Skip to main content

Sophos

Integrate Sophos with Cloudaware to inventory tenants, endpoints, endpoint groups, and users for unified security reporting.

info
  • Audience: Cloudaware administrators, SecOps teams, endpoint security teams, and cloud operations teams
  • Outcome: Sophos endpoint security data is available in CMDB for tenant visibility, endpoint inventory, user context, coverage review, and reporting

Capabilities

The integration supports:

  • Read-only discovery of Sophos tenants, endpoints, endpoint groups, and users
  • CMDB visibility into endpoint security inventory for coverage review and operational reporting
  • Endpoint and user context that can support security investigations and asset correlation
  • Search and reporting for Sophos objects using CMDB Navigator, CMDB list views, and reports

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Sophos service principal with a read-only role.
  • Client ID and Client Secret for the Sophos service principal.

Add a Sophos Account to Cloudaware

  1. In Cloudaware, go to Admin.
  2. Find Sophos, then click + ADD.
  3. Enter the following values:
    • Name: A display name for the Sophos integration.
    • Client ID: The Sophos service principal client ID.
    • Client Secret: The Sophos service principal client secret.
  4. Click Save.
  5. Confirm that the integration status indicator is green.
tip

Allow the initial discovery cycle to complete after enabling the integration.

View Sophos Data in CMDB

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select SOPHOS.
  3. Open an object list, e.g., Sophos Endpoints, to view discovered records.

Supported Objects

Cloudaware ingests the following Sophos objects:

Sophos ObjectCMDB Object API Name
Sophos EndpointCA10SPH__CaSophosEndpoint__c
Sophos Endpoint GroupCA10SPH__CaSophosEndpointGroup__c
Sophos TenantCA10SPH__CaSophosTenant__c
Sophos UserCA10SPH__CaSophosUser__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Verify that the Sophos Client ID and Client Secret are correct.
  • Confirm that the Sophos service principal is active and has a read-only role.
  • Re-enter the Client Secret by editing the integration in Cloudaware.

No Sophos Data Appears in CMDB

  • Allow the initial discovery cycle to complete.
  • Confirm that the service principal can access the expected Sophos tenants and endpoint data.
  • In CMDB Navigator, verify that you are viewing the SOPHOS section and related resources.

Some Endpoints or Users Are Missing

  • Confirm that the missing endpoints or users are visible in Sophos Central.
  • Check whether the service principal has access to the tenant that owns the missing records.
  • Review recent Sophos changes after the next discovery cycle completes.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate the Sophos Client Secret, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select Sophos.
  3. Under the tab Credentials, Accounts, or Tenants, select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select Sophos.
  3. Under the tab Credentials, Accounts, or Tenants, select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated Sophos service principal for Cloudaware discovery.
  • Assign only the read-only permissions required for tenant, endpoint, group, and user discovery.
  • Do not reuse personal administrator credentials or broad service principals for the integration.
  • Rotate the Sophos Client Secret according to your organization's credential management policy.
  • Review Sophos data visibility with your security team, because endpoint names, user records, tenant details, and security case context may contain sensitive operational information.
  • Remove or disable unused Sophos service principals when the integration is retired.