Commission a Sophos Central tenant securely
A Central tenant is ready only when access, roles, directory, licenses, monitoring, audit, and recovery are defined. Installing one product is not …
Practical guides for secure Sophos Central operations: configure the tenant, secure access, synchronize directories, control licenses, monitor changes, and operate automations safely.
The articles follow the administrative lifecycle of a Central tenant: access and roles, directory and user maintenance, licensing, monitoring, automation, platform operations, and Enterprise structures. Product-specific Endpoint, Firewall, Email, or MDR configuration remains in the relevant specialist category.
SophosID, Central tenant, portals, navigation, and a controlled start in cloud management.
A Central tenant is ready only when access, roles, directory, licenses, monitoring, audit, and recovery are defined. Installing one product is not …
Administrator access, passkeys, federated sign-in, roles, Custom Roles, and least privilege.
Secure Central access requires more than a strong password: redundant MFA, minimal roles, a tested recovery process and clear IdP rules.
For Sophos Central SSO with Entra ID, verify the domain, tenant ID, email mapping, and MFA first. A differing UPN requires a dedicated OIDC app with …
Sophos Central uses SP-initiated OIDC with an ID token. Fully test the provider, callback, claims, domain, and MFA before selecting Federated …
AD FS requires a verified domain, matching email identities, and a claims-aware Relying Party Trust using the values supplied by Central.
Central roles follow least privilege. Reserve Super Admin for roles and API Credentials, and use Custom Roles to restrict products and especially …
User lifecycle and synchronization with Active Directory, Microsoft Entra ID, or Google Workspace.
This checklist protects users, groups and mailboxes from duplicates and unintended deletion during Sophos Central Directory Sync.
AD Sync is not a blind import. The source directory, OU filters, deletion behaviour, service account, schedule and error handling must be defined …
Sophos Central imports users and groups from Microsoft Entra ID. This guide covers app registration, permissions, filters, the first sync, and secret …
Google Directory Sync imports mailboxes, groups, and distribution lists for Sophos Email or Phish Threat. Plan filters, OAuth permissions, and any …
Users can originate manually, by CSV, from protected devices, or a directory. Clear source ownership prevents duplicates, incorrect roles, and …
Manual users are changed in Central; synchronized users in the authoritative directory. A new display name does not resolve wrong logins or duplicate …
Stop known recreation sources before deletion. Devices and Sophos software remain, while the associated mailbox is removed from Mailboxes.
Turn the shared Computers & Servers view into a reliable worklist by assessing inventory, protection, software scope, and lifecycle separately.
License models, activation, usage, trials, renewals, and the technical effects of expiration.
Sophos Central has no single counting model. Endpoint is generally licensed per user, Server per protected server, and Email per protected mailbox; …
A Central trial needs a named owner, a deliberate existing-versus-new tenant decision, a limited test scope, and a plan to license or clean up after …
The Licensing page shows entitlements, terms, and usage. Activation and renewal can change software components, while expired licenses restrict …
Current Sophos documentation covers setup links and a user's device view, but not a procedure for merging logins or forcing a license correction.
Alerts, Account Health, dashboards, reports, Audit Logs, export, retention, and operational escalation.
Audit Logs show who made a Central change, when, and from which IP address. The portal displays and exports no more than 90 days, so longer evidence …
Account Health assesses recommended settings and device states. A score below 100 requires review, while a green score does not prove complete …
Central dashboards are personal working views, not shared operating documentation. A useful dashboard shows alerts, health, protection status, and …
Alert emails become an operational process only when recipients, severities, cover, escalation and regular tests are defined.
Validate legacy Custom Reports before saving because their filters and time range can't be changed afterward. Delivery and visibility remain tied to …
API credentials, technical identities, third-party access, secret rotation, and secure automation.
API credentials are independent machine identities. A minimal service principal role, secure secret transfer, expiration monitoring, and traceable …
Integration Credential Manager stores third-party credentials used by Sophos integrations. Manage health, usage, inactivity, and changes separately …
Safely configure Data Ingest, Response Actions, Log Collector and Microsoft 365 in Sophos Central and verify the data flow.
Global platform functions, privacy, data sharing, Early Access Programs, and controlled changes.
Global Settings apply tenant-wide or provide shared objects. Policies control selected users and devices. Scope, priority, and rollback must be clear …
Cloud analysis improves detection and support but may transfer files, URLs, emails, logs, or telemetry. Every tenant-wide sharing option needs a …
EAP functions are prerelease versions and belong on a few non-critical pilot devices. Entry, device scope, monitoring, and rollback must be defined …
Co-branding displays a company or partner logo in selected user views and reports. Verify the logo source, preview, output, and rollback before …
Enterprise Management, sub-estates, Enterprise administrators, and master licensing.
Central Enterprise manages several separate Central tenants as sub-estates. It does not replace product configuration and requires clear access, …
Enterprise Management is a far-reaching structural change. Trial tenants are excluded, existing administrators can lose tenant access, and only …
Master Licensing creates a shared license pool for sub-estates. Conversion is irreversible, moves license management to Enterprise, and can remove …
SophosID, Support Portal, Partner Assistance, Remote Assistance, and secure preparation of a support case.
Central Admin, Self Service, Support, and firewall portals serve different purposes. Sign-in, licensing, access, and Remote Access are key …
Sophos ID is the personal identity for Sophos services. Secure management combines a verified business account with two MFA methods, appropriate …
Automatic self-service access applies to new and existing users, but turning it off later does not revoke existing access. Licenses, email addresses, …
Since July 2026, Sophos Support Assistant guides troubleshooting and case creation. Good preparation remains essential for an efficient support case.
Partners, Sophos Support, and Enterprise administrators use different access paths. Every access needs a purpose, owner, suitable duration, and …