Assign Sophos Fusion administration roles correctly
The appropriate Sophos Fusion (formerly Sophos Central) role follows the principle of least privilege: reserve Super Admin for role and API management, use Admin for broad administration, Help Desk for support tasks, Read-only for viewing only, and User only for the Self Service Portal. Use a Custom Role for more granular permissions.
Which administration role fits?
Sophos Fusion contains five predefined roles. Additional XDR and product-specific features depend on the available licences. If the required product licence is missing, its capability may be hidden entirely in role management.
Info: Predefined roles can’t be edited or deleted.
Super Admin
Super Admin has full access and also manages roles, role assignments, Custom Roles, API Tokens, and API Credentials. This role can open Sophos Support cases and enable Remote Assistance.
Important: The tenant must always have at least one Super Admin.
Admin
Admin has broad access to licensed Sophos Fusion features but can’t manage roles, role assignments, API Tokens, or API Credentials. An Admin can also use support cases and Remote Assistance. On the Quarantined Messages page, this role can release quarantined emails.
Help Desk
Help Desk generally has read access to settings but can also view sensitive logs and reports, receive alerts and clear them only when the Alerts page is opened from the dashboard, update Sophos agents, scan computers, and change co-branding. The role can open Sophos Support cases but can’t enable Remote Assistance. Help Desk can’t manage roles or API credentials.
With a Phish Threat licence, Help Desk can view users, campaigns, series, results, and reports. However, the role can’t report email as spam or change the users assigned to a Phish Threat campaign. Unavailable edit buttons and missing role options are therefore expected restrictions, not a display error.
Read-only
Read-only can view settings, sensitive logs, reports, and alerts and open Sophos Support cases. With a Phish Threat licence, users, campaigns, series, results, and reports are visible. However, the role can’t enable Remote Assistance, manage roles or API Credentials, assign policies, change settings, clear alerts, update agents, or scan computers. Licence actions such as Start Trial and Apply License Key are also unavailable.
User
User has no administration rights and uses only the Self Service Portal. Access and the user lifecycle are explained in Set up Sophos Fusion Self Service Portal access.
Sophos Fusion roles apply only to the Sophos platform. They do not grant administration rights in Microsoft 365 and do not replace either a Microsoft 365 Global Administrator or any required admin consent there. For cross-product setup, assign and verify the Sophos and Microsoft 365 tasks separately; follow the relevant component guide for its procedure.
ITDR in the Sophos Fusion role model
Sophos ITDR uses the predefined Sophos Fusion administration roles. Super Admin and Admin can access licensed features, while Help Desk and Read-only generally have read-only access; User remains limited to the Self Service Portal. Sophos documents neither a separate predefined ITDR role nor an ITDR-specific Custom Role capability. Therefore, don’t interpret a visible Custom Role option as an “ITDR permission”.
For ITDR setup, use an existing Super Admin or Admin and, before the maintenance window, verify that My Products > Identity > Settings > Integrations and the intended action are available. Then test the intended least-privileged account for ongoing read access. Licence-dependent capabilities may be absent entirely without the appropriate licence; in Custom Roles, capabilities apply only to the selected products. Planning Sophos ITDR: Prerequisites, licenses, regions, and roles explains the separate Sophos and Entra roles and the undocumented minimum ITDR role.
Assign or change a role
Only a Super Admin can assign or change administration roles. A user can have only one role at a time; a new assignment replaces the existing one.
The Global Settings > Access Control > Admins and Roles page has two tabs: Admins manages administrator accounts, while Roles shows roles and their members. Use the Roles tab to assign a role. The navigation and tabs use the labels shown here; controls in the member dialog are labelled Role Members, Edit, Available Users, and Assigned Users.
- Open
Global Settings > Access Control > Admins and Roles. - Select the
Rolestab and then the required role. - Select
Editnext toRole Members. - Move users between
Available UsersandAssigned Users, then selectSave.
You can change several administrators together in the same dialog. Before saving, check for each selected person that the new role is intended to replace their existing role completely.
After the first administration role is assigned, the user receives an email to set up their administration account. Verify delivery and a successful sign-in path; the role appearing in the list does not prove that the invitation and MFA setup are complete.
The role of an administrator who is currently signed in can’t be changed. The administrator must sign out first; if their own role needs changing, another Super Admin must make the change. Then test the sign-in with the affected account and verify that only the intended pages and actions are available.
Review role details and additional rights
Under Global Settings > Access Control > Admins and Roles > Roles, select a role name to open its details page. It shows the access level Full, Help Desk, or Read-only, specialist capabilities, and the list of assigned administrators. Select a name to open that administrator’s complete user details.
The most important capability fields mean:
- Access sensitive logs & reports permits access to sensitive logs and reports, including Audit Logs.
- Access policy management permits changes to policy settings.
- Access policy assignment permits assigning existing policies to users and devices.
- Start Live Response sessions on computers or servers permits a direct connection to investigate and remediate the respective device type.
- Manage Data Collection and Investigation settings for computers or servers permits enabling Live Response and Data Lake uploads in the respective Data Collection and Investigation policy.
Live Response and Data Collection and Investigation are available only to Super Admins or Custom Roles for which both the required product and the appropriate capability are selected. Review the details page before assignment and during the quarterly review; the role name alone does not prove the effective rights.
Custom roles
Only Super Admins can create Custom Roles under Global Settings > Access Control > Admins and Roles > Roles > Add role. After selecting Add role, enter the Name and Description and choose a Base Role. Then give each required Product its own Access Type: Full, Help Desk, Read-only, or None.
A practical example is an Endpoint Help Desk role with the Base Role Read-only: give Endpoint Protection the Access Type Help Desk, Mobile Read-only, and every unneeded product None. Under Additional access and management options, select only the explicitly required rights for logs, policy assignment, or Live Response. Available options depend on the product, Access Type, and licence scope. Save creates the role; only then assign it to an administrator and test it with that account.
Policy Management and Policy Assignment
For Custom Roles, Policy Management and Policy Assignment are not the same:
- Policy Management permits creating, changing, and deleting policies.
- Policy Assignment permits assigning existing policies to users, groups, or devices.
The two options are mutually exclusive. Policy Management is broader. If enabled for a Help Desk or Read-only Base Role, the Custom Role receives the same capabilities as the Full Base Role for managing policies, devices, and users. Do not assume that this additional right is harmless simply because the Base Role is restricted.
Consider shared settings
Some global settings are shared by Endpoint and Server, and in some cases also by Encryption. These include Tamper Protection, Allowed Applications, Website Management, Proxy Configuration, Blocked Items, Bandwidth Usage with additional Encryption access, DLP Rules, Manage Content Control List, Reject Network Connections, and the XDR Threat Analysis Center.
If a Custom Role lacks access to Endpoint Protection or Server Protection, the shared settings are read-only and exclusions cannot be added or managed. Where a setting also uses Encryption, the Custom Role must include that product as well. This isn’t a UI fault but a consequence of the cross-product setting.
Critical capabilities and their prerequisites
Additional rights do not take effect solely because the checkbox is visible. The Base Role, product, and access type must also be appropriate:
| Additional right | Required role combination |
|---|---|
| Start Live Response sessions on computers | Endpoint Protection with Full or Help Desk |
| Start Live Response sessions on servers | Server Protection with Full or Help Desk |
| Manage Data Collection and Investigation settings for computers | Endpoint Protection with Full; permits, among other things, Live Response and Data Lake uploads for computers |
| Manage Data Collection and Investigation settings for servers | Server Protection with Full; permits, among other things, Live Response and Data Lake uploads for servers |
| Enable global search management | Endpoint Protection or Server Protection, or both if required, with Full |
| Turn off tamper protection for computers | Base Role Help Desk plus Endpoint Protection with Full |
| Remove computers from isolation | Base Role Help Desk plus Endpoint Protection with Full |
| Turn off tamper protection for servers | Base Role Help Desk plus Server Protection with Full |
| Remove servers from isolation | Base Role Help Desk plus Server Protection with Full |
Logs & Reports access applies to all products and access types in the Custom Role. The same applies to Policy Management and Policy Assignment, although these two rights continue to have separate effects. Test each combination with a test account: a permitted action must succeed, and an action that isn’t permitted must fail. Live Response, Data Lake uploads, disabling Tamper Protection, and removing isolation in particular must have a named owner and be reviewed quarterly.
Licence-dependent XDR rights
With an XDR licence, Sophos Fusion extends roles with individual investigation and response capabilities. These rights aren’t included wholesale in “XDR access”:
| Action | Permitted predefined role or Custom Role |
|---|---|
| View Intelligence Report | Super Admin, Admin, Help Desk, Read-only |
| Request Intelligence Report | Super Admin, Admin, Help Desk |
| Add or remove a Clean and Block entry | Super Admin, Admin |
| View blocked entries | Super Admin, Admin, Help Desk, Read-only |
| View on-demand Threat Graph | Super Admin, Admin, Help Desk, Read-only |
| Request on-demand Threat Graph | Super Admin, Admin, Help Desk |
| Isolate devices or remove them from isolation | Super Admin, Admin |
| Request Forensic Snapshot | Super Admin, Admin, Help Desk |
| Start Live Response on computers | Super Admin, Admin, or Custom Role with base role Full/Help Desk and Endpoint Protection access |
| Start Live Response on servers | Super Admin, Admin, or Custom Role with base role Full/Help Desk and Server Protection access |
| Manage Data Collection and Investigation for computers | Super Admin, Admin, or Custom Role with base role Full and Endpoint Protection access |
| Manage Data Collection and Investigation for servers | Super Admin, Admin, or Custom Role with base role Full and Server Protection access |
A visible menu item does not prove permission. For particularly powerful actions, test both a permitted and a denied case with a test account and document the licence status together with the role.
Add an administrator
Only a Super Admin can assign an administration role. Under Global Settings > Access Control > Admins and Roles > Admins, either create a new user as an admin or assign an existing user to a role under the Roles tab.
For a new administrator, select Add Admin on the Admins tab. On the Add User page, enter the name, email address, and intended role. Exchange Login and Manager are optional. If required, move a group from Available groups to Assigned groups. Save completes the setup; Save and Add Another saves the record and opens the next one immediately. Sophos Fusion then automatically sends the welcome email for setting up the administration account.
Don’t create an existing user again. On the Roles tab, open the target role, select Edit under Role Members, and use the picker arrows to move the person from Available Users to Assigned Users. Save applies the assignment. If the user already has another role, the new selection replaces it completely.
Email setup link relates to protecting a device and is separate from the welcome email for administrator access. A personal setup link isn’t used as a substitute for a centrally managed software rollout.
Revoke an administrator role or delete a user
Only a Super Admin can remove administrators. These are two different actions: revoking the administration role retains the normal Sophos Fusion user, while Delete user deletes the user object.
To revoke only the role, open Global Settings > Access Control > Admins and Roles > Roles. For the required role, select Edit next to Role Members. Under Assigned Users, select the person and use the picker arrows to remove them. The person then remains as a user without those administration rights and may continue to have product-specific user functions.
To delete the user, open the administrator’s name under Global Settings > Access Control > Admins and Roles > Admins and select Delete user. First check devices, policies, mailboxes, the Directory Owner, and support responsibility.
A deleted user can reappear automatically. If they sign in on an assigned device that is still managed by Sophos Fusion, Sophos Fusion recreates them as a user. If they originate from AD, Entra ID, or Google Directory and remain in the active sync scope there, the next directory run also recreates them. Sustainable offboarding therefore removes the source assignment or disables the account before deleting the Sophos Fusion object.
Resolve role problems caused by duplicate email addresses
An administration role requires an email address that is unique within the tenant and across other Sophos Fusion accounts. If the address is missing, or if the same email address or username already exists, Sophos Fusion refuses the assignment. For a conflict in another Sophos Fusion tenant, an alternative address must be stored there or the responsible administrator must remove the record that is no longer required.
For AD-synchronised duplicates, use this controlled procedure:
- Open My Environment > Users & Groups and search for the complete email address.
- If multiple results appear, decide which user should receive the administration role.
- Open every other editable duplicate record, select Edit, remove the duplicate email address, and confirm with Save.
- Repeat the search until only the intended unique record remains.
- Open that user, select Edit, set the intended role under Role, and select Save.
If only one non-editable user is visible or the change can’t be saved, the email is usually already used in another Sophos Fusion or SSP account. Deleting more synchronised users locally does not resolve this cross-tenant conflict.
Resend the welcome email and SSP invitation
Sophos Fusion sends the welcome email or Self Service Portal notification only once when a role is assigned. The URL it contains does not expire. If the message is also absent from the spam filter, there is no separate Resend button: after checking the consequences, the user must be removed from Sophos Fusion and recreated with the appropriate role or SSP assignment.
Before deletion, check devices, policies, mailboxes, and group relationships. If the same email address is already associated with another Sophos Fusion Admin Account or with a Self Service Portal in another Sophos Fusion account, recreating the user won’t deliver another welcome email. An email address can be used only once; first resolve the conflict in the other account.
Delete a Custom Role
Only a Super Admin can delete a Custom Role; predefined roles can’t be removed. Sophos Fusion blocks deletion while administrators are still assigned to the Custom Role. First move these people to another role in a controlled manner or remove them from the role.
The path is Global Settings > Access Control > Admins and Roles > Roles. In the role list, select the relevant row somewhere outside the role name and select Delete. A second Delete confirms the permanent deletion. Then review test accounts and documented role assignments so that no automation or handover document continues to reference the removed role.
A user can have only one administration role. The new role replaces the old one. After every assignment, test the sign-in in a private browser session and verify that sensitive logs, policy changes, Live Response, and product access work exactly as intended.
Quarterly role review
The review covers:
- all Super Admins and their MFA recovery,
- users without a current owner,
- Custom Roles and their base roles,
- product access set to
Full,Help Desk,Read-only, orNone, - sensitive logs and reports,
- Policy Management and Policy Assignment,
- Live Response and Data Collection,
- API Credentials as separate technical identities.
Unused Custom Roles are deleted only after no members or processes depend on them. Review role changes in the Audit Log.
Common problems
Role can’t be assigned
The user has no email address, the same email address already exists in Sophos Fusion, or it is assigned to another Sophos Fusion account. For synchronised duplicates, correct the directory source and matching instead of simply creating more users.
Own role can’t be changed
An administrator can’t replace their own active role. A second Super Admin makes the change after the affected person has signed out.
Custom Admin sees a product but can’t change global settings
Review product access, Base Role, additional capability, and Shared Settings together. Access to only Endpoint or only Server may be insufficient for shared settings.
Admin access works, but MFA recovery doesn’t
Roles and authentication are separate. Prepare at least two MFA methods and a second Super Admin as described in Secure Sophos Fusion sign-in with MFA, passkeys, and an IdP.