Activate, review, and renew Sophos Fusion licenses
The license page in Sophos Fusion (formerly Sophos Central) is more than a commercial overview. A new or changed license scope can install software components on devices, enable functions, or restrict protection and access to Fusion after expiration.
The current path is Profile icon > Licensing. It shows the product, license type, term, and reported usage. The figures are not necessarily updated in real time and must always be assessed together with device, user, and product reports.
Check a license before activation
Compare the License Schedule, tenant, and product scope before redeeming a key. An activation code can only be used once. If several tenants or firewalls exist, there must be no doubt about which account or device owns the license.
The review should include:
- name and data region of the Fusion tenant,
- product and edition,
- quantity or agreed usage,
- term and start and end dates,
- initial purchase, upgrade, or renewal,
- affected devices and components already installed,
- responsible Sophos Partner.
A license change can update devices outside a planned update window. For example, adding XDR to existing Endpoint protection can cause Fusion to install the required components on affected computers. A newly assigned Device Encryption feature can likewise install software immediately.
Activate the license
- Click the Profile icon and open Licensing.
- Select Apply Activation Code or Apply License Key.
- Paste the key from the License Schedule and apply it.
- Compare the product, edition, quantity, and term again after activation.
- Check which components were installed or updated on pilot devices.
A trial initially requires no activation key. The new license scope is only activated when switching to a paid license.
Interpret usage correctly
The calculation is product-specific. Endpoint products are user-based for most customers. A user may own several devices, while each device is assigned to one active user. Usage is calculated independently for each license type. A user consuming Endpoint therefore does not automatically consume XDR or Device Encryption as well.
Important details:
- Devices offline for more than 30 days are temporarily excluded from Endpoint usage.
- When such a device returns, it automatically consumes a license again.
- Duplicate local logins can appear as several Fusion users and increase usage.
- An endpoint without active real-time scanning does not count toward Endpoint Protection usage.
- RDS sessions require Server Protection and are not licensed as normal Endpoint users.
- Other products such as Email, Server, Firewall, Wireless, or Switch use their own calculation models.
The product display may understate contractual usage. If figures differ, the Sophos EULA or the specific license agreement takes precedence over the counter in the portal.
Find the cause of increased usage
For Endpoint users, go to Reports > Users. Review active users, assigned devices, and last activity. This report helps with root-cause analysis, but it is not a complete license report for every product.
Common causes include:
- the same person using different local logins on several computers,
- old or newly installed devices coming back online,
- incorrectly assigned logins after imaging or a domain migration,
- enabled product components that are not required on every device,
- test or pilot devices that were never cleaned up.
Assign Sophos Fusion licenses to users explains how to associate several logins with an existing user. A license is not manually selected like a Microsoft 365 plan. Fusion calculates usage from the product, device, user assignment, and activity.
Monitor trials
Fusion trials normally run for 30 days. Several trials can run in parallel unless their features overlap. The first banner appears at the beginning with 28 days remaining and confirms that the trial is active. A purchase warning follows three days before expiration. After expiration, the notice remains until a license is applied to the product or its use stops.
Start a new trial under My Products > Free Trials by selecting Start Trial for the required product. The trial then appears on the Licensing page and the product download or onboarding becomes available. In the License # column, trial licenses begin with C and regular licenses with L; Expires shows the end date.
A Sophos Partner or Account Manager can extend an active trial. After expiration, the same product trial cannot immediately be restarted by the customer; Fusion normally enforces a 30-day waiting period. A product with a regular license is not also offered as a trial.
If you want to keep the product, Buy Now on the Free Trials page takes you to the partner selection page. The purchase itself is completed with a Sophos Partner; clicking Buy Now does not activate a license.
Trial tenants have size limits, including up to 1,000 objects per object type, such as users, groups, mailboxes, or devices. This trial limit no longer applies after switching to a paid license.
Do not allow a trial to become an unnoticed production dependency. Define the purchasing decision, rollback, data retention, and post-expiration behavior before the technical pilot starts.
Technical questions about the running product belong with Sophos Support. Extensions, licensing feedback, and purchases belong with the Sophos Partner or Account Manager. This separation prevents a technical case without commercial authority from stalling as an assumed trial-extension request.
Check product availability in the data region
Not every Sophos product is available in every Fusion data region. Sophos lists restrictions for individual products such as ITDR, Sophos Mobile, or APX access points in Australia, Brazil, Canada, India, and Japan. The US and EU regions support the full product range.
For Sophos ITDR, the current product-specific availability gate also applies: ITDR is available only in the Sophos Fusion data regions Germany, Ireland, and US. Before purchase or activation, check the existing tenant’s region under Account Details > Account Preferences. Match these region and UI labels exactly against the License Schedule; the company’s location or billing address does not replace this check. For the complete region, license, and role review, see Planning Sophos ITDR: Prerequisites, licenses, regions, and roles.
Choose the region before creating the tenant and purchasing licenses, based on the portfolio that will actually be used. An incompatible license in a tenant in an unsupported region cannot be repaired by repeatedly redeeming it. The Sophos Partner must cancel the license and reissue it for a suitable new Fusion tenant.
Do not change a data region solely for one possible future feature. Evaluate privacy, existing devices, directories, integrations, support, and migration effort together.
Expiration and renewal
Fusion displays a notice at every sign-in starting 30 days before a license ends. You can dismiss it, but it returns at the next sign-in and is visible to all administrators with access. View licenses opens the Licensing page, where you can apply a key or ask the partner to renew.
The warning becomes more urgent after expiration. If all licenses have expired and no action is taken, the final warning cannot be dismissed: until renewal, only the Licensing page remains accessible in the Fusion account, and the tenant may later be deleted.
Exact behavior depends on the product and license type. Endpoint impacts can include:
- existing devices no longer receive updates,
- new devices cannot be protected,
- policies can no longer be changed,
- unlicensed components are removed,
- pages and products disappear from navigation,
- Tamper Protection can remain active even after the license is cancelled.
For Sophos Email, make sure before final expiration that mail flow, MX records, and connectors no longer point to an inactive service. Firewall subscriptions have different consequences and are covered in the Firewall category.
Prepare a renewal without interruption
Start the operational review at least 60 days before expiration:
- Record the license inventory and actual usage.
- Remove devices, users, and products that are no longer required.
- Agree the desired edition and new functions with the partner.
- Clarify the License Schedule and automatic or manual activation.
- Pilot the technical effects of an upgrade.
- After renewal, verify the term, usage, and device components again.
A purchase order alone does not confirm a renewal. The decisive evidence is the new status in the correct Fusion tenant and continued update and protection functionality on the devices.
Common problems
Usage exceeds purchased quantity
Separate the review by license type first. Then check active users, device assignments, duplicate logins, and recently reactivated devices. Fusion does not automatically disable functions for every calculated overage, but contractual underlicensing still needs to be corrected.
Usage does not fall immediately after deletion
License calculations are delayed. For Endpoint, a deleted device can still affect the calculation until the 30-day window ends. Do not repeatedly delete or reinstall the inventory. Wait for the documented period and check again.
License activated, but function is missing
Check the tenant, product edition, term, and affected devices. Then verify the agent mode, software package, and policy assignment. Not every license immediately installs every function on every device.
Fusion only shows Licensing
If all licenses have expired, access may be restricted to this page. Apply a valid key or clarify the renewal status with the Sophos Partner.