<?xml version="1.0" encoding="UTF-8"?>
	<rss version="2.0"
		xmlns:content="http://purl.org/rss/1.0/modules/content/"
		xmlns:wfw="http://wellformedweb.org/CommentAPI/"
		xmlns:dc="http://purl.org/dc/elements/1.1/"
		xmlns:atom="http://www.w3.org/2005/Atom"

			>

	<channel>

		<title>Sophos Firewall: Sophos Authentication for Thin Client (SATC) with Sophos Server &#8211; MODIVA</title>
		<atom:link href="https://modiva.org/forums/topic/sophos-firewall-sophos-authentication-for-thin-client-satc-with-sophos-server/feed/" rel="self" type="application/rss+xml" />
		<link>https://modiva.org/forums/topic/sophos-firewall-sophos-authentication-for-thin-client-satc-with-sophos-server/feed/</link>
		<description></description>
		<lastBuildDate>Fri, 05 Jun 2026 22:07:07 +0000</lastBuildDate>
		<generator>https://bbpress.org/?v=2.6.14</generator>
		<language>en-US</language>

		
														
					
				<item>
					<guid>https://modiva.org/forums/topic/sophos-firewall-sophos-authentication-for-thin-client-satc-with-sophos-server/#post-7847</guid>
					<title><![CDATA[Sophos Firewall: Sophos Authentication for Thin Client (SATC) with Sophos Server]]></title>
					<link>https://modiva.org/forums/topic/sophos-firewall-sophos-authentication-for-thin-client-satc-with-sophos-server/#post-7847</link>
					<pubDate>Sun, 13 Aug 2023 22:42:47 +0000</pubDate>
					<dc:creator>Patrick</dc:creator>

					<description>
						<![CDATA[
						<h2 id="mcetoc_1g2p3o4bk0"><b>Overview</b></h2>
<p>Sophos Authentication for Thin client (SATC) with Sophos Server Protection enables Sophos Firewall to authenticate users accessing a server or remote desktop. SATC is included with Sophos Server Protection in Sophos Central. It&#8217;s part of Sophos Central Server Core Agent and is available with any Server Protection license in Sophos Central. Currently, SATC with Sophos Server Protection only supports Windows Remote Desktop Services. You must download the Windows Server installer from Sophos Central. The installers that you can download would depend on the licenses you have.</p>
<p>Sophos Firewall controls those authenticated users using a session-based approach via an identity-based firewall rule providing more granular access controls per user group.</p>
<h2 id="mcetoc_1g2p3o4bk1"><strong>What To Do</strong></h2>
<p><b>Follow the steps below to set up new SATC client integration with Sophos Server Protection:</b></p>
<ol>
<li>In Sophos Central, select your username on the top right side and then select Early Access Program. Find &#8220;New Server Protection Features&#8221; in the Early Access Program and select join.<img fetchpriority="high" decoding="async" src="https://community.sophos.com/resized-image/__size/2294x722/__key/communityserver-discussions-components-files/258/pastedimage1652257076910v1.png" alt=" " width="1147" height="361" /><br />
<span lang="EN-US"><br />
</span></li>
<li><span lang="EN-IN">Once you have gone through the join process, there will be a join device option in the bottom right corner. Select this and add the terminal server. </span></li>
<li><span lang="EN-US">Add the eligible devices:</span><img decoding="async" src="https://community.sophos.com/resized-image/__size/1484x772/__key/communityserver-discussions-components-files/258/pastedimage1652257126794v3.png" alt=" " width="742" height="386" /></li>
<li><span lang="EN-IN">Once this is done, it may take some time to apply to the terminal server. When writing this article, the versions shown in the screenshot below are the latest versions supporting SATC.</span><img decoding="async" src="https://community.sophos.com/resized-image/__size/1280x960/__key/communityserver-discussions-components-files/258/pastedimage1652257260837v5.png" alt=" " />&nbsp;</li>
<li><span lang="EN-IN"><span lang="EN-US">You can validate by checking the </span><span lang="EN-US">SophosNetFilter.exe</span><span lang="EN-US"> service running from the task manager &gt; Details:</span></span><img decoding="async" src="https://community.sophos.com/resized-image/__size/1252x1116/__key/communityserver-discussions-components-files/258/pastedimage1652257284222v6.png" alt=" " width="626" height="558" /><span lang="EN-IN"><span lang="EN-US"> </span></span></li>
<li><span lang="EN-IN"><span lang="EN-US">Turn off tamper protection for server protection. Note the current settings before you turn off tamper protection, as you need to change these back once SATC is activated.</span></span></li>
<li><span lang="EN-IN"><span lang="EN-US">Ensure IPS is turned on in the server&#8217;s threat protection policy. This setting is on by default. For more information, refer the screenshot below:<br />
Path On Sophos Central: Server Protection &gt; Policies &gt; Threat Protection &gt; Settings &gt; Server Protection default settings &gt; Runtime Protection.</span></span><img loading="lazy" decoding="async" src="https://community.sophos.com/resized-image/__size/1774x460/__key/communityserver-discussions-components-files/258/pastedimage1652257328129v7.png" alt=" " width="887" height="230" />&nbsp;</li>
<li><span lang="EN-IN"><span lang="EN-US">Set up SATC with Sophos Server Protection.</span></span></li>
<li><span lang="EN-IN"><span lang="EN-US">On the server, open a command-line console/Power Shell. Add new parameter Satc PendDuration Ms in SATC, run the following command <strong>to turn on SatcPendDurationMs</strong> parameter<br />
command: &#8211; <strong>reg add &#8220;HKLM\Software\Sophos\Sophos Network Threat Protection\Application&#8221; /v SatcPendDurationMs /t REG_DWORD /d 300</strong></span></span><img loading="lazy" decoding="async" src="https://community.sophos.com/resized-image/__size/1744x368/__key/communityserver-discussions-components-files/258/pastedimage1652257409765v8.png" alt=" " width="872" height="184" />&nbsp;</li>
<li><span lang="EN-IN"><span lang="EN-US">Please ensure to reboot the Terminal Server once changes are applied.</span></span></li>
<li><span lang="EN-IN"><span lang="EN-US">Lastly, check the windows registry to confirm the changes under: HKLM\Software\Sophos\Sophos Network Threat Protection\Application</span></span><img loading="lazy" decoding="async" src="https://community.sophos.com/resized-image/__size/1438x890/__key/communityserver-discussions-components-files/258/pastedimage1652257439471v10.png" alt=" " width="719" height="445" /></li>
</ol>
<p><span lang="EN-IN"><span lang="EN-US">If you face any issues or need further assistance with this, kindly reach out to our Support team</span></span></p>
						]]>
					</description>

					
					
				</item>

					
		
	</channel>
	</rss>

