Overview
The Sophos Central integration connects your Sophos endpoint protection platform to Junto, enabling your AI agent to monitor endpoints, investigate security alerts, and take response actions across your managed tenants.
What you can do once connected
List and inspect managed endpoints — health status, OS, isolation state
View and investigate security alerts with severity and category details
Trigger on-demand malware scans on endpoints
Isolate compromised endpoints from the network (with approval)
Run Live Discover queries for endpoint investigation
Execute XDR data lake queries for advanced threat hunting
Prerequisites
A Sophos Central account at the Partner or Organization level (single-tenant accounts are not supported)
Admin or Owner role in your Junto organization
Important: You must use a Partner or Organization-level Sophos account. Single-tenant accounts cannot list tenants and are not compatible with this integration.
Step 1: Connect to Sophos Central
In Junto, navigate to Settings → Integrations → Sophos Central
Click "Connect to Sophos"
A popup will open redirecting you to Sophos's login page
Log in with your Sophos Central credentials
Grant Junto permission to access your Sophos account
The popup closes and you'll see a success message
After connecting, your configuration card will display your account type (Partner or Organization), data region, and connection date.
Step 2: Test your connection
Click "Test Connection" on the configuration card
Junto verifies your OAuth token and API connectivity
A green badge confirms the connection is healthy
Step 3: Map your companies to Sophos tenants
If you manage multiple tenants in Sophos Central, you'll need to map each one to the corresponding Junto company.
Click "Manage Company Mapping"
A dialog shows your Junto companies and available Sophos tenants
Auto-mapping (recommended)
Click "Run Auto-Map" to match by name:
Exact matches are applied immediately
Fuzzy matches (80%+ similarity) are shown as suggestions
Manual mapping
Select the correct Sophos tenant from the dropdown for each company. Each tenant shows its data region for easy identification.
Click "Save Mappings" when done.
Using the integration
Once connected and mapped, your AI agent can investigate security issues during triage. For example:
"Are there any critical security alerts for Acme Corp?"
"What's the health status of DESKTOP-ABC123?"
"Scan John's laptop for malware"
"List all endpoints that are currently isolated"
Approval requirements
Some actions require explicit approval before the agent can proceed:
Action | Approval |
View endpoints and alerts | None required |
Trigger endpoint scan | One-time approval per session |
Run Live Discover query | One-time approval per session |
Isolate an endpoint | Manager approval required |
Run XDR data lake query | Approval required every time |
Managing the connection
Disconnecting
Go to Settings → Integrations → Sophos Central
Click "Disconnect"
Confirm the disconnection
To reconnect, repeat the setup flow with your Sophos credentials.
Troubleshooting
Issue | Solution |
OAuth popup won't open | Check your browser's popup blocker settings |
"Cannot list tenants" error | You're using a single-tenant account — a Partner or Organization account is required |
No tenants in mapping dialog | Verify your Sophos account has multiple tenants configured |
Connection test fails | Try disconnecting and reconnecting — the OAuth token may have expired |
Agent can't access Sophos data | Ensure the company is mapped to a Sophos tenant and the connection test passes |
