Secure Sophos Central sign-in with MFA and passkeys
Sophos Central controls policies, exclusions, Live Response and device isolation. A compromised administrator account can therefore cause more damage than a single infected endpoint. MFA is the minimum requirement, but it does not replace appropriate roles or a recovery process.
Set up MFA immediately and redundantly
Every administrator must register at least two MFA methods and is prompted for MFA at every sign-in. Sophos supports passkeys and authenticator apps with time-based one-time passwords, or TOTP.
Register two independent methods for privileged accounts, such as a passkey on a hardware security key and an authenticator app on a separate device. Two passkeys on the same laptop do not provide genuine redundancy. Sophos also identifies two passkeys on separate devices or two separate authenticator registrations as possible combinations.
Replacement hardware security keys and documented recovery information belong in a protected corporate vault. They must not be stored in one employee’s personal password manager or in an open ticket.
Understand passkeys correctly
Passkeys are phishing-resistant when the key is bound to the genuine Central domain and protected by a device PIN or biometrics. A synchronised passkey is convenient, but inherits the security and recovery characteristics of the Apple, Google or Microsoft account used.
For Super Admins, a managed hardware security key is a particularly robust method. Before making this a tenant-wide requirement, verify that emergency access, replacement keys and offboarding work.
Microsoft Authenticator is not supported for a Sophos passkey outside a federated Entra ID sign-in. The app can still be used as a TOTP authenticator. Depending on the platform, cross-device passkeys require Bluetooth, physical proximity and a QR-code workflow.
An account can register no more than ten passkeys. SMS and email plus PIN are deprecated methods; new users and users whose MFA has been reset must use TOTP or passkeys. After five consecutive incorrect sign-in attempts, Central initially locks the account for one minute. Further failed attempts gradually extend the lockout to a maximum of five hours. If no second Super Admin can help, Sophos Support must unlock the account.
Federated sign-in through an Identity Provider
With a supported Identity Provider, Sophos Central can delegate sign-in to the central corporate identity. This simplifies Conditional Access, lifecycle management and central account suspension. Central uses a service-provider-initiated flow, or SP-initiated SSO: sign-in starts at Sophos Central and is redirected from there to the IdP.
The setup follows a fixed sequence. First verify the organisation’s domain using a DNS TXT record. DNS propagation can take up to 24 hours. A successful verification remains valid for one year and must then be renewed. Next associate the Identity Provider with the verified domain, and activate the required sign-in option only at the end. These tasks require Super Admin permissions.
Central can either permit federated credentials only or also allow a Sophos Central email address and password. With Microsoft Entra ID, Central continues to display both options even when Federated credentials only is selected. With other identity providers, this setting instead redirects straight to the IdP without a selection step. This difference must be included in the lockout test.
Clarify the following points before activation:
- unambiguous mapping between the email address and Central login,
- MFA and access rules at the IdP,
- behaviour for guest and partner accounts,
- at least one tested emergency access method,
- prevention of lockout caused by an incorrect domain or IdP configuration.
Federated sign-in does not automatically synchronise Endpoint users or device groups. These are separate functions.
When the UPN and email address differ
Central initially identifies the account by its stored email address. If Microsoft Entra ID uses a different User Principal Name internally, the Entra app requires a customised OpenID Connect configuration with the optional email claim and the appropriate Microsoft Graph permissions. The user continues to enter the email address assigned in Central and then authenticates on the Microsoft page with the UPN.
The standard instructions are sufficient when the email address and UPN are identical. Test a differing configuration with a test account first because a missing or incorrect claim prevents the mapping even when authentication in Entra succeeds.
Roles remain essential
MFA protects the identity, but does not restrict its permissions. Use Super Admin only for tenant, role, API and other far-reaching changes. Help Desk, Read-only and Custom Roles reduce the potential impact of an error or compromised account.
Plan Sophos Central Endpoint roles and permissions explains product-specific role assignment.
Lost MFA device and lockout
Test the recovery process before it is needed:
- Use the second registered method.
- Ask a Super Admin in the tenant to select Reset MFA on the user object.
- Enter the security code delivered by Sophos by email at the next sign-in.
- Register two new MFA methods.
- If no other Super Admin is available, contact Sophos Support with verifiable account details.
After recovery, remove old methods, register new ones and inspect Audit Logs for unusual sign-ins or changes.
Deleting the Sophos entry directly in the authenticator app does not remove the method from Central. It remains registered there but no longer supplies valid codes. The method must therefore also be removed in Central or reset by a Super Admin. If all local methods are deleted, only a second registered method, a reset by another Super Admin or the verified Sophos Support process remains.
Regular review
At least quarterly, review administrators, roles, API credentials, MFA methods and external identities. When a person leaves or changes role, do not merely disable Central access; also remove the account from administrator roles and relevant IdP groups.