Skip to content
Avanet

Configure Sophos Central alert email notifications

Sophos Central can send Alerts by email. An enabled default rule is not yet an incident process. What matters is who receives which notifications, how quickly they respond and what happens during absence or delivery failure. Only a Super Admin can manage the global settings.

Work with cross-product alerts

My Environment > Alerts combines notifications from all products managed in Central, including installation, updates, licenses, connectivity, and threats. The list shows Severity as High, Medium, or Low; status as Open, Closed, Reopened, or Resolved; the number of grouped Events; and the affected device. When a later Event corrects the cause of an earlier Event in the same Alert, Central can close it automatically as Resolved.

Select the Alert Title to open a slideout with the Alert and Associated events. The full-screen icon shows the same details on a complete page. Group combines matching Alerts by threat or Event; Count shows the group size, and the arrow at the right expands its Alerts.

High, Medium, and Low have direct filters on their metrics. The general filter above the list combines Status, Severity, Products, Category, Available actions, Alert title, and date range. Multiple values define the required scope together. Apply activates the selection; Reset to defaults followed by Apply removes it. The Column Customizer controls visible columns.

After selecting one Alert or a group, Actions shows available steps. With multiple selection, Central offers only actions available for all selected Alerts. Depending on Alert type, these include:

  • Mark As Acknowledged removes the notification from the active list but neither resolves the threat nor clears local quarantine.
  • Mark As Resolved confirms that the cause has already been resolved on the Windows device and clears Alert and quarantine display, but performs no cleanup itself.
  • Clean Up can remove ransomware from a server.
  • Reinstall Endpoint Protection opens the Installers page for reinstallation.
  • Contact Support appears for suitable failures, such as failed malware cleanup.
  • Authorize PUA allows the application on all computers and is available only for computer Alerts.

With XDR, Threat Graphs can offer additional investigation, blocking, and cleanup actions. A legitimate application detected as malware is instead reviewed and allowed on the Events page, not from the Alerts list.

Close an Alert in its details with Close alert or after selection through Actions > Close alert. The Closed filter reveals closed entries again. Closing changes only workflow status.

In Alert details, Email Alert changes frequency for exactly that Alert type. Central creates an exception in the global email Alert settings, where it can later be reviewed or edited. For a malware outbreak of at least 100 Detections on one device within 24 hours, Central resumes normal individual notifications only after the outbreak is marked Resolved. Investigate and remediate the cause first.

Separate rules by responsibility

The current path is Global Settings > Platform > Notification Settings > Configure Email Alerts. Only a Super Admin can manage these tenant-wide settings.

Under Administrators, Central shows each administrator’s name, email address, and role. Yes or No determines whether that person receives default Alert emails. This setting grants neither Central access nor a new role; it controls notification only.

Under Distribution lists, maintain additional lists, ticketing systems, or individual people without Central access. Add email address records the address and description, and Save stores it. To remove one, select the existing address and confirm Delete. After every change, test delivery with a controlled Alert or designated test path.

Rather than sending every notification to individuals, use monitored functional mailboxes or ticketing systems.

Distribution lists can notify external people or a ticketing system without granting Central access. They aren’t available in a Sophos Central trial, however. Account for this licensing limit in a production-like test rather than misdiagnosing it as a permission or delivery problem.

If a person needs Sophos Central Admin access, create them separately as an administrator with the appropriate role and MFA. An entry under Distribution lists is only an email recipient and never an access permission.

A practical model separates:

  • High Alerts and critical incidents to Security Operations with immediate escalation,
  • Medium Alerts to Endpoint Operations with a defined response time,
  • Low Alerts or operational notices for daily or periodic review,
  • licence, Health and platform notifications to the responsible service owner.

Keep rules small enough that it remains clear why a recipient receives a notification. Duplicate rules create unnecessary alert floods.

Understand frequency

Frequency can be controlled by exactly one characteristic: severity, product or Alert category. The available values are Immediately, Hourly, Daily and Never.

Hourly and Daily do not produce a digest email. Sophos sends the first Alert immediately and then limits the same Alert per device to no more than one email per hour or day. Five affected devices can therefore still generate five emails.

Immediately is sent without throttling, but it does not guarantee delivery at the same moment as the original Detection. Some Alerts are created only after a timer expires or when a Recovery Event does not occur. An email can therefore arrive later even for a device that has since been deleted. If the same Alert recurs, its original timestamp remains; the count and Event history show the new occurrences.

Not every Event creates an Alert. If a notification is missing from the active Alert list, check Reports > General Logs > Events, previous workflow actions and the specific Alert logic. The language for a directly addressed Central role member follows that person’s user profile; distribution lists without a Central sign-in use the account’s default language.

If a directly addressed person still receives the wrong language, select another language temporarily under the profile icon at Language, then select the required language again. This resaves the language marker in the user profile. For a distribution-only address without a sign-in, or an incorrect account language affecting several administrators, Sophos Support must check the account language. Provide the tenant UUID, affected address, required language and enabled Remote Assistance.

Custom Rules without losing recipients

A Custom Rule can restrict the administrator role, specific recipients or distribution lists, computer and server groups, and Alert types.

By default, administrators see all Alerts. A Custom Rule restricts delivery to selected roles, people, products, Events, or severities. Complete the wizard as follows:

  1. Select + Create rule.
  2. Under Role, select the affected administrator role and choose Next.
  3. Under Administrators & Distribution lists, select the actual recipients and continue.
  4. Under Computers & Servers, select the intended computer and server groups. If the tenant has no device groups, this step does not appear. Without a selected device group, only Alerts from products not associated with a device are delivered.
  5. Under Alert Types, select at least one option for every offered attribute. Narrow the choice by Severity, product, and Alert Category.
  6. Enter a meaningful name and description and finish with Save.

The rule then appears under Custom rules. Its expansion arrow shows details; the adjacent icons pause, edit, or delete it. Hover over an icon before acting to avoid applying the wrong rule operation.

When the first Custom Rule is enabled, however, Sophos disables the previous settings under Administrators & Distribution lists. If these recipients should continue to receive all matching Alerts, represent them explicitly in their own Custom Rule.

A rule becomes invalid and is disabled when none of its recipients remain. If all Custom Rules are eventually disabled, Sophos returns to the default behaviour and sends all Alerts to all administrators and distribution lists in the account. Check this fallback when offboarding a recipient.

If every computer and server group is deleted from the tenant, a rule can remain active when it also includes Alert types for products not associated with devices. Not every Alert requires an Endpoint or Server object. After group cleanup, therefore review the rule status and actual product scope rather than only the device-group list.

Exceptions change the frequency for individual Alert types. They can be created in the Alert and reviewed or edited in the global Exceptions list. Remove obsolete exceptions regularly.

Consider more than Endpoint threats

Alert types include more than malware. Failed installation, disrupted communication, outdated protection, a required restart, licence problems, Account Health or an outbreak can also require attention.

Data Loss Prevention email notifications are a special case: a notification about a DLP rule violation does not automatically create a Central Alert. Test DLP escalation separately.

Operate Firewall Alerts Configurator

Central manages firewall Alert repetition separately under Global Settings > Platform > Notification Settings > Firewall Alerts Configurator. Each firewall belongs to exactly one Alert Category:

  • Default uses Sophos defaults, often repeating after eight hours. Some Alert types are set to Never there by default.
  • Verbose repeats an unresolved problem every hour.
  • Silent repeats it every 24 hours.

Assign firewalls under Assigned Firewall for each category. Removing a firewall from Verbose or Silent automatically returns it to Default. It cannot be left unassigned by removing it from the Default list.

For individual firewall Alert types, configure severity, up to ten occurrences, and a block period of Immediately, 1 Hour, 4 Hours, 8 Hours, Daily, or Never. Throttling suppresses only repeated notifications for the same problem. Events remain visible under Logs and Reports > Events and still require analysis during troubleshooting. Reset to Sophos defaults discards custom frequencies.

Approve User Activity Verification deliberately

The User Activity Verification API can send questions with predefined answers to Android devices, iPhones, or iPads. It requires Sophos Intercept X for Mobile installed and registered with Sophos Central. The function can also provide automatic mobile notifications about a critical attack.

The API is available to every Central customer but is not a general push channel for arbitrary endpoints. It can be turned off tenant-wide under Global Settings > Platform > User Activity Verification. Central then answers every call to this API with 403 Forbidden. Before disabling it, check whether incident-response or Mobile processes use it; afterward, confirm the expected block with a controlled API test.

Verify delivery

Before production use, check the sender, spam filters, transport rules, ticket parsing and mobile notifications. A rule is not considered functional solely because it is configured.

Perform a controlled test at least quarterly. Also inspect Audit Logs for changes to notification rules.

Do not confuse an Alert with its email

Email is only a transport channel. The current status, all Events and available actions are in Sophos Central. Deleting an email does not change the Alert, and closing an Alert does not guarantee that its technical cause has been resolved.

The bell icon Notifications is not a second Alert list. Notification Center collects medium- and low-priority notices such as product information or maintenance announcements. High-priority messages appear as banners. Session dismiss hides a notice only until the next sign-in, while Permanently dismiss hides it permanently. Neither action changes an Endpoint Alert or resolves a technical cause.

Operational handling is described in Handle Sophos Endpoint Alerts and Account Health.

Document the escalation path

Define a response time, primary team, deputy and next escalation point for each severity. High Alerts outside office hours need a different channel from an unattended mailbox.

When using MDR or an external SOC, clarify which notifications Sophos or the provider already handles and which remain with the internal team.

Frequently asked questions

Should every Alert be sent to every administrator?

No. This causes alert fatigue and unclear ownership. Separate rules by severity and responsible process.

Does a configured rule prove that Alerts arrive?

No. Spam filters, transport rules, ticket parsers or invalid recipients can prevent delivery. A controlled end-to-end test is required.