Transfer Sophos Firewall to another Sophos Central account
A Sophos Firewall can be transferred to another Sophos Central account if registration and license management are to be located in a different account in the future. This is relevant, for example, when changing companies, clearing out clients, changing service providers, incorrectly registered firewalls or consolidated central structures.
The distinction is important: The transfer affects the registration of the appliance and the license assignment in the Sophos Central context. No local firewall configuration is transferred, no WebAdmin access to the firewall is created, and no central backups, reports, logs or support access are moved. If the firewall is managed via Sophos Central, this management assignment must also be checked separately.
For the terms and portals, Sophos portals: SophosID, Central, support and firewall access fits first. The serial number of the affected firewall should be documented in advance; The procedure is in Find the Sophos Firewall serial number.
⚠️ Important: An account transfer is not a backup, a migration process or an authorization concept. The target account then manages the registration and license allocation, but does not automatically have access to the firewall, its configuration, local backups or central reporting data.
When a transfer makes sense
A transfer makes sense if the firewall is registered in the wrong Sophos Central account or license responsibility and ownership need to be changed.
Typical cases:
- The firewall was accidentally registered in the wrong central tenant.
- A company consolidates multiple Central accounts.
- A customer changes service provider or license partner.
- An appliance is transferred to another organizational unit.
- License management and firewall operation should be separated organizationally.
This does not mean a technical replacement of the firewall, a backup/restore, an HA migration or the transfer of local admin access. For backup and recovery topics, Sophos Firewall Backup and Restore Properly Plan is the better article.
Account transfer or subscription transfer?
Sophos Central distinguishes between two similar-sounding processes. These should be separated cleanly before the change.
- Transfer Firewall to Another Central Account: The firewall registration and license view switches to a different Sophos Central account. Wrong tenant, company change, service provider change, account consolidation
- Transfer subscriptions between firewalls: A paid subscription is moved from one firewall to another firewall. Replacement device, model change, license was activated on wrong appliance
- Migrate or replace firewall locally: Configuration, interfaces, ports, HA, backups and restores are technically planned. Hardware Replacement, XG to XGS Migration, Reimage, Site Migration
This article covers the first case: a firewall is transferred between Sophos Central accounts. If a license is intended for a replacement device or another appliance, the process is different and must be checked with model, subscription, serial number and, if necessary, RMA context.
What is transferred and what is not
- Registration/License Assignment: will be transferred to the target account
- local firewall configuration: remains unchanged on the firewall
- local admin users: are not changed automatically
- Device Access / WebAdmin / SSH: remains unchanged
- Central Firewall Management: must be checked separately
- Reporting and Logs: must be evaluated separately depending on the Central context
- Backups: are not transferred and are not replaced by the transfer
- Support Access: does not arise automatically from the transfer
The new account does not automatically receive WebAdmin access to the firewall through the license transfer. Local access, MFA, device access and admin roles remain separate topics. Securing Sophos Firewall access: Configuring device access correctly is relevant for local access hardening.
If the firewall is managed centrally or integrated into Central Reporting, the status should be documented beforehand. Activate Central Firewall Reporting is suitable for Central Reporting. Connect Sophos Firewall to Sophos Central is suitable for the basic structure of the Central connection.
Preparation before transfer
Before the transfer, it should be clear who starts the process, who accepts it and which account is responsible afterwards. This prevents typical problems with incorrect SophosID accounts, expired invitations or unclear license responsibility.
Check in advance:
- Document serial number, model and current Central account.
- Confirm an administrator email address in the target account.
- Clarify whether the transfer only affects license/registration or whether Central Firewall Management also needs to be re-registered.
- Record current license status, expiration dates and renewal responsibilities.
- Check the backup time and secure storage master key if technical work is planned in parallel.
- Evaluate central reporting, firewall management, support access and partner responsibility separately.
- Prepare internal asset, support and contract documentation.
Sophos advises that sensitive data must be removed before transfer. In practical terms, this means: If the firewall changes owners or clients, local configuration, backups, reports, logs, VPN data, certificates and access must not remain silently with the wrong operator. The account transfer itself does not automatically clean up this data.
Transfer firewall to Sophos Central account
The transfer is started in the source account in Sophos Central in the Licensing > Firewall licenses area.
Procedure:
- Sign in to the source Sophos Central account with an authorized account.
- Open the profile or account menu.
- Open Licensing > Firewall licenses.

- Switch to the Firewall licenses tab.

- Select the firewalls to be transferred.
- Select Transfer firewalls.

- Enter the email address of the target account.
- Read and confirm the required confirmations carefully.
- Check the information and trigger the transfer with Confirm.
- Pay attention to the confirmation email.

The exact labeling may vary slightly depending on the Sophos Central view or language. It is crucial that the firewall is selected in the license area and transferred to the correct target account.
Accept transfer in destination account
The transfer is not yet completed after sending. The administrator in the target account must actively accept the transfer. According to Sophos, the request will be automatically rejected if it is not accepted within three days.
Procedure in the target account:
- Sign in to Sophos Central with an administrator of the target account.
- Open the profile or account menu.
- Open Licensing > Firewall licenses.
- Select Accept firewalls.
- Check and accept the firewalls offered.
- Check serial number, model, name and license details.
The administrator in the source account then receives confirmation that the transfer has been accepted. If no confirmation is received or the firewall is not visible in the target account, first check the target account, email address, spam filter, role rights and the expiry of the three-day period.
Check after transfer
After the transfer you should not only file the confirmation email. A brief operational check is important:
- In the target account, check whether the firewall appears under the firewall licenses.
- Check serial number and model against documentation.
- Check license status and term.
- Check whether the firewall in the source account is no longer mistakenly listed as a license-relevant device.
- Verify that Central Firewall Management or Reporting continues to function as expected.
- If you want Central Management to switch to a different account, schedule local de-registration and re-registration separately.
- Do not automatically expand local firewall access, but rather manage it consciously.
- Update internal inventory, license, renewal and support documentation.
If support cases are opened afterwards, the new account assignment should be known internally. The support process is described in How to open a support ticket with Sophos.
Typical errors
Incorrect target account
The email address of the target account should be checked carefully before submitting. Otherwise, confusion can easily occur if there are multiple tenants, service provider accounts or historical SophosID accounts.
Transfer confused with firewall management
A license transfer does not automatically mean that the firewall will be managed centrally in the new account. If Central Firewall Management is used, the registration should be checked separately.
Request expires
The recipient must accept the transfer within the acceptance period. If the request expires, the transfer must be restarted in the source account. You should therefore coordinate the timing with the target account and not trigger it shortly before holidays, tenant changes or admin absences.
Subscription transfer chosen instead of account transfer
If the firewall is in the correct account but you want a subscription to a different device, Transfer subscriptions is the correct operation. However, if the firewall itself is to be visible in another central account, Transfer firewalls is required. The mix-up costs time and can lead to false expectations when it comes to replacement devices.
Local admin rights are expected
The target account does not automatically receive local WebAdmin rights. Admin users, MFA, Device Access and SSH remain local security decisions of the firewall.
Documentation is not updated
After the transfer, the asset list, license management, support responsibility and renewal process should be adjusted. Otherwise it will be unclear which account is relevant for the next support case.
Checklist
Before the transfer:
- Serial number, model, source account and destination account documented.
- Administrator in the target account is known and accessible.
- Clarified whether only license/registration or also central management is affected.
- License terms, renewal responsibility and support responsibility checked.
- Confidential local data is evaluated separately in the event of a change of owner or client.
- Backup and SSMK checked if technical changes take place at the same time.
During the transfer:
- Firewall clearly selected in the source account under Licensing > Firewall licenses.
- Destination email address carefully checked.
- Transfer confirmation documented in the source account.
- Acceptance in the target account scheduled within three days.
After the transfer:
- Firewall found in target account using serial number and model.
- License details and expiry dates checked.
- Central firewall management, reporting and support access controlled separately.
- Local admin access, MFA and device access continue to be consciously evaluated.
- Asset, license, renewal and support documentation updated.