Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A Sophos exclusion is an exception to a particular protection feature—not a universal switch for Sophos security. Choose the narrowest exclusion that addresses the actual false positive, performance issue, or compatibility problem, and limit it to the affected devices whenever possible. Sophos’s official guidance warns: “Exclusions may significantly reduce your protection.”
What a Sophos exclusion changes
Sophos Central offers several exclusion types, each tied to a particular feature. A file or folder scanning exclusion, for example, is not the same as an exploit mitigation, ransomware, website, or hashing exclusion. The affected protection, available platforms, and management controls depend on the exclusion type and your product configuration.
Before creating one, identify four things: the protection feature involved, who or what needs the exception, the object or path being exempted, and the platform or scan mode it affects. Sophos’s documentation lists file/folder exclusions for Windows and Mac/Linux, plus Windows options such as AMSI Protection, Malicious Network Traffic Prevention (IPS), hashing, and driver detection. Other feature-specific exclusions have their own settings and effects. Check the current help for your product and operating system rather than assuming one exclusion type works everywhere.
Choose an exclusion that matches the problem
| Problem | Use this approach | Why it is narrower |
|---|---|---|
| An application is incorrectly detected as malware | Use the detection event’s SHA when available. | A path exception could also allow a malicious replacement or a modified file placed at the same location. |
| An application slows down while accessing a particular folder | Use a process exclusion for the application’s full path rather than excluding the folder. | Files in the folder may still be detected if malware arrives through another route. Files written by the excluded process are not scanned through that route; other protection may remain, depending on the exclusion and configuration. |
| An exploit or ransomware control is blocking an application | Investigate the relevant exploit mitigation or ransomware exclusion separately; narrow the exception and retain available mitigations. | These are distinct protection areas, not ordinary scanning exclusions. Disabling them is not a general performance fix. |
| A website is blocked or categorized incorrectly | Use a website exclusion only when its broader web-control effect is acceptable. | Sophos says an excluded website is also not checked for its website category for web control. |
| A file-hashing issue is suspected | Do not use a hashing exclusion as a routine scanning workaround; use it only if Sophos asks. | This exclusion stops Event Journals and the Data Lake from generating file hashes. |
For feature-specific behavior, consult Sophos’s documentation on global exclusions, using exclusions safely, and feature and platform options. Confirm that the page applies to your Sophos product and operating system.
#1 Best Overall
- XGS 88 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- Equipped with 4 x 2.5 GE copper ports, supporting up to 9.9 Gbps firewall performance for small offices and branch deployments.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
Set a global exclusion in Sophos Central
The following path is for global exclusions in Sophos Central customer help. A global exception applies across users, computers, and servers, so use it only when that broad scope is justified. If only selected endpoints need the exception, use the relevant policy instead.
- In Sophos Central, go to Global Settings > Protection and Remediation > Allow and Block > Global Exclusions.
- Select the exclusion type that matches the protection feature and choose or enter its value.
- For a Windows file or folder exclusion, specify the path and select whether it applies to real-time scanning, scheduled scanning, or both.
- Review the selected type, path, scope, and scan modes, then save the change.
Labels and available controls can differ by product, platform, role, and tenant configuration. For a policy-targeted exception, open the relevant policy and use its exclusions settings; the exact policy location depends on the Sophos product and policy type. Use the applicable current Sophos Central help page rather than substituting the global path.
Rank #2
- XGS 118 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, delivering up to 15.5 Gbps firewall performance for mid sized organizations.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
Keep Windows scanning exclusions precise
For Windows file or folder exclusions, use the full path of the specific approved application or object. Sophos permits certain wildcards, but warns that *.* is invalid on the Global Exclusions page. Broad patterns such as *.exe and whole-drive exclusions can exempt far more than the affected application.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →- Do not exclude an entire drive.
- Do not exclude
C:Windows,C:ProgramData, a user-profile folder such asC:Users<Username>, or the Startup folder. - Use the actual vendor-approved application path for your environment; example paths are not universal recommendations.
- Check whether an exclusion is drive-specific before relying on it for files accessed through a network share.
For Sophos’s Windows-specific cautions and path examples, see Global Exclusions and Using exclusions safely.
Rank #3
- Network administrators' main fears are that SSL inspection will have a performance impact or cause something to break, impacting the user experience. Sophos Firewall removes the blind spots caused by encrypted traffic by allowing you to use SSL inspection while maintaining performance efficiency.
- TLS 1.3 Decryption: Remove an enormous blind spot with intelligent TLS inspection that’s fast and effective, supporting the latest standards with extensive exceptions and point-and-click policy tools to make your job easy.
- Deep Packet Inspection: Stop the latest ransomware and breaches with high-performance streaming deep packet inspection, including next-gen IPS, web protection, and app control, as well as deep learning and sandboxing powered by SophosLabs Intelix.
- Sophos Firewall and the XGS Series appliances with dedicated Xstream Flow Processors enable the ultimate in application acceleration, high-performance TLS inspection, and powerful threat protection
- Specifications: Firewall throughput: 35,000 Mbps| Firewall IMIX: 20,000 Mbps | Firewall Latency (64 byte UDP): 4 µs | IPS throughput: 7,000 Mbps | Threat Protection throughput: 1,400 Mbps
Account for operating system and management scope
Windows
Sophos recommends policy-scoped exceptions when only some devices need them. Confirm whether the exception affects real-time scanning, scheduled scanning, or both, and avoid broad paths or patterns.
macOS
Sophos documents scanning and ransomware exclusion scenarios using POSIX paths. Verify the current product’s supported types and behavior before applying a Windows procedure to a Mac. See Sophos Central exclusions help.
Rank #4
- XGS 118 with 3 Years Standard Protection - Next-generation firewall appliance with Standard Protection subscription providing firewall, VPN, intrusion prevention, web security, and application control, managed through Sophos Central for unified policies and reporting.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, delivering up to 15.5 Gbps firewall performance for mid sized organizations.
- Protects users from ransomware, malware, phishing, and intrusion attempts before they reach endpoints or applications.
- SD-WAN features deliver reliable, optimized application performance and intelligent multi link failover.
- Includes Standard Protection – Comprehensive security package with firewall, intrusion prevention, VPN, web security, and application control to defend against everyday threats and keep business operations safe.
Linux
The available guidance covers Linux servers: it recommends full paths and policy scope, and warns that exclusions reduce protection. Do not assume that Windows exclusion types or controls are available on Linux. Consult Sophos Central help for your Linux product.
Enterprise and partner-managed tenants
Templates, delegated roles, and management hierarchy can change where exclusions are set and who can edit them. In an Enterprise template view, some exclusions created from events may not appear in the Global Exclusions list managed there. If a control is locked or missing, check your assigned role and management structure, and ask the appropriate Sophos Central administrator. See Sophos Central Enterprise help.
Best Value
- XGS 128 (Hardware Only) - Next-generation firewall appliance only; add a Sophos subscription to enable IPS, web security, VPN, and advanced threat defense.
- 9 x 2.5 GE copper ports and 1 SFP fiber port, providing up to 19.1 Gbps firewall throughput for larger offices.
- Purpose built next generation firewall hardware engineered for high performance, visibility, and reliable operation in business networks.
- SD-WAN optimization provides resilient connectivity and intelligent traffic routing across multiple WAN connections.
- VPN ready architecture supports secure site to site networking and encrypted remote employee access.
Review and remove exceptions
Record the issue, affected feature, object or path, scope, and reason for each exception. Recheck whether the problem still occurs after the related application or Sophos configuration changes, then remove exclusions that are no longer needed. Keep the remaining exception limited to the smallest scope and object that resolves the issue.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

