Skip to content
Avanet

Set up Sophos Email quarantine self-service

Quarantine self-service lets users review eligible messages through a quarantine summary or the Sophos Fusion Self Service Portal (SSP). The configuration has three independent layers: an Email Security policy controls quarantine and the summary schedule, User Settings permit specific actions, and the central sign-in configuration grants portal access. The workflow works only when all required layers agree.

Operational boundary: This runbook covers end-user quarantine. Administrator actions in Quarantined Messages, native M365 quarantine, and user allow/block rules are separate processes. Data Control events don’t appear in End User Quarantine. Don’t weaken settings in those areas as a quick workaround.

Define prerequisites and the target state

Before the change, record:

  • protected users, groups, and distribution lists, and their effective Email Security policy;
  • the summary time zone, delivery days, and time slots;
  • whether portal access will be granted automatically to all eligible users or selectively by invitation email;
  • whether users may only read or may also use Release, Release and Allow, Delete, and Delete and Block;
  • whether Emergency Inbox is required and who authorizes emergency operation;
  • exactly one accountable owner per distribution list;
  • a personal test mailbox and, if distribution lists are used, a test list with an owner.

SSP requires an eligible Sophos license. Users must have a valid email address in Sophos Fusion (formerly Sophos Central) that hasn’t already been used for a Sophos Fusion Admin trial account. Administrators don’t need a separate SSP invitation; they sign in with their Sophos Fusion Admin credentials.

Configure End User Quarantine and summaries

Make the changes in the policy that is actually effective:

  1. Under Email Security, open the policy and go to Settings > Inbound > Anti-spam > Quarantine Summary Settings.
  2. Set Quarantine for the required message categories and enable Include in End User Quarantine only where users may manage those messages themselves.
  3. Turn on Send a quarantine summary email.
  4. Select the correct time zone, delivery days, and one or more time slots. All days are selected by default; select an item again to clear it. For a 24/7 schedule, select every day and every hour.
  5. Select Save, then record the policy name, priority, and settings in the change.

Only one Quarantine Summary Settings configuration applies to each user. With multiple assigned policies, the highest-priority policy normally wins. If that policy contains External addresses or domains, however, Sophos uses the next policy in priority order without External entries; if none exists, Base Policy applies. Check the effective policy rather than only the policy most recently edited.

A summary contains only new messages quarantined since the previous summary. After activation, it isn’t sent until at least one new eligible message exists. Summary emails themselves don’t appear in Message History. Enabling Quarantine Summary format under Global Settings > Products and Services > Email > User Settings applies the format optimized for small screens.

Grant SSP access

For automatic provisioning:

  1. Open Global Settings > Access Control > Sign-in and Identity > Sophos Sign-in.
  2. Under User Access, enable Sophos Fusion Self Service Portal access.
  3. Verify that new users and existing users without access receive the invitation email.

Disabling automatic access later doesn’t revoke access from already authorized users; it only stops users added afterward from receiving access automatically. Therefore, turning it off isn’t an access-revocation method.

For a targeted invitation, open My Environment > Users & Groups, select the users, select Email Setup Link, choose Sophos Fusion Self Service Welcome/Setup Email, and select Save. The message comes from do-not-reply@fusion.sophos.com, has the exact English subject pattern Welcome to Sophos Fusion <First Last name>, and contains a setup link that doesn’t expire. Sophos Fusion can accept a selection containing no valid address but sends no message to that user.

Limit user actions and Emergency Inbox

Under Global Settings > Products and Services > Email > User Settings, enable only approved functions:

  • With Release/Delete off, users can read messages but can’t act on them. When enabled, Release, Release and Allow, Delete, and Delete and Block are available in the summary or SSP where the message permits them.
  • Allow/Block List is an additional security decision and isn’t enabled automatically with Release/Delete. Review existing smart-banner and allow/block workflows before changing it.
  • Emergency Inbox shows users only their inbox through SSP during a delivery outage. Messages are stored for 14 days while Sophos Email retries delivery. When the mail server returns, the Emergency Inbox itself isn’t expected to deliver the messages.
  • Allow release of M365 quarantine emails belongs to the separate Microsoft 365 quarantine integration. Even when enabled, Microsoft 365 messages categorized as Malware, High Confidence Phish, or DLP aren’t available in SSP for security reasons.

Users can release only categories supported by End User Quarantine, including Authentication failure, Unscanned, Intelix Threat, Malicious URL, Confirmed Spam, and Bulk. An available action therefore depends on category, policy, and global user permissions. Don’t bypass a missing button with broader allow lists.

Verify owners and recipient mapping

Quarantine summaries are sent only to user mailboxes, not directly to aliases, distribution lists, or public folders:

  • Users receive their own summary.
  • For a distribution list, its assigned owner receives the summary and manages list quarantine in SSP separately from personal quarantine. Under My Products > Email Security > Mailboxes, select the list, select Add, choose exactly one user in Add Distribution List Owner, and select Save. A user can own multiple lists. With Active Directory or Microsoft Entra ID synchronization, also maintain the owner on the matching source object.
  • With Active Directory synchronization, shared-mailbox summaries go to associated delegates. Microsoft Entra ID doesn’t recognize those delegate associations here, so the summary goes only to the shared-mailbox address.
  • Public-folder owners receive the summary; the folder itself doesn’t.
  • For an alias, the user associated with the alias receives the summary.

Validate with representative users

A test is meaningful only after a new, harmless message eligible for End User Quarantine enters quarantine after activation. Never release production malware for testing.

  1. Record the test user’s effective policy, category, Include in End User Quarantine, schedule, and time zone.
  2. Wait for a new eligible message or use an approved harmless test case.
  3. Verify that the summary arrives in the expected slot and shows only the expected message.
  4. Sign in to SSP as the test user and verify personal quarantine, message preview, and exactly the approved actions.
  5. If a distribution list is involved, sign in as its owner and confirm that list quarantine appears separately.
  6. Test an allowed action only with a demonstrably harmless message, then confirm delivery or removal.
  7. Test Emergency Inbox only in an approved outage exercise, distinguishing visibility, the 14-day limit, and normal delivery retries.

Troubleshoot systematically

No summary: First verify that a new eligible message was quarantined after activation or the previous summary. Then check effective policy priority, the External fallback, Include in End User Quarantine, schedule, time zone, mailbox address, and category. If eligible new messages exist, an administrator can temporarily choose another language under Profile Menu > Language, then switch back to the original language.

Invitation email is missing: Check that the user’s address is valid and unique. If it was used for a Sophos Fusion Admin trial account, resolve the old account conflict through the approved account process. An Audit Log entry doesn’t prove delivery. Before sending another invitation, the blocking old user account must be removed; then send Sophos Fusion Self Service Welcome/Setup Email again.

Portal access or actions are missing: Check license, user identity, automatic or targeted access grant, effective User Settings, message category, and Include in End User Quarantine. For a distribution list, also check the owner and directory source. More portal rights don’t turn a Data Control or non-releasable message into an end-user case.

The link says message is already released: Microsoft 365 Safe Links may visit the release link while scanning it. After security approval, add hmr.sophos.com to the do-not-rewrite URL list in the responsible Safe Links policy. Test with a new quarantine summary afterward; an old link that has already been visited isn’t a valid retest.

For escalation, collect the tenant, user address, policy name and priority, category, quarantine time, scheduled slot and time zone, access method, owner mapping, and a screenshot of the missing or incorrect action. Never put passwords, setup links, or confidential message content in the ticket.