Skip to content
Avanet

Sophos Phish Threat: Calculating licensing and usage correctly

Sophos Phish Threat is licensed per user who receives an email from a Phish Threat campaign. This applies both to attack simulations and to training-only campaigns. The number of campaigns or emails per person does not increase the licence requirement: each unique recipient counts once within the period under review.

Quick check: Under Profile icon > Licensing, check the product, quantity, and expiry date. The calculated usage is available under Reports > Email Security > License Usage Summary. However, this report combines Sophos Email and Sophos Phish Threat and does not show the two products separately. For a reliable comparison, you also need the actual campaign recipients.

Prerequisites for a reliable review

Before comparison, the following information should be available:

  • access to the correct Sophos Fusion tenant and a sufficiently authorised administrator role,
  • the current License Schedule showing the product, purchased quantity, and term,
  • for MSP customers, whether Phish Threat is billed via the monthly Flex model,
  • a list of campaigns, sending periods, and unique recipients,
  • if Sophos Email is used simultaneously, the number of users considered there in the same period and Shared Mailboxes.

For operational comparison, the portal number should always be checked together with the current License Schedule.

When a user consumes a licence

Assigning a user to a planned campaign alone does not trigger usage. What matters is that a campaign email is sent or delivered to that user. The send date is therefore more important than the campaign’s creation, start, or end date.

For regular Phish Threat licences, there are two perspectives that should not be confused:

  1. Portal usage: Sophos calculates usage daily from the unique users who have received campaign emails in the past 30 days.
  2. Licence requirement: During the licence term, the licensed quantity must cover all users who actually use Phish Threat. A recipient dropping out of the rolling display after 30 days does not create a rotating licence pool.

A user counts only once, even if they receive one or one hundred campaign emails. Multiple campaigns sent to the same target group therefore do not automatically increase the required licence quantity, whereas an additional target group does.

Example: Repeated campaigns to the same users

An organisation has 80 licensed users. In September, the same 80 people first receive a phishing simulation and later a training-only campaign. The second email does not add another 80 users: the total remains 80 unique recipients.

If an additional 20 other people are contacted in the second campaign, the unique target group comprises 100 users. Then licence inventory and contractual requirements for 100 users must be checked.

Classifying sends across billing boundaries

Sophos assigns usage to the period in which the campaign emails are delivered. If a campaign sends messages in intervals, recipients from the same campaign may therefore appear in different billing periods.

Sending scenarioUsage in the first periodUsage in the second period
One campaign, all 20 emails before the cutoff200
One campaign, 16 emails before and 4 after the cutoff164
Two campaigns, 20 recipients; 10 receive another email in the same period200
First campaign to 20 recipients; of 10 emails in a second campaign, 2 go out before and 8 after the cutoff208

The example illustrates two rules: each unique recipient counts once per period, and the actual delivery date determines the period. For capacity planning and renewal, however, consider the entire target group rather than an arbitrarily small subset shortly before the cutoff date.

Monthly Flex billing for MSP customers

Monthly Sophos Phish Threat licensing is available through the MSP Flex programme. Billing is based on the unique recipients to whom campaign emails were sent during the relevant billing period. Multiple emails to the same person count once in that period. If no campaign emails are sent in a month, no Phish Threat usage is incurred for that month.

Billing runs monthly from the first through the last calendar day. According to Sophos, usage data is usually collected on the 22nd of each month, although this date may shift for operational reasons. The invoice month must therefore be distinguished from the recorded usage window. In Sophos’s example, usage billed on June 30 covers May 23 through June 22. A campaign email sent on June 23 is included in the July 22 reading and billed on July 31. Campaigns that span the reading date are split accordingly.

For comparison, you export or document at least:

  • campaign name,
  • actual sending period,
  • unique recipients,
  • recipients whose messages were sent after the expected reading date,
  • the expected reading date and the resulting usage window.

Checking licence usage in Sophos Fusion

  1. Open Profile icon > Licensing.
  2. Check that Sophos Phish Threat, the expected licence type, number and the correct expiry date are in the current tenant.
  3. Open Reports > Email Security > License Usage Summary.
  4. Select the latest scan by date and local time and document it along with the displayed usage.
  5. Identify the unique recipients of Phish Threat campaigns sent in the last 30 days.
  6. If Sophos Email is active, consider its relevant users and Shared Mailboxes separately.
  7. Compare the portal figure, campaign recipients, Email usage, and purchased quantity. Note that Sophos recalculates Phish Threat usage daily and updates the Sophos Email component every four hours.

Why the report does not directly match the Phish Threat figure

The License Usage Summary is a combined unique usage of Sophos Email and Sophos Phish Threat. It does not list the product proportions separately. A higher figure therefore does not prove that a Phish Threat campaign had too many recipients. Similarly, the Phish Threat component cannot be determined reliably by simple subtraction when the same identities occur in both products.

For root-cause analysis, maintain two inventories: mailboxes processed by Sophos Email and recipients contacted by Sophos Phish Threat. How is Sophos Fusion licensed? explains the fundamentals of cross-product counting models.

Success criteria after comparison

The review is complete when:

  • the product and expiry date under Profile icon > Licensing match the License Schedule,
  • all campaigns with sends in the relevant 30-day or Flex billing period have been considered,
  • the same recipient has not been counted more than once within a period;
  • the combined character of the License Usage Summary is considered in the evaluation,
  • the quantity purchased covers the actual and planned target group;
  • for campaigns close to a billing boundary, the send times—not only the campaign start date—have been checked.

A screenshot of the licence page alone is not sufficient as monthly evidence. Instead, keep a concise operational record containing the License Schedule, report date, campaign list, unique recipient count, and any documented discrepancies.

Deleting or ending campaigns and cleaning up recipients

Ending or deleting a campaign does not retroactively remove licence usage already incurred. The affected recipients remain in the rolling 30-day window. The displayed usage can decrease only after more than 30 days have passed since their last campaign email.

Do not delete a campaign to correct a supposedly incorrect figure, as this removes useful context for the review. Before any cleanup, document the campaign name, target group, sending status, and sending times.

For the next campaign, compare the target groups with the purchased quantity before launch. Although a campaign with staggered sending may appear in the display only gradually, the entire planned target group must already be covered by the licence when the campaign is approved.

What happens after the licence expires

After expiry, the Phish Threat area displays a licence banner. New campaign emails and reminders are not sent while the licence is expired. After renewal, these pending emails are sent.

Campaigns that have already been sent behave differently: Sophos continues to record phishing data and interactions. Licence expiry therefore stops new sends but does not delete the existing campaign or its ongoing data collection.

For operation, it follows:

  1. Check the expiry date regularly under Profile icon > Licensing.
  2. Complete the renewal before the next scheduled send.
  3. After renewal, check licence status and the new expiry date.
  4. Check open campaigns for emails and reminders sent after renewal.
  5. Reconcile recipients and time windows again, because the delayed sends may trigger usage in the new period.

General activation and renewal checks are described in Activate, check, and renew Sophos Fusion licences.

Resolving typical deviations

Usage is higher than expected

First, check whether the combined figure from the License Usage Summary is being compared with a Phish Threat-only estimate. Then combine all campaigns with sends in the past 30 days and deduplicate their recipients. Training-only campaigns also count. For Flex, also check whether part of a staggered campaign fell within the current billing period.

Before evaluating the figures, wait for the next daily recalculation of Phish Threat usage and, for Sophos Email, the update that may take up to four hours. If the discrepancy remains in the latest scan, compare specific user identities, sending data, and mailboxes rather than campaign sizes alone. Only then should you discuss a quantity adjustment with the Sophos partner.

Usage does not decrease after a campaign is deleted

This is expected. Deleting or ending a campaign does not undo messages already sent. Record the affected recipient’s last send date and check the display again after the rolling 30-day window has elapsed. Repeatedly deleting and recreating the campaign will not help.

The report is missing or does not show the expected licence

Check the following points in order:

  1. Are you signed in to the correct Sophos Fusion tenant?
  2. Is Sophos Phish Threat displayed under Profile icon > Licensing with a valid term?
  3. Does your administrator role have sufficient access? If views or campaign functions are missing, check the assigned administrator role.
  4. Has the campaign email already been sent, or is the user only scheduled so far?
  5. Are you expecting a combined report figure even though no relevant usage occurred in the period under review?

If the product or term is already missing under Profile icon > Licensing, this is not a reporting issue. Check activation and tenant assignment with the Sophos partner.

The Flex billing does not fit the calendar month

First, distinguish the invoice month from the usage window for the reading, which usually occurs on the 22nd, and compare that window with the actual sending times. Campaigns with interval-based sending can move some recipients into the next period. Because the reading date may shift for operational reasons, ask the Sophos partner to confirm the actual date if the total still appears implausible. Provide the campaign list, sending data, and invoice.

Unexpected emails are sent after renewal

Pending campaign emails and reminders may be sent after renewal. Therefore, follow a clear stop/go sequence before renewing:

  1. Check active campaigns, staggered sends, and reminders individually.
  2. Pause the affected campaign. With staggered sending, this prevents emails that have not yet been scheduled from being sent; emails already sent cannot be recalled.
  3. While the campaign is active, set the end date so that no further campaign emails or reminders are sent. A campaign that has already ended can no longer be edited.
  4. Check that no unwanted sends remain pending. Only then renew the licence.