Skip to content
Avanet

Configure OpenID Connect and Okta for Sophos Fusion SSO

Sophos Fusion (formerly Sophos Central) can use an OpenID Connect provider for SP-initiated Single Sign-on. Sign-in starts at Sophos Fusion and is redirected from there to the identity provider. An IdP-initiated dashboard link alone is therefore not a valid functional test.

Prerequisites

Requirements include a Super Admin, a domain verified in Fusion, a tested fallback administrator, and an OIDC provider that accepts the authorization requests expected by Sophos. Every affected Fusion account must be assigned to one domain and exactly one identity provider.

Set up the domain before the provider:

  1. Open Global Settings > Access Control > Sign-in and Identity > Sophos Sign-in > Verify domains.
  2. Under Federated domains, select Add domain and enter your domain. example.com only represents your organization’s domain and must be replaced.
  3. Use Copy to obtain the displayed TXT record, publish it in public DNS, and wait for propagation. Sophos states that this can take up to 24 hours.
  4. In Fusion, select Verify domain ownership for the domain, then Verify. The status must show the domain with a verification date.

Verification lasts for one year and can be renewed during that year. Add its expiry to operational planning; a federation that works today does not remove the need to reverify later.

Fusion requires four provider values:

FieldMeaning
Client IDPublic identifier of the OIDC application created for Sophos Fusion
IssuerExact issuer URL whose value matches the iss claim in the ID token
Authz endpointHTTPS endpoint for the authorization request
JWKS URLHTTPS endpoint containing the provider’s public signing keys

The callback URL is exactly https://federation.sophos.com/login/callback. Sophos requests openid profile email, response_type=id_token, and response_mode=form_post. The provider must return an ID token; Sophos does not request an authorization code in this flow.

Configure the Okta app

In the Okta Admin Console, create an application under Applications > Create App Integration:

  1. Select OIDC – OpenID Connect, then Single-Page Application.
  2. Assign a unique name such as Sophos Fusion SSO.
  3. Under Grant type, clear the core grant Authorization Code.
  4. Under Advanced > Other grants, enable Implicit (hybrid).
  5. Enter https://federation.sophos.com/login/callback as the Sign-in redirect URI.
  6. Remove existing Sign-out redirect URIs.
  7. Initially restrict assignment to a defined pilot group. Sophos shows all organization users as a simple example; a pilot group provides a more controlled rollout.
  8. Save and record the Client ID.

The selected Okta Authorization Domain provides the Issuer. With a Custom Domain, for example, it may be https://login.example.com. This normally produces:

Issuer:         https://login.example.com
Authz endpoint: https://login.example.com/oauth2/v1/authorize
JWKS URL:       https://login.example.com/oauth2/v1/keys

Do not copy values from an example. Verify them against discovery or provider configuration in the actual Okta tenant. An Issuer using a different Authorization Server may have different paths.

Create the provider in Sophos Fusion

  1. Open Global Settings > Access Control > Sign-in and Identity > Federated identity providers.
  2. Select Add identity provider and enter a name and description.
  3. Select Type: Open ID Connect and the matching vendor, such as Okta.
  4. Enter the Client ID, Issuer, Authz Endpoint, and JWKS URL exactly.
  5. Select the verified domain. Multiple domains are possible, but a user remains assigned to exactly one.
  6. Select IdP enforced MFA only when the provider guarantees MFA for all affected identities. With No IdP enforced MFA, Fusion enforces its own MFA check after successful IdP authentication.
  7. Save, reopen the provider, and enable it with Turn on after configuration is complete.

Sophos lists OIDC as a possible provider for Google Workspace but does not supply a comparable complete field set in the Fusion guide. Obtain the values from the actual Google or Cloud Identity OIDC configuration and validate them in the pilot. Do not transfer Okta paths to Google.

Sign-in mode and pilot

Under Global Settings > Access Control > Sign-in and Identity > Sophos sign-in, first select Sophos Central Admin or Federated credentials. After saving, the administrator making the change checks that Fusion has automatically added them to a Custom Sign-in Rule with Sophos sign-in. This rule is an additional fallback, not a replacement for a separately tested second Super Admin.

Start the positive test at https://fusion.sophos.com in a private browser session. After the pilot email address is entered, the browser must redirect to Okta, request the intended MFA there, and then open the Sophos Fusion dashboard with the expected role. Then test at least these cases:

  • valid pilot user with IdP MFA,
  • user without app assignment,
  • incorrect or unverified domain,
  • expired IdP session,
  • sign-out followed by a new SP-initiated sign-in,
  • second Super Admin through the fallback path.

Consider Federated credentials only only after a successful pilot. Assigning the IdP app to every user does not replace checking that each Fusion account is assigned to the correct domain and provider.

Troubleshooting

  • Invalid redirect or sign-in loop: Check callback, application type, and the implicit ID-token flow.
  • Unknown issuer: The iss value in the ID token must match Fusion’s Issuer field exactly.
  • Signature cannot be verified: Check the JWKS URL, HTTPS availability, and currently published key.
  • User is not found: Compare the email claim, Fusion email address, and domain assignment.
  • Provider cannot be enabled: Required fields, the domain, or a URL format is incomplete or invalid.
  • MFA is missing or appears twice: Review the IdP policy together with Fusion’s IdP enforced MFA selection.

Deactivate or roll back safely

Before maintaining the OIDC provider, change Sophos sign-in back to Sophos Central Admin or Federated credentials. Two Super Admins then test their Sophos access in private browser sessions. To return fully to Sophos Central Admin email and password, users without a usable Sophos password set a new one with Reset Password.

Only after these tests should you turn off the Fusion provider or withdraw IdP app assignments. Retain the domain, provider values, IdP app, and Custom Sign-in Rule until sign-in, roles, and the Self Service Portal have been confirmed through the fallback path. If the fallback fails, keep the OIDC provider active and restore the previous sign-in setting.

Sign-in Rules, break-glass access, MFA recovery, and changing the tenant mode are explained in Secure Sophos Fusion sign-in with MFA, passkeys, and an IdP.

Frequently asked questions

Does Sophos Fusion support the Authorization Code Flow?

For this OIDC flow, the current Sophos guide describes an implicit request using response_type=id_token without requesting an authorization code. The provider app must match this documented behavior exactly.