Commission a Sophos Central tenant securely
A Central tenant is ready only when access, roles, directory, licenses, monitoring, audit, and recovery are defined. Installing one product is not …
Practical guides for secure Sophos Central operations: configure the tenant, secure access, synchronize directories, control licenses, monitor changes, and operate automations safely.
The articles follow the administrative lifecycle of a Central tenant: access and roles, directory and user maintenance, licensing, monitoring, automation, platform operations, and Enterprise structures. Product-specific Endpoint, Firewall, Email, or MDR configuration remains in the relevant specialist category.
SophosID, Central tenant, portals, navigation, and a controlled start in cloud management.
A Central tenant is ready only when access, roles, directory, licenses, monitoring, audit, and recovery are defined. Installing one product is not …
Administrator access, passkeys, federated sign-in, roles, Custom Roles, and least privilege.
Secure Central access requires more than a strong password: redundant MFA, minimal roles, a tested recovery process and clear IdP rules.
For Sophos Central SSO with Entra ID, verify the domain, tenant ID, email mapping, and MFA first. A differing UPN requires a dedicated OIDC app with …
Sophos Central uses SP-initiated OIDC with an ID token. Fully test the provider, callback, claims, domain, and MFA before selecting Federated …
AD FS requires a verified domain, matching email identities, and a claims-aware Relying Party Trust using the values supplied by Central.
Central roles follow least privilege. Reserve Super Admin for roles and API Credentials, and use Custom Roles to restrict products and especially …
User lifecycle and synchronization with Active Directory, Microsoft Entra ID, or Google Workspace.
AD Sync is not a blind import. The source directory, OU filters, deletion behaviour, service account, schedule and error handling must be defined …
Sophos Central imports users and groups from Microsoft Entra ID. This guide covers app registration, permissions, filters, the first sync, and secret …
Google Directory Sync imports mailboxes, groups, and distribution lists for Sophos Email or Phish Threat. Plan filters, OAuth permissions, and any …
Users can originate manually, by CSV, from protected devices, or a directory. Clear source ownership prevents duplicates, incorrect roles, and …
Manual users are changed in Central; synchronized users in the authoritative directory. A new display name does not resolve wrong logins or duplicate …
Deleting a Central user removes neither devices nor Endpoint software. Directory Sync or a device still in use can recreate the user automatically.
License models, activation, usage, trials, renewals, and the technical effects of expiration.
Sophos Central has no single counting model. Endpoint is generally licensed per user, Server per protected server, and Email per protected mailbox; …
The Licensing page shows entitlements, terms, and usage. Activation and renewal can change software components, while expired licenses restrict …
Central does not assign Endpoint licenses manually. Multiple logins for the same person can create duplicate users and should be mapped to one …
Alerts, Account Health, dashboards, reports, Audit Logs, export, retention, and operational escalation.
Audit Logs show who made a Central change, when, and from which IP address. The portal retains at most 90 days, so operations need recurring exports …
Account Health assesses recommended settings and device states. A score below 100 requires review, while a green score does not prove complete …
Central dashboards are personal working views, not shared operating documentation. A useful dashboard shows alerts, health, protection status, and …
Alert emails become an operational process only when recipients, severities, cover, escalation and regular tests are defined.
A scheduled Central report needs a business owner, appropriate recipients, and expiration monitoring. Legacy reports in particular stop after six …
API credentials, technical identities, third-party access, secret rotation, and secure automation.
API credentials are independent machine identities. A minimal service principal role, secure secret transfer, expiration monitoring, and traceable …
Integration Credential Manager stores third-party credentials used by Sophos integrations. Operate health, usage, inactivity, and rotation separately …
Global platform functions, privacy, data sharing, Early Access Programs, and controlled changes.
Global Settings apply tenant-wide or provide shared objects. Policies control selected users and devices. Scope, priority, and rollback must be clear …
Cloud analysis improves detection and support but may transfer files, URLs, emails, logs, or telemetry. Every tenant-wide sharing option needs a …
EAP functions are prerelease versions and belong on a few non-critical pilot devices. Entry, device scope, monitoring, and rollback must be defined …
Enterprise Management, sub-estates, Enterprise administrators, and master licensing.
Central Enterprise manages several separate Central tenants as sub-estates. It does not replace product configuration and requires clear access, …
Enterprise Management is a far-reaching structural change. Trial tenants are excluded, existing administrators can lose tenant access, and only …
Master Licensing creates a shared license pool for sub-estates. Conversion is irreversible, moves license management to Enterprise, and can remove …
SophosID, Support Portal, Partner Assistance, Remote Assistance, and secure preparation of a support case.
Central Admin, Self Service, Support, and firewall portals serve different purposes. Sign-in, licensing, access, and Remote Access are key …
Automatic self-service access applies to new and existing users, but turning it off later does not revoke existing access. Licenses, email addresses, …
Since July 2026, Sophos Support Assistant guides troubleshooting and case creation. Good preparation remains essential for an efficient support case.
Partners, Sophos Support, and Enterprise administrators use different access paths. Every access needs a purpose, owner, suitable duration, and a …