| Device | User | Public IP | VPN | Agent | Last Seen | Status |
|---|
| IP Address | Description | Status |
|---|
Every field below is live — saved changes are versioned (see history below) and take effect on each agent's next check-in automatically, no separate push step or agent restart required.
| Check Interval (seconds) | |
|---|---|
| VPN Required for Remote Users | |
| Internet Block Enabled | |
| Server-Outage Cache Validity (hours) | |
| VPN Connect Grace Timer (minutes) | |
| OTP Validity (minutes) | |
| Maintenance Mode Duration (minutes) | |
| Max Temporary Access Duration (minutes) | |
| Max Emergency Access Duration (minutes) | |
| OTP Notification Emails | |
| Remote Support — Allowed Roles |
Read Only can never initiate a Remote Support session, regardless of this setting.
|
| VPN Client Launch Command |
Full path to the VPN client executable the tray icon's "Connect VPN Now" button launches. Leave blank to use the agent's built-in auto-detection for common Sophos install locations; set this only if your deployment installs somewhere non-standard.
|
| VPN Gateway Allow-List |
Always allowed through the firewall even while a device is blocked. The agent already allows common VPN ports (IKE, IPsec, OpenVPN, WireGuard, standard SSL-VPN 443) automatically -- only add an entry here if your VPN gateway uses a non-standard port. Two entry formats: "host:port" allows only that specific destination (narrow, recommended for normal use). A bare port number (e.g. "8443") allows that port to any destination -- more permissive, useful when a VPN gateway rotates through many/unknown backend IPs, but be aware it means anything on the internet using that port becomes reachable while blocked, not just your VPN. Use bare-port entries deliberately, not as a default.
|
| VPN Egress IP Ranges |
Optional, but the strongest available VPN-connected signal when set: if a device's actual public IP falls in one of these ranges, it's trusted as VPN-connected directly, without relying on local adapter/connection detection (which can be unreliable for some third-party VPN clients). Find your VPN gateway's egress range from your network team if you have one, or leave blank to rely on adapter detection alone.
|
| Trusted VPN Client Program |
Full path to the VPN client's actual connecting program. If set, that specific program is allowed to reach any destination while a device is blocked -- not restricted by port or IP. This is scoped by program identity, not by network destination, which is why it's safe: Windows Firewall verifies the actual executable making the connection, so an unrelated or compromised process can't exploit this rule. Use this instead of (or alongside) the VPN Gateway Allow-List above when your VPN gateway rotates through a pool of backend IPs rather than using one fixed address.
|
| Enforcement Mode |
Full Block is the strongest guarantee: nothing gets through except what's explicitly allowed. Web Traffic Only blocks web browsing by port (80/443) -- meaningfully weaker, and only safe if your VPN gateway does NOT also use port 443, since Windows Firewall's rule precedence cannot reliably guarantee a narrow allow-exception overrides a broader block on the same port; the agent tests its own connection to this management server immediately after switching and automatically reverts if that connection is lost. Browser Block avoids that port conflict entirely by blocking specific browser applications (Chrome, Edge, Firefox, etc.) by their exact program identity instead of by port -- the management server, VPN client, antivirus, and every other application are completely unaffected regardless of what port they use, since a Block rule scoped to a browser's exact executable path never competes with anything else.
|
| Blocked Browser Applications |
Only used by Browser Block mode above. Executable filenames to block (e.g. "chrome.exe", "msedge.exe") -- the agent finds each one's actual installed path on every machine automatically, so this list doesn't need to include paths. Leave blank to use the built-in default list (Chrome, Edge, Firefox, Brave, Opera, Internet Explorer); add others here (e.g. an internal or legacy browser) if your organization uses one not in that list.
|
| Terminate Existing Connections on Block |
Aggressive -- understand this before enabling. Windows Firewall only blocks new outbound connections; it does not close connections that were already open before blocking began (e.g. browser tabs opened just before the grace timer expired can keep working indefinitely otherwise). Enabling this closes the entire application that owns any such connection the moment blocking starts -- e.g. the user's whole browser, not just that one tab. Core Windows system processes are never touched regardless of this setting. Only applies in Full Block mode. Off by default; enable deliberately if you need blocking to take effect immediately rather than only for new connections going forward.
|
| Notification Message |
| Version | Changed By | When | Grace | Check Interval |
|---|
When a device goes remote without VPN, it gets one grace window per calendar day with a visible countdown and unblocked access before enforcement blocks it — once VPN connects successfully that day, later disconnects/reconnects, Wi-Fi changes, sleep, or reboot do not grant a second window; enforcement resumes immediately until the next day. Maintenance OTPs are generated per-device from the Devices tab and are only ever delivered by email — never shown in this console.
This account sends every system email: login verification codes, admin invitations, temporary-access and maintenance OTP notifications, password-reset notices, Emergency Access alerts, and future notifications. Most providers (Office 365, Zoho, Gmail) require an app-specific password here rather than your normal mailbox password.
| SMTP Server / Host | |
|---|---|
| SMTP Port | |
| Encryption | |
| SMTP Username | |
| SMTP Password | |
| From Email Address | |
| From Display Name |
| Time | Actor | Action | Target | Details |
|---|
A controlled, always-expiring exception for a broad VPN outage — scoped to a single device, a single user's devices, or every device in the organization. This is not a permanent whitelist: every grant has a hard expiry, requires a stated reason, and is fully audited. Configured recipients (Policy Settings → SMTP notification list) are emailed when a grant is created.
| Scope | Reason | Granted By | Expires | Status |
|---|
Push signed Windows Desktop Agent installers to devices. Updates install silently — no wizard, no prompts — and apply automatically on the device's next check-in, including devices that are currently offline (their job simply stays pending until they reconnect). VPN enforcement continues uninterrupted during the update; a failed install reports back and does not change the device's recorded version.
| Version | Type | Min Windows | Signed | Size | Uploaded By | Uploaded |
|---|
| Device | From → To | Status | Initiated By | Created | Last Attempt | Result / Failure Reason |
|---|
Session history and audit trail for Remote Support access. The user generates a code themselves from their status window and reads it to whoever they're talking to -- entering it below connects immediately, since sharing the code is what they're consenting to.
| Device | User | Requested By | Reason | Duration | Status | Created | Ended | Result |
|---|
| Name | Role | MFA | Status | Last Login |
|---|
| Role | Expires |
|---|