Secure Sophos Central sign-in with MFA and passkeys
Sophos Central controls policies, exclusions, Live Response and device isolation. A compromised administrator account can therefore cause more damage than a single infected endpoint. MFA is the minimum requirement, but it does not replace appropriate roles or a recovery process.
Set up MFA immediately and redundantly
Every administrator must register at least two MFA methods and is prompted for MFA at every sign-in. Sophos supports passkeys and authenticator apps with time-based one-time passwords, or TOTP.
Register two independent methods for privileged accounts, such as a passkey on a hardware security key and an authenticator app on a separate device. Two passkeys on the same laptop do not provide genuine redundancy. Sophos also identifies two passkeys on separate devices or two separate authenticator registrations as possible combinations.
Replacement hardware security keys and documented recovery information belong in a protected corporate vault. They must not be stored in one employee’s personal password manager or in an open ticket.
Each administrator account can register at most ten TOTP authenticator apps. A browser authenticator extension is technically possible, but it is a third-party product not developed or supported by Sophos. Before installation, review the publisher, permissions, update path, and corporate policy. For a privileged account, an extension in the same browser profile as the Central session does not provide good factor separation.
Manage registered methods in the profile under Manage login settings or Manage MFA. Deleting an entry only from the local authenticator app does not remove it from Central. When changing devices, first test a second method, then remove the old Central registration, and reset the old device only afterward.
Configure an authenticator app
After signing in with an existing method, open profile icon > My info > Manage MFA. Alternatively, Sophos ID > My Profile > Manage MFA opens the same management page. Reauthenticate, select the plus icon on Multi-Factor Authentication, choose Authentication App under Set up MFA method, and then select Set up now.
Scan the one-time QR code with the approved authenticator app. Enter its generated security code in Central, optionally assign a unique device name, and choose Continue. Successful enrollment confirms registration; another Continue completes the workflow. At the next test sign-in, enter the app’s current verification code after email address and password.
An account can have no more than ten authenticator apps. Do not store the QR code or underlying TOTP secret as a screenshot. After testing, configure a second independent method before removing an old device or registration.
Configure a browser-based authenticator app
A browser extension can generate TOTP codes, but privileged accounts should use one only after a deliberate risk assessment:
- In Central, open profile icon > My info > Manage MFA and confirm with an existing method.
- Under Multi-factor Authentication, select the plus icon, choose Authentication App, and open Set up now.
- Keep the one-time QR code open. In another tab, install the approved extension from the browser’s official extension store.
- Return to the QR code page, open the extension beside the address bar, and select Add Account > Scan QR from screen.
- Enter the generated code under Verify Your Device > Security Code, optionally assign a unique device name, and select Continue.
- Under profile icon > My info > Manage MFA, verify the method is registered. A test sign-in must work with the username and password and the extension’s code.
The QR code is a one-time registration secret and must not be stored as a screenshot or sent in a ticket. Review the publisher, requested browser permissions, update source, and data synchronization before approval. Because the browser profile, Central session, and TOTP secret would otherwise reside together, retain a separate method on another device or hardware key.
Manage registered MFA methods
Open profile icon > My info > Manage MFA or Sophos ID > My Profile > Manage MFA. After reauthentication, Central shows all registered methods, their default or display name, and last use.
Use the plus icon to add another authenticator app or passkey. At most ten registrations are possible per method type. From a method’s three-dot menu, select Rename, enter a new name, and confirm with the check mark. Delete removes the registration from Central.
At least two MFA methods must remain registered. Once only the required minimum remains, Central does not allow another deletion. Continue closes management and returns to the Central dashboard. Test the new method in a separate sign-in before removing the old one.
Configure a passkey and choose its storage
Add a passkey as another method only after an authenticator app is configured. Under profile icon > My info > Manage MFA, reauthenticate, select the plus icon, and choose Passkey. The operating system or credential manager guides PIN or biometric verification. On Windows, for example, this can be a fingerprint through Windows Hello. After Passkey Saved, confirm with OK, check the new registration in the method list, and finish with Continue.
Storage location is part of the security decision. Options include a credential manager on the local computer, such as a browser, operating system, or enterprise password manager; a device-bound authenticator such as YubiKey; or a mobile device through a QR-code workflow. For resilience, register passkeys on more than one controlled device. Central permits at most ten passkeys.
Sign in with a passkey or authenticator app
For passkey sign-in, open the Central sign-in address, enter the email address, and select Continue. On the passkey page, Login with passkey starts the registered method, such as fingerprint, device PIN, or hardware key. The Central dashboard opens after successful verification.
When a passkey and authenticator app are registered, Central prefers the passkey. Try another way permits another method after entering the password. For classic authenticator sign-in, enter the email address and select Continue, then enter the password and choose Sign in. On MFA Validation Required, enter the current authenticator code.
Test both workflows after setup, device changes, and browser updates. A stored passkey alone is not sufficient recovery when the credential manager, device access, and Central session are affected by the same failure or account lockout.
My info, role, and local password
Under profile icon > My info, an administrator sees the current role, Central sign-in address, and password and MFA settings. Selecting the role name opens its full permissions. The email address is therefore also an important mapping attribute for sign-in, role review, and support cases.
Change a local Sophos password under My info > Password > Change password. After verification, Central shows the current password prefilled. The new password requires at least eight characters, including a lowercase letter, uppercase letter, and either a number or special character. After Reset Password, Central signs the administrator in automatically with the new password and returns to the portal; the old password becomes invalid immediately. With federated sign-in, change the password at the responsible identity provider instead.
Account Details also contain personal email subscription settings. These subscriptions are not the tenant-wide Alert recipients under Configure Email Alerts. Manage administrators, distribution lists, and ticketing systems that receive security notifications through Configure Sophos Central alert emails and notifications.
Understand passkeys correctly
Passkeys are phishing-resistant when the key is bound to the genuine Central domain and protected by a device PIN or biometrics. A synchronised passkey is convenient, but inherits the security and recovery characteristics of the Apple, Google or Microsoft account used.
For Super Admins, a managed hardware security key is a particularly robust method. Before making this a tenant-wide requirement, verify that emergency access, replacement keys and offboarding work.
Microsoft Authenticator is not supported for a Sophos passkey outside a federated Entra ID sign-in. The app can still be used as a TOTP authenticator. Depending on the platform, cross-device passkeys require Bluetooth, physical proximity and a QR-code workflow.
An account can register no more than ten passkeys. Replacement of legacy factors and lockout logic are covered separately below because they affect both TOTP and passkey accounts.
Current documented support includes Windows 10 and 11, macOS 10.15.7 or later, Android 9 or later, and iOS and iPadOS 16 or later. Sophos lists minimum browser versions of Chrome 118, Firefox 119, Safari 537.36, and Edge 119. Common stores include Windows Hello, Google Password Manager, iCloud Keychain, and 1Password; Sophos names YubiKey 5 and YubiKey NFC as device-bound keys. Other combinations can work when browser and operating-system vendors implement the required passkey protocols.
Sophos estimates this support covers about 98 percent of browser and operating-system combinations in use and common credential managers. This is a reach estimate, not a platform guarantee. Test the operating system, browser, credential manager, synchronization policy, and recovery with the versions actually deployed.
Synchronized passkeys work for Sophos sign-in, but synchronization remains a credential-manager function. iCloud Keychain can, for example, make passkeys available across Macs, iPhones, and iPads using the same iCloud identity. The credential-manager vendor is responsible for synchronization failures. Cross-device passkeys require Bluetooth enabled on computer and mobile device, nearby devices, and a QR-code scanner.
Microsoft Authenticator can use a Sophos passkey only in the context of federated Entra ID sign-in. Without that sign-in method, registration typically shows Failed to add passkey or Microsoft Authenticator doesn’t support this passkey. It remains independently usable as a TOTP app.
With 1Password Business, team or Shared Vault policies can block passkey registration. 1Password then appears in the enrollment dialog but is disabled. The responsible 1Password administrator must permit enrollment in Team Policies; repeatedly deleting the Sophos MFA method does not correct that external policy.
Deprecated MFA methods and account lockout
SMS and email plus PIN are deprecated MFA methods. New Central users must use a TOTP authenticator app or passkey. When MFA is reset for an existing user with SMS or email plus PIN, Central treats the user as new during reenrollment and likewise requires TOTP or a passkey.
After five consecutive incorrect sign-in attempts, Central initially locks the account for one minute. Further attempts with the same account gradually extend the lockout to at most five hours. Do not continue automated attempts after a lockout. If no second method or another Super Admin is available, Sophos Support can unlock the account after identity verification.
Federated sign-in through an Identity Provider
With a supported Identity Provider, Sophos Central can delegate sign-in to the central corporate identity. This simplifies Conditional Access, lifecycle management and central account suspension. Central uses a service-provider-initiated flow, or SP-initiated SSO: sign-in starts at Sophos Central and is redirected from there to the IdP.
The setup follows a fixed sequence. First verify the organisation’s domain using a DNS TXT record. DNS propagation can take up to 24 hours. A successful verification remains valid for one year and must then be renewed. Next associate the Identity Provider with the verified domain, and activate the required sign-in option only at the end. These tasks require Super Admin permissions.
Central can either permit federated credentials only or also allow a Sophos Central email address and password. With Microsoft Entra ID, Central continues to display both options even when Federated credentials only is selected. With other identity providers, this setting instead redirects straight to the IdP without a selection step. This difference must be included in the lockout test.
Select the mode under Global Settings > Access Control > Sign-in and Identity > Sophos sign-in. It generally applies to all Central products. Custom Sign-in Rules can be defined for individual administrators, for example to preserve controlled Sophos sign-in as a fallback during the pilot. A user can be assigned to only one verified domain and identity provider.
With Federated credentials only, users cannot reset their Sophos password themselves. If the tenant later returns to Sophos sign-in only, these accounts may not yet have a usable password and must complete Reset Password. Self Service Portal users with federated-only sign-in receive no separate password-creation invitation and sign in directly through the IdP.
Expand MFA Coverage extends MFA to managed users in additional Sophos portals such as Self Service Portal, Partner Portal, and Support Portal. Once enabled, it cannot be disabled again. Save it tenant-wide only after a pilot with the actual portal users affected.
Clarify the following points before activation:
- unambiguous mapping between the email address and Central login,
- MFA and access rules at the IdP,
- behaviour for guest and partner accounts,
- at least one tested emergency access method,
- prevention of lockout caused by an incorrect domain or IdP configuration.
Federated sign-in does not automatically synchronise Endpoint users or device groups. These are separate functions.
When the UPN and email address differ
Central initially identifies the account by its stored email address. If Microsoft Entra ID uses a different User Principal Name internally, the Entra app requires a customised OpenID Connect configuration with the optional email claim and the appropriate Microsoft Graph permissions. The user continues to enter the email address assigned in Central and then authenticates on the Microsoft page with the UPN.
The standard instructions are sufficient when the email address and UPN are identical. Test a differing configuration with a test account first because a missing or incorrect claim prevents the mapping even when authentication in Entra succeeds.
Manage and enable identity providers
Only a Super Admin can manage a federated identity provider. At least one suitable domain must be verified first. Under Global Settings > Access Control > Sign-in and Identity > Federated identity providers, Add identity provider creates Microsoft Entra ID, OpenID Connect, or Microsoft AD FS. Partially completed providers can be saved but enabled only after complete and valid configuration.
Select the finished provider and choose Turn on. It can then be used for federated sign-in. Providers can also be edited or deleted there. Before selecting Federated credentials only, assign every affected administrator and user to a verified domain and enabled provider; otherwise, lockout occurs. First test the provider with individual accounts while preserving fallback access.
Executable provider guides are available for Microsoft Entra ID, OpenID Connect and Okta, and Microsoft AD FS.
Roles remain essential
MFA protects the identity, but does not restrict its permissions. Use Super Admin only for tenant, role, API and other far-reaching changes. Help Desk, Read-only and Custom Roles reduce the potential impact of an error or compromised account.
Plan Sophos Central Endpoint roles and permissions explains product-specific role assignment.
Lost MFA device and lockout
Test the recovery process before it is needed:
- Use the second registered method.
- Ask a Super Admin in the tenant to select Reset MFA on the user object.
- Enter the security code delivered by Sophos by email at the next sign-in.
- Register two new MFA methods.
- If no other Super Admin is available, contact Sophos Support with verifiable account details.
After recovery, remove old methods, register new ones and inspect Audit Logs for unusual sign-ins or changes.
Deleting the Sophos entry directly in the authenticator app does not remove the method from Central. It remains registered there but no longer supplies valid codes. The method must therefore also be removed in Central or reset by a Super Admin. If all local methods are deleted, only a second registered method, a reset by another Super Admin or the verified Sophos Support process remains.
Reset MFA as a Super Admin
Only a Super Admin can reset another user’s MFA registrations. Go to My Environment > Users & Groups > Users, open the user name, select Reset MFA, and then select Reset again. A status message at the bottom confirms success.
Central automatically sends the user a verification email containing a security code. At the next sign-in, the user must enter that code and configure MFA again completely. Verify delivery, caller identity, and successful reenrollment; reset alone does not restore secure access. If the current account is locked and no other Super Admin is available, use verified recovery through Sophos Support.
Regular review
At least quarterly, review administrators, roles, API credentials, MFA methods and external identities. When a person leaves or changes role, do not merely disable Central access; also remove the account from administrator roles and relevant IdP groups.