Skip to content
Avanet

Secure Sophos Central Partner and Remote Assistance

Sophos Central provides several external administration paths. Partner Assistance is intended for the assigned service provider, Remote Assistance for Sophos Support, and Enterprise Admin Access for administrators in the organization’s own Central Enterprise structure. They are granted separately and must not be treated as interchangeable “support access” methods.[1]

Quick path: Define the purpose, owner, and end time; open Profile icon > Support settings and enable only the required Assistance option; have a second administrator verify the displayed state; and turn access off as soon as the work is complete. Then review the changes under Reports > General logs > Audit Logs.[1][5]

Distinguish the access paths

AccessRecipientTypical purposeDuration
Partner AssistanceSophos Partner assigned to the customerOngoing administration and service deliveryActive until disabled again
Remote AssistanceSophos SupportAnalysis of a specific Central caseSelectable for 3, 7, 14, 30, or 60 days
Enterprise Admin AccessAdministrators of the organization’s own Central Enterprise accountManagement of a sub-estateCannot be revoked in the sub-estate after approval
API CredentialApplication or third-party platformDefined machine accessUntil expiration or deletion

Partner Assistance and Remote Assistance are off by default. Remote Assistance defaults to seven days, and Central displays the exact expiration date and time.[1] Use a personal administrator account for an external organization only when no suitable delegated path exists and responsibility is explicitly defined. API credentials are technical identities with their own lifecycle, not a substitute for time-controlled support access.

Who can grant access?

Super Admin and Admin can create support cases and enable Remote Assistance. Help Desk and Read-only can create support cases but cannot enable Remote Assistance. Enterprise Admin Access in a sub-estate requires the Super Admin role.[1][2]

Check the acting account before granting access. If it lacks the required role, do not share a common Super Admin login as a temporary workaround. A named authorized administrator performs the change and remains responsible for revocation and review.

Keep the support case separate from remote access

Current Sophos pages describe more than one way to start a support case. The regular Central path is Help icon > Support center > Create a support case. If the Sophos Support Assistant is available in the tenant through its Early Access Program, it appears under the Sparkle icon and can connect the administrator to a human agent or display and create cases.[3][4]

The visible route therefore depends on the tenant and its EAP participation. Neither the Help menu nor Support Assistant grants permanent remote access by itself. If the optional session access is selected while creating a Central case, Sophos turns Remote Assistance off automatically after 120 hours. Disable it manually as soon as an investigation finishes earlier.[3]

Partner Assistance

A tenant can enable Partner Assistance under Profile icon > Support settings. When it is off, the assigned partner sees only high-level information such as purchased services and current usage. Enabling it allows the partner to open the Central tenant and configure Central services on the customer’s behalf.[1]

Partner Assistance is not a time-limited support code. It may be appropriate for an IT partner providing ongoing administration, but it requires a contractual basis, named responsibilities, and regular review. Before approval, record the partner assignment, service scope, escalation path, and permitted activities. Review the option immediately after a partner change or contract end rather than waiting for the next annual review.

Sophos Remote Assistance

Remote Assistance gives Sophos Support direct access to the Central session. Under Profile icon > Support settings, it can be enabled for 3, 7, 14, 30, or 60 days; the default selection is 7 days. Record the displayed expiration in the case documentation.[1]

Grant access only when this information is available:

  • case number and technical question,
  • responsible internal administrator,
  • shortest suitable duration,
  • permitted tests and maintenance windows,
  • affected products and potentially sensitive data,
  • date for review and early deactivation.

Remote Assistance for Central is not the same function as the Remote Assistance ID or Support Access on a Sophos Firewall, switch, access point, or NDR appliance. Those product-specific methods have their own paths, durations, and acceptance criteria.

Grant and revoke access

  1. Record the case, service request, or Enterprise purpose and name an internal owner.
  2. Sign in with an authorized personal administrator account and open Profile icon > Support settings.
  3. Verify the partner assignment. For Remote Assistance, select the shortest duration that covers the agreed investigation window.
  4. Enable only the intended option. A second administrator verifies the option, duration, and displayed expiration; record these values in the case or change documentation.
  5. When the work is complete, return to the same page, disable access manually, and verify the off state. Do not wait for automatic expiry when the work finishes earlier.
  6. Review the Audit Log for changes made during the approved window.

If activation fails, first check the role, partner assignment, and selected access path. Remote Assistance being absent for Help Desk or Read-only is an expected role restriction, not a browser fault.[2]

Enterprise Admin Access

A Central Enterprise administrator manages sub-estates belonging to the same organization. A Super Admin in the sub-estate must first approve access. Afterward, Enterprise Admin Access cannot be switched off in the sub-estate like temporary support access.[1]

The workflow is covered in Enable Sophos Central Enterprise Management. Confirm the organization assignment, Enterprise Super Admins, and later revocation path before enabling it.

Review activity in the Audit Log

Under Reports > General logs > Audit Logs, Central shows the past seven days by default and allows a range of up to 90 days. Each monitored activity includes fields such as Date, Modified by, Item type, Item modified, Description, and IP address. Date and search filters take effect only after selecting Update.[5]

For acceptance, narrow the period to the external session and search for the acting account or known IP address. Review at least support settings, new administrators, roles, policies, exclusions, and API credentials. Reconcile the start, end, acting organization, and relevant change references with the entries found.

Disabling access proves only that this channel is closed. Local administrators, integrations, API credentials, policies, or exclusions created during the session remain until they are removed separately. If an expected activity is missing, do not assume that no change occurred: check the date range, Update, search term, and acting account again, and record the discrepancy in the case.

Quarterly review

Review Partner Assistance, Remote Assistance, Enterprise Admin Access, personal administrators, and API credentials. Also reconcile Partner Info, Customer ID, active support cases, and audit entries. The complete case workflow is covered in Open a support case with Sophos.

Frequently asked questions

Does the partner see nothing without Partner Assistance?

The assigned partner can still see high-level information such as purchased services and usage. Direct portal access and configuration on the customer’s behalf require Partner Assistance.[1]

Does Remote Assistance end automatically?

Yes, after the selected duration. When granted during case creation, Sophos turns it off after 120 hours. Disable and verify it manually as soon as the work is complete.[1][3]

Does disabling access remove all changes made?

No. It closes only the access channel. Accounts, credentials, policies, or exclusions created during the session must be reviewed and removed separately where necessary.

Sources

[1] https://docs.sophos.com/central/customer/help/en-us/ManageYourAccount/AccountDetails — Account details - Sophos Central Admin [2] https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/GlobalSettings/AccessControl/Roles/AdministrationRoles — Administration roles - Sophos Central Admin [3] https://docs.sophos.com/central/customer/help/en-us/ManageYourAccount/Technical_support — Get additional help - Sophos Central Admin [4] https://docs.sophos.com/central/customer/help/en-us/AI/SupportAssistant — Sophos Support Assistant - Sophos Central Admin [5] https://docs.sophos.com/central/customer/help/en-us/ManageYourProducts/LogsReports/Logs/AuditLogs — Audit Logs - Sophos Central Admin