Transfer Sophos Firewall to another Sophos Central account
Use Transfer firewalls to move the license and account assignment of a Sophos Firewall to another Sophos Central account. The administrator of the target account must accept the request within three days.
The Central management registration is not transferred. If central management must also move, the firewall must then be deregistered from the old account and registered in the new account separately.
⚠️ Important: Sophos requires confidential data to be removed before the transfer. When ownership or service provider changes, local configuration, access credentials, certificates, backups, and documentation must therefore be handed over or cleaned up separately. The account transfer does not do this.
This process is suitable for an incorrect account assignment, tenant consolidation, or a change of owner or service provider. It is not suitable for hardware replacement or migration to another appliance.
What is transferred—and what is not
- Transferred: the firewall’s license and claim assignment.
- Remain unchanged: the local firewall configuration and local administrators, MFA, WebAdmin, and SSH.
- Not transferred: Central Firewall Management, Central Reporting, and Central backups. They remain assigned to the existing account.
The target account does not automatically receive WebAdmin or Central Management access to the firewall. License assignment, local administration, and Central Management are three separate responsibilities.
Check before the transfer
First, choose the correct operation:
- To move to another Central account:
Transfer firewalls - To transfer a subscription to another firewall:
Transfer subscriptions - To migrate the configuration to another appliance: backup, restore, or a migration project
Before starting:
- Record the serial number, model, source account, and target account. The serial number can be found using these methods.
- Confirm the email address of an administrator in the target account and agree on when the request will be accepted.
- Record the current license status, expiration date, and future responsibility for renewal and support.
- Check whether the appliance is a Hardware as a Service (HWaaS) device. HWaaS firewalls cannot be transferred between Central accounts.
- For HA, record both serial numbers, the HA mode, and the Initial Primary. Sophos does not clearly document which devices in an HA pair must be selected for an account transfer, so confirm the selection with the partner or Sophos.
- Clarify partner, enterprise, and other special models with the responsible partner or Sophos in advance; this standard procedure applies to Sophos Central Admin.
- If Central Management must also move, download any required Central backups first. When a firewall is removed from Central Management, Sophos deletes the associated Central backup files.
A firewall backup is not required for an account transfer alone. However, when the operator changes or additional technical changes are planned, a current backup and the Secure Storage Master Key should be available. The procedure is described in Create or restore a Sophos Firewall backup.
When changing service providers, also establish who will take responsibility for local administration, API access, certificates, VPN profiles, support cases, and renewal. The transfer does not remove any existing local access held by the previous operator.
Start the transfer in the source account
- In the Sophos Central source account, open the profile icon.
- Open Licensing > Firewall licenses.

- Select the correct firewall by its serial number.
- Click Transfer firewalls.

- Enter the email address of the administrator in the target account.
- Read and select the required confirmations.
- Check the details and submit with Confirm.

An airplane icon next to the firewall indicates the pending transfer. The sender also receives a confirmation email.
Accept the transfer in the target account
- Sign in to the target account within three days.
- Open Licensing > Firewall licenses from the profile icon.
- Click Accept firewalls.
- Verify the firewall by its serial number and model.
- Select the firewall and accept it with Accept.
- Check the subscription and expiration date in the firewall details.
After acceptance, the administrator of the source account receives a confirmation. If the request is not accepted within three days, Sophos rejects it automatically and the transfer must be started again.
Check after the transfer
- Find the firewall in the target account by its serial number and check the license details.
- Verify that the firewall is no longer listed as a transferable license assignment in the source account.
- If the license status on the appliance appears outdated, run Synchronize under
Administration > Licensing. - Check Central Management and Reporting separately; a successful license transfer does not confirm these services.
- Document responsibility for renewal, support, and local administration.
- When the operator changes, check local administrators, MFA, WebAdmin, SSH, and Device Access separately.
If Central Management must also move, first download the required Central backups. Then deregister the firewall from the old account, register it in the new account, and accept the Central services there. Connect Sophos Firewall to Sophos Central describes this separate procedure.
If the transfer does not work
- Transfer firewalls is missing: Check the role, Central portal being used, and HWaaS status.
- The request is no longer available: Check the three-day deadline and restart the transfer in the source account.
- The firewall does not appear in the target account: Check the target account, administrator email address, and serial number.
- The license status on the firewall is outdated: Run Synchronize under
Administration > Licensing.