Secure Sophos Central Partner and Remote Assistance
Sophos Central provides several external administration paths. Partner Assistance is intended for the assigned service provider, Remote Assistance for Sophos Support, and Enterprise Admin Access for administrators in the organization’s own Central Enterprise structure. They are granted separately and must not be treated as interchangeable “support access” methods.[1]
Quick path: Define the purpose, owner, and end time; open Profile icon > Support settings and enable only the required Assistance option; have a second administrator verify the displayed state; and turn access off as soon as the work is complete. Then review the changes under Reports > General logs > Audit Logs.[1][5]
Distinguish the access paths
| Access | Recipient | Typical purpose | Duration |
|---|---|---|---|
| Partner Assistance | Sophos Partner assigned to the customer | Ongoing administration and service delivery | Active until disabled again |
| Remote Assistance | Sophos Support | Analysis of a specific Central case | Selectable for 3, 7, 14, 30, or 60 days |
| Enterprise Admin Access | Administrators of the organization’s own Central Enterprise account | Management of a sub-estate | Cannot be revoked in the sub-estate after approval |
| API Credential | Application or third-party platform | Defined machine access | Until expiration or deletion |
Partner Assistance and Remote Assistance are off by default. Remote Assistance defaults to seven days, and Central displays the exact expiration date and time.[1] Use a personal administrator account for an external organization only when no suitable delegated path exists and responsibility is explicitly defined. API credentials are technical identities with their own lifecycle, not a substitute for time-controlled support access.
Who can grant access?
Super Admin and Admin can create support cases and enable Remote Assistance. Help Desk and Read-only can create support cases but cannot enable Remote Assistance. Enterprise Admin Access in a sub-estate requires the Super Admin role.[1][2]
Check the acting account before granting access. If it lacks the required role, do not share a common Super Admin login as a temporary workaround. A named authorized administrator performs the change and remains responsible for revocation and review.
Keep the support case separate from remote access
Current Sophos pages describe more than one way to start a support case. The regular Central path is Help icon > Support center > Create a support case. If the Sophos Support Assistant is available in the tenant through its Early Access Program, it appears under the Sparkle icon and can connect the administrator to a human agent or display and create cases.[3][4]
The visible route therefore depends on the tenant and its EAP participation. Neither the Help menu nor Support Assistant grants permanent remote access by itself. If the optional session access is selected while creating a Central case, Sophos turns Remote Assistance off automatically after 120 hours. Disable it manually as soon as an investigation finishes earlier.[3]
Partner Assistance
A tenant can enable Partner Assistance under Profile icon > Support settings. When it is off, the assigned partner sees only high-level information such as purchased services and current usage. Enabling it allows the partner to open the Central tenant and configure Central services on the customer’s behalf.[1]
Partner Assistance is not a time-limited support code. It may be appropriate for an IT partner providing ongoing administration, but it requires a contractual basis, named responsibilities, and regular review. Before approval, record the partner assignment, service scope, escalation path, and permitted activities. Review the option immediately after a partner change or contract end rather than waiting for the next annual review.
Sophos Remote Assistance
Remote Assistance gives Sophos Support direct access to the Central session. Under Profile icon > Support settings, it can be enabled for 3, 7, 14, 30, or 60 days; the default selection is 7 days. Record the displayed expiration in the case documentation.[1]
Grant access only when this information is available:
- case number and technical question,
- responsible internal administrator,
- shortest suitable duration,
- permitted tests and maintenance windows,
- affected products and potentially sensitive data,
- date for review and early deactivation.
Remote Assistance for Central is not the same function as the Remote Assistance ID or Support Access on a Sophos Firewall, switch, access point, or NDR appliance. Those product-specific methods have their own paths, durations, and acceptance criteria.
Grant and revoke access
- Record the case, service request, or Enterprise purpose and name an internal owner.
- Sign in with an authorized personal administrator account and open Profile icon > Support settings.
- Verify the partner assignment. For Remote Assistance, select the shortest duration that covers the agreed investigation window.
- Enable only the intended option. A second administrator verifies the option, duration, and displayed expiration; record these values in the case or change documentation.
- When the work is complete, return to the same page, disable access manually, and verify the off state. Do not wait for automatic expiry when the work finishes earlier.
- Review the Audit Log for changes made during the approved window.
If activation fails, first check the role, partner assignment, and selected access path. Remote Assistance being absent for Help Desk or Read-only is an expected role restriction, not a browser fault.[2]
Enterprise Admin Access
A Central Enterprise administrator manages sub-estates belonging to the same organization. A Super Admin in the sub-estate must first approve access. Afterward, Enterprise Admin Access cannot be switched off in the sub-estate like temporary support access.[1]
The workflow is covered in Enable Sophos Central Enterprise Management. Confirm the organization assignment, Enterprise Super Admins, and later revocation path before enabling it.
Review activity in the Audit Log
Under Reports > General logs > Audit Logs, Central shows the past seven days by default and allows a range of up to 90 days. Each monitored activity includes fields such as Date, Modified by, Item type, Item modified, Description, and IP address. Date and search filters take effect only after selecting Update.[5]
For acceptance, narrow the period to the external session and search for the acting account or known IP address. Review at least support settings, new administrators, roles, policies, exclusions, and API credentials. Reconcile the start, end, acting organization, and relevant change references with the entries found.
Disabling access proves only that this channel is closed. Local administrators, integrations, API credentials, policies, or exclusions created during the session remain until they are removed separately. If an expected activity is missing, do not assume that no change occurred: check the date range, Update, search term, and acting account again, and record the discrepancy in the case.
Quarterly review
Review Partner Assistance, Remote Assistance, Enterprise Admin Access, personal administrators, and API credentials. Also reconcile Partner Info, Customer ID, active support cases, and audit entries. The complete case workflow is covered in Open a support case with Sophos.
Frequently asked questions
Does the partner see nothing without Partner Assistance?
Does Remote Assistance end automatically?
Does disabling access remove all changes made?
Sources
[1] https://docs.sophos.com/central/customer/help/en-us/ManageYourAccount/AccountDetails — Account details - Sophos Central Admin [2] https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/GlobalSettings/AccessControl/Roles/AdministrationRoles — Administration roles - Sophos Central Admin [3] https://docs.sophos.com/central/customer/help/en-us/ManageYourAccount/Technical_support — Get additional help - Sophos Central Admin [4] https://docs.sophos.com/central/customer/help/en-us/AI/SupportAssistant — Sophos Support Assistant - Sophos Central Admin [5] https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/LogsReports/Logs/AuditLogs — Audit Logs - Sophos Central Admin