Skip to content
Avanet

Map Sophos Fusion Endpoint users and groups correctly

A Sophos Fusion (formerly Sophos Central) user represents a person, a login is a sign-in name detected by the endpoint, and a computer is the managed device. For reliable policy assignment, first map the login to the correct person, then verify user groups and policy order.

This article covers identities that bring together a person’s Endpoint policies and device events. Account-wide user administration is covered in Manage Sophos Fusion users safely, and administrative permissions in Sophos Fusion roles and permissions. Neither is the same as Endpoint mapping. Computer and computer-group management is also covered separately.

Understand the mapping model

ObjectWhat it representsWhere to check it
Userperson in Sophos FusionMy Environment > Users & Groups > Users
Loginthat person’s local or domain sign-in nameopen the user, Summary > Logins
Computermanaged endpointMy Environment > Devices > Computers

One user can have several devices. A shared computer can in turn be associated with several users. User and computer groups are therefore not interchangeable containers: a user group follows the person, while a computer group follows the device.

Add users from the right source

Sophos Fusion can receive users in four ways:

  • automatically when the endpoint agent reports the signed-in user of a protected device;
  • manually through My Environment > Users & Groups > Add User;
  • as a bulk import through Import users from CSV;
  • through a directory service such as Active Directory or Microsoft Entra ID.

For normal operations, define which source is authoritative for each user population. If a person is already synchronized from a directory service, do not add them again manually or by CSV. The Central user administration guide covers creation, import, export, and deletion. For source configuration, use the separate guides Synchronize Microsoft Entra ID with Sophos Fusion and Synchronize Active Directory with Sophos Fusion.

Map detected logins to a person

Under My Environment > Users & Groups > Users, open the person. On the Summary tab, the Logins section shows the assigned sign-in names. Select Edit to reassign logins.

Before changing anything, compare the username, domain or computer name, and the devices shown under Devices. An entry such as CORP\muster is not automatically the same as PC01\muster: the latter can be a local account. After saving, ask the person to sign in again on the affected computer. Then check Summary > Logins, Devices, and the Last Active time.

Use user groups for Endpoint policies

Under My Environment > Users & Groups > Groups, Add Group creates a local group. Enter a unique Group Name, move people from Available Users into the selection, and save. In the group details, Edit changes the members. Deleting a group does not delete its users.

A user group is appropriate when a setting should follow a person across their devices, such as Web Control or Data Loss Prevention for a department. Use computer groups for kiosk, lab, or production devices because the requirement must apply regardless of who signs in.

The group’s Policies tab shows enabled and applied policies. A policy opened there can also be assigned to other groups; editing it affects every target of that policy.

Determine and verify the effective policy

User and computer policies for the same feature do not receive automatic priority based on target type. If both match a computer, the policy higher in the policy list wins. The Base policy remains available as a fallback. Settings for one feature are not combined from multiple policies.

Plan Sophos Fusion Endpoint policies safely explains planning and priority. For a specific user, open Users & Groups > Users, select the person, and check the Policies tab. Check the Policies tab on the computer as well. If the result is unexpected, use this order:

  1. Which operating-system login is actually signed in?
  2. Is that login assigned to the correct person under Summary > Logins?
  3. Are the person and computer in the expected groups?
  4. Is the intended policy enabled and above other matching policies for the same feature?
  5. Has the computer reported to Central since the change?

Only investigate the protection feature itself after these five checks pass. This separates an assignment error from a problem inside the policy.

Clean up the mapping when someone leaves

Before deleting a person, check Logins, Devices, Policies, groups, and the identity source. Then select the person on the Users tab and click Delete. Deleting a user removes neither the associated devices nor the Sophos software installed on them.

You can reassign logins that are still required after deleting the user. A user can reappear if they sign in to an associated device that is still managed, or if they remain in a synchronized directory. Make lasting changes to directory users at the source. A Phish Threat assignment within the last 30 days can also cause a deleted user to appear again in Users & Groups. See the Central user administration guide for the complete deletion and export workflow.

Common symptoms

The user policy does not apply

First check the login that is actually signed in and its assignment. Then compare user and computer groups and the order of all matching policies for the same feature. The computer’s Policies tab is the decisive check for the effective assignment.

One person appears more than once

Compare the email address, login prefix, and identity source. Do not delete users merely because their display names look alike. Assign a clearly identified login to the correct person through Summary > Logins > Edit, and clean up a synchronized duplicate at its directory source.

A deleted user reappears

Check whether the person signed in again on a managed device, is still supplied by the directory service, or was recently used in Phish Threat. Deleting the user again in Central does not remove an active source.

Frequently asked questions

Does a user policy take priority over a computer policy?

No. If both policies cover and match the same feature, their position in the policy list decides.

Does deleting a user group also delete its members?

No. Deleting the group removes the group, but not the users it contains.