Sophos Central Big Sur



Skip to end of metadataGo to start of metadata

Status page provided by StatusCast. closed Latest Status Update: 4/1/21 19:00 UTC - At approximately 18:00 EDT / 22:00 UTC on 3/26/21 a maintenance script was executed on Sophos Central that caused a number of Partner Administrator accounts to lose their role assignments and as a result Partner/Customer User accounts affected by this issue may not have visibility to data, including. Sophos Central: macOS 11 (Big Sur) Central Endpoint EAP is now live! Release Notification. Sophos Anti-Virus for Linux is free and compatible with most major 64-bit Linux distributions, including CentOS, Debian, Red Hat, SUSE and Ubuntu, but it isn't integrated into the PC and Mac.

The latest operating system from Apple, macOS11 Big Sur, has arrived and it brings with it a few significant architecture modifications. In this article, we will take a look at these changes, as well as some of the things you might consider doing to automate much of the deployment of Intercept X on macOS. Tuesday, November 10, 2020 Apple is releasing the latest operating system—MacOS 11 or Big Sur—for Macintosh computers Thursday, November 12. At this time, Sophos is not compatible with Big Sur.

Apple made some significant changes under the bonnet of the macOS operating system called Big Sur. As of Big Sur's release in November 2020, the antivirus programme we use - Sophos Central - is not compatible and will not protect a computer from viruses. Additionally the VPN client we use doesn't work properly.

Until Sophos and Fortinet produce versions that support it CSCS will be blocking the installation of Big Sur. This is likely to last until the end of March 2021 but will be regularly reviewed.

If you try to install Big Sur on a computer with Sophos Central you will be able to download it, but when you try to run the installer you will see a message advising that it has been blocked.

Big

If you click details you'll see more details saying that 'use of application macOS Big Sur Installer has been blocked by your administrator'


If you absolutely must install Big Sur, uninstall Sophos Central. Install the University's MacAfee AntiVirus (which is free for Cambridge staff and students) https://help.uis.cam.ac.uk/service/security/antivirus/mac. Then do the Big Sur update.

Sophos Antivirus Big Sur


Acdsee photo manager 12 free. download full version.




The latest operating system from Apple, macOS11 Big Sur, has arrived and it brings with it a few significant architecture modifications. In this article, we will take a look at these changes, as well as some of the things you might consider doing to automate much of the deployment of Intercept X on macOS.

These changes started to appear with macOS Catalina (10.15) – Apple is beginning to deprecate the use of system wide kernel extensions in favour of user space system extension APIs. This allows software like network extensions and endpoint security solutions to extend the functionality of macOS without requiring kernel-level access.

An interesting third party review of some of the most significant changes in the last decade Apple have recently introduced can be found here.

Unfortunately, we didn’t have a GA version of Intercept X for Mac available on the first day of release. The good news is that we now have an Early Access Program (EAP) available in Central, whereby customers can nroll devices running macOS11 in order to receive a pre-release version of Sophos Endpoint v10.0.2.

TIP: As you can appreciate, we don’t typically recommend using EAP (pre-release) software on a production system. If you would like to prevent users from upgrading to BigSur AND if you or your customer are using Sophos Endpoint, then it’s worth noting that the SophosLabs have added an Application Control detection for the Big Sur installer. This means that you can control its rollout by blocking the application – the installer is classified as a “System Tool”.

Big Sur Google Maps

Most of you are probably aware of the process on how to join an EAP and then enroll devices, however if you would like some info on this process click here. Typically, we don’t make EAPs available to Sophos Central MSP accounts, however given that some customers may be purchasing new Apple hardware that comes pre-shipped running Big Sur, we have extended the EAP to MSP customers too.

Big Sur Camping

About new hardware, the following Macintosh models (at the time of writing) use the new Apple M1 ARM-based system chipset:

  • MacBook Air (M1, 2020)
  • Mac mini (M1, 2020)
  • MacBook Pro (13-inch, M1, 2020)

Sophos Intercept X for Mac does not natively support this new chipset; however, it can be made to work using a piece of backwards compatibility software called Rosetta 2. This software needs to be installed on the Mac before joining it to the EAP and it updating to 10.0.2. More info on this process is also covered in the EAP community post above.

On testing the deployment of Intercept X on a brand new macOS11 device, I found the installation routine quite user intensive with several prompts required to allow permissions etc. before a complete protected state could be achieved.

There are several things that can be done to reduce these prompts, specifically using an MDM provider (such as Sophos Mobile or JAMF) to essentially pre-trust extensions using the Sophos ‘Teams ID’ of 2H5GFH3774. This is a trusted ID that is used in the development of Sophos code, to automatically whitelist our software:

I found that this configuration made the deployment of Intercept X for Mac on macOS Catalina and older, virtually ‘silent’. There were still some prompts that required user interaction when deploying on Big Sur, however this will still down on the amount of interaction required without any applied MDM settings.

Our wonderful professional services team have also created a number of scripts to use with JAMF to automate deployment on Macs. Info on this can be found here.

Big Sur Os

Expect to see some more information in the new year, once a GA version of 10.0.2 for Mac is available, on how to automate the deployment further. Guru raghavendra vaibhava episodes.