Commission a Sophos Fusion tenant securely
A Central tenant is ready only when access, roles, directory, licenses, monitoring, audit, and recovery are defined. Installing one product is not …
Practical guides to operating Sophos Fusion Admin, formerly Sophos Central Admin, securely: set up tenants, secure access, synchronize directories, manage licences, monitor changes and run automations safely.
The articles follow the administrative lifecycle of a tenant in Sophos Fusion Admin: access and roles, directory and user maintenance, licensing, monitoring, automation, platform operations and Enterprise structures. Product-specific Endpoint, Firewall, Email or MDR configuration remains in the relevant specialist category.
SophosID, tenants, portals, navigation and the controlled transition from Sophos Central to Sophos Fusion Admin.
A Central tenant is ready only when access, roles, directory, licenses, monitoring, audit, and recovery are defined. Installing one product is not …
Sophos Fusion is the new name for Sophos Central. This runbook guides admins through the local transition without renaming existing APIs, callbacks, …
Administrator access, passkeys, federated sign-in, roles, Custom Roles, and least privilege.
Secure Sophos Fusion access requires more than a strong password: redundant MFA, minimal roles, a tested recovery process and clear IdP rules.
For Sophos Fusion SSO with Entra ID, verify the domain, tenant ID, email mapping, and MFA first. A differing UPN requires a dedicated OIDC app with an …
Sophos Fusion uses SP-initiated OIDC with an ID token. Fully test the provider, callback, claims, domain, and MFA before selecting Federated …
AD FS requires a verified domain, matching email identities, and a claims-aware Relying Party Trust using the values supplied by Sophos Fusion.
Sophos Fusion roles follow least privilege. Reserve Super Admin for roles and API Credentials, and use Custom Roles to restrict products and …
User lifecycle and synchronization with Active Directory, Microsoft Entra ID, or Google Workspace.
This checklist protects users, groups and mailboxes from duplicates and unintended deletion during Sophos Fusion Directory Sync.
AD Sync is not a blind import. The source directory, OU filters, deletion behaviour, service account, schedule and error handling must be defined …
Sophos Fusion imports users and groups from Microsoft Entra ID. This guide covers app registration, permissions, filters, the first sync, and secret …
Google Directory Sync imports mailboxes, groups, and distribution lists for Sophos Email or Phish Threat. Plan filters, OAuth permissions, and any …
Users can originate manually, by CSV, from protected devices, or a directory. Clear source ownership prevents duplicates, incorrect roles, and …
Manual users are changed in Central; synchronized users in the authoritative directory. A new display name does not resolve wrong logins or duplicate …
Stop known recreation sources before deletion. Devices and Sophos software remain, while the associated mailbox is removed from Mailboxes.
Turn the shared Computers & Servers view into a reliable worklist by assessing inventory, protection, software scope, and lifecycle separately.
License models, activation, usage, trials, renewals, and the technical effects of expiration.
Sophos Fusion has no single counting model. Endpoint, Server, Email, and Sophos Switch follow different rules; the contract, EULA, and …
A Sophos Fusion trial needs a named owner, a deliberate existing-versus-new tenant decision, a limited test scope, and a plan to license or clean up …
The Licensing page shows entitlements, terms, and usage. Activation and renewal can change software components, while expired licenses restrict …
Current Sophos documentation covers setup links and a user's device view, but not a procedure for merging logins or forcing a license correction.
Alerts, Account Health, dashboards, reports, Audit Logs, export, retention, and operational escalation.
Audit Logs show who made a Central change, when, and from which IP address. The portal displays and exports no more than 90 days, so longer evidence …
Account Health assesses recommended settings and device states. A score below 100 requires review, while a green score does not prove complete …
Sophos Fusion dashboards are personal working views, not shared operating documentation. A useful dashboard shows alerts, health, protection status, …
Alert emails become an operational process only when recipients, severities, cover, escalation and regular tests are defined.
Validate legacy Custom Reports before saving because their filters and time range can't be changed afterward. Delivery and visibility remain tied to …
API credentials, technical identities, third-party access, secret rotation, and secure automation.
API credentials are independent machine identities. A minimal service principal role, secure secret transfer, expiration monitoring, and traceable …
Integration Credential Manager stores third-party credentials used by Sophos integrations. Manage health, usage, inactivity, and changes separately …
Safely configure Data Ingest, Response Actions, Log Collector and Microsoft 365 in Sophos Fusion and verify the data flow.
Global platform functions, privacy, data sharing, Early Access Programs, and controlled changes.
Global Settings apply tenant-wide or provide shared objects. Policies control selected users and devices. Scope, priority, and rollback must be clear …
Cloud analysis improves detection and support but may transfer files, URLs, emails, logs, or telemetry. Every tenant-wide sharing option needs a …
EAP functions are prerelease versions and belong on a few non-critical pilot devices. Entry, device scope, monitoring, and rollback must be defined …
Co-branding displays a company or partner logo in selected user views and reports. Verify the logo source, preview, output, and rollback before …
Enterprise Management, sub-estates, Enterprise administrators, and master licensing.
Sophos Central Enterprise manages several separate Sophos Fusion tenants as sub-estates. It does not replace product configuration and requires clear …
Enterprise Management is a far-reaching structural change. Trial tenants are excluded, existing administrators can lose tenant access, and only …
Master Licensing creates a shared license pool for sub-estates. Conversion is irreversible, moves license management to Enterprise, and can remove …
SophosID, Support Portal, Partner Assistance, Remote Assistance, and secure preparation of a support case.
Sophos Fusion Admin, Self Service, Support, and firewall portals serve different purposes. Sign-in, licensing, access, and Remote Access are key …
Sophos ID is the personal identity for Sophos services. Secure management combines a verified business account with two MFA methods, appropriate …
Automatic self-service access applies to new and existing users, but turning it off later does not revoke existing access. Licenses, email addresses, …
Since July 2026, Sophos Support Assistant guides troubleshooting and case creation. Good preparation remains essential for an efficient support case.
Partners, Sophos Support, and Enterprise administrators use different access paths. Every access needs a purpose, owner, suitable duration, and …
Sophos Fusion Admin is the central management interface for a tenant’s licensed products, users, devices and account. The current product name is Sophos Fusion Admin, even though technical addresses and documentation paths may still contain central.
For customer sign-in, open https://central.sophos.com/manage/login. A redirect to a path under /manage/central-login and the page title Sophos Central Login are currently expected. This older technical name therefore indicates neither a sign-in error nor a different management platform.
This overview is deliberately limited to the shared platform. Setup and operation of individual products belong in the relevant specialist guide within the topic areas listed below.
Open role management under Global Settings > Access Control > Admins and Roles. On the administration roles page, Super Admin and Admin can access licensed products. Only Super Admin can also manage roles and role assignments—including a custom role—as well as API Tokens and API Credentials. Help Desk and Read-only have more limited or read-only capabilities.
A custom role can restrict access to specific products and selectively add permissions for Policies or for Logs and Reports. The options shown also depend on the available product licences, so a missing feature is not necessarily a display error. The complete guide to planning, assigning and checking roles is in Access, MFA, and roles.
These Sophos roles are separate from roles in Microsoft 365. Managing Sophos administration roles does not define Microsoft 365 roles and, in particular, does not replace any administrator or consent permissions required there.
After changing a role, sign in with a dedicated test administrator in a private browser session. Only the licensed products and the actions intended for Super Admin, Admin, Help Desk, Read-only or the selected custom role should be visible. At least one permitted action must work, while an intentionally withheld action must be denied.
If an expected product or feature is missing, first check the product licence, which products have been enabled for the role, and which additional permissions it has for Policies and for Logs and Reports. Do not broaden the role as a precaution. If the discrepancy persists, stop the change and resolve it using the detailed role guide before using the account in production.