Sophos Phish Threat: automatically enroll new users
Automatic enrollment lets Sophos Phish Threat add users newly added to the Sophos Fusion (formerly Sophos Central) account to a campaign or campaign series. It is useful, for example, for mandatory introductory training for new employees. However, it is not a dynamic group filter: when enabled, it includes every new Fusion user, not just members of a particular department or new-hire group.
Enable the setting under Enroll Users while creating the campaign or series. For a standalone campaign, the option is Auto-enroll new users to this campaign; for a series, it is Auto-enroll new users to this series.
Define the purpose and scope first
Use automatic enrollment when every user subsequently created in this Fusion account should receive the same baseline campaign. If only some new starters are eligible, maintain an explicit user or group selection instead.
The technical trigger is the addition of a user to Sophos Fusion, not the employee’s start date in the HR system. For this feature, Sophos documentation does not distinguish between users created manually, imported, or provisioned from a directory. Do not therefore treat the provisioning source as a filter.
Prerequisites, roles, and licensing limits
Before configuring the feature, you need:
- a valid Sophos Phish Threat license with enough capacity for the current and expected audience;
- a Sophos Fusion administrator account permitted to create Phish Threat campaigns or campaign series;
- verified recipient domains and a tested delivery path for Phish Threat messages;
- a campaign or series whose language, template, training, schedule, and passing score have already been reviewed;
- documented approval to enroll users created in the future without reviewing each one;
- a process that addresses accounts created in error, external accounts, and ineligible users before they are created in Fusion.
A Fusion role or the existence of a user does not replace a Phish Threat license. Conversely, a license does not grant administrative rights. Capacity must allow for growth: a user counts toward licensing as soon as a campaign email is sent to that user. See the Sophos documentation on Phish Threat licensing and usage for details of the counting model.
Behavior by campaign type
New users do not receive their first message at the same time in every mode:
| Target | Enrollment of the new user | First relevant message |
|---|---|---|
| Standalone Phishing, Credential Harvesting, Attachment, or Training campaign | immediately after automatic enrollment | 24 hours later |
| Simulated attack series | in the next campaign generated by the series; never retroactively in a campaign already under way | according to the schedule of the next generated campaign |
| Security training series | in every training campaign generated by the series; always starting with the first course | according to the series schedule, not necessarily on the enrollment date |
A standalone campaign with automatic enrollment remains active until an administrator ends it manually. Do not rely on its originally scheduled end date as the sole lifecycle control.
In a training series, each newly enrolled user starts with course 1, even if other participants have progressed further. That user’s courses are shifted accordingly. For example, course 1 starts on January 1; a user added on January 15 receives course 1 on February 1 and course 2 on March 1. A user added later also begins with course 1, not with whichever course is current on that calendar date.
Configure automatic enrollment
First configure the entire campaign or series and complete every wizard step carefully. Plan and review recurring campaign-series workflows with the same care.
- Open My Products > Phish Threat > Campaigns.
- Select New Campaign for a standalone campaign or New Series for a series.
- Configure the type, language, attack or training, templates, and reminders. Test the content and delivery with a controlled internal mailbox.
- Under Enroll Users, select the approved Users or Groups.
- Enable Auto-enroll new users to this campaign or Auto-enroll new users to this series, as appropriate.
- Select Next to proceed to Review and Schedule.
- Check the name, type, existing recipients, schedule, training, and automatic-enrollment setting. For a series, also check its interval and end.
- Select Done only after a second person has reviewed the configuration.
Before selecting Done, you can return to Enroll Users and disable the option. Continue a draft under Campaign Drafts with Finish, or remove it with Discard. Discarding a draft does not trigger a production send.
Validate under controlled conditions
You cannot fully test the feature with an existing user because it responds to a newly added Fusion user. Use only an approved internal test account in a verified domain.
- After selecting Done, open the campaign or series under My Products > Phish Threat > Campaigns and confirm that automatic enrollment is enabled in the saved configuration.
- Record the start time, current recipient count, and approved test account.
- Add the test account to Sophos Fusion as a new user through the normal user process.
- Confirm that it appears as enrolled in the expected campaign or series.
- Check the expected delivery time: 24 hours later for a standalone campaign; at the scheduled start of the next generated campaign for a simulated attack series; or on the newly enrolled user’s next course date for a training series.
- Use the account to verify delivery, the link or training, and event capture. Do not report the absence of a message as an error before the applicable time window has elapsed.
- Then compare recipient and license totals and document the test.
Do not repeatedly recreate a test account merely to avoid waiting. That can produce extra user objects and recipients, as well as campaign data that is difficult to interpret.
Data protection and operational control
Phish Threat campaigns process recipients’ personal and behavioral data. Restrict access to the configuration and results to those who need it. Document the purpose, legal basis or internal approval, retention period, and escalation path in accordance with your organization’s requirements.
The option’s reach is especially important: a newly created Fusion user can be enrolled even if the campaign owner has not reviewed that user individually. Coordinate user onboarding, directory synchronization, and Phish Threat operations accordingly. Use results for the defined security-awareness purpose; without further review, do not use them as isolated evidence of performance or fault.
Troubleshoot specific problems
New user is not enrolled
First confirm that the user was added to this Fusion account after activation and that the option is enabled on the correct object. Also confirm that the campaign or series was completed and is active, rather than merely saved as a draft. In a simulated attack series, the user will not join a campaign already under way, but only the next generated campaign.
User is enrolled but has not yet received a message
Match the expected delivery time to the mode. A standalone campaign has a 24-hour wait; a series follows its schedule. Then check the email address, verified domain, validity and available capacity of the account’s Phish Threat license, campaign status, and mail flow. Enrollment in Fusion does not prove delivery to the mailbox.
Unintended users are enrolled automatically
This is expected if the feature was mistaken for a department filter: it applies to every new user in the Fusion account. Open the running standalone campaign and immediately select Pause. Select Edit, go to Enroll Users, disable Auto-enroll new users to this campaign, and remove only unintended recipients whose campaign email has not yet been sent. Save the changes and check the remaining recipient list. Select Resume only if the campaign should continue for those recipients; otherwise use Delete. Sent messages cannot be recalled, and recipients whose campaign email has already been sent cannot be removed.
The recipient count is growing unexpectedly
Compare the timing of the increase with manual account creation, imports, and directory-synchronization runs. Check whether the option is enabled in several campaigns or series. Document the specific new users, not just the total, and compare expected sends with license capacity.
Stopping, rollback, and lifecycle
A rollback can limit only future enrollment and future delivery. It cannot retroactively remove delivered messages, captured events, or license usage already incurred.
- Before Done: Disable the option under Enroll Users, or discard the draft under Campaign Drafts with Discard.
- Running standalone campaign: Open the campaign and select Pause so pending attack, training, and reminder emails are not sent. Open Edit, go to Enroll Users, disable Auto-enroll new users to this campaign, and save. Remove unintended recipients only if their campaign email has not yet been sent. Check the remaining list and select Resume only if the campaign should continue. Otherwise use Delete; deletion cannot be undone.
- Active series: Open the series and select End this series. Under Upcoming Campaigns, identify every entry already generated by the series and record its name and scheduled start. Ending the series does not end those campaigns. End each campaign separately as soon as that action becomes available, one week before its scheduled start. Keep checking Upcoming Campaigns against your dates until no previously generated campaign can start.
- Messages already sent: There is no technical recall. Notify the help desk and internal owners, document the recipients and delivery time, and manage further communication through the approved incident process.
- License usage: Ending or deleting a campaign does not retroactively remove recipients from the rolling usage window.
After saving a standalone campaign, check under Edit > Enroll Users that Auto-enroll new users to this campaign is disabled and that only intended users remain. Compare campaign status and mail flow at every pending attack, training, and reminder time, and confirm that the paused or deleted campaign sends no further email. For an ended series, compare Upcoming Campaigns with your list and monitor every recorded start date until all generated campaigns have been ended individually. Treat removal of a user from Sophos Fusion as a separate user-lifecycle process: stopping a campaign is not the same as deleting a user. See Safely delete and offboard Sophos Fusion users.