What are the key advantages of SOPHOS Central Intercept X Advanced with XDR Corporate?
Central management – Every device managed from one cloud console.
Ransomware rollback – CryptoGuard stops encryption and restores affected files.
Exploit prevention – More than 60 mitigations active by default.
Cross-surface investigation – Correlates endpoint, firewall, email and cloud signals.
Extended retention – 90 days of telemetry in the data lake.
Important note – Windows Server and Linux need separate licences.
Sophos Central console – Cloud-based management for policies, alerts and reporting.
Endpoint protection agent – Deep learning malware detection on Windows and macOS workstations.
CryptoGuard ransomware protection – Blocks malicious encryption and restores affected files where possible.
Exploit prevention – More than 60 anti-exploit mitigations active by default.
XDR threat hunting – Query endpoint, firewall, email and cloud telemetry from one console.
Important – Windows Server and Linux need a separate Workload Protection subscription.
This is the endpoint protection and extended detection and response package for user workstations, managed entirely from the Sophos Central cloud console with no on-premises management server. In October 2025 Sophos dropped the Intercept X name from its endpoint line, so the same product appears in current documentation as Sophos XDR, and the earlier version of this licence was sold as Intercept X Advanced with EDR.
One agent – The same installer covers protection and XDR telemetry.
90-day data lake – Investigate devices that are offline, wiped or encrypted.
Root cause analysis – Shows how an attack entered and what it touched.
Included integrations – Third-party sources feed XDR without extra integration licences.
Evidence for auditors – Exportable detection timelines support incident reports and reviews.
Upgrade path – Sophos MDR can be added later on the same agent.
The decisive question is not how many devices you have, but whether someone in your organisation will actually read the detections. XDR produces investigation material; it does not act on it for you. Companies without that capacity usually get more value from the managed service tier than from the XDR tooling.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Common |
| NIS 2 in the European Union | Rare | By sector | By sector |
| Security questionnaire from large customers | ✓ | ✓ | ✓ |
| Staff available to triage detections | ✕ | Limited | ✓ |
| This product fits | With MDR | ✓ | ✓ |
The Swiss reporting obligation does not apply to every company. Under the revised Information Security Act it applies to operators of critical infrastructure, which includes energy and drinking water suppliers, transport companies and cantonal and municipal administrations, and those organisations must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it, with a further 14 days to complete the report. What this product contributes to that deadline is concrete: the 90-day data lake and the root cause analysis timeline let you state when the attack started, which device was first affected and what the attacker touched, at a point when the affected machine may already be encrypted or offline. What it does not do is decide whether an incident is reportable, file the report on your behalf, or cover the servers and operational systems that are usually at the centre of such an incident, because those need a separate Sophos Workload Protection subscription. It also does not replace an incident response process, a defined responsible person, or the out-of-hours availability needed to notice an attack in time to report it within 24 hours. This information is not legal advice; whether your organisation falls under the reporting obligation should be clarified with your own legal advisers.
No software product makes a company compliant with the NIS 2 Directive, because the directive addresses organisational measures rather than tooling. NIS 2 requires entities in scope to have risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, measures around access control and cryptography, and to issue an early warning to the responsible authority shortly after becoming aware of a significant incident. This product supports the incident handling and detection part of that list directly, and the retained telemetry gives you the factual basis for the early warning and the follow-up report. It does not address business continuity, backup, crisis management, supply chain assessment of your own suppliers, staff training, or governance and accountability at management level, and it does not cover server or Linux workloads without an additional subscription. Those remaining categories have to be built as processes and, where relevant, purchased as separate products.
Yes, for a specific block of questions, and it is worth knowing exactly which. It answers the items on malware and ransomware protection on workstations, centrally enforced security policies, endpoint detection and response capability, retention period for security telemetry, role-based administrative access, and whether security events can be exported for review. The 90-day retention figure and the named detection capabilities are the kind of concrete answers that stop a questionnaire from bouncing back. It does not answer questions on server and workload protection, full disk encryption and key recovery, patch and vulnerability management, mobile device management, email filtering and phishing defence, backup and restore testing, or 24/7 monitoring coverage, and large customers in regulated sectors routinely ask about all of those. The cheapest way to close most of that gap is to stay inside the Sophos family rather than mix vendors: Sophos Workload Protection covers the server questions, Sophos Central Device Encryption covers encryption and key recovery, Sophos Mobile covers mobile devices, and moving up to Sophos MDR answers the 24/7 monitoring question with a named service instead of a promise.
The single decisive difference is how far back and how far sideways you can investigate. Sophos Endpoint, previously sold as Intercept X Advanced, gives you the same prevention engine but no hosted telemetry to query afterwards. Sophos EDR adds investigation across endpoints and servers with 30 days of retained data, while this XDR licence extends the same workflow to firewall, email, cloud and third-party sources and retains 90 days. Sophos MDR is not a different tool but the same platform with Sophos analysts operating it around the clock, and it is licensed separately.
| Capability | Sophos Endpoint | Sophos EDR | Sophos XDR |
|---|---|---|---|
| Prevention engine and CryptoGuard | ✓ | ✓ | ✓ |
| Threat hunting and live queries | ✕ | ✓ | ✓ |
| Telemetry beyond the device | ✕ | Endpoints only | ✓ |
| Data lake retention | ✕ | 30 days | 90 days |
| 24/7 analyst service | ✕ | ✕ | ✕ |
The most common follow-up purchase is server coverage: this licence covers Windows and macOS workstations, and Windows Server and Linux machines need a separate Sophos Workload Protection subscription, which surprises buyers who expected a file server or Exchange server to be included. There is a regional point that matters for Swiss and European buyers: the Sophos Central data region is chosen once when the account is created, the European options are Germany and Ireland, and Sophos operates no data region in Switzerland, so Swiss organisations with a strict in-country storage requirement should clarify this before ordering. Each device may upload a maximum of 2 GB of telemetry per day to the data lake, and once that limit is reached the device stops uploading until the limit resets, with the skipped data never sent afterwards, which means a noisy or heavily used machine can have gaps in exactly the period you later want to investigate. Encryption management, mobile device management, email filtering and patch management are not part of this licence and are sold as separate Sophos products. Finally, XDR is tooling and not a service: the detections arrive in the console whether or not anyone is on duty to look at them.
No. Sophos MDR is a separate service in which Sophos analysts monitor and respond on your behalf around the clock. It runs on the same agent and the same console, so it can be added later without reinstalling anything on your devices.
Yes. Since November 2025 all Sophos XDR subscriptions automatically include the third-party integrations, so telemetry from other security products can be brought into the same investigation view without ordering separate integration pack licences.
Telemetry already uploaded to the Sophos data lake remains available for 90 days independently of the device, so you can still reconstruct what happened on a machine that is offline, wiped or fully encrypted. That is the practical reason the data lake matters more than the local event journals on the machine itself.
Corporate identifies the commercial customer category, which Sophos distinguishes from its separate education, government and non-profit categories. The protection scope and the features in the console are the same; only the customer category differs.
Sophos endpoint protection with XDR investigation, managed from Sophos Central with 90 days of telemetry. Windows Server needs its own licence.
Sophos Intercept X Advanced with XDR, Sophos, Sophos XDR, Sophos Endpoint, Intercept X Advanced with EDR, endpoint detection and response, extended detection and response, Sophos Central, ransomware protection, threat hunting
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Service.
More information about cookies