Assign Sophos Central administration roles correctly
The appropriate Sophos Central role follows the principle of least privilege: reserve Super Admin for role and API management, use Admin for broad administration, Help Desk for support tasks, Read-only for viewing only, and User only for the Self-Service Portal. Use a Custom Role for more granular permissions.
Which administration role fits?
Sophos Central contains five predefined roles. Additional XDR and product-specific features depend on the available licences.
Info: Predefined roles can’t be edited or deleted.
Super Admin
Super Admin has full access and also manages roles, role assignments, Custom Roles, API Tokens, and API Credentials.
Important: The tenant must always have at least one Super Admin.
Admin
Admin has broad access to the licensed Central features but can’t manage roles, role assignments, API Tokens, or API Credentials.
Help Desk
Help Desk generally has read access to settings but can also view sensitive logs and reports, receive alerts and clear them only when the Alerts page is opened from the dashboard, update Sophos agents, and scan computers. Help Desk can’t manage roles or API credentials.
Read-only
Read-only can view settings, sensitive logs, reports, and alerts, but can’t manage roles or role assignments, assign policies, change settings, clear alerts, update agents, or scan computers.
User
User has no administration rights and can only open the Self-Service Portal.
Assign or change a role
Only a Super Admin can assign or change administration roles. A user can have only one role at a time; a new assignment replaces the existing one.
- Open
Global Settings > Access Control > Admins and Roles. - Select the
Rolestab and then the required role. - Select
Editnext toRole Members. - Move users between
Available UsersandAssigned Users, then selectSave.
The role of an administrator who is currently signed in can’t be changed. The administrator must sign out first; if their own role needs changing, another Super Admin must make the change. Then test the sign-in with the affected account and verify that only the intended pages and actions are available.
Custom roles
Only Super Admins can create Custom Roles under Global Settings > Access Control > Admins and Roles > Roles > Add role. Select a base role and assign the Access Type Full, Help Desk, Read-only, or None for each product. Further options, for example for logs, policies, or Live Response, depend on the product, Access Type, and licence scope.
A practical example is a Firewall Monitoring role with the base role Help Desk, the product Firewall, and the Access Type Help Desk; products that aren’t required receive None. This allows monitoring, diagnostics, logs, and reports, but not configuration or policy changes.
Manage Sophos Firewall through Central
When a Sophos Firewall is connected to Sophos Central, access to the firewall’s web admin console depends on the SFOS version:
- Up to SFOS 22.0 MR1: Only Admin and Super Admin could open the firewall through Central; the session received the same rights as the local
adminaccount. - From SFOS 22.0 MR2: Each time someone accesses the firewall, it automatically maps the role assigned in Sophos Central to
Full,Help Desk,Read-only, orNone.
The predefined roles are mapped as follows:
- Super Admin and Admin receive
Full. - Help Desk receives
Help Deskfor monitoring, diagnostics, logs, and reports, but without configuration or policy changes. - Read-only can view settings, configuration, and status but can’t change anything.
- User and Custom Roles with
Nonefor the Firewall product receive no access.
The general Central role Help Desk and the firewall Access Type Help Desk don’t have the same permission set. On the firewall, the narrower monitoring and diagnostic permissions of the firewall Access Type Help Desk apply.
When accessed through Central, the firewall creates or updates the user and applies the Central role. A Central-managed User can’t be edited locally. Role changes take effect the next time the firewall is opened from Central, so close and reopen an existing session.
If firewall access doesn’t work
- Account disabled: The message
Sign-in failed. The user account is disabled in the firewall.means that the associated firewall account is disabled. Sophos Central doesn’t enable it automatically. - Normal user or guest with the same username: For
Sign-in failed. A non-administrative or guest user with the same username already exists in the firewall., a firewall administrator must first change the User Type of the existing account to an administrative type. Then open the firewall from Central again. - Same username in multiple authentication systems: The most recent sign-in determines the active permissions. Roles and User Types should therefore be consistent across Central, the Identity Provider, and the local firewall.
- Grouped firewall is missing: Sophos lists
NR-15693as a known issue in which Help Desk and Read-only accounts may not see grouped firewalls. The Admin role is a documented workaround but significantly expands permissions. - Existing session is disconnected: Only one Central Manager session is possible per firewall. If a second person signs in, the first loses their Session Token and may see
Unable to load page. Check your network connection.