Skip to content
Avanet

Plan Sophos Central Endpoint roles and permissions

Sophos Central separates administrators through predefined roles and Custom Roles. For Endpoint operations, however, the role name alone is insufficient: policy management, Live Response, Data Lake, isolation, Tamper Protection and XDR actions have additional requirements. A role that is too broad increases risk, while one that is too narrow blocks support precisely when an incident is in progress.

Understand the standard roles

RoleTypical useImportant limitation
Super Admintenant, role, API and credential managementfull access, so do not use it as a daily support account
Admincomprehensive product administrationcannot manage roles, API tokens or API credentials
Help Desksupport, computer scans, agent updates and alertssettings are generally read-only; particularly sensitive response actions are unavailable
Read-onlymonitoring, audit and inspectionno changes, scans or cleanup
UserSelf Service Portalno administration rights

At least one Super Admin must remain in the tenant. For resilient operations, maintain at least two responsible Super Admins, but use their accounts only for tasks that genuinely require this role. Secure Sophos Central sign-in with MFA and an IdP explains MFA and recovery.

Use an Endpoint Custom Role instead of blanket full access

Only a Super Admin can create a Custom Role under Global Settings > Access Control > Admins and Roles > Roles > Add role. It is based on a standard role and receives an Access Type such as Full, Help Desk, Read-only or None for each product.

A practical Endpoint Help Desk role might be structured as follows:

  • base role Help Desk
  • product Endpoint Protection
  • Access Type appropriate to the actual task
  • all unnecessary products set to None
  • Logs and Reports only where operationally required
  • decide separately on policy management and policy assignment
  • do not enable Live Response, Data Collection and isolation automatically

After every role change, use a test account to verify which menus, devices and actions are actually available. A role name is not evidence of permission.

Shared Settings require several product permissions

Some settings are shared by Endpoint and Server. If a Custom Role does not have access to both products, some of these Shared Settings remain read-only. Individual functions also require Encryption access.

Shared settings include:

  • Tamper Protection
  • allowed applications
  • Website Management
  • proxy configuration
  • Blocked Items
  • bandwidth usage
  • DLP rules and Content Control Lists
  • rejecting network connections to unsafe devices
  • XDR Threat Analysis Center

This is a common reason why an apparent Endpoint Full role cannot change a global exclusion or shared setting. The answer is not automatically Super Admin, but a deliberately extended Custom Role.

Grant policy permissions separately

Sophos distinguishes between managing and assigning policies:

  • Enable policy management permits creating, editing and deleting policies.
  • Enable policy assignment permits enabling or disabling existing policies and assigning users, groups, devices or device groups.

An operations team can therefore assign policies without being permitted to change the protection baseline itself. Conversely, a security team can maintain policy content while production assignments follow a change process. Structure Sophos Central Endpoint policies correctly describes structure and priority.

Live Response and data collection

Permission to start a Live Response session is set explicitly. For computers, Endpoint Protection with Full or Help Desk must be available. The permission for servers is separate and requires Server Protection.

Managing Live Response and Data Lake uploads is also a separate permission. For computers, Sophos requires Endpoint Protection with Full. Starting a session and enabling the function globally are therefore two different tasks.

Live Response provides a powerful remote shell. Role approval, MFA, audit and the session workflow are covered in Isolate a Sophos Endpoint and investigate with Live Response.

Tamper Protection and isolation

Turning off Tamper Protection and removing a computer from Admin Isolation are not casually enabled through general Help Desk access. For these options, Sophos requires a Custom Role with the Help Desk base role, Endpoint Protection and the Full Access Type.

Grant these permissions only to people who perform a documented maintenance or incident process. Every use is recorded in Central Logs. Permanent access for the entire first-level support team is rarely appropriate.

Additional XDR permissions

With an XDR licence, the standard roles receive additional capabilities:

  • Super Admin and Admin can request Intelligence Reports, manage Clean and block entries, view Blocked Items, request On-Demand Threat Graphs, isolate or release devices, and request Forensic Snapshots.
  • Help Desk can request Intelligence Reports and Threat Graphs, view Blocked Items and request Forensic Snapshots, but cannot perform every response action.
  • Read-only can view Intelligence Reports, Blocked Items and existing On-Demand Threat Graphs.

The actual interface also depends on the licence, product assignment and data source. Test XDR functions with a representative device. Manage Sophos XDR Cases and Detection Suppression Rules explains Cases, Suppression Rules and exposure data.

Role changes and offboarding

A person can hold only one Central administration role. A new assignment replaces the previous one. The role of a currently signed-in person cannot be changed; they must sign out first. Another Super Admin changes a person’s own role.

Before removing an administrator, hand over open Cases, scheduled Reports, API credentials and operational responsibilities. A disabled IdP account alone does not prove that all Central roles and local recovery paths have been removed.

Service principals are not ordinary administrators. Securely automate Sophos Central Endpoint API explains role selection, secret rotation, tenant ID and data region.

If a role cannot be assigned, first check for a missing email address, duplicate user objects and an email address already used in another Central tenant. Duplicate synchronised objects are a common cause for AD-synchronised users.

Regular review

At least quarterly, review:

  1. active administrators and their last use,
  2. the number of Super Admins and MFA redundancy,
  3. Custom Roles and assigned products,
  4. policy, Live Response, Data Lake and isolation permissions,
  5. roles belonging to people who have left or changed position,
  6. API Credentials and Service Principals outside user roles.

A role review is complete only when the permission, test account and documented business requirement agree.

Frequently asked questions

Why can an Endpoint Full role not change a global exclusion?

Several global settings are shared by Endpoint and Server. If the Custom Role lacks the required access to both products, these Shared Settings may be read-only.

Can Help Desk remove a computer from isolation?

Not automatically. A Custom Role needs the Sophos-required combination of the Help Desk base role, Endpoint Protection, Full Access Type and the explicitly enabled additional permission.

Does policy management enable Live Response?

No. Live Response, policy management, policy assignment and Data Collection management are separate permissions and are granted individually.