Sophos Phish Threat: Calculating licensing and usage correctly
What matters is not the number of campaigns, but which unique users receive campaign emails. The combined licence report, billing boundaries, and …
These guides help administrators license and set up Sophos Phish Threat, prepare reliable email delivery, run targeted campaigns and training, evaluate results, and meet governance requirements.
The articles follow the administrative workflow: licensing and onboarding, delivery preparation, campaign design and targeting, training, user reporting, analysis, troubleshooting, and governance.
Understand licence consumption and calculate usage before rolling out simulations.
What matters is not the number of campaigns, but which unique users receive campaign emails. The combined licence report, billing boundaries, and …
Verify user domains, prepare the environment, and follow the supported setup sequence.
Getting started with Sophos Phish Threat covers domain verification, email delivery, campaign creation, and evaluation.
Configure direct delivery, sender exceptions, Microsoft 365, and Google Workspace, and resolve delivery failures.
If Phish Threat emails are missing, check the campaign schedule and Bounced Mailboxes first. Then rule out recipient and synchronization errors, …
A practical runbook for permissions, provider selection, activation, quick testing, Safe Links, troubleshooting, and rollback of API direct delivery.
A secure allowlisting process for mail gateways, proxies, firewalls, and scanners—with dynamic Sophos values, validation, and rollback.
This runbook distinguishes Graph-based direct delivery from the SMTP route and explains the Microsoft 365-specific permission, Defender, and routing …
This guide limits the Google Workspace exceptions to Sophos Phish Threat and shows setup, acceptance tests, troubleshooting, rollback, and regular …
Build, launch, monitor, and manage individual phishing simulation campaigns.
Campaigns are managed differently depending on their status. Drafts can be completed or discarded, while active campaigns can be paused and adjusted …
Set up a single Phish Threat campaign from its objective, attack, and training through recipients, testing, scheduling, and validation.
Plan recurring simulations and operate campaign series safely.
Campaign series automate recurring attack simulations or security training. Before launch, check the series type, domains, recipients, passing …
Automatically enrol new users and keep campaign audiences current.
Automatic enrollment adds users created in Fusion in the future to a campaign or series. Their actual start depends on the campaign type and series …
Configure training senders and the automated emails that accompany user training.
The training sender applies to automated training messages, not simulated attack emails. A verified domain, a successful test, and checks for the …
Deploy and operate the Outlook add-in for reporting suspicious messages.
From the target mailbox and SophosLabs setting through supported Outlook clients and Microsoft 365 assignment to reporting tests and migration from …
Review campaign outcomes, user responses, and available reports.
An administrative process for reliable metrics, delivery and user events, risk prioritization, CSV/PDF exports, follow-up actions, and data …
Investigate missing images and open-tracking results that do not match expectations.
An Open is normally generated when the external 1×1 pixel is retrieved, but Sophos Phish Threat can also add one after a Click. An Open therefore …
Plan data protection, retention, access, and governance for phishing simulations.
A governance runbook for approved Sophos Phish Threat campaigns, covering data minimization, clear responsibilities, restricted access to results, and …