Skip to content
Avanet

Assign Sophos Central administration roles correctly

The appropriate Sophos Central role follows the principle of least privilege: reserve Super Admin for role and API management, use Admin for broad administration, Help Desk for support tasks, Read-only for viewing only, and User only for the Self-Service Portal. Use a Custom Role for more granular permissions.

Which administration role fits?

Sophos Central contains five predefined roles. Additional XDR and product-specific features depend on the available licences.

Info: Predefined roles can’t be edited or deleted.

Super Admin

Super Admin has full access and also manages roles, role assignments, Custom Roles, API Tokens, and API Credentials.

Important: The tenant must always have at least one Super Admin.

Admin

Admin has broad access to the licensed Central features but can’t manage roles, role assignments, API Tokens, or API Credentials.

Help Desk

Help Desk generally has read access to settings but can also view sensitive logs and reports, receive alerts and clear them only when the Alerts page is opened from the dashboard, update Sophos agents, and scan computers. Help Desk can’t manage roles or API credentials.

Read-only

Read-only can view settings, sensitive logs, reports, and alerts, but can’t manage roles or role assignments, assign policies, change settings, clear alerts, update agents, or scan computers.

User

User has no administration rights and can only open the Self-Service Portal.

Assign or change a role

Only a Super Admin can assign or change administration roles. A user can have only one role at a time; a new assignment replaces the existing one.

  1. Open Global Settings > Access Control > Admins and Roles.
  2. Select the Roles tab and then the required role.
  3. Select Edit next to Role Members.
  4. Move users between Available Users and Assigned Users, then select Save.

The role of an administrator who is currently signed in can’t be changed. The administrator must sign out first; if their own role needs changing, another Super Admin must make the change. Then test the sign-in with the affected account and verify that only the intended pages and actions are available.

Custom roles

Only Super Admins can create Custom Roles under Global Settings > Access Control > Admins and Roles > Roles > Add role. Select a base role and assign the Access Type Full, Help Desk, Read-only, or None for each product. Further options, for example for logs, policies, or Live Response, depend on the product, Access Type, and licence scope.

A practical example is a Firewall Monitoring role with the base role Help Desk, the product Firewall, and the Access Type Help Desk; products that aren’t required receive None. This allows monitoring, diagnostics, logs, and reports, but not configuration or policy changes.

Manage Sophos Firewall through Central

When a Sophos Firewall is connected to Sophos Central, access to the firewall’s web admin console depends on the SFOS version:

  • Up to SFOS 22.0 MR1: Only Admin and Super Admin could open the firewall through Central; the session received the same rights as the local admin account.
  • From SFOS 22.0 MR2: Each time someone accesses the firewall, it automatically maps the role assigned in Sophos Central to Full, Help Desk, Read-only, or None.

The predefined roles are mapped as follows:

  • Super Admin and Admin receive Full.
  • Help Desk receives Help Desk for monitoring, diagnostics, logs, and reports, but without configuration or policy changes.
  • Read-only can view settings, configuration, and status but can’t change anything.
  • User and Custom Roles with None for the Firewall product receive no access.

The general Central role Help Desk and the firewall Access Type Help Desk don’t have the same permission set. On the firewall, the narrower monitoring and diagnostic permissions of the firewall Access Type Help Desk apply.

When accessed through Central, the firewall creates or updates the user and applies the Central role. A Central-managed User can’t be edited locally. Role changes take effect the next time the firewall is opened from Central, so close and reopen an existing session.

If firewall access doesn’t work

  • Account disabled: The message Sign-in failed. The user account is disabled in the firewall. means that the associated firewall account is disabled. Sophos Central doesn’t enable it automatically.
  • Normal user or guest with the same username: For Sign-in failed. A non-administrative or guest user with the same username already exists in the firewall., a firewall administrator must first change the User Type of the existing account to an administrative type. Then open the firewall from Central again.
  • Same username in multiple authentication systems: The most recent sign-in determines the active permissions. Roles and User Types should therefore be consistent across Central, the Identity Provider, and the local firewall.
  • Grouped firewall is missing: Sophos lists NR-15693 as a known issue in which Help Desk and Read-only accounts may not see grouped firewalls. The Admin role is a documented workaround but significantly expands permissions.
  • Existing session is disconnected: Only one Central Manager session is possible per firewall. If a second person signs in, the first loses their Session Token and may see Unable to load page. Check your network connection.