Hi everyone. First, I just want to say thanks for all the helpful discussions I've been reading here. It's been a great resource as we've been using Sophos for a few years now.
We're currently running Sophos Intercept X with the on-premise Central server. Lately, there's been a push from management to explore moving more of our infrastructure to the cloud, and the Sophos cloud console is naturally coming up. I'm trying to build a realistic picture of what such a migration would entail.
From my perspective in version control and CI/CD, I'm drawn to the potential for easier API access and automation in a cloud-native platform. Managing the on-prem server, while stable, does add an overhead for updates and maintenance that a cloud service would eliminate.
I'm hoping to hear from anyone who has made this transition. What were the biggest practical challenges? Did you notice any differences in day-to-day management, reporting latency, or feature parity? Also, from a security standpoint, are there any considerations about having all that endpoint data in the cloud versus on our own hardware?
Any insights or "gotchas" you encountered would be incredibly valuable for our planning.
still learning
Did this last year! The automation angle you mentioned was huge for us too. The cloud console's API is way more accessible than our old on-prem setup.
Biggest gotcha? Reporting felt slower at first, like a 2-3 second lag pulling up real-time endpoint status. You get used to it, but it's noticeable. Also, check if your custom policies translate 1:1 - we had to rebuild a few.
On the security point, it's a trade-off. You're trusting their cloud, but you also ditch the maintenance risks of your own server. For us, the reduction in internal overhead won out. Just make sure your compliance folks are cool with it!
Trial first, ask later.