Skip to content
Avanet

Register a Sophos Access Point in Sophos Fusion

To register a Sophos Access Point today, open My Products > Wireless > Access Points in Sophos Fusion (formerly Sophos Central). You can add one device by serial number or provision several devices from a CSV file. The current workflow does not use an automatic first-time wizard sequence of Access Point, SSID, and site.

Quick registration path

  1. Sign in at https://fusion.sophos.com and open My Products > Wireless > Access Points.
  2. Click Register, enter the serial number, and click Register again. Sophos Fusion validates the serial number.
  3. After registration, enter and save a unique hostname, such as lon-hq-3f-ap01. Adapt the example to your site, floor, and naming convention.
  4. Check the registration status, Config status, and then a real wireless client.

For several devices, use Register > Bulk Provisioning instead.

Requirements before registration

The Access Point must be able to communicate with Sophos Fusion, be at factory-default settings, and have been deleted from any Sophos Firewall or Sophos Fusion account where it was previously registered.

Before starting, verify that:

  • You can access Wireless in Sophos Fusion and have the serial number from the device or its packaging.
  • The overview of current AP6 models shows which models can be managed through Sophos Fusion and which device fits the deployment location, radio bands, uplink, PoE, and SKU region.
  • Power, network access, and communication with Sophos Fusion work. DHCP, DNS, NTP, PoE, and ports are covered in Sophos Central Wireless requirements.
  • Registration itself can complete without a licence, but ongoing management of each AP6 through Sophos Fusion requires a valid AP6 Support and Services licence. The Sophos Fusion licensing guide explains how this applies in practice.

Register one Access Point or use CSV

One device

Open My Products > Wireless > Access Points, click Register, enter the serial number, and confirm with Register again. That confirmation starts validation. Once registration succeeds, enter and save the hostname; the device then appears in the list.

Historical wizard screen with a serial-number field
Historical interface for orientation: follow the current text path My Products > Wireless > Access Points > Register.

This image shows an older wizard. Do not use it as evidence of the current sequence or field layout.

Several devices with Bulk Provisioning

Create a CSV file with serial numbers in the first column. Every row must contain a unique serial number. Open My Products > Wireless > Access Points > Register, click Bulk Provisioning, and upload the file.

Handle AP6 account assignment and location

Account transfer has a special case for AP6: if an AP6 registered to another Sophos Fusion account is offline, Sophos Fusion can deregister it from that account and register it to the new one during validation. If that AP6 is online, Sophos Fusion reports an error.

An AP6 initially selects a default region from its SKU. It can only be assigned to a site within that SKU region. Match the exact SKU to the installation country before ordering and again before site assignment; Plan AP6 sites, floorplans, and regions covers the region check and controlled site assignment. Sites also restrict available frequency bands for the location. Changing an Access Point’s location restarts it to apply the configuration, so plan a maintenance window and retest afterwards.

A site is not a documented mandatory stage immediately after Register. Create it separately under My Products > Wireless > Sites for geographic assignment and appropriate regulatory radio settings. Plan and assign an SSID separately as well.

Historical wizard screen for adding an SSID
Historical interface for orientation: SSID and site are not documented mandatory stages in the current registration sequence.

Verify registration through to the client

Three views answer different questions:

  • Access points registration status: Shows the registration process. On failure, Sophos Fusion gives a reason and may link to the AP6 Registration Guide.
  • Config status: Shows whether configuration and update state are current, pending, or offline. It does not replace registration status.
  • AP6 Task queue: Shows tasks sent from Sophos Fusion to that AP6 and their result. For ongoing profiles and recurring task-queue errors, see Manage AP6 in Sophos Fusion.

Complete the wireless configuration before testing a client: under My Products > Wireless > SSIDs, select an existing SSID or create one, carefully review its encryption and password, and assign it to the Access Point. The guide Set up an AP6 SSID with a client VLAN covers the switch, gateway, and pilot workflow.

A green device status is not a complete wireless acceptance test. Connect a test client to the intended SSID and check in order:

  1. The client authenticates and receives an address from the expected network.
  2. DNS resolution works and the intended internal or external destinations are reachable.
  3. Guest or IoT clients cannot reach networks from which the intended VLAN and firewall rules should isolate them.
  4. The Access Point stays online and Config status is no longer pending or failed after the change.

Troubleshoot, reset, or remove safely

Registration fails

Read the reason under Access points registration status, then check in this order:

  1. The serial number and old account assignment.
  2. For an AP6, the SKU/site region.
  3. The network path against the linked Central Wireless requirements.
  4. Whether the error matches the special case of an AP6 that is registered elsewhere and online.

Only after fixing the cause should you reset the Access Point and click Retry. A speculative reset does not fix another account assignment or a region mismatch.

If registration still fails, give Sophos Support the AP6 serial number, the affected Sophos Fusion account or tenant, the exact registration status and error, and the results of the network-requirement checks. This evidence is more useful than another undocumented reset.

After registration, check the AP6 Support and Services licence in the Sophos Fusion tenant as part of the management and status checks. A missing valid entitlement prevents ongoing management through Sophos Fusion, even though registration can complete without a licence. A reset does not change the entitlement; resolve the licensing in the tenant.

Remove a device from Sophos Fusion

Delete removes the Access Point from Sophos Fusion; it is not a factory reset or a one-click rollback. Before deletion, record the serial number, site, SSID assignments, and intended next management path. You cannot delete an Access Point while a mesh network is assigned: delete the mesh network first. Confirm that Sophos Fusion no longer lists the AP before registering it to another account.