How is Sophos Central licensed?
Sophos Central is a shared management platform, not one license product. Endpoint, XDR, MDR, Server, Device Encryption, Email, Firewall, Wireless, and other services have their own usage and expiration rules.
The key consequence is that a number on the Central Licensing page must always be assessed together with the product name and license contract. Portal-calculated usage supports control but replaces neither the License Schedule nor EULA.
Main counting models
| Product type | Typical counting basis | Important detail |
|---|---|---|
| Endpoint, XDR, and MDR for endpoints | Usually user | Usage is calculated separately by license type from active users and devices |
| Device Encryption | User or actively protected device according to contract | Under Flex, installation alone may not trigger usage; the Encryption policy is decisive |
| Server Protection | Protected server | RDS sessions are covered through Server Protection, not as normal Endpoint users |
| Sophos Email | Protected users and shared mailboxes | Aliases, distribution lists, and public folders generally need no separate license |
| Firewall | Appliance, virtual instance, and subscriptions | Base License, Support, and Security subscriptions have separate effects |
| Wireless, Switch, and Access Points | Device or support service | Model and term depend on hardware generation and service |
Products, bundles, and names change. For an order, always use the current License Schedule for the specific customer, not an old product list from an article or quote.
Product models that are often misunderstood
Some Central products count neither like Endpoint nor like traditional hardware. The following classification helps with monthly reviews and renewals:
| Product | What counts | Operational detail |
|---|---|---|
| Sophos Email | Individual users and shared mailboxes for which at least one message was processed in the last 30 days | Aliases, distribution lists, and public folders do not count; the display updates about every four hours |
| Sophos Mobile | Assigned users or devices without a user | Several devices for one user count once; only devices synchronized within the last 30 days are considered |
| Sophos Phish Threat | Unique recipients of a simulation or training campaign | Daily calculation considers recipients from the last 30 days; deleting or ending a campaign does not remove usage retroactively |
| Sophos AP6 | Support and Services per AP6 managed through Central | Without a valid and sufficient subscription, local management remains possible but Central cannot change the AP |
| Sophos Switch | Support and Services per deployed switch | Central configuration, firmware, 24/7 Support, and Advanced RMA require a subscription for each device |
| Workspace Protection | Highest consumption among included products | The largest count among Protected Browser users, ZTNA users, DNS Protection devices, and Email Monitoring mailboxes determines bundle quantity |
Workspace Protection includes Protected Browser, ZTNA, DNS Protection for endpoints, and Email Monitoring System. It does not include full Sophos Endpoint unless the combined Sophos Endpoint Plus Workspace Protection bundle was purchased. Xstream Protection for Sophos Firewall covers only standalone DNS Protection and does not grant DNS Protection for endpoints.
Standalone DNS Protection from Xstream Protection requires at least one currently licensed firewall in the tenant. If the final suitable license expires or every licensed firewall moves to another tenant, DNS Protection ends in the original tenant. When an MSP removes the final Flex firewall, access can end within one day. Air Gap licensing does not support DNS Protection because the service requires a firewall activated or managed in Central. With a mix of trial and purchased licenses, the service remains available while at least one is valid.
For Workspace Protection, the same authenticated user counts once across several devices. ZTNA considers authenticated users from the last 30 days. Sophos Cloud Gateways additionally includes an average bandwidth entitlement of 15 GB per user per month. Include this limit in capacity planning rather than investigating it only after restriction.
Hardware with and without a Central service
An AP6 or Sophos Switch does not automatically stop working without Central Support and Services. Its local web interface and CLI remain management paths. What is lost is change through Sophos Central, including central configuration and firmware management. Personal phone support, chat, support cases, and Advanced RMA also require the appropriate service.
This matters when quantity differs. If only some AP6 devices or switches managed in Central are licensed, Central shows an undersubscription warning. Reconcile inventory and subscription quantity per device rather than ignoring the banner. APX Access Points do not need an AP6 Support and Services license; APX and AP6 are separate generations for licensing.
Sophos Email after expiration
Sophos Email and Sophos Email Plus are different feature levels. Portal Encryption is an add-on whose quantity cannot exceed purchased Sophos Email quantity. It is assigned through a Secure Message policy and is required for custom encryption-portal branding. An existing Email customer can trial Portal Encryption but cannot trial the base service and add-on simultaneously.
DMARC Manager is available as an add-on for Sophos Email and Sophos Email Monitoring System and is included in Sophos Email Plus. MSP customers can also purchase Sophos Email as a Monthly Flex SKU; business counting rules stay the same.
License Usage Summary combines Sophos Email and Phish Threat usage into one unique total and does not show the products separately. For root-cause analysis, also review mailbox inventory, processed messages, and Phish Threat recipients.
Exceeding purchased Email quantity does not stop protection immediately. Central flags the account, creates an Alert, and identifies uncovered mailboxes in License Usage Summary; all mailboxes initially remain protected. Then reduce quantity or expand licensing.
Actual license expiration is more critical. Sophos may temporarily provide up to 30 additional protection days, but this is not a guaranteed grace period. In Gateway Mode, move MX records away from Sophos after final expiration or messages are rejected. In Mailflow Mode, Sophos begins automatic Microsoft 365 cleanup; still inspect connectors and mail-flow rules manually afterward. A renewal during any granted transition starts retroactively at the previous license end.
Sophos Mobile and Phish Threat
For Mobile, each user assigned to a managed device consumes one license regardless of device count. A device without a user counts as one license itself. Usage display can be inaccurate and excess is therefore not immediately enforced technically; contractual need remains authoritative. Independently, Android Enterprise technically limits simultaneous enrollment to ten devices per user.
Phish Threat counts a recipient once a campaign or training-only email is sent. The same user needs only one license during the term despite many emails. After expiration, no new campaigns or reminders are sent, while data from already sent campaigns continues to be collected. Under MSP Flex, monthly billing follows recipients of campaigns sent during the billing period.
User-based does not mean manual assignment
For Endpoint, a license is not assigned through a checkbox like a Microsoft 365 plan. Sophos Central detects active users on protected devices and maps devices to those identities.
One user can use several devices. Each device is assigned to only one user for calculation. If the same person signs in to two devices with different local accounts, Central can identify two users and count twice. Map the logins to an existing user after business verification.
License types are also counted independently. A user with Endpoint on device A and XDR on device B can create one Endpoint and one XDR usage. Device Encryption follows its own function and policy state.
Inactive devices and calculation delay
For Endpoint, devices disconnected for more than 30 days temporarily stop counting toward license usage. When a device returns, it counts again and updates its components.
This is a calculation rule, not a lifecycle strategy. Remove obsolete, lost, or retired devices through documented offboarding so inventory, Alerts, and ownership remain clear.
The portal count can react with delay. An immediate discrepancy after installation, deletion, or user assignment therefore does not prove an error.
Contractual usage takes precedence
Sophos explicitly states that in-product calculation can differ from actual licensing duty under the EULA. If Central underestimates consumption, real usage remains authoritative. A displayed technical count is not permission to underlicense.
Conversely, functions are not always blocked immediately when Central reports excess. Investigate and reconcile the deviation with the Sophos Partner before it becomes a renewal or compliance problem.
Initial purchase, upgrade, and renewal
An initial purchase activates a new product in a tenant. An upgrade expands or replaces functions during an active term. A renewal extends existing usage rights.
This distinction matters technically. An upgrade can install new agent components or expose policies. A renewal should primarily extend the term, but a changed edition can also alter functions.
Customer types such as Commercial, Education, and Government can have different purchasing terms. Verify eligibility with the Sophos Partner rather than assuming it from the organization’s name.
Monthly license review
A reliable review compares:
- license product, edition, and term on the Licensing page,
- actual users, devices, servers, or mailboxes,
- installed and enabled product components,
- inactive, duplicate, or incorrectly assigned objects,
- ordered quantity and contractual counting basis,
- upcoming changes from growth, projects, or M&A.
Technical activation, usage review, and renewal are covered in Activate, review, and renew Sophos Central licenses.