Skip to main content

Setting Up the Sophos Central Integration

Updated over a week ago

Overview

The Sophos Central integration connects your Sophos endpoint protection platform to Junto, enabling your AI agent to monitor endpoints, investigate security alerts, and take response actions across your managed tenants.

What you can do once connected

  • List and inspect managed endpoints — health status, OS, isolation state

  • View and investigate security alerts with severity and category details

  • Trigger on-demand malware scans on endpoints

  • Isolate compromised endpoints from the network (with approval)

  • Run Live Discover queries for endpoint investigation

  • Execute XDR data lake queries for advanced threat hunting

Prerequisites

  • A Sophos Central account at the Partner or Organization level (single-tenant accounts are not supported)

  • Admin or Owner role in your Junto organization

Important: You must use a Partner or Organization-level Sophos account. Single-tenant accounts cannot list tenants and are not compatible with this integration.

Step 1: Connect to Sophos Central

  1. In Junto, navigate to Settings → Integrations → Sophos Central

  2. Click "Connect to Sophos"

  3. A popup will open redirecting you to Sophos's login page

  4. Log in with your Sophos Central credentials

  5. Grant Junto permission to access your Sophos account

  6. The popup closes and you'll see a success message

After connecting, your configuration card will display your account type (Partner or Organization), data region, and connection date.

Step 2: Test your connection

  1. Click "Test Connection" on the configuration card

  2. Junto verifies your OAuth token and API connectivity

  3. A green badge confirms the connection is healthy

Step 3: Map your companies to Sophos tenants

If you manage multiple tenants in Sophos Central, you'll need to map each one to the corresponding Junto company.

  1. Click "Manage Company Mapping"

  2. A dialog shows your Junto companies and available Sophos tenants

Auto-mapping (recommended)

Click "Run Auto-Map" to match by name:

  • Exact matches are applied immediately

  • Fuzzy matches (80%+ similarity) are shown as suggestions

Manual mapping

Select the correct Sophos tenant from the dropdown for each company. Each tenant shows its data region for easy identification.

Click "Save Mappings" when done.

Using the integration

Once connected and mapped, your AI agent can investigate security issues during triage. For example:

  • "Are there any critical security alerts for Acme Corp?"

  • "What's the health status of DESKTOP-ABC123?"

  • "Scan John's laptop for malware"

  • "List all endpoints that are currently isolated"

Approval requirements

Some actions require explicit approval before the agent can proceed:

Action

Approval

View endpoints and alerts

None required

Trigger endpoint scan

One-time approval per session

Run Live Discover query

One-time approval per session

Isolate an endpoint

Manager approval required

Run XDR data lake query

Approval required every time

Managing the connection

Disconnecting

  1. Go to Settings → Integrations → Sophos Central

  2. Click "Disconnect"

  3. Confirm the disconnection

To reconnect, repeat the setup flow with your Sophos credentials.

Troubleshooting

Issue

Solution

OAuth popup won't open

Check your browser's popup blocker settings

"Cannot list tenants" error

You're using a single-tenant account — a Partner or Organization account is required

No tenants in mapping dialog

Verify your Sophos account has multiple tenants configured

Connection test fails

Try disconnecting and reconnecting — the OAuth token may have expired

Agent can't access Sophos data

Ensure the company is mapped to a Sophos tenant and the connection test passes

Did this answer your question?