Skip to content
Avanet

Configure Sophos Central Self Service Portal access

The Sophos Central Self Service Portal lets users perform certain tasks without an administrator. Visible functions depend on the licensed product. Typical examples include managing quarantined email, Device Encryption recovery, and Mobile tasks.

The portal is available only with Sophos Email, Sophos Central Device Encryption, or Sophos Mobile. Endpoint Protection alone does not automatically provide an endpoint user portal.

Portal purpose and license boundaries

Users can perform only the self-service tasks of the licensed product. Examples include managing quarantined messages with Sophos Email, Central Device Encryption recovery, or Sophos Mobile tasks. At least one of these three licenses is required.

For Sophos Email, User Settings additionally determine which functions users receive in the portal. An invitation therefore does not enable every possible action automatically. Before rollout, assess the license, user assignment, and permitted function scope together.

Distinguish administrators and users

Central administrators do not need a separate self-service invitation. They sign in with their Central administrator credentials. Regular users receive their own portal access, which does not grant administrative permissions.

User access does not replace an administrator role. Conversely, a user does not become an administrator simply by receiving a SophosID or Self Service Portal access.

Enable automatic access

Go to Global Settings > Access Control > Sign-in and Identity > Sophos Sign-in > User Access and enable Sophos Central Self Service Portal access.

Activation affects two groups:

  • newly added users will automatically receive access and an invitation email,
  • existing users without access will also receive access and an invitation email.

Before tenant-wide activation, review the user inventory, email quality, synchronized service accounts, and product scope. Blanket invitations to machine accounts, shared mailboxes, or users with no self-service purpose create confusion and unnecessary support cases.

Invite individual users

For a targeted rollout, send invitations manually:

  1. Open My Environment > Users & Groups.
  2. Select the required users.
  3. Select Email Setup Link.
  4. Select Sophos Central Self Service Welcome/Setup Email and save.

The message comes from do-not-reply@central.sophos.com, has an English welcome subject, and contains a setup link without an expiration date. Because the email is in English, include a short internal user notice in the rollout.

Central also permits selecting users without a valid email address and may show no error. A successful audit entry therefore does not prove that a message was delivered.

Email does not arrive

First check the user object, email address, spam filter, transport rules, and sender allowlist. The same address may also have been used for an old Sophos Central administrator trial account. In that case, the invitation is not delivered correctly until the old account conflict is resolved.

Resending has an important caveat: for this error, Sophos requires removal or cleanup of the affected user account before sending a new invitation. Merely selecting Email Setup Link again may record a send in the Audit Log even though no email was generated.

Before deleting a user, review device assignments, policies, Email functions, Encryption recovery, and directory synchronization. A synchronized object may otherwise reappear on the next run or lose valid assignments. The complete lifecycle is covered in Delete Sophos Central users safely.

Control the rollout

A pilot should include a few users from every affected product. Verify:

  • delivery and clarity of the invitation email,
  • sign-in and the MFA or password process,
  • visible self-service functions,
  • product and user assignment,
  • behavior for a blocked or deleted user,
  • support path for account conflicts.

Only then enable automatic access tenant-wide. Quarterly, review users without a valid email address, leavers, and portal access no longer required.

The portal itself and its separation from Central Admin, Partner Portal, and Support Portal are explained in the Sophos portals overview.

Frequently asked questions

Does Endpoint Protection require the Self Service Portal?

No. The portal requires Sophos Email, Central Device Encryption, or Sophos Mobile. Endpoint Protection alone does not satisfy the license requirement.

Do users lose access when User Access is turned off?

No. Already authorized users keep it. The setting only prevents automatic access for users added in the future.

Does the Audit Log prove that the email was received?

No. A user without a valid address can be selected, and an account conflict may record a send even though no usable invitation arrives.