Integration: Kaseya MDR and Sophos
Kaseya MDR
NAVIGATION At the partner level: Settings > Integrations > + New Integration > choose organization > Next > Sophos
NAVIGATION At the organization level: Organizations > Edit Organization (pencil icon) > + New Application > Sophos
PERMISSIONS Permission to manage integrations or organization applications in Kaseya MDR
Sophos Central Partner
NAVIGATION Configure > Settings & Policies > API Credentials
PERMISSIONS Access to Sophos threat data. Partner Super Admin includes the required permissions by default. For custom roles, grant Full access to Endpoint and Server Protection and Enable access to logs and alerts.
The Kaseya MDR and Sophos integration retrieves threat data from Sophos and surfaces it in Kaseya MDR, enabling the SOC to monitor and respond to threats across all managed tenants.
Prerequisites
-
This integration requires API credentials generated from Sophos Central Partner. Sophos Central Admin (tenant-level) API credentials are not supported by the Kaseya MDR Sophos integration and will result in an authentication or configuration error.
How to...
To generate the API credentials required for the integration, complete the following steps:
-
Log in to Sophos Central Partner.
-
Go to Settings & Policies > API Credentials.
-
Click Add Credentials.
-
Enter a name and description, for example, Kaseya MDR, and then click Add.
-
Copy the Client ID and click Show Client Secret.
-
Copy the Client Secret.
-
In Kaseya MDR, navigate to Settings > Integrations.
-
Click + New Integration.
-
Select the organization that will receive the Sophos data, and then click Next.
-
To create a new organization and use it for the integration, click Create New Organization and use.
-
Each organization can have one connection per application type.
-
-
Under Endpoint Security, locate Sophos and click Connect.
-
Enter the Client ID and Client Secret generated in Sophos Central Partner.
-
Click Next.
-
Complete the Organization Mapping step and save the integration.
When configured at the partner level, Sophos Monitor appears in Settings > Integrations with a Connected status and displays the associated organization.
-
In Kaseya MDR, from the side navigation menu, go to Organizations.
-
Click Edit Organization (pencil icon) for the organization you want to connect Sophos to.
-
Click +New Application.
-
Under Endpoint Security, locate Sophos and click Connect.
NOTES Partner-level configuration is recommended. Configuring the same Sophos Monitor instance for multiple organizations may result in duplicate events and alerts. -
Enter the Client ID and Client Secret generated in Sophos Central Partner.
-
Click Next.
-
Complete the Organization Mapping step and save the integration.
When configured at the organization level, the Sophos application appears under the organization's Applications tab.
To disable the integration:
-
Navigate to the Sophos integration.
-
If the integration was configured at the partner level, go to Settings > Integrations, locate Sophos, and select View details.
-
If the integration was configured at the organization level, go to Organizations, select the organization, and then open the Applications tab.
-
-
Select Disconnect Application.
-
Confirm the action.
Results
-
Sophos activity is no longer associated with organizations in Kaseya MDR.
-
Existing Sophos deployments and configurations remain unchanged.
-
If Sophos is configured at the partner level, disconnecting it affects all organizations mapped to that connection.
The integration can be reconnected later using the same workflow, if needed.
FAQ
No. This integration requires API credentials generated from Sophos Central Partner. Sophos Central Admin (tenant-level) credentials are not supported and will result in an error during configuration.
A custom role must have:
-
Endpoint and Server Protection: Full
-
Feature: Enable access to logs and alerts
Partner Super Admin includes the required permissions by default.

















