Sophos
Integrate Sophos with Cloudaware to inventory tenants, endpoints, endpoint groups, and users for unified security reporting.
info
- Audience: Cloudaware administrators, SecOps teams, endpoint security teams, and cloud operations teams
- Outcome: Sophos endpoint security data is available in CMDB for tenant visibility, endpoint inventory, user context, coverage review, and reporting
Capabilities
The integration supports:
- Read-only discovery of Sophos tenants, endpoints, endpoint groups, and users
- CMDB visibility into endpoint security inventory for coverage review and operational reporting
- Endpoint and user context that can support security investigations and asset correlation
- Search and reporting for Sophos objects using CMDB Navigator, CMDB list views, and reports
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Sophos service principal with a read-only role.
- Client ID and Client Secret for the Sophos service principal.
Add a Sophos Account to Cloudaware
- In Cloudaware, go to Admin.
- Find Sophos, then click + ADD.
- Enter the following values:
- Name: A display name for the Sophos integration.
- Client ID: The Sophos service principal client ID.
- Client Secret: The Sophos service principal client secret.
- Click Save.
- Confirm that the integration status indicator is green.
tip
Allow the initial discovery cycle to complete after enabling the integration.
View Sophos Data in CMDB
- In Cloudaware, open CMDB Navigator.
- In the left pane, select SOPHOS.
- Open an object list, e.g., Sophos Endpoints, to view discovered records.
Supported Objects
Cloudaware ingests the following Sophos objects:
| Sophos Object | CMDB Object API Name |
|---|---|
| Sophos Endpoint | CA10SPH__CaSophosEndpoint__c |
| Sophos Endpoint Group | CA10SPH__CaSophosEndpointGroup__c |
| Sophos Tenant | CA10SPH__CaSophosTenant__c |
| Sophos User | CA10SPH__CaSophosUser__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Verify that the Sophos Client ID and Client Secret are correct.
- Confirm that the Sophos service principal is active and has a read-only role.
- Re-enter the Client Secret by editing the integration in Cloudaware.
No Sophos Data Appears in CMDB
- Allow the initial discovery cycle to complete.
- Confirm that the service principal can access the expected Sophos tenants and endpoint data.
- In CMDB Navigator, verify that you are viewing the SOPHOS section and related resources.
Some Endpoints or Users Are Missing
- Confirm that the missing endpoints or users are visible in Sophos Central.
- Check whether the service principal has access to the tenant that owns the missing records.
- Review recent Sophos changes after the next discovery cycle completes.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate the Sophos Client Secret, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select Sophos.
- Under the tab Credentials, Accounts, or Tenants, select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select Sophos.
- Under the tab Credentials, Accounts, or Tenants, select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Sophos service principal for Cloudaware discovery.
- Assign only the read-only permissions required for tenant, endpoint, group, and user discovery.
- Do not reuse personal administrator credentials or broad service principals for the integration.
- Rotate the Sophos Client Secret according to your organization's credential management policy.
- Review Sophos data visibility with your security team, because endpoint names, user records, tenant details, and security case context may contain sensitive operational information.
- Remove or disable unused Sophos service principals when the integration is retired.