Configure the Sophos Firewall login disclaimer and messages
Sophos Firewall can show administrators a login disclaimer before they gain access. Under Administration > Messages, it is also possible to customize text for authentication, SMTP events, and SMS credentials. All these messages are limited to 256 characters.
My assessment is deliberately clear: The login disclaimer provides virtually no technical security benefit. It neither prevents automated sign-in attempts or the use of stolen credentials, nor verifies identity or limits permissions. In normal operation, it mainly adds another click to every sign-in, which is usually accepted as a matter of routine.
SFOS 22 nevertheless marks a disabled disclaimer as Noncompliant in the Firewall health check. The Login disclaimer should be enabled check belongs to the CIS standard and has Medium severity. Enabling it turns this item green or Compliant, but that only confirms that the notice is enabled. It does not make the sign-in itself more secure. If there is no legal, contractual, or internal compliance requirement, the feature should not be enabled merely to improve the score. The Health Check allows Override status for such deliberate decisions; Interpret the Sophos Firewall Health Check correctly explains how to mark and document them.
The disclaimer is therefore a notice and compliance feature, not a technical access control. It replaces neither Device Access nor the Local Service ACL, named admin accounts, roles, strong passwords, MFA, or audit logs. Legally relevant wording must be approved by the responsible legal or compliance team rather than copied from an arbitrary template.
Login disclaimer in seven steps
- Define the purpose, audience, language, contact, and a maximum of 256 characters.
- Keep a second tested admin or recovery path open.
- Under Administration > Admin settings > Login disclaimer settings, select Enable login disclaimer and save with Apply.
- Open the Modify link or edit and save the disclaimer under Administration > Messages > Administration.
- Open the preview under Login disclaimer settings and check the text, line breaks, and completeness.
- Perform a real admin sign-in in a private browser window, read the notice, and confirm it with I accept.
- Test rejection, incorrect credentials, permitted roles, Audit Trail, and, in HA, a fresh sign-in after a planned failover separately.
⚠️ The disclaimer must not contain passwords, internal IP addresses, recovery codes, support secrets, or unnecessary system details. A checkbox or I accept does not automatically make wording legally binding. At the same time, enabling the feature must not endanger the only tested admin session: a second admin account and recovery path remain available before the change.
Which messages SFOS 22 can customize
Under Administration > Messages, SFOS groups templates by event:
- Authentication: Confirmation of sign-in and sign-out, failed sign-in, and disconnection.
- SMTP: Messages for blocked and received emails.
- Administration: Disclaimer for administrator sign-in.
- SMS customization: SMS text with the dynamic attributes
{username},{password}, and{expirydate}.
Use Edit to change text, Apply to save it, and Reset to restore the Sophos default. Reset is not an undo for a single word; it discards the custom version of that message. Preserve the previous text in the change record before editing it.
These templates are separate from the delivery paths. Administration > Messages changes the content but configures neither the SMTP server, Notification List, nor SMS gateway. Set up notification email on Sophos Firewall explains email transport; guest users and the SMS gateway remain in Create guest users securely on Sophos Firewall.
Plan the disclaimer text
A good sign-in notice remains short, unambiguous, and free of technical secrets. It can include:
- Access is restricted to authorized administrators.
- Use and changes may be logged.
- Continuing means the notice has been read.
- A contact for accidental or unauthorized access attempts.
- A reference to an internally maintained policy if the link is reachable from the management network.
A neutral documentation example can look like this:
Authorized administrators only. Sign-ins and changes may be logged. By continuing, you acknowledge this notice. Contact: noc@example.com
.example is a reserved documentation domain. Adapt the contact, wording, and any policy reference to the organization. Keep the text below 256 characters and do not present it as a universal legal template.
Avoid:
- long policies that nobody can reliably read in the small sign-in window;
- statements such as “completely secure”, “fully monitored”, or “automatically legally binding”;
- specific firmware versions, internal hostnames, or network plans;
- personal data of an individual employee when a functional contact is possible;
- contradictory wording in multiple languages without a responsible owner.
Enable the login disclaimer
The switch and the text are located in two different areas. This distinction matters:
- Open Administration > Admin settings.
- Go to Login disclaimer settings.
- Select Enable login disclaimer.
- Click Apply.
- Use the link to change the text or go to Administration > Messages.
After entering credentials, administrators must click I accept. The current Sophos guide lists the notice before access to WebAdmin, User Portal, and CLI. This does not imply any network permission: reachability and authentication remain controlled independently.
The protection layers remain separate:
- Local administrators and Device Access profiles determine identity and permissions.
- Device Access and Local Service ACL limit the networks from which WebAdmin or SSH can be reached.
- MFA, password protection, and Login Restrictions remain active unchanged.
- The disclaimer only adds a visible notice to these controls.
Maintain the disclaimer text under Messages
The actual content is changed under Administration > Messages:
- Expand Administration.
- Select Edit.
- Enter the approved text with no more than 256 characters.
- Select Apply.
- Return to Administration > Admin settings > Login disclaimer settings.
- Open the Preview link.
The preview confirms appearance and content, not the complete sign-in process. Only a new private browser session shows whether the disclaimer appears after the credentials and requires I accept. An existing admin session is not reliable evidence.
If the text is unusable, Reset restores the Sophos default. For controlled rollback, preserve the previous custom version anyway, because Reset does not return to that customer-specific text.
Change authentication and SMTP messages safely
Authentication and SMTP messages directly affect users or email workflows. Test changes functionally, not only editorially.
An authentication error message should not unnecessarily reveal whether a username exists, a password was wrong, or MFA is missing. A generic failure message reduces information for attackers. Test a successful sign-in, an incorrect password, sign-out, and forced disconnection with test accounts.
SMTP message text changes neither mail routing nor the cause of a block. After an edit, test one controlled allowed and one controlled blocked message. Mail logs and Message History remain the technical evidence; visible wording alone does not prove correct SMTP processing.
Align the SMS template with the provider
SFOS permits these placeholders for SMS customization:
{username}{password}{expirydate}
Keep the placeholders exactly as written. The SMS provider may require a preapproved template. If wording, order, or additional text differs from it, the SMS server may reject the message. Obtain the binding provider template first and then align the SFOS message with it.
A login disclaimer preview does not test SMS. Test connection on the SMS gateway also confirms only its intended test path. Complete evidence consists of a controlled guest user, an actually received SMS, correct placeholder values, and a successful sign-in.
An SMS containing {password} carries credentials. Treat the recipient, validity period, device protection, and deletion like passwords. Do not add internal details to the text, and create screenshots or tickets without real credentials.
Validate the change
The acceptance test separates appearance, access, and delivery:
- Preview: Disclaimer complete, readable, and below 256 characters.
- Positive admin sign-in: The notice appears after the credentials and I accept enables the intended access.
- Negative test: Incorrect credentials remain rejected; the disclaimer does not bypass authentication.
- Roles: A read-only admin gains no additional permissions by accepting.
- Device Access: Unauthorized source networks still cannot reach WebAdmin.
- CLI: Test the CLI access used in the environment separately without broadening SSH access for the test.
- Email and SMS: Perform one genuine controlled delivery test for each; preview and message text alone are insufficient.
- Audit: Verify the change, administrator, and time in Audit Trail; compare the expected text separately with Preview and the change documentation. Analyze configuration audit logs on Sophos Firewall explains the interpretation.
- HA: After a planned failover, test a fresh sign-in to the active node; do not promise continuation of existing WebAdmin or CLI sessions.
Troubleshoot by symptom
The disclaimer does not appear
Verify that Enable login disclaimer is selected and saved with Apply under Admin settings. Then use a new private browser session. An old session or only editing the text under Messages does not prove the switch is active.
The text is wrong or truncated
Check character count, line breaks, and special characters. Shorten it to no more than 256 characters and review the preview again. If the custom version cannot be repaired safely, use Reset and re-enter the approved text from the change record.
Sign-in fails after the change
Do not assume the disclaimer caused it. Check credentials, MFA, Administrator authentication methods, Login Restrictions, Block login, Device Access, and the certificate separately. Use the open recovery session to disable the disclaimer temporarily if that is necessary to isolate the cause safely. Do not broadly open an ACL or authentication method.
The SMS is not delivered
Check the provider template, exact placeholders, SMS gateway, mobile number format, and provider response. If the provider requires a registered template, do not keep changing the text speculatively. Validate the complete guest-user workflow, not only Test connection.
Health Check asks for a login disclaimer
Sophos Firewall Health Check rates the feature as a compliance recommendation. The disclaimer does not provide technical protection such as MFA or a narrow ACL. Decide based on the organization’s audit, customer, and legal requirements; Interpret Sophos Firewall Health Check correctly explains this boundary.
Rollback
- Keep the previous custom text from the change record ready.
- For a text-only error, re-enter the previous version under Administration > Messages or deliberately use Reset.
- For a sign-in issue, use the open recovery session to clear Enable login disclaimer and select Apply.
- Restore authentication, SMTP, or SMS templates individually to the documented previous state; do not change all message areas at once.
- Retest a new private sign-in, roles, Device Access, and, where applicable, email and SMS delivery.
- Document the change and rollback in Audit Trail and the change record.
Checklist
- Purpose, owner, language, and maximum of 256 characters defined.
- Text reviewed by legal or compliance owners where required.
- Second admin and recovery path tested.
- Disclaimer enabled under Admin settings and saved with Apply.
- Message maintained under Administration > Messages.
- Preview and new private sign-in tested.
- I accept expands neither the role nor Device Access.
- Authentication, SMTP, and SMS text each tested with a real event.
- SMS template and placeholders match the provider.
- Audit Trail, HA test, and rollback documented.