Skip to content
Avanet

Manage Sophos Central users and groups

Users in Sophos Central are more than an address book. They connect logins, devices, groups, policies, mailboxes, administration, and license usage. Define which system owns an identity before creating it.

The current path is My Environment > Users & Groups. Users can be created manually, by CSV, through Directory Service, or automatically when a user signs in to a protected device.

Choose the correct source

MethodSuitable forConsiderations
ManualIndividual local users, test or emergency accountsLifecycle and changes must be maintained in Central
CSV importOne-time larger import without a directoryLater updates need a clear process
AD or Entra IDEnterprise identities and groupsChanges normally occur in the source platform
Google DirectoryEmail and Phish Threat objects from Google WorkspaceRequires the appropriate Sophos license and OAuth permissions
Automatically from deviceDetection of active Endpoint loginsLocal accounts can create duplicates and additional license usage

Use one authoritative source for the same user population where possible. Manual and synchronized objects with similar but non-identical email addresses frequently create duplicates.

Under My Environment > Users & Groups > Users, the list shows health, name, email address, optional Exchange Login, Last Active, group, and role. Last Active is the last time the user was reported to Sophos Central. The role column is visible only when the signed-in person has administrator permissions. Select a column heading to sort; Last Active is emphasized by default. The user name opens the complete profile. Green means no or only low Alerts, orange means medium, and red means critical Alerts on at least one assigned device. Health is an investigation entry point, not an independent device finding. Shared mailboxes managed in Microsoft Entra ID can also appear as users; they have neither administration roles nor associated devices.

The page manages users and groups and, when needed, starts device protection. Groups let the same user policy be assigned to several people. Users do not necessarily need to exist before centralised software deployment: obtain the tenant-bound installer from My Environment > Installers. When it runs on a device, Central automatically adds the signed-in user. Then verify in the user profile that Central associated the expected login and device.

Add a user manually

  1. Open My Environment > Users & Groups.
  2. Select Add User.
  3. Enter a display name without a domain prefix.
  4. Add the email address and, if required, manager or Exchange Login.
  5. Optionally search for and assign an existing user group.
  6. Assign an administrator role only for an administrative responsibility. Only a Super Admin can assign an administrator role in this dialog.
  7. Optionally send a setup link for the required protection type.
  8. Finish with Save or Save and Add Another.

A setup link requires internet access and local administrator permissions for installation. It is usually not the preferred method for a managed rollout through MDM, RMM, GPO, or software distribution.

For existing users, select the required people on Users and choose Email Setup Link at the top right. If several protection types are licensed, select only the required scope in the dialog. The link does not replace a controlled enterprise rollout and should not be sent to users without local installation rights.

The User role grants no administrative permissions and is intended for the Self Service Portal. A user who receives an administrator role gets an email explaining how to set up the administration account. Assign administrator roles according to least privilege. See Assign Sophos Central administrator roles correctly.

Import users by CSV

Under Import users from CSV, Central provides a template. Maximum file size is 1 MB. The import can include groups and create them when required.

A CSV import is blocked while Central is synchronizing Active Directory, Microsoft Entra ID, or Google Cloud Directory. In the import dialog, select the file through Browse. Create new groups creates missing groups named in the CSV; Give users access to Sophos Central Self Service sends Self Service Portal registration. Add then imports the records.

Email addresses control matching:

  • a match to an existing manual user updates that object,
  • a match to a Directory Service-managed user causes Central to skip the row,
  • a row containing a previously unknown manager can cause Central to create an additional user object for the manager.

The imported-user count can therefore exceed the number of CSV rows. Use a small test file before production import and review the change in the Audit Log.

Use groups for policies

Create groups and assign users under Groups. A group collects users for shared policies. Deleting a group does not delete its users.

The group list shows the name and number of users. The name opens its details. For a new group, select Add Group, assign a unique Group Name, and search for people under Available Users. Picker arrows move them into the assigned list; Save completes creation.

To change a group, open it and select Edit below the name. Add or remove members with the same picker arrows and save with Save. To delete it, either select the group in the list and choose Delete at the top right, or use Delete below the name on its detail page. In Confirm Group Deletion, choose Yes. First record the members and inspect Policies to identify active policies applied through the group. Deletion keeps users but can end their prior policy assignment. If a local group is deleted by mistake, recreate it with the same name, recorded members, and intended policy assignments, then validate the result on a pilot user.

On a group’s details page, Policies shows active policies. A policy opened and edited there can be assigned to several groups. The change affects every assignment, not only the group currently being viewed.

Name groups for stable functions, such as Finance-Users or Endpoint-Pilot, rather than temporary projects without an owner. Maintain synchronized groups in the source platform.

Validate the user profile

After creation, open the user profile and review:

  • email address and authoritative source,
  • administrator role and MFA status,
  • group memberships,
  • assigned logins,
  • devices and last contact,
  • applied policies,
  • linked mailboxes and current Events.

A lock icon identifies an object synchronized from AD or Entra ID. Its master data cannot be changed directly in Central like a manual user.

The left column with health and account details remains visible across tabs. A role badge opens the assigned administrator-role definition. For a Central administrator, MFA information also appears; a Super Admin can use Reset to permit new MFA method setup. Perform reset only after identity verification and through a documented recovery process.

A manual user can be changed through Edit. First & Last name must not contain a domain name. For a directory object, this field shows the supplied Display Name, which need not follow a first-name/last-name pattern. Super Admins can assign Super Admin, Admin, Help Desk, Read-only, or User, but cannot change their own role. User permits only Self Service Portal. Email address, optional Exchange Login, groups, and setup link can also be maintained. Save stores the profile change. Review the role, groups, and email address again in Summary. For synchronized users, master data remains in the source, while Central groups and additional logins can still be permitted.

Read profile areas separately:

  • Recent Events shows the latest device Events; Events contains the full list with severity, reporting agent, details, and a link to Events Report.
  • Devices shows device type and operating system, as well as servers the user connected to through Remote Desktop Services. The device name opens details. Depending on product, Actions can offer Update Now, Scan Now, Diagnose, or Delete. Delete removes only the Central object and does not uninstall Sophos, so it is not a cleanup step.
  • Policies shows names, enabled state, and included functions. Editing a policy affects every user assigned to it.
  • Groups shows memberships and permits Edit for locally managed assignments.
  • Logins shows sign-ins assigned to the user. Change them only after reviewing device and license effects.

Do not casually allow a device-specific false positive globally from the user profile. An offered action can create an exclusion for every user and computer. Business assessment and the narrowest scope follow the Sophos Endpoint exclusions runbook.

Export the user list

Under My Environment > Users & Groups > Users, Export to CSV creates users.csv. Active filters are included. For an administrator list, first select Admins only; for a full export, remove unintended filters. Document the filename, tenant, filter, and export date because users.csv alone does not prove its scope later.

Distinguish user and device policies

A user policy follows the user across devices. A device policy applies to a particular device or device group independently of the signed-in person. When both apply to the same function, order on the Policies page decides. Central checks from top to bottom and uses the first matching policy.

Group membership alone therefore does not guarantee that the expected policy wins. Check the policy actually applied on the user or device details.

Review a user’s policies

Open My Environment > Users & Groups > Users, select the user name, and go to Policies. The list shows enabled policies applied to the user. Summary shows the name, enabled state, and symbols for each policy’s functions.

Selecting a policy name opens its details and, with a suitable role, permits editing. The change affects all users assigned to that policy, not only the open profile. Review assignments, priority, and affected groups before saving. For the complete list, move from Summary to Policies, then verify on the user or pilot device which policy actually applies.

Avoid duplicates

Common causes include:

  • different local logins for the same person,
  • differing UPN and email addresses,
  • parallel manual and synchronized creation,
  • two directory sources with overlapping scope,
  • imaging with a local installation account.

Assign logins to an existing user only after business verification. Current licensing behavior is covered in Merge Sophos Central logins and correct license usage.

Frequently asked questions

Must every Endpoint user be created manually before installation?

No. Users can arise through Directory Sync or operation of a protected device. A planned source remains important to prevent duplicates and incorrect assignment.

Can a CSV import change synchronized users?

No. When the email address matches a Directory Service-managed user, Central skips that user during import.

Does removing a group also delete its users?

No. Users remain. Still review which policies were assigned through the group before deletion.