Skip to content
Avanet

How is Sophos Central licensed?

Sophos Central is a shared management platform, not one license product. Endpoint, XDR, MDR, Server, Device Encryption, Email, Firewall, Wireless, and other services have their own usage and expiration rules.

The key consequence is that a number on the Central Licensing page must always be assessed together with the product name and license contract. Portal-calculated usage supports control but replaces neither the License Schedule nor EULA.

Main counting models

Product typeTypical counting basisImportant detail
Endpoint, XDR, and MDR for endpointsUsually userUsage is calculated separately by license type from active users and devices
Device EncryptionUser or actively protected device according to contractUnder Flex, installation alone may not trigger usage; the Encryption policy is decisive
Server ProtectionProtected serverRDS sessions are covered through Server Protection, not as normal Endpoint users
Sophos EmailProtected users and shared mailboxesAliases, distribution lists, and public folders generally need no separate license
FirewallAppliance, virtual instance, and subscriptionsBase License, Support, and Security subscriptions have separate effects
Wireless, Switch, and Access PointsDevice or support serviceModel and term depend on hardware generation and service

Products, bundles, and names change. For an order, always use the current License Schedule for the specific customer, not an old product list from an article or quote.

Product models that are often misunderstood

Some Central products count neither like Endpoint nor like traditional hardware. The following classification helps with monthly reviews and renewals:

ProductWhat countsOperational detail
Sophos EmailIndividual users and shared mailboxes for which at least one message was processed in the last 30 daysAliases, distribution lists, and public folders do not count; the display updates about every four hours
Sophos MobileAssigned users or devices without a userSeveral devices for one user count once; only devices synchronized within the last 30 days are considered
Sophos Phish ThreatUnique recipients of a simulation or training campaignDaily calculation considers recipients from the last 30 days; deleting or ending a campaign does not remove usage retroactively
Sophos AP6Support and Services per AP6 managed through CentralWithout a valid and sufficient subscription, local management remains possible but Central cannot change the AP
Sophos SwitchSupport and Services per deployed switchCentral configuration, firmware, 24/7 Support, and Advanced RMA require a subscription for each device
Workspace ProtectionHighest consumption among included productsThe largest count among Protected Browser users, ZTNA users, DNS Protection devices, and Email Monitoring mailboxes determines bundle quantity

Workspace Protection includes Protected Browser, ZTNA, DNS Protection for endpoints, and Email Monitoring System. It does not include full Sophos Endpoint unless the combined Sophos Endpoint Plus Workspace Protection bundle was purchased. Xstream Protection for Sophos Firewall covers only standalone DNS Protection and does not grant DNS Protection for endpoints.

Standalone DNS Protection from Xstream Protection requires at least one currently licensed firewall in the tenant. If the final suitable license expires or every licensed firewall moves to another tenant, DNS Protection ends in the original tenant. When an MSP removes the final Flex firewall, access can end within one day. Air Gap licensing does not support DNS Protection because the service requires a firewall activated or managed in Central. With a mix of trial and purchased licenses, the service remains available while at least one is valid.

For Workspace Protection, the same authenticated user counts once across several devices. ZTNA considers authenticated users from the last 30 days. Sophos Cloud Gateways additionally includes an average bandwidth entitlement of 15 GB per user per month. Include this limit in capacity planning rather than investigating it only after restriction.

Hardware with and without a Central service

An AP6 or Sophos Switch does not automatically stop working without Central Support and Services. Its local web interface and CLI remain management paths. What is lost is change through Sophos Central, including central configuration and firmware management. Personal phone support, chat, support cases, and Advanced RMA also require the appropriate service.

This matters when quantity differs. If only some AP6 devices or switches managed in Central are licensed, Central shows an undersubscription warning. Reconcile inventory and subscription quantity per device rather than ignoring the banner. APX Access Points do not need an AP6 Support and Services license; APX and AP6 are separate generations for licensing.

Sophos Email after expiration

Sophos Email and Sophos Email Plus are different feature levels. Portal Encryption is an add-on whose quantity cannot exceed purchased Sophos Email quantity. It is assigned through a Secure Message policy and is required for custom encryption-portal branding. An existing Email customer can trial Portal Encryption but cannot trial the base service and add-on simultaneously.

DMARC Manager is available as an add-on for Sophos Email and Sophos Email Monitoring System and is included in Sophos Email Plus. MSP customers can also purchase Sophos Email as a Monthly Flex SKU; business counting rules stay the same.

License Usage Summary combines Sophos Email and Phish Threat usage into one unique total and does not show the products separately. For root-cause analysis, also review mailbox inventory, processed messages, and Phish Threat recipients.

Exceeding purchased Email quantity does not stop protection immediately. Central flags the account, creates an Alert, and identifies uncovered mailboxes in License Usage Summary; all mailboxes initially remain protected. Then reduce quantity or expand licensing.

Actual license expiration is more critical. Sophos may temporarily provide up to 30 additional protection days, but this is not a guaranteed grace period. In Gateway Mode, move MX records away from Sophos after final expiration or messages are rejected. In Mailflow Mode, Sophos begins automatic Microsoft 365 cleanup; still inspect connectors and mail-flow rules manually afterward. A renewal during any granted transition starts retroactively at the previous license end.

Sophos Mobile and Phish Threat

For Mobile, each user assigned to a managed device consumes one license regardless of device count. A device without a user counts as one license itself. Usage display can be inaccurate and excess is therefore not immediately enforced technically; contractual need remains authoritative. Independently, Android Enterprise technically limits simultaneous enrollment to ten devices per user.

Phish Threat counts a recipient once a campaign or training-only email is sent. The same user needs only one license during the term despite many emails. After expiration, no new campaigns or reminders are sent, while data from already sent campaigns continues to be collected. Under MSP Flex, monthly billing follows recipients of campaigns sent during the billing period.

User-based does not mean manual assignment

For Endpoint, a license is not assigned through a checkbox like a Microsoft 365 plan. Sophos Central detects active users on protected devices and maps devices to those identities.

One user can use several devices. Each device is assigned to only one user for calculation. If the same person signs in to two devices with different local accounts, Central can identify two users and count twice. Map the logins to an existing user after business verification.

License types are also counted independently. A user with Endpoint on device A and XDR on device B can create one Endpoint and one XDR usage. Device Encryption follows its own function and policy state.

Inactive devices and calculation delay

For Endpoint, devices disconnected for more than 30 days temporarily stop counting toward license usage. When a device returns, it counts again and updates its components.

This is a calculation rule, not a lifecycle strategy. Remove obsolete, lost, or retired devices through documented offboarding so inventory, Alerts, and ownership remain clear.

The portal count can react with delay. An immediate discrepancy after installation, deletion, or user assignment therefore does not prove an error.

Contractual usage takes precedence

Sophos explicitly states that in-product calculation can differ from actual licensing duty under the EULA. If Central underestimates consumption, real usage remains authoritative. A displayed technical count is not permission to underlicense.

Conversely, functions are not always blocked immediately when Central reports excess. Investigate and reconcile the deviation with the Sophos Partner before it becomes a renewal or compliance problem.

Initial purchase, upgrade, and renewal

An initial purchase activates a new product in a tenant. An upgrade expands or replaces functions during an active term. A renewal extends existing usage rights.

This distinction matters technically. An upgrade can install new agent components or expose policies. A renewal should primarily extend the term, but a changed edition can also alter functions.

Customer types such as Commercial, Education, and Government can have different purchasing terms. Verify eligibility with the Sophos Partner rather than assuming it from the organization’s name.

Monthly license review

A reliable review compares:

  • license product, edition, and term on the Licensing page,
  • actual users, devices, servers, or mailboxes,
  • installed and enabled product components,
  • inactive, duplicate, or incorrectly assigned objects,
  • ordered quantity and contractual counting basis,
  • upcoming changes from growth, projects, or M&A.

Technical activation, usage review, and renewal are covered in Activate, review, and renew Sophos Central licenses.

Frequently asked questions

Are all Sophos Central products licensed per user?

No. Endpoint products are often user-based, Server Protection is calculated per server, and Email by protected mailboxes. Firewall, Wireless, and other products have their own models.

Is the portal Usage count legally authoritative?

It is an important control signal, but the License Schedule and EULA take precedence. Clarify actual usage with the Sophos Partner when values differ.

Does an Endpoint inactive for more than 30 days continue consuming a license?

The current Endpoint calculation temporarily stops counting it. It resumes usage when it comes online again. The device should still remain properly inventoried and be removed when retired.