Planning Sophos ITDR: Prerequisites, licenses, regions, and roles
Before you set up Sophos ITDR, establish which region, licenses, and roles apply. You also need to decide whether the data will come from Microsoft Entra ID, on-premises Active Directory, or both, and assign day-to-day ownership of ITDR Findings. Use this quick check to cover all six decisions.
Pre-setup quick check:
- Check the existing tenant’s data region under Account Details > Account Preferences. The documented regions for ITDR are Germany, Ireland, and US.
- Confirm that ITDR has been activated in the correct tenant; My Products > Identity should then be visible. The available documentation provides neither a definitive public SKU name nor a general licensing metric, so check both points against the License Schedule and with the Sophos Partner.
- Confirm a Microsoft Entra ID P1 or P2 license for every Entra integration. Entra ID Free is not an adequate basis for planning.
- Designate a Sophos administrator to perform the setup and an Entra administrator who can grant tenant-wide admin consent. These are separate roles.
- Decide whether to connect Microsoft Entra ID, on-premises Active Directory, or both. The ITDR integration does not replace Central Directory Sync.
- Assign someone to review and manage ITDR Findings on an ongoing basis. An MDR license does not transfer this routine task to Sophos MDR.
Once the license is active, ITDR appears under My Products > Identity, with configuration available under My Products > Identity > Settings. If Identity is missing, do not proceed straight to creating an integration. Check the data region, tenant, license status, and role first.
1. Check the data region before purchasing a license or choosing a tenant
The current product-specific availability information lists exactly these Sophos Fusion data regions for ITDR:
- Germany
- Ireland
- US
ITDR is listed as unsupported in Australia, Brazil, Canada, India, and Japan. Do not extrapolate from the broader statement that the US and EU regions support all products: for ITDR, only the specific list Germany, Ireland, and US applies.
The existing tenant’s region is decisive; the company’s location and billing address are not. Buying a license does not make ITDR available in an unsupported region. If an ITDR license has already been purchased for a tenant in an ineligible region, Sophos’s documented commercial remedy is to cancel it through the Sophos Sales Partner and issue a new license key for a new Fusion tenant in a supported region.
This is not a documented in-place migration. The reviewed documentation provides no basis for assuming that a tenant’s region can be changed later or that configurations and data will transfer automatically. Before creating a new tenant, obtain separate approval for data protection, data residency, existing products, integrations, and the migration effort.
2. Check Sophos and Microsoft licenses separately
An Entra connection has two independent licensing requirements.
Sophos ITDR in the correct tenant
The ITDR product documentation requires an activated ITDR license. Only then should My Products > Identity or My Products > Identity > Settings become available.
However, the reviewed ITDR documentation does not provide an unambiguous ordering SKU, a general metric for counting users or identities, or a reliable statement that ITDR is included in another Sophos package. It therefore supports neither an inferred SKU nor a quantity formula. Before activation, obtain written confirmation of at least the following:
- name and data region of the Fusion tenant;
- product description and term on the License Schedule;
- agreed scope and start date;
- responsible Sophos Partner;
- intended Entra and AD environments.
General activation and verification in Sophos Fusion (formerly Sophos Central) are covered in “Activate, check, and renew Sophos Fusion licenses”. For ITDR, the practical check remains the same: Identity is visible in the correct tenant, and the intended administrator account can open Settings.
Microsoft Entra ID P1 or P2
Sophos requires Entra ID P1 or P2 for the Microsoft Entra ID integration. The entitlement may be a standalone product, an add-on, or part of another Microsoft plan. Sophos gives Microsoft 365 E3 and E5, Microsoft Business Premium, and Microsoft 365 Frontline Worker F1, F3, and F5 as examples. What matters, however, is the effective P1/P2 entitlement in the tenant being connected, not merely the display name of a purchased package.
Entra ID Free is not sufficient. Although the Free edition provides Microsoft APIs, it limits the available data and Posture Checks that can be run. An integration may therefore show Provisioning Failed. A technically reachable API endpoint is not proof of licensing.
After an upgrade from Free to P1 or P2, Sophos states that Microsoft-provided information such as admin or MFA status may be delayed by up to one week. Account for this delay in the schedule. After an upgrade, check the Authentication Methods Activity Report in the Microsoft Entra admin center, and bear in mind that ITDR cannot show the current status until Microsoft has updated the data.
3. Define roles before granting consent
Two administrative domains are involved in the setup:
- Sophos Fusion: The ITDR integration instructions explicitly list a Sophos Fusion Administrator role as a prerequisite.
- Microsoft Entra ID: The Entra account used must be able to grant tenant-wide admin consent.
The phrase Sophos Fusion Administrator role is too imprecise to identify either a distinct predefined role or a minimum Custom Role. The published Fusion role tables list Super Admin, Admin, Help Desk, Read-only, and User, but identify neither an ITDR-specific permission nor a role with that exact name. Consequently, no specific minimum ITDR role can be established: the documentation proves neither that Super Admin is always required nor that a self-defined Custom Role will suffice.
For a controlled rollout:
- Select an existing Super Admin or Admin as the setup account without granting permanent Super Admin rights unnecessarily.
- Before the maintenance window, use this account to confirm that My Products > Identity > Settings > Integrations and the intended setup action are available.
- Have the separate Entra administration team designate an account that can perform Grant Tenant Wide Admin Consent.
- Record the Sophos and Microsoft accounts, responsible person, time, and purpose of consent in the change log.
- After setup, test with the intended least-privileged Fusion role: authorized pages must be visible, while changes outside its permissions must remain blocked.
A visible page does not prove that a change is permitted. Conversely, license-dependent permissions may be entirely absent without the appropriate license. For details about predefined and custom roles, see “Assign Sophos Fusion administration roles correctly”. Neither that article nor this one claims that a specific “ITDR Custom Role” exists unless Sophos publishes a verifiable ITDR permission matrix.
4. Choose identity providers and the scope of monitored identities
ITDR supports these identity providers:
- Microsoft Entra ID for cloud-based identity data;
- on-premises Active Directory through the separate ITDR sensor.
You can add multiple Microsoft Entra ID tenants through Identity Settings. This does not mean that a one-time check of licensing, consent, or ownership automatically applies to every tenant. For each connection, document the tenant ID or unique tenant name, P1/P2 entitlement, consent account, person responsible for operations, and expected scope.
The monitored identity population includes active human and non-human identities:
- Human identities: for example, employees, guests, and external users.
- Non-Human Identities (NHI): for example, applications, Service Principals, Service Accounts, machines, and other identities that authenticate or authorize access or perform transactions between systems.
ITDR collects both human and non-human identities, but currently calculates Risk Scores only for active user identities. Service Principals, applications, and deleted or disabled users do not receive a Risk Score.
5. Define responsibilities between the customer and MDR
ITDR is software that the customer monitors; it is not a managed service. The customer’s operating process must name a primary owner and deputy, set triage time frames, and define both ownership and the remediation procedure.
If Sophos MDR is licensed separately, the MDR Operations Team also investigates identity threats. Clear boundaries apply:
- MDR focuses primarily on active identity threats.
- MDR reviews only a subset of critical or high-severity Findings that may indicate an active threat.
- The customer remains responsible for ongoing monitoring and management of ITDR Findings.
- Additional Entra ID context can help MDR assess correlated users and risks more quickly in identity and non-identity investigations.
An MDR license therefore does not provide comprehensive triage of all ITDR Findings or automatic remediation of every identity risk. Before go-live, define who handles routine Findings, when an active incident is escalated to MDR, and who approves changes in Entra ID or AD.
6. Keep product boundaries separate
ITDR complements other Sophos capabilities; it does not replace them. Keeping that boundary clear prevents a successful ITDR rollout from being treated as acceptance of other products.
Central Directory Sync
The Entra and AD sensor integrations provide ITDR with identity and directory data for Posture, Directory, and Findings. Dark web monitoring is configured separately for domains that are imported automatically from Entra or added and verified manually. Neither these ITDR integrations nor dark web monitoring replace Central Directory Sync. A configured ITDR environment therefore does not confirm that Central users or groups are synchronized for other products, nor does it replace mapping, filtering, or deletion rules. The prerequisites for the separate directory synchronization process are covered in “Sophos Central Directory Sync: Prerequisites and architecture”.
XDR and MDR
ITDR Findings are not XDR Detections or Cases. XDR license entitlements and XDR roles must therefore not be interpreted as an ITDR license or ITDR permission. MDR, in turn, is a separately licensed service with the limited investigation scope described above; it does not take over routine daily Findings.
Firewall, NDR, and Active Threat Response
Sophos Firewall identity features, NDR or NDR Essentials, and Active Threat Response remain separate products or workflows. An Identity visible in ITDR does not configure a firewall rule, validate an NDR sensor, or automatically trigger a firewall or ATR action. These integrations require their own licensing, role, data, and acceptance checks.
ZTNA
Sophos ZTNA controls access to applications using its own gateway, connector, policy, and Identity configuration. ITDR assesses identity risks and misconfigurations; it does not automatically provide a ZTNA access path or replace a ZTNA policy. A shared Identity source does not make the two product workflows identical.
7. Acceptance before technical onboarding
Do not begin Entra authorization or sensor deployment until the following points are documented:
- The specific Fusion tenant and its region have been identified.
- The region is Germany, Ireland, or US.
- The ITDR license is activated in the correct tenant, and My Products > Identity is visible.
- The License Schedule, term, and partner contact have been recorded; no unsupported SKU or quantity key has been assumed.
- P1 or P2 entitlement has been confirmed for each Entra tenant.
- The tenant or domain, responsible person, and intended scope have been documented for each provider.
- The Fusion setup account can open Identity > Settings > Integrations and perform the required action.
- A separate Entra account can grant tenant-wide admin consent.
- Human identities and NHI have been included to the expected extent.
- Customer responsibility for Findings and possible escalation to MDR have been defined.
- Directory Sync, XDR, MDR, Firewall/NDR/ATR, and ZTNA have been treated as separate workflows.
Success criterion: Preparation is complete only when the menu item is visible and there is evidence for the region, both licensing levels, both administrative domains, each provider’s scope, and the person responsible for operations. Validate the integration itself and its data quality separately afterward.
Documentation limitations
This article is based on product, region, role, and FAQ content reviewed as of September 20, 2026. It does not describe independent product or lab testing. In particular, the available evidence does not cover:
- a definitive public ITDR SKU or a general license counting model;
- an exact minimum ITDR Custom Role or individual ITDR permission names;
- an in-place migration between Fusion data regions;
- an ITDR-specific retention or end-of-life commitment;
- any automatic effect of ITDR on Central Directory Sync, XDR, Firewall, NDR, Active Threat Response, or ZTNA.
If any of these points is required for a procurement, data protection, or authorization decision, confirm it for the specific tenant with the Sophos Partner or Sophos Support before setup rather than inferring it from documentation for adjacent products.