Skip to content
Avanet

Configure Sophos Central alert email notifications

Sophos Central can send Alerts by email. An enabled default rule is not yet an incident process. What matters is who receives which notifications, how quickly they respond and what happens during absence or delivery failure. Only a Super Admin can manage the global settings.

Separate rules by responsibility

Recipients and severity levels are defined in the global Alert settings. Rather than sending every notification to individuals, use monitored functional mailboxes or ticketing systems.

Distribution lists can notify external people or a ticketing system without granting Central access. They aren’t available in a Sophos Central trial, however. Account for this licensing limit in a production-like test rather than misdiagnosing it as a permission or delivery problem.

A practical model separates:

  • High Alerts and critical incidents to Security Operations with immediate escalation,
  • Medium Alerts to Endpoint Operations with a defined response time,
  • Low Alerts or operational notices for daily or periodic review,
  • licence, Health and platform notifications to the responsible service owner.

Keep rules small enough that it remains clear why a recipient receives a notification. Duplicate rules create unnecessary alert floods.

Understand frequency

Frequency can be controlled by exactly one characteristic: severity, product or Alert category. The available values are Immediately, Hourly, Daily and Never.

Hourly and Daily do not produce a digest email. Sophos sends the first Alert immediately and then limits the same Alert per device to no more than one email per hour or day. Five affected devices can therefore still generate five emails.

Immediately is sent without throttling, but it does not guarantee delivery at the same moment as the original Detection. Some Alerts are created only after a timer expires or when a Recovery Event does not occur. An email can therefore arrive later even for a device that has since been deleted. If the same Alert recurs, its original timestamp remains; the count and Event history show the new occurrences.

Not every Event creates an Alert. If a notification is missing from the active Alert list, check Reports > General Logs > Events, previous workflow actions and the specific Alert logic. The language for a directly addressed Central role member follows that person’s user profile; distribution lists without a Central sign-in use the account’s default language.

If a directly addressed person still receives the wrong language, select another language temporarily under the profile icon at Language, then select the required language again. This resaves the language marker in the user profile. For a distribution-only address without a sign-in, or an incorrect account language affecting several administrators, Sophos Support must check the account language. Provide the tenant UUID, affected address, required language and enabled Remote Assistance.

Custom Rules without losing recipients

A Custom Rule can restrict the administrator role, specific recipients or distribution lists, computer and server groups, and Alert types.

When the first Custom Rule is enabled, however, Sophos disables the previous settings under Administrators & Distribution lists. If these recipients should continue to receive all matching Alerts, represent them explicitly in their own Custom Rule.

A rule becomes invalid and is disabled when none of its recipients remain. If all Custom Rules are eventually disabled, Sophos returns to the default behaviour and sends all Alerts to all administrators and distribution lists in the account. Check this fallback when offboarding a recipient.

Exceptions change the frequency for individual Alert types. They can be created in the Alert and reviewed in the global Exceptions list. Remove obsolete exceptions regularly.

Consider more than Endpoint threats

Alert types include more than malware. Failed installation, disrupted communication, outdated protection, a required restart, licence problems, Account Health or an outbreak can also require attention.

Data Loss Prevention email notifications are a special case: a notification about a DLP rule violation does not automatically create a Central Alert. Test DLP escalation separately.

Verify delivery

Before production use, check the sender, spam filters, transport rules, ticket parsing and mobile notifications. A rule is not considered functional solely because it is configured.

Perform a controlled test at least quarterly. Also inspect Audit Logs for changes to notification rules.

Do not confuse an Alert with its email

Email is only a transport channel. The current status, all Events and available actions are in Sophos Central. Deleting an email does not change the Alert, and closing an Alert does not guarantee that its technical cause has been resolved.

The operational process is explained in Handle Sophos Endpoint Alerts and Account Health.

The current browser notifications for the signed-in administrator are shown separately in the Notification Center. This interface does not replace email rules or a shared operational queue.

Document the escalation path

Define a response time, primary team, deputy and next escalation point for each severity. High Alerts outside office hours need a different channel from an unattended mailbox.

When using MDR or an external SOC, clarify which notifications Sophos or the provider already handles and which remain with the internal team.

Frequently asked questions

Should every Alert be sent to every administrator?

No. This causes alert fatigue and unclear ownership. Separate rules by severity and responsible process.

Does a configured rule prove that Alerts arrive?

No. Spam filters, transport rules, ticket parsers or invalid recipients can prevent delivery. A controlled end-to-end test is required.