Sophos Email: check licensing and data region before onboarding
The Sophos Fusion (formerly Sophos Central) data region must be agreed before the tenant is submitted. Sophos states that the submitted selection can no longer be changed. Sophos Email also appears in a product availability matrix whose contents can change. Don’t take a region claim from an old quote, a screenshot or this article. Check the intended region in the current matrix immediately before submission.
Quick path: confirm the license requirement, record the owner and intended data region, check Sophos Email in the current regional availability matrix, and record dated approval. Only then should the authorized person submit the tenant.
Product boundary: Sophos Email in Sophos Fusion
This workflow covers Sophos Email in Sophos Fusion. Mail Protection on a Sophos Firewall is a different product; it isn’t another name for Sophos Email. Availability of firewall features therefore proves neither a Sophos Email license nor Sophos Email availability in a Sophos Fusion data region.
The data region doesn’t choose the mail architecture either. For the choice between Mailflow and Gateway and the remaining prerequisites, see Sophos Email: choose an architecture and plan onboarding.
Assign ownership before submission
The customer-side tenant owner is accountable for the region decision. A partner or Sophos Fusion administrator can prepare the information and check the matrix, but shouldn’t silently make the decision for the customer. A clear split works well:
- Tenant owner: confirms data residency, contractual and internal compliance requirements.
- Licensing or procurement contact: confirms that the planned offer includes Sophos Email. Edition, term and quantity are recorded separately from the region choice.
- Partner or Sophos Fusion administrator: opens the live matrix, checks the EMAIL entry and records the result.
- Authorized submitter: compares the region and approval once more immediately before submission.
This makes it clear who decided, who checked and who submitted. Verbal approval alone isn’t enough for a choice that can’t be changed after submission.
Prepare the decision record
Before checking, create a short record in the ticket, change or onboarding log:
- customer or planned tenant and responsible tenant owner;
- exact selected Sophos Fusion data region;
- business or regulatory reason for that choice;
- required product Sophos Email and internally confirmed license requirement;
- reviewer, review date and link to the live matrix used;
- approver and approval time;
- planned submission time and an explicit stop condition for discrepancies.
Don’t copy a colored cell into a template as permanently valid information. The record should show when and by whom the live information was checked, not turn a dynamic matrix into a static claim.
Checklist immediately before submission
- Compare the region: The region in the submission form matches the approved region in the decision record character for character.
- Check the product: In the live matrix, inspect the intersection of the EMAIL row and the intended region column. Don’t infer anything from adjacent products or colors outside that cell.
- Confirm license scope: The quote, order or partner confirmation names Sophos Email. The region check doesn’t replace this commercial check.
- Perform a four-eyes check: A second authorized person compares the tenant, region, product and current matrix state.
- Update the record: Record date, time, reviewer, approval and result in the ticket or change. Store customer data in screenshots only under your internal privacy rules.
- Submit only now: If approval is missing, the matrix is unclear or anything differs, stop. Don’t submit based on an assumption.
Validate safely and stop on conflicts
Validation passes when the same region label appears in the approved record and the not-yet-submitted form, the live intersection for EMAIL has been checked unambiguously, and both the licensing contact and tenant owner have approved. This validates the pre-submission decision; it doesn’t test Mailflow or Gateway delivery.
If the matrix is unavailable, loads incompletely or the colored cell isn’t unambiguous, wait and retry with a supported browser. Don’t substitute search snippets or old screenshots. If it remains unclear, obtain written confirmation from Sophos or the managing partner for the specific intended region.
If the live matrix conflicts with a quote, partner statement or internal requirement, do not submit. Record the region, time, visible conflict and affected documents, then escalate to Sophos or the partner. If a tenant has already been submitted with the wrong region, don’t invent an unsupported region-change or migration process. Send the tenant identifier and decision record to Sophos or the partner and request written next steps.