Skip to content
Avanet

Delete and offboard Sophos Fusion users safely

The deletion itself is short: On the Users tab under My Environment > Users & Groups, select the user and click Delete. Safe offboarding starts earlier. Sophos Fusion (formerly Sophos Central) can recreate the object from a directory source or when the user signs in again to an associated device that Sophos Fusion still manages.

Quick procedure for controlled offboarding

  1. Verify your permission and the user’s identity; you can’t delete your own account.
  2. Remove a directory-sourced user from the active synchronization scope and prevent further sign-ins on associated managed devices.
  3. For Phish Threat, check Last Targeted and Last Enrolled and wait out any current 30-day window.
  4. Prepare the effects on devices, logins, and the mailbox shown in Sophos Fusion.
  5. Under My Environment > Users & Groups > Users, select the user and click Delete.
  6. Check the user list immediately, after the next relevant sync, and while monitoring for possible device sign-ins.

Checks before deletion

Permission and administrator access

A Super Admin or Admin can delete users. Only a Super Admin can delete a user who is an administrator. Even a Super Admin can’t delete their own account.

Before removing an administrator, keep another tested Super Admin available as a recovery path. Record roles, MFA methods, federated sign-in, open investigations, and operational ownership. This is an offboarding recommendation: The official deletion page doesn’t state that Delete immediately terminates an existing session. Check sessions separately instead of inferring their state from the missing user object. See Assign Sophos Fusion administrative roles correctly for role removal.

Stop automatic recreation sources

For a user added through AD, Microsoft Entra ID, Google Directory, or another directory service, disable the source account or remove it from the synchronized scope first. If the record stays in the source, Sophos Fusion adds it again at the next directory synchronization. Wait for a successful sync and verify the scope using that exact user.

Sophos Fusion also adds the user again if they sign in to an associated device that Sophos Fusion still manages. Assign that device to a remaining owner or handle it through the approved device process first. Deleting a user isn’t device offboarding.

Understand Phish Threat, mailbox, and login effects

If the user was enrolled in a Phish Threat campaign within the last 30 days, the deleted user can appear again under Users & Groups. Check Last Targeted and Last Enrolled. If the relevant date is still inside the 30-day window, defer deletion until that window has passed.

Delete removes the associated mailbox from Mailboxes. The Sophos page describes the association in Sophos Fusion; it doesn’t say that an external mailbox or messages are deleted. For Sophos Email, check mail flow, shared-mailbox ownership, and policies separately against the actual configuration.

Logins assigned to a deleted user can be reassigned from another user’s details page with Edit. Do this only when both identities demonstrably represent the same person. Record the login, device association, and target profile first; an unverified merge can distort later attribution.

Delete the user

  1. Sign in at fusion.sophos.com and open My Environment > Users & Groups.
  2. Select the Users tab.
  3. Select the checkbox next to each user you want to delete.
  4. Click Delete.

For bulk deletion, apply the same pre-checks to every person. If the source, mailbox, or device association is unclear for even one record, remove that user from the selection and investigate it separately.

Validate the result

Immediately after deletion, search Users & Groups > Users using the full email address or known login. The user must no longer be listed. Associated devices and installed Sophos software are expected to remain; their presence doesn’t mean that user deletion failed.

Then run the checks that match the user’s sources:

  • After a successful directory synchronization, the user remains absent.
  • The user doesn’t sign in again on a formerly associated managed device. If they do and the user reappears, this is the recreation trigger documented by Sophos.
  • After the Phish Threat window passes, the record remains absent.
  • The intended mailbox state under Mailboxes and the separately checked Email configuration are correct.
  • Reassigned logins appear only in the verified target profile.

If operational evidence is required, record the time, acting administrator, and result, and also review the Audit Log. The assigned Sophos page doesn’t specify an event name, so an assumed message string isn’t a reliable success criterion.

Accidental deletion and recovery limits

The official deletion instructions don’t document an Undo or Restore function. After accidental deletion, stop further cleanup, record the affected object, and recreate it in a controlled manner through the still-authoritative user source. Manage Sophos Fusion users and groups explains the normal creation paths.

Automatic recreation by directory synchronization or device sign-in isn’t a documented rollback. Sophos doesn’t state on the deletion page that roles, groups, policies, MFA, Phish Threat history, or mailbox associations are fully restored. Compare each assignment with the pre-deletion record after recreation. Logins can then be reassigned to the appropriate user with Edit.

Common problems

Delete is unavailable or the action is rejected

Check your role and the target account first. An Admin can’t delete an administrator, and nobody can delete their own account. Another Super Admin must perform the action for an administrator.

The mailbox is missing after deletion

Removing the associated mailbox from Mailboxes is an explicitly documented effect. Don’t hastily recreate an external mailbox: Check the Sophos Fusion view, external mail platform, and mail flow separately first.

Devices are still visible

This is expected. Delete removes neither devices nor Sophos software. Owner changes, migration, or device removal are separate procedures with their own validation.

Frequently asked questions

Why does a deleted user reappear?

The user is still in a synchronized directory source, signs in to an associated device that Sophos Fusion still manages, or is still within the 30-day window of a Phish Threat campaign. Identify and clean up that source, then validate again.

Does deleting the user also uninstall Endpoint?

No. Associated devices and Sophos software remain and must be managed separately.

Can an Admin delete another administrator?

No. Only a Super Admin can delete a user who is an administrator. Super Admins and Admins can delete regular users, but nobody can delete their own account.