Rename Sophos Fusion users and correct master data
For a name change, spelling correction, or new email domain, first determine which system manages the user. Display name, email address, UPN, and device logins assigned to the user are different attributes.
Identify the authoritative source
Go to My Environment > Users & Groups and open the user on the Users tab. The Summary tab shows security status, administration role, account details, devices, policies, groups, and logins. A padlock icon shows that the object was imported from Active Directory or Microsoft Entra ID.
- Manual user: Change master data directly in Central through Edit.
- Synchronized user: Correct the name, email address, and other source attributes in the authoritative directory, then synchronize.
- Automatically detected device login: First determine whether it should be assigned to an existing business user.
A shared mailbox managed in Microsoft Entra ID can also appear as a user in Central. It has no administration role or associated devices, and some options are unavailable. Do not treat such an object like a personal user account when correcting names.
Do not delete and recreate a synchronized object manually just to change its name. Source, groups, policies, mailboxes, and license assignment can otherwise diverge.
Change a manual user
- Go to My Environment > Users & Groups and select the Users tab.
- Select the user, open the Summary tab, and choose Edit in the left-hand pane.
- Carefully adjust First & Last name, Email Address, the optional Exchange Login, and Add to groups.
- Change Role only for an actual role change. You can’t amend your own administration role, and only a Super Admin can assign administration roles to other users.
- Click Save and review the user profile again.
Do not include a domain name in First & Last name. For a user added through a directory service, this field shows the directory’s Display Name, so it may not follow a first-name/last-name format. The primary email address and login are more important for technical mapping than the visible display name.
Plan a domain or UPN change
Before synchronizing a new email domain, review:
- verified domain and federated sign-in,
- UPN and
emailclaim from the identity provider, - Directory Sync matching,
- primary and alternative email addresses,
- administrator access and MFA recovery,
- shared mailboxes and groups,
- device logins using the old domain.
Test the change with a regular user first and separately with a non-critical administrator. Keep an existing Super Admin reachable during migration.
Validate after the change
On Summary, verify the name, Email Address, role, and security status. Then confirm that Devices, Policies, Events, logins, groups, and mailboxes still represent the same real-world user. On the Users tab under My Environment > Users & Groups, also search for a second object with the old or new email address.
For administrators, test sign-in in a private browser session. Security and recovery are described in Secure Sophos Fusion (formerly Sophos Central) sign-in with MFA, passkeys, and an IdP.
Common problems
Edit is unavailable
Central doesn’t allow account details to be changed for a user imported from Active Directory. The padlock identifies imports from Active Directory or Microsoft Entra ID. Therefore, identify the specific source system before making a correction; for an AD user, make it in Active Directory.
Two users exist after synchronization
The email address, UPN, or source object did not match the existing Central user. Do not delete either object immediately. First compare devices, logins, policies, mailboxes, and roles.
New name but old device logins
Changing the display name does not change local Windows or macOS logins. Assign them separately in the user profile or migrate them on the devices or in the directory.