Endpoint security
PlannedSophos Central (Intercept X)
By Sophos
Alerts, endpoint inventory and isolation from Sophos Central.
What you can connect
Capabilities and availability
Each capability has its own setup and status. Review the details before enabling it for your organisation.
Endpoint telemetry
PlannedSetup is not available yet
Importing Sophos Central (Intercept X) detections and devices, and isolating hosts through it, is not available. Use Microsoft Defender for endpoint telemetry and response, or the Qorionix sensor on endpoints Sophos Central (Intercept X) protects.
Response actions
PlannedSetup is not available yet
Importing Sophos Central (Intercept X) detections and devices, and isolating hosts through it, is not available. Use Microsoft Defender for endpoint telemetry and response, or the Qorionix sensor on endpoints Sophos Central (Intercept X) protects.
What to know before connecting
Importing Sophos Central (Intercept X) detections and devices, and isolating hosts through it, is not available. Use Microsoft Defender for endpoint telemetry and response, or the Qorionix sensor on endpoints Sophos Central (Intercept X) protects.
- Polling Sophos Central (Intercept X) detections and device inventory into XDR alerts and endpoints.
- Isolate, release and scan response actions through the Sophos Central (Intercept X) API.
Roadmap timing: No release date is committed. Microsoft Defender telemetry and response, and the Qorionix sensor, are available.
More in Endpoint security
Endpoint security
CrowdStrike Falcon
Imports the alerts CrowdStrike Falcon raises for your tenant and the devices it protects into the Qorionix XDR incident queue, beside your own sensor and Microsoft Defender. Network containment and other Falcon response actions are not available through this integration yet.
Endpoint security
Microsoft Defender for Business
Imports the alerts Microsoft Defender for Business (and Defender for Endpoint) raises for your tenant into the Qorionix incident queue, lists the devices Defender protects beside the hosts running the Qorionix sensor, exports the CVE findings its Threat & Vulnerability Management module has for each device, and carries out isolate, release-from-isolation and antivirus scan through the Defender for Endpoint API — each one through the same approval queue and audit trail as an action on our own sensor. Requires one Entra app registration with Microsoft Graph: SecurityAlert.Read.All; WindowsDefenderATP: Machine.Read.All, Machine.Isolate, Machine.Scan, Vulnerability.Read.All (application permissions, admin consent required).
Endpoint security
SentinelOne Singularity
Imports the threats SentinelOne Singularity detects for your tenant and the agents it protects into the Qorionix XDR incident queue, beside your own sensor and Microsoft Defender. Network isolation and other SentinelOne response actions are not available through this integration yet.