence model cover on-premises, virtual and cloud servers across AWS, Azure, Google Cloud and Oracle Cloud, with the same policy structure applied to both platforms. The Linux feature set is narrower than the Windows one, so expect the protection core on Linux and the control and monitoring policies on Windows.
Sophos renamed the Server Lockdown policy to Unauthorized File Protection in Sophos Central, and the allowed and blocked files and folders you had defined are not affected by the change. Because Server Lockdown itself reaches end of support in October 2026, plan the transition rather than waiting for it, and use the monitor mode first to see what would be blocked before you switch enforcement on.
Server protection for Windows and Linux, managed from Sophos Central, with CryptoGuard rollback. EDR and XDR are separate editions.
Sophos Central Intercept X Advanced for Server Corporate, Sophos, Intercept X, Central Server Protection, server protection, anti-ransomware, deep learning, file integrity monitoring
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies