Commission a Sophos Central tenant securely
A new Sophos Central tenant is not fully configured when the first endpoint is protected or the first firewall connected. The cloud platform controls administrators, licenses, users, global settings, alerts, reports, integrations, and support access. Establish these foundations before a broad product rollout.
Activate the account without creating a second tenant
Activate a tenant provisioned by Sophos or a partner through the welcome email. The message comes from do-not-reply@central.sophos.com. Verify the sender domain, recipient address, and associated organization before opening it.
If the welcome email is missing, do not immediately create a new trial or second Central account. Use the official Sophos Central Account Activation path or ask the Sophos Partner to review the registered address and invitation. A second tenant can split licenses, users, devices, and later support cases across two accounts.
After activation, verify Company Info, data region, Customer ID, partner assignment, and license inventory before downloading software. A trial tenant and a production tenant prepared by a partner are not automatically the same account.
Understand the current navigation
Sophos reorganized the Central interface in 2026. Important areas are now located here:
| Task | Current area |
|---|---|
| Alerts | My Environment > Alerts |
| Users and groups | My Environment > Users & Groups |
| Devices of all product types | My Environment > Devices |
| Account Health Check | My Environment > Account Health Check |
| Global Settings | Gear icon in the top taskbar |
| Help and interactive guides | Help icon in the top taskbar |
| Customer ID | Profile icon below the account name |
| Licenses | Profile > Licensing |
The former People area is now Users & Groups. Global Settings is no longer under My Products, but remains directly accessible through the gear icon. Do not reuse old screenshots and menu paths without verification.
Cross-product platform functions are under Global Settings > Platform. Notifications configures email alerts for administrators, Firewall Alerts, and User Activity Verification. Depending on the source model, Directory service synchronizes users and supported devices with Active Directory, Microsoft Entra ID, or Google Directory. Early Access Programs are also managed in this area. Platform navigation groups these entry points but does not replace the relevant operating guide or product boundaries.
Sophos Help is the integrated search and task assistance in the Central portal. Open it through the Help icon. It is distinct from a technical support case. Finding an article or interactive guide does not create a case.
Help search is case-insensitive and combines multiple terms with OR by default. +begriff makes a term mandatory, -begriff excludes it, * is a wildcard, and title:begriff limits the search to page titles. Quotation marks do not provide true phrase search. For narrow results, use something like +firewall +policy -email rather than an assumed phrase search.
Sophos Help contains help pages, videos, short articles, Collections, and interactive guides. Some guides only demonstrate a task; others accept input and perform the change. Before starting, determine which type it is. Treat a performed change like any other administrator change and verify it technically and in the Audit Log.
Select the personal light or dark mode through the profile. Sophos Mobile and Sophos Cloud Optix also adopt it. Firewall Management pages remain in light mode regardless. This is a display limitation, not a browser or tenant error.
Find profile and account functions
The profile icon groups personal and organizational account functions. It contains contact and partner details, Licensing, language selection, and sign-out. License activation and management, trials, and Early Access Programs are separate processes; a profile entry does not prove that rollout is complete.
Administrators and roles are not managed in the personal profile. Open the gear icon and use Global Settings > Access Control > Admins and Roles. This deliberately separates account information, license status, and permissions management.
Use Help and Guidance
The Help and Guidance icon in the taskbar provides product help as well as current cybersecurity assessments, training and certification offerings, product demonstrations, feature showcases, and other information. An assessment can support alignment with security frameworks but does not replace an independent compliance review or technical tenant validation.
Do not confuse training, demonstration, and informational content with a Central change. Before running interactive product guides, determine whether they only demonstrate or actually modify settings.
Understand Getting Started and Product Setup
Sophos Central consists of the management dashboard and separate product components installed on devices. The general Getting Started workflow assumes antimalware or Endpoint and Server protection as the entry point. A useful order is: activate the existing tenant, install the appropriate software, verify registered devices in Central, configure security policies, and only then automate user and device creation.
Central opens Product Setup automatically on first sign-in. If the page is closed, reopen it through Help > Product Setup. Select Endpoint Protection or Server Protection, followed by the installer for the target operating system. Always obtain the installer from the correct tenant and test it on a pilot device before broad distribution.
MDR, Device Encryption, Mobile, and other Central products have separate onboarding flows. The general Getting Started index is a starting sequence, not a shared installation manual for every licensed product. Visible functions remain grouped by product names such as Endpoint in Central.
Languages and browser boundaries
The Central interface supports English, German, French, Japanese, Italian, Spanish, Brazilian Portuguese, Korean, and Traditional Chinese. Endpoint agents have separate lists: Windows additionally supports European Portuguese, Simplified Chinese, Polish, and Czech; macOS supports English, German, French, Japanese, Italian, and Spanish; Linux 7 and 9 support English and Japanese. The portal language therefore does not automatically determine the installed agent language.
Central Admin supports current versions of Google Chrome, Microsoft Edge, Mozilla Firefox, and Apple Safari on macOS. Sophos targets the current and previous versions of Chrome, Firefox, and Safari. A detected unsupported browser is redirected to central.sophos.com/unsupported. Mobile devices are not supported for Central Admin, and Phish Threat in this context is limited to Chrome. Keep the administrator browser current and verify compatibility before a critical change.
Use Notifications Center
The bell icon opens medium- and low-priority notifications, including product news and maintenance notices. Its number shows unread or available notifications. High-priority notifications also appear as banners.
Depending on the notification, Turn on and More info are available. In the three-dot menu, Session dismiss removes it only until the next sign-in, while Permanently dismiss hides it permanently for that user. Use permanent dismissal only after understanding the content, ownership, and possible impact.
1. Document the tenant and ownership
Under Profile > Company Info, review company and contact details, update them where necessary, and save with Save. Then reread the company name and primary contact address. Also document Customer ID, Central data region, contract owner, and emergency contacts. Profile > Partner info shows the assigned partner’s contact details. This documents partner assignment but does not automatically grant Partner Assistance or other portal access.
Personal Account Details also group the password, MFA, email subscriptions, and account and partner information. Notification control and tenant-wide administration still remain in their designated settings.
The tenant belongs to the customer organization, not to a personal administrator or individual service provider. At least two responsible people know the recovery and support path.
2. Secure administrator access
Create two independent Super Admins before further changes. Every administrator uses a personal account, MFA with two independent methods, and an appropriate role.
Restrict Super Admin to roles, API credentials, especially critical settings, and recovery. Use Admin, Help Desk, Read-only, or Custom Roles for daily operations.
Full implementation is covered in Secure Sophos Central sign-in with MFA, passkeys, and an IdP and Assign Sophos Central administrator roles correctly.
3. Review license scope and technical effects
Under Profile > Licensing, review the product, edition, quantity, and term. Activation or upgrade can change agent components immediately. Test new functions on pilot devices first.
Details are in Activate, review, and renew Sophos Central licenses.
4. Select the user source
Before bulk import, decide whether users and groups will be maintained manually, through CSV, Active Directory, Microsoft Entra ID, or Google Directory.
Overlapping sources create duplicates, incorrect groups, and license discrepancies. A managed Directory Service is usually more stable for enterprise identities than permanent CSV maintenance. Begin with a pilot group and expand after successful matching.
5. Separate Global Settings and policies
Global Settings apply tenant-wide or provide central lists and platform functions. Policies apply product-specific protection values to selected users, devices, or groups.
A global exclusion is therefore far riskier than a narrowly assigned policy exclusion.
6. Configure alerts and notifications
Alerts appear in the portal, while email is distributed through separate rules. Separate recipients, severity levels, and escalation paths by responsibility. One personal mailbox is not a reliable alert channel.
Also review the Notifications bell regularly. It contains product news, maintenance warnings, and other medium- or low-priority notices. Only high-priority notices also appear as banners. Session dismiss hides a notice until the next sign-in; Permanently dismiss removes it permanently for that user.
7. Prepare audit and retention
The portal shows administrative Audit Log changes for at most 90 days. Before production operation, decide whether monthly exports are sufficient or whether the API or a SIEM is required.
The first controlled test is a harmless change that is then found and exported in the Audit Log. This validates roles, time zone, and retention before an incident.
Give scheduled reports an operational owner and expiration control. Personal legacy reports in particular stop after six months and cannot simply be transferred when an administrator changes. The complete process is in Schedule, export, and monitor Sophos Central reports.
8. Configure dashboards and Account Health
Review Central Overview as the starting point. Build personal dashboards around tasks rather than collecting every widget. Treat Account Health as a review requirement, not a certificate.
Operational guidance is provided in Configure Sophos Central dashboards for operations and Use Sophos Central Account Health Check correctly.
9. Minimize API and third-party access
API Credentials, Partner Assistance, and Remote Assistance are independent access paths. Give each a documented purpose, minimum required permissions, duration, and owner.
Store and monitor API secrets in a secret store. Keep Remote Assistance off by default and enable it for a limited time only for a specific support case. Secure Sophos Central Partner and Remote Assistance explains the differences and durations.
Under Account preferences > Privacy, do not enable data sharing for samples, logs, Threat Graphs, Intercept X, generative AI, and Intelix as one package.
10. Test operational handover
The tenant is ready for handover only when a second administrator can perform these tasks without relying on the implementer:
- sign in and explain MFA recovery,
- review the role and license status,
- assess the user source and last synchronization,
- open an alert and identify the responsible person,
- export the Audit Log,
- review API credentials and support access,
- find the Customer ID and Sophos Partner.
Acceptance checklist
- Two independent Super Admins with tested MFA and recovery
- Roles based on least privilege
- Correct Company Info, Customer ID, and data region documented
- Licenses, term, and pilot effect reviewed
- One authoritative source for users and groups defined
- Alert email and escalation tested
- Audit export and retention tested
- API, partner, and support access inventoried
- Privacy and data sharing approved by the responsible functions
- Scheduled reports assigned an owner and expiration control
- Dashboard, Account Health, and monthly review defined
- Operational handover passed by a second person