Skip to content
Avanet

Prepare Sophos Fusion Directory Sync safely for Sophos Email

Directory Sync is a shared Sophos Fusion (formerly Sophos Central) platform function. It provides users, groups, email addresses, aliases and, depending on the source, other objects that Sophos Email can use. The sync itself is not a Sophos Email feature: it configures neither domains, mail flow, MX routing nor Email policies.

Quick path: choose one authoritative source for users and user groups per domain, reconcile unique email addresses and existing Central objects, prepare AD or Entra permissions, preview a limited selection, and synchronise only after reviewing the proposed additions, changes and deletions. Turn off, Purge data and deleting a source are three different operations; don’t use them as interchangeable reset steps.

Define the source model before the first run

Central manages directory sources under Global Settings > Platform > Directory service. Before configuration, record the authoritative system for every domain and object type:

  • users and user groups from on-premises Active Directory (AD) or Microsoft Entra ID;
  • devices and device groups only from AD;
  • Public Folders only from AD, together with users and user groups from the same domain;
  • Shared Mailboxes according to source type; a mailbox in a Microsoft 365 group requires Entra ID or Google Directory.

At most one source of each directory type is allowed per domain: one AD source and one Entra ID source. Even when both are configured, users and user groups must come from one authoritative source. AD may run in parallel only for the separate device and device-group scope. Users and email addresses must be unique within the Central tenant and must not be synchronised to multiple Sophos Fusion Admin accounts. Central supports up to 25 directory sources; trials also limit the number of directory objects.

This source choice also determines the mailbox inventory that will later be used by the Sophos Email Monitoring System (EMS). Directory Sync only prepares this inventory. Set up EMS and configure provider-specific journaling according to the EMS guide or the guide for the email provider in use.

Directory Sync doesn’t merge records merely because their display names match. It can take ownership of a matching, manually created Central object and later remove its directory data during a purge. Before the pilot, the comparison list must therefore include at least the primary email address, aliases, UPN or domain login, source object, existing Central identity, groups and linked mailbox.

If users need the Sophos Fusion Self Service Portal (SSP) for self-service email administration, configure User access before Directory Sync. This allows new and existing users to receive the intended notification and portal access.

Prepare AD Sync

AD Sync requires a Central administrator, the current Active Directory Synchronization Setup software, .NET Framework 4.6.2, API credentials with the Service Principal Directory Sync role, and an account with read access to the entire selected forest. Give the AD account only the required rights and use LDAP over SSL where possible. The firewall or proxy must reach the Central destinations required by Sophos.

Every user to be protected needs a unique email address in AD. By default, the utility doesn’t synchronise disabled users and mailboxes. For shared mailboxes, keep Exclude disabled user accounts turned on; turning it off can create duplicate shared mailboxes. Users and user groups are synchronised together. Shared mailboxes and public folders require Sync users and user groups.

Limit the selection with search bases, such as a pilot OU, and LDAP filters. A filter change can move previously synchronised objects out of scope and delete them from Central. The full configuration, examples and AD-specific limits are in Synchronise Active Directory with Sophos Fusion.

Prepare Microsoft Entra ID

Entra ID requires a Sophos Fusion admin role, Microsoft Entra ID, a dedicated Azure Application and the Microsoft Graph Application permission Directory.Read.All with admin consent. Central needs the tenant domain, Application (client) ID, client-secret Value and expiry date. Object ID and Secret ID are not the required values. Office 365 GCC High isn’t supported for this sync.

Before connecting, existing Central users and groups need matching Entra objects, and every user to be protected needs an email address. Different UPNs, email addresses or endpoint logins can create separate users. Entra ID synchronises users and groups, but not devices, device groups, public folders or delegation details for shared mailboxes.

After entering the application details, select Test connection, then Save, then Test connection again. Filter changes also require Test connection first and only then Save or Save & Sync. Synchronise Microsoft Entra ID with Sophos Fusion describes the full application and filter configuration.

Preview, approve and run the production sync

Don’t review a preview only for its number of new objects. Compare the users, groups, email addresses, aliases and mailboxes to be added, changed and removed with the expected inventory.

Active Directory

  1. Check search bases, OUs, user and group filters, and Exclude disabled user accounts.
  2. Start Preview and Sync and pay particular attention to Users to Add, Users to Modify and planned deletions.
  3. Select Approve Changes and Continue only when every change is understood.
  4. After import, check the source, last run, object counts and protected Email objects.

The AD preview can show members from other domains even though production sync adds to a group only users from that group’s domain. Cross-domain groups therefore need a practical membership test.

Microsoft Entra ID

An Entra preview is available only after setup is complete. Pause a running source with Turn off; after its status changes, Preview and the Preview tab appear. The result remains valid for seven days or until the next sync. Results with more than 20,000 records must be exported as JSON.

After review, enable the source with Turn on and start Synchronize. A successful connection test proves application access only, not the right selection. Success is confirmed only when source and timestamp are current and users, groups, aliases, shared mailboxes and intended protected recipients match the expected inventory.

Move from AD to Entra ID without creating duplicates

Before migration, prepare valid AD and Entra sources for the same domain and reconcile users between them. Equal display names aren’t enough. Compare email address, UPN or login, groups, aliases and mailbox association in particular.

For Entra ID as the only source, run and approve one final AD sync. Then pause AD with Turn off, add Entra ID, synchronise and perform a full review. Uninstall the AD software or revoke its technical identity only after approval.

If AD must continue to supply devices, limit its filters to devices and device groups before switching. Entra ID takes over users and user groups; AD is then turned back on only for the separate device scope. Two green source statuses don’t replace checking that their object scopes don’t overlap.

Explicitly accept the migration effects:

  • A matching Entra user updates the existing object; its associated mailbox is retained.
  • An unmatched AD user can be deleted from Central together with its mailbox.
  • An unmatched AD group remains but is no longer updated.
  • Existing AD shared mailboxes and public folders remain at their last AD state but are no longer updated; associated users are no longer shown for shared mailboxes.
  • New Entra shared mailboxes can be created as well. An uncontrolled on-premises AD sync run after migration can remove shared mailboxes because the object types differ.

Don’t repeatedly switch sources when deletions are unexpected. Correct matching, filters and the expected inventory first.

Check protected objects and troubleshoot methodically

After every first run, filter change or source migration, check at least:

  • expected users and groups, memberships and unique email addresses;
  • aliases, personal and Shared Mailboxes, and Public Folders; when preparing EMS, pay particular attention to whether Shared Mailboxes in Microsoft 365 groups were imported through Entra ID or Google Directory rather than AD;
  • source, status, last-sync time, warnings and object counts;
  • protected recipients and groups intended for Sophos Email;
  • unexpected new, duplicate, stale or removed objects.

If an object is missing, start at the source: email attribute, status, OU or search base, filter and group membership. Then inspect the source status and events under Reports > Logs > General Logs > Events. For AD, also check utility version, credentials, proxy, LDAP connection and AD Sync logs. Early utility versions don’t support current authentication; if automatic upgrade fails, use the current installer and enter credentials with the Service Principal Directory Sync role.

For Verification failed due to invalid client ID, confirm that the value is the Application (client) ID, not an Object ID. If it is correct, set Enabled for users to sign in? to Yes in the Entra admin centre under Enterprise apps > All applications > [App] > Properties. The connection must be verified before saving the configuration after a filter change is expected: select Test connection, then Save or Save & Sync.

For support escalation, prepare the issue description, tenant and licence details, timestamp, sync version, all relevant logs, screenshots and the public IP of the sync system at collection time. Enable Remote Access only for the specific case after internal approval.

Turn off, purge or delete a source

Turn off pauses synchronisation but doesn’t automatically delete synchronised objects. Use this state for a controlled change, preview or migration. Record active instances, the schedule and the last successful sync before pausing.

For an AD purge, open the source under Global Settings > Platform > Directory service, pause it with Turn off, and select Purge data. Users and user groups also removes shared mailboxes and public folders. Managed devices and their associated users, and administrators, are exceptions and aren’t deleted. There is no undo after explicit confirmation.

Deleting or disconnecting a Directory Source is an additional lifecycle step, not a synonym for Turn off or Purge data. Before final deletion, purge synchronised data using the source-specific process, check remaining protected objects, and only then remove the source and any unneeded application, secret or API credentials. Abort without an approved object list, owner, acceptance and documented target model.

If Directory Sync isn’t the intended ownership model, learn next how to manually add, import and manage Sophos Email mailboxes.