Skip to content
Avanet

Plan and enable Sophos Central Enterprise Master Licensing

With Enterprise Master Licensing, licenses are no longer managed independently in each sub-estate but as a shared pool at Enterprise level. Enterprise Super Admins allocate limits to sub-estates from that pool.

The conversion cannot be reversed. Afterward, regular administrators in sub-estates can no longer buy licenses or apply activation keys.

If you are still defining the tenant structure and roles, start with Sophos Fusion Enterprise (formerly Sophos Central Enterprise) and sub-estates. Enterprise Management must already be enabled before the licensing conversion.

Terms

  • Enterprise usage: licenses currently consumed across the Enterprise,
  • Enterprise limit: total purchased quantity,
  • Enterprise remaining: quantity not yet allocated or available,
  • Sub-estate usage: actual usage in a sub-estate,
  • Sub-estate limit: upper limit allocated to that sub-estate.

Allocation is not the same as actual usage. Monitor both values.

Under Profile > Licensing, License Management Type shows whether the enterprise pool or individual Sub-Estate Licenses are in use. You can only activate and manage licenses on this Enterprise page when Enterprise Master Licenses is enabled.

Transfer or consolidation

Transfer is appropriate only when one sub-estate already owns every full license and Enterprise Management is enabled in that sub-estate. Those licenses move into the Enterprise pool.

Consolidation is required when several sub-estates have independent licenses. Enterprise Management must be enabled in one of them. After the request, the customer and Sophos Partner receive an email and create a consolidation plan together. The process can take several days and requires a new activation key, which is usually applied automatically.

In either case, afterward there is:

  • no return to individual licensing,
  • central management in Sophos Fusion Enterprise,
  • a shared pool for eligible sub-estates,
  • no local activation by sub-estate administrators.

Sophos M365 Backup and Recovery currently does not support Enterprise Master Licensing. It requires separate licenses for each Microsoft 365 tenant.

Before conversion

For every sub-estate, record the product, edition, term, purchased quantity, usage, and expected growth. Also identify trial licenses and add-ons.

An add-on can technically be allocated even when the required base product is missing. It then provides no complete benefit. Always review allocations as product combinations.

Perform the conversion

Transfer a centrally licensed sub-estate

  1. Sign in to Sophos Fusion and open Profile > Licensing.
  2. Select Convert to Enterprise Master Licenses.
  3. Review the irreversible effects and affected licenses.
  4. Confirm with Convert to Enterprise Master Licenses.
  5. Verify that all licenses appear on the Enterprise Licensing page and that all sub-estates use the master pool.

Consolidate several license holdings

  1. Under Profile > Licensing, request the conversion with Convert to Enterprise Master Licenses and read the confirmation.
  2. On the Licensing page, verify that the requested conversion is shown.
  3. Wait for the request email and complete the consolidation plan with the Sophos Partner.
  4. If the new key is not processed automatically, enter it in Apply consolidation enterprise licenses activation key and select Apply.
  5. Verify that all licenses are in the Enterprise pool and all sub-estates obtain their licenses from it.

Trial licenses in sub-estates can be converted to full licenses in the master pool during consolidation. Account for this in the plan beforehand.

Apply a later or upgraded license key under Profile > Licensing as well. Depending on the view, you see Apply Activation Key or the Apply license key link. Use the key in the License Schedule sent by Sophos; it is not derived from an existing License ID.

Allocate licenses

Under My Sub-Estates > Sub-Estates, select a sub-estate and open Allocate Licenses. There are three deliberate choices for each license type:

  • a specific Sub-estate limit for a fixed cap,
  • a blank limit for unlimited use up to the quantity available in the Enterprise pool,
  • Don’t use in this sub-estate when the sub-estate must not receive that license type.

Don't use removes the product from that sub-estate. A change can therefore affect technical functions and protection and must be treated as a change.

Save the selection with Allocate Licenses. A numerical allocation must not exceed the Enterprise Limit. Compare Enterprise Allocation with Enterprise Limit before saving. For identical product licenses, Sophos recommends using only one matching license position per sub-estate and setting the other identical positions to Don't use.

Standalone products such as XDR, MDR, and CIXA provide their standalone functionality without an additional license. Add-ons, by contrast, provide their extra benefits only with the required base product. Sophos Fusion does not prevent an add-on from being applied first, so application order does not prove that the product combination is complete.

Over-usage and renewal

When a sub-estate uses more than its limit, the excess appears at both sub-estate and Enterprise level. After a renewal with fewer licenses, previous allocations can also exceed the new Enterprise Limit and cause Invalid allocation limit set.

Under My Sub-Estates > Sub-Estates > Allocate Licenses, reduce limits in a controlled way or deliberately remove products with Don’t use in this sub-estate. Select Save after changing each sub-estate. Continue across additional sub-estates until Enterprise Allocation no longer exceeds Enterprise Limit. Arbitrarily reducing the first visible sub-estate can turn off production functions.

Acceptance and operations

After transfer, consolidation, or an allocation change, verify:

  • Enterprise Limit, Usage, and Remaining for each license type,
  • sub-estate limit and actual usage,
  • product availability in every sub-estate,
  • add-on and base product,
  • expected protection and product functions after changed limits,
  • Audit Log and license warnings,
  • renewal date and responsible partner.

For the overall view, open My Sub-Estates > Licenses. It lists sub-estate, license, start and end date, and usage. You can click the counts for licenses that are near expiration, expired, over their usage limit, or trials to filter the list. CSV export is available only in the All licenses view.

Review utilization at least monthly. Start capacity planning early enough before renewal that reduced or new limits do not become visible only on the expiration date. Newly activated or renewed licenses become available in the pool to master-licensed sub-estates; sign in after activation and verify the intended allocation rather than assuming it is automatically suitable.

Frequently asked questions

Can Master Licensing be turned off again later?

No. After transfer or consolidation, license management remains at Enterprise level.

What does Don't use in this sub-estate do?

The sub-estate cannot use that license type from the master pool. The associated product can therefore become unavailable.

What does a blank Sub-estate limit mean?

The sub-estate can use that license type up to the total quantity available. Enter a number instead when you need a fixed capacity limit.

Does M365 Backup and Recovery support the master pool?

No. According to the current Sophos position, each Microsoft 365 tenant requires its own license.