If you have ever looked at a Sophos invoice and wondered what “Intercept X Advanced with XDR” actually buys you, you are in good company. Our owner, Scott, put it plainly: “Even I get lost in all the name changes.” Sophos has renamed these products several times, and old names linger on renewals.
This guide sorts it out. An “endpoint” is any computer or server on your network, and endpoint protection is the security software that runs on each one. Sophos sells it in levels. Each level builds on the one below. Names and details below are as of October 2026, from Sophos’s own pages.
The short version: Intercept X is now Sophos Endpoint
In October 2025 Sophos dropped the Intercept X name from its endpoint products. In Sophos’s words, “Sophos Intercept X” is now “Sophos Endpoint”. “Central Intercept X Advanced” became “Sophos Endpoint – User”, and the server version became “Sophos Endpoint – Server”. The protection itself carried over; the label changed.
Going back further, Sophos merged its EDR and XDR options in 2021, when Intercept X Advanced with EDR became Intercept X Advanced with XDR. And before Intercept X Advanced became the standard, many offices ran an older, more basic level called Central Endpoint Protection, which Sophos retired and upgraded to Intercept X Advanced.
The levels today
| Name today | Former names | What it adds | Who it fits |
|---|---|---|---|
| Sophos Endpoint (User and Server versions) | Intercept X Advanced, Intercept X Advanced for Server; earlier Central Endpoint Protection; Intercept X Essentials customers move here at renewal | The core protection: AI malware detection, exploit blocking, ransomware protection with file rollback | Every business, as the baseline |
| Sophos EDR | New level added in late 2025 | Tools to investigate and respond: detections, case summaries, searchable device history, remote isolation | Businesses with an IT team or provider who will actually investigate alerts |
| Sophos XDR | Intercept X Advanced with XDR (earlier “with EDR”) | Pulls in firewall, email, identity, cloud and third-party data, so one investigation sees the whole picture | Businesses running several security products that should be read together |
| Sophos MDR | Sophos MDR Essentials | Sophos’s own analysts watch, hunt and respond 24/7; includes XDR | Businesses that want experts on watch around the clock |
| Sophos MDR Plus | Sophos MDR Complete | Full incident response with a dedicated lead, a response-time commitment and a breach protection warranty | Businesses where a serious incident would be especially costly |
Level 1: Sophos Endpoint, the protection on every machine
This is the software that stops bad things from running. According to Sophos’s Endpoint page, it includes deep learning malware detection (AI trained to recognize malicious files it has never seen before), more than 60 exploit mitigations switched on by default (blocks on the tricks attackers use to abuse software flaws), and CryptoGuard, which spots ransomware encrypting files and rolls those files back. It also has adaptive attack protection, which tightens defenses when it sees signs of a hands-on attacker.
Ransomware rollback matters more than it sounds. Today’s ransomware gangs pressure victims in several ways at once, and getting files back quickly takes away some of that leverage.
A few related options: Sophos sold a cheaper Intercept X Essentials level, but it is no longer sold because, Sophos says, it lacked the full defenses; those customers upgrade at renewal. Sophos Endpoint 100 is a simpler license for organizations with up to 100 employees. And Sophos Endpoint for Legacy Platforms is an add-on for older Windows and Linux systems past normal support.
Servers versus workstations
It is the same protection, licensed two ways. Sophos’s licensing guidelines list Sophos Endpoint per user and Sophos Endpoint for Server per server. EDR and XDR come in both versions too, and MDR is counted per user and per server.
Levels 2 and 3: EDR and XDR, the investigation tools
Blocking is only half the job. EDR (endpoint detection and response) records what happens on your computers so someone can investigate. Sophos EDR adds prioritized detections, AI case summaries, plain-language search, and response actions such as stopping a process or cutting a device off the network.
XDR (extended detection and response) widens the view beyond computers. Sophos XDR brings in data from email, firewalls, identity, cloud and third-party tools, and stores it in the Sophos Data Lake, a central store of security records that can be searched. That lets an investigator see that the odd sign-in, the suspicious email and the strange laptop are one attack.
The catch: EDR and XDR are tools. Someone skilled has to read the results.
Levels 4 and 5: MDR, people watching around the clock
MDR (managed detection and response) is a service, not just software. Sophos’s own security analysts monitor, investigate and hunt for threats 24/7, and Sophos MDR includes XDR. Sophos renamed the MDR tiers in 2026: MDR Essentials is now Sophos MDR, and MDR Complete is now Sophos MDR Plus. If an older invoice says “Intercept X Advanced with MDR”, it belongs to this family.
According to Sophos’s MDR service description, both tiers include 24/7 investigation, threat hunting and response actions such as isolating a computer. The customer chooses how much Sophos may do: act first and notify, ask before acting, or only notify with guidance. MDR Plus adds full incident response for confirmed incidents, with an assigned incident response advisor, a service level agreement and a breach protection warranty, subject to Sophos’s terms. This kind of always-on watching is the same idea behind our own AI-assisted operations: machines flag, people decide.
One console: Sophos Fusion
All of these are managed from one place. In July 2026 Sophos announced Sophos Fusion, which it calls the evolution of Sophos Central. According to the Fusion page, there is nothing extra to license, and the new name is arriving in consoles over the coming months. If you still see “Sophos Central”, it is the same console.
How FTI does it
FTI is a Sophos partner, and we implement the full Sophos toolbox for our clients: firewall, endpoint, email, Wi-Fi, ZTNA (secure remote access), phishing training and MDR, all in one console and all working together, as explained in Sophos Synchronized Security, explained simply. Our team sets it up, keeps it updated and watches it. Which endpoint level fits is decided client by client, based on your risk, your systems and who else is watching. More on why we chose Sophos. Any level reduces risk; none removes it.

