Skip to content
Avanet

Enable Sophos Fusion Enterprise Management

Enterprise Management turns a Sophos Fusion (formerly Sophos Central) account into the starting point of a higher-level Enterprise structure. Associated Sophos Fusion accounts are linked as sub-estates. Activation is therefore not a harmless interface switch. If you are still defining roles, data regions, and tenant boundaries, start with Sophos Fusion Enterprise and sub-estates.

Prerequisites

Sophos requires a Sophos Fusion tenant that isn’t a trial account and Super Admin permissions in the starting tenant.

For a safe migration, Avanet also recommends:

  • at least two planned Enterprise administrators,
  • documented sub-estates, data regions, and responsibilities,
  • decision on individual or later master licensing,
  • tested local Super Admin who will not be converted for Enterprise.

Use a dedicated Enterprise account

Sophos allows the existing Sophos Fusion Admin account to become the first Enterprise administrator. After conversion, however, that account can no longer sign in as a regular administrator to the previous Sophos Fusion Admin tenant.

A new, unique Enterprise administrator account is therefore usually safer. Its email address must not already belong to another Sophos Fusion account. A separate account simplifies roles, audit, and emergency access.

Enable Enterprise Management

Enterprise Management divides a larger organization into separate sub-estates, such as by site, and enables higher-level security administration by Enterprise administrators. After activation, only an Enterprise Super Admin can disable it in Sophos Fusion Enterprise. Protect this recovery path organizationally and technically before migration.

  1. Open the profile icon and select Account preferences.
  2. Enable Enterprise Management.
  3. Select Save, then Continue.
  4. Select Create a new account, or use Use my Sophos Fusion login credentials to create the first Sophos Fusion Enterprise admin to convert the existing account.
  5. Enter unique account details for the first Enterprise administrator.
  6. Complete Enable Enterprise Management and Save.
  7. For a new account, open the email setup link and set the password.
  8. Sign in separately with the Enterprise account and review sub-estates.

If an existing Sophos Fusion account already used federated sign-in and that same account is converted, Enterprise adopts the corresponding sign-in settings. Test the sign-in path in a private browser session beforehand.

As an immediate success check, Account preferences shows that Enterprise Management is on and identifies the Enterprise administrator. Then sign in with that account on the regular Sophos Fusion sign-in page; the sign-in opens Sophos Fusion Enterprise.

Approve sub-estate access

Linking alone does not automatically grant access to every existing sub-estate. A local Super Admin opens Profile > Account preferences there, verifies that Enterprise Management is enabled and the Enterprise administrator details are displayed, and then enables Enterprise Admin access.

Only then can the Enterprise administrator open the sub-estate and receive broad permissions there. Document approval per sub-estate with an owner, date, and purpose.

After opt-in, the local administrator cannot disable it. Only an Enterprise Super Admin can disconnect the sub-estate at Enterprise level.

Acceptance

After activation, verify:

  • sign-in with two Enterprise administrators,
  • a working local Super Admin in every sub-estate,
  • the correct list and names of all sub-estates,
  • each sub-estate’s data region,
  • Enterprise access approval status,
  • Alert and dashboard visibility,
  • Audit Log entries for activation and approvals,
  • unchanged local licenses unless Master Licensing was enabled separately.

Enterprise Management and Enterprise Master Licensing are separate steps. Enabling the structure does not automatically move every license into one pool.

Turn off the Enterprise structure

Unlinking one sub-estate is not the same as turning off the entire Enterprise structure. Only an Enterprise Super Admin can use the profile icon to disable Enterprise Management under Account Preferences. Every sub-estate must first have at least one administrator with the Super Admin role. Master Licensing must also be neither enabled nor in the process of conversion.

When these conditions are met, select Disable enterprise management, review the information under Confirm disable, select the acknowledgment option, and finish with Disable enterprise.

This signs out all Enterprise administrators. Enterprise Super Admins who enabled Enterprise Management are assigned the Super Admin role for their Sophos Fusion Admin account. All other Enterprise administrators are deleted and can be added again later to the appropriate Sophos Fusion Admin account if required. Verify and document local Super Admin access and the intended role assignment before disabling the structure.

Common problems

Previous administrator can no longer open the tenant

The account was converted to Enterprise administrator and is no longer available for normal Sophos Fusion Admin sign-in. Another local Super Admin must manage the tenant.

Sub-estate is visible but cannot be opened

The local Super Admin has not yet granted Enterprise Admin access. The link alone is insufficient.

Enterprise Management cannot be enabled

Check the role, trial status, and account assignment. The function requires a paid tenant and Super Admin.

Local administrator cannot revoke access

This is by design. After approval, only an Enterprise Super Admin can disconnect the sub-estate.

Frequently asked questions

Can Enterprise Management be tested in a trial?

No. Sophos does not permit activation from trial tenants.

Should the existing Super Admin account be used?

Usually not. That account loses normal Sophos Fusion Admin access. A dedicated Enterprise account and a remaining local Super Admin are safer.

Who can turn Enterprise Admin access off again?

After opt-in, only an Enterprise Super Admin can disconnect the sub-estate at Enterprise level.