Integrate Sophos Email with Threat Analysis Center
The Sophos Email integration lets Sophos Fusion (formerly Sophos Central) send data about email events to Sophos for analysis. The short workflow is: open Sophos Email in the Marketplace, provide internal domains and IP ranges during the first integration setup, turn on the integration under Integration Details, and select Save. The tile must then show one active integration with an Online health status.
Clear boundary: This is a shared Threat Analysis integration managed in Sophos Fusion. It changes neither MX records, connectors, Gateway routing, nor Email Security policies, and it is not a mail-flow setup. Use the separate Sophos Email architecture and onboarding guide for those decisions.
Check the prerequisites
An active Sophos Email license is required; Sophos states this explicitly. The administrator account must also be able to access Threat Analysis Center > Integrations > Marketplace in the correct Sophos Fusion tenant and save changes. If the tile is missing or cannot be configured, check this access first and then the license entitlement. MDR and XDR integrations in Sophos Fusion explains the broader distinction between integration types and the Data Lake.
Before opening the setup, assemble your own internal domains and internal IP addresses or ranges. Sophos requests these details when this is the first integration you have added. Follow the prompt that is actually shown: do not enter third-party domains, public example data, or guessed ranges. The Sophos Email license and tenant assignment can be confirmed in the licensing and region check.
Enable and save the integration
- In Sophos Fusion, open Threat Analysis Center > Integrations > Marketplace.
- Search for Email and select the Sophos Email tile.
- If Sophos Fusion asks for internal domains and IPs for this first integration, enter the prepared tenant-specific domains and IP addresses or ranges completely. Fill only the fields actually requested on the page; do not transfer field labels or defaults from other integrations.
- On the Sophos Email page, under Integration Details, turn on the integration.
- Select Save.
This enables event submission. It does not configure how messages reach Sophos Email or how they are filtered there.
Validate health and event data
Return to Threat Analysis Center > Integrations > Marketplace. The Sophos Email tile must now show one active integration with an Online health status. This is the first proof that the saved integration is active.
Health alone does not prove that a specific event has arrived. Sophos validates the data before it appears; it should then be available in the Sophos Data Lake. For functional acceptance, choose a representative, already expected Email event after the enablement time, record its time and tenant, and verify after a reasonable processing interval that the corresponding record is present in the analysis workflow. There is no need to generate a malicious message.
Acceptance requires both layers:
- tile: one active integration and Online health;
- data: an expected Sophos Email event traceable in the correct tenant after Sophos validation.
Troubleshoot by symptom
- Tile missing or integration cannot be enabled: check the correct tenant, Sophos Email license, and the account’s Marketplace access. Do not try to fix this by changing mail flow.
- Save is blocked: for the first integration, check that all internal domains and IP addresses or ranges requested on the page have been completed. Do not copy field names or formats from another integration.
- Tile does not show an active integration or Online: reopen Sophos Email, check the switch under Integration Details and the saved state. Then allow the status to refresh instead of immediately creating a second configuration.
- Online but no data yet: data appears in the Data Lake only after Sophos validation. Compare only events after enablement, check tenant and time window, and allow sufficient processing time.
- Data remains absent: recheck licensing, required details, saved enablement, and whether a representative Email event exists. For escalation, record the tenant, enablement time, visible tile status, and expected event timestamp, but avoid disclosing message content or personal data unnecessarily.
Until the tile is Online and a representative event has been demonstrated, the integration is not fully accepted. MX, connector, or Email-policy changes are not an appropriate repair attempt.