Skip to content
Avanet

Create and securely manage a Sophos ID account

A Sophos ID is the personal account a person uses to sign in to Sophos services. It isn’t the same as a Sophos Fusion (formerly Sophos Central) tenant and doesn’t grant administrator permissions by itself. The tenants, support data and functions shown depend on invitations, account associations and roles.

Quick process: Confirm the business address and owner, look for an existing invitation or account, and only then open the Sophos ID sign-in or registration page. After signing in, register at least two MFA methods, verify the correct tenant and expected role, and protect recovery with a second Super Admin.

When a Sophos ID is required

Sophos ID is the shared sign-in identity for Sophos Fusion, the Support Portal and some account and licensing transactions. Local Sophos Firewall accounts, Central Self Service Portal users and API Credentials are separate identities.

Before creating an account, establish:

  • Which Sophos service is required?
  • Is there already an invitation from a customer, partner or Sophos Fusion tenant?
  • Which business email address remains assigned to this person while they are responsible?
  • Who can grant the required role and reset MFA in an emergency?

Use individual accounts for administrators. A shared team mailbox as a login prevents clear attribution and complicates MFA, recovery and offboarding.

Separate the account, role and tenant

Sophos ID answers who is signing in. A Sophos Fusion administration role defines what that person may do in a specific tenant. A local firewall administrator account and a partner or support profile are separate permission contexts again.

One person can use the same email address in several Sophos contexts. Check the displayed customer name or tenant before every change. A successful sign-in only proves the identity, not the correct role in the correct tenant. Sophos Fusion administrative roles explains role selection.

Create or sign in to Sophos ID

  1. Search invitations, welcome messages and the password manager for an existing account. Use the invitation for an existing Sophos Fusion organisation; don’t inadvertently create a second tenant through a trial registration.
  2. Open the Sophos Fusion sign-in. This external page, controlled by Sophos, uses Sophos ID for sign-in and registration.
  3. Enter the business email address. The current Sophos flow proceeds to sign-in, verification or registration depending on the account state. Only use codes for a process you initiated, and check the sender and recipient address.
  4. Store a new password only in the password manager. For an existing account, use Forgot your password? in the same sign-in flow instead of creating a similarly named second account.
  5. After entry, open the expected service and tenant. Compare the customer name, role and visible assets with the approved request.

When a new Sophos Fusion account is activated, the welcome message contains Create Password. Activation also selects the Central Admin Portal location where data is stored. This tenant decision isn’t part of routine Sophos ID sign-in and must be agreed with the owner before activation.

Set up resilient MFA and passkeys

Sophos requires modern MFA for Sophos Fusion administrators. Password sign-in uses a TOTP authenticator app; a passkey can be used after initial enrollment. SMS and email-plus-PIN are no longer available for new enrollments.

Sophos Fusion administrators must register at least two MFA methods. A resilient combination is one passkey and one TOTP app on independent devices, or two passkeys in separate device ecosystems. Sophos recommends passkeys and permits up to ten. Add the first passkey after setting up an authenticator app under Profile icon > My info > Manage MFA.

Don’t keep both methods solely on one phone. Give methods meaningful names and review them after changing devices. Before deleting or resetting an old device, test sign-in with the replacement method in a private browser window. A method can’t be deleted if that would take the account below the required minimum.

Control joiners, movers and leavers

Joiner: Record the account owner, business address, target tenant, approved role and two MFA methods. Jointly verify the first sign-in without sharing the password or TOTP seed.

Mover: When responsibilities change, adjust roles and tenant associations rather than sharing or replacing the Sophos ID. Remove unneeded customer, partner, support and licensing contexts separately.

Leaver: Confirm a second operational Super Admin before departure. Then revoke admin roles, tenant and partner access, and support and licensing associations. Disable the business mailbox and MFA devices according to the internal offboarding process. Disabling the mailbox alone doesn’t remove Sophos permissions.

At least quarterly, review active admins, Super Admins, external providers, recently used MFA methods and documented owners. The Sophos portals overview helps identify all separate access paths.

Handle a lost authenticator and recovery

If a second method is still available, sign in with it, open Profile icon > My info > Manage MFA, register the replacement first and then remove the lost method. If theft is suspected, also review the password, sessions, roles and recent administrative changes.

If all methods are lost for a user in a Sophos Fusion tenant, a tenant Super Admin resets MFA through My Environment > Users & Groups > Users > > Reset MFA > Reset.

For an eligible customer user, a Partner Super Admin instead uses My Business > My Customers > Customers > > Launch customer > My Environment > Users & Groups > > Reset MFA. A confirmation appears at the lower right when this action succeeds. A Partner Super Admin who enters the customer tenant from the Partner dashboard using SSO can’t change that customer’s Super Admin MFA settings.

For a managed partner user, a Partner Super Admin uses Global Settings > Access Control > Administer MFA > > Reset MFA. In every context, trigger a reset only after verifying identity through a pre-agreed channel; the affected user must set up MFA again at the next sign-in.

If no available administrator has authority to reset MFA for the affected account, Sophos Support must handle recovery. Prepare the company name, affected email address, tenant details, time, last successful sign-in and verifiable entitlement information. See Open a Sophos support ticket.

Validate sign-in and permissions

After enrollment, a role change or recovery, test:

  • sign-in with the primary method and separately with the recovery method;
  • the customer name or tenant and expected admin role;
  • access to one harmless page covered by the role, plus a negative test of a disallowed function;
  • that old MFA methods and unnecessary tenant access have been removed;
  • the owner, reviewer, date and next review in the operating record.

Troubleshoot common failures

No email: Check spam and quarantine, search for do-not-reply@central.sophos.com, and verify the exact address entered. If a Sophos Fusion welcome message is missing, don’t create a second account; use the inviter or Sophos Fusion activation process.

Wrong or empty tenant: First check the email address and organisation selected. Then ask a Super Admin to verify the invitation, user association and role. A new Sophos ID doesn’t fix missing tenant permission.

TOTP rejected: Enable automatic time synchronization on the phone, select the entry for the correct email address and wait for a fresh code. Don’t keep guessing: Sophos temporarily locks an account after five consecutive failures, and further failures lengthen the lockout.

Passkey fails: Try another supported browser or the enrolled device, and select the TOTP method through Try another way. For cross-device use, check Bluetooth and proximity. According to Sophos, Microsoft Authenticator as a passkey store isn’t supported without federated Entra ID sign-in.

All MFA methods lost: Use the tenant, eligible customer-user or managed partner-user reset path above, according to the affected account. Contact Sophos Support with prepared ownership and tenant evidence whenever the available role lacks authority to reset that account’s MFA.

Account locked after failed sign-ins: Stop retrying. Wait for the increasing lockout period—initially one minute and at most five hours—or contact Sophos Support to have the account unlocked. Resetting MFA does not clear this lockout.