Use Sophos Central Account Health Check correctly
Account Health Check shows whether Sophos Central finds recommended protection functions, device modes, and security-relevant settings in the tenant. It is a useful operational tool, but not a penetration test, compliance certificate, or complete risk assessment.
The current path is My Environment > Account Health Check. Available checks depend on licenses and managed products.
What the score actually means
Central shows an overall score, scores by security area, and individual checks. Every value ranges from 0 to 100. The Overall Health Score is the lowest individual value, not the average of all checks.
Calculation differs by check. Examples include:
- the percentage of endpoints or servers in the correct Agent Mode,
- the percentage of devices with active Tamper Protection,
- a globally enabled or disabled protection function,
- the percentage of centrally managed firewalls in the backup schedule,
- policy and exclusion states compared with Sophos recommendations.
A value of 100 means this particular Sophos check found no deviation. It does not assess custom firewall rules, identity risks outside Sophos visibility, backup restore tests, or the business necessity of an exclusion, among other things.
Understand score formulas
The overall score is always the lowest score among active Health Checks. Within a security area, Central likewise uses the lowest associated individual check. A very good average therefore cannot hide one weak protection area.
| Health Check | Calculation |
|---|---|
| Endpoint or Server agent mode | Percentage of devices in the correct Agent Mode and therefore carrying all licensed software. 900 of 1,000 applicable devices produce 90 points. |
| Endpoint or Server tamper protection | Percentage of devices with locally active Tamper Protection. Global tamper protection produces 100 when enabled and 0 when disabled. If the global switch is off, the Endpoint and Server checks also fall to 0. |
| Threat Protection Policies | Central deducts 10 points from a policy for every setting that does not match the recommendation. For several policies of the same type, it calculates an average. Options without a Sophos recommendation are not scored. |
| Policy Exclusions and Global Exclusions | Central deducts 20 points for each exclusion Sophos identifies as unsafe. With several policies, it calculates an average. The check looks only for especially risky patterns and does not assess every unnecessary exclusion. |
| MDR authorized contact | A stored contact produces 100; a missing contact produces 0. Central does not test actual reachability. |
| Protection improvement | With one recommended data-sharing option off, 60 points remain; with two, 30; with all three, 0. |
| Automatic firewall backups | Never produces 0. With a daily, weekly, or monthly schedule, the score is the percentage of relevant firewalls included. Two of three firewalls produce 66 points; all produce 100. |
A dash instead of a score means Central cannot currently calculate or display the value. It must not be interpreted as 100 or “not applicable.”
Filter Health Check data by product
The product filter changes the overall and individual scores and the issues shown. It is available only with MDR Plus and at least one managed firewall.
- All health checks shows all available security areas.
- MDR breach protection warranty shows areas relevant to that warranty but omits Firewall and automatic firewall backup warnings.
- Network limits the view to the firewall Health Score and automatic firewall backup warnings.
Always document a filtered score together with the active filter. Otherwise, two screenshots from the same tenant can show different overall scores even though nothing changed technically.
Prioritize deviations
Order remediation by potential impact and reach:
- Globally disabled protection functions such as Tamper Protection.
- Missing or incorrect protection on many devices.
- Unsafe global or policy exclusions.
- Unprotected or incorrectly licensed Agent Modes.
- Missing firewall backups and operational hygiene.
A low score caused by a disabled global switch is more urgent than a small, explainable group of excluded systems. Conversely, do not automatically ignore an apparently harmless exclusion if it opens a broad path or process.
Use Auto-Fix only after change review
For supported checks, Central offers Fix automatically. It applies Sophos recommendations to every affected device or setting. This can be useful, but it changes production policies and global settings.
The action depends on the check. For Endpoint Threat Protection and Server Threat Protection, Central resets every option assessed by the check to its recommended value in all affected policies. For Endpoint Agent Mode, it installs the complete licensed software set on all affected computers. For Global Exclusions, it removes global exclusions identified as unsafe. For Policy Exclusions, it deletes such entries from all affected Endpoint and Server policies. In each case, select Fix automatically in the warning and confirm the change again. The resulting actions can then be traced in the Audit Log.
Before Auto-Fix, review:
- Which objects and devices are affected?
- Which setting will change specifically?
- Are there medical systems, production equipment, VDI, or other sensitive exceptions?
- Is there a maintenance window and technical owner?
- How will the function be tested after the change?
- Is rollback documented?
After Auto-Fix, do not merely wait for a score of 100. The Audit Log must show the expected changes, affected devices must remain healthy, and the business application must be tested. See Analyze and retain Sophos Central Audit Logs.
After the next refresh, a green exclusion check means only that Central no longer recognizes any particularly unsafe pattern assessed by that check. It is not a complete review of all exclusions. Continue reviewing necessity, scope, and ownership regularly.
The Protection improvement check can also flag tenant-wide sharing of Threat Graph data, Intercept X data, and malware samples.
Correct an Endpoint Threat Protection policy manually
To avoid tenant-wide Auto-Fix, open the name of the affected policy in the Health Check warning. Central opens Settings, displays a warning at the top, and marks settings that differ from the Sophos recommendation in red.
For the Base Policy, Reset can restore recommended values. For a derived policy or deliberate individual correction, enable or reconfigure each red option. Understand the reset boundary: Device Isolation and SSL/TLS decryption of HTTPS websites are not enabled by Reset. If required, assess and enable them separately. Finish with Save at the top and verify that the warning and red markings disappear.
Correct a Server Threat Protection policy manually
The workflow is the same for Server policies: open the policy name from Health Check, inspect red deviations under Settings, and use Reset for the Base Policy or targeted correction for other policies. Then save with Save.
The Server reset has different exceptions from the Endpoint reset. It enables neither SSL/TLS decryption of HTTPS websites nor Enable CPU branch tracing. Enable SSL/TLS Decryption manually only after compatibility testing. CPU Branch Tracing is not required for the recommended health state; if already enabled, it can remain enabled. After saving, the tab must show recommended protection.
Correct Endpoint Agent Mode manually
Agent Mode determines whether a computer receives only Endpoint Protection, the XDR components, or XDR Sensor. When Account Health warns of Product unassigned or Upgrade available, the device does not use the complete licensed software set.
The affected-computer count in the warning links to the filtered device list. If the link fails, open My Environment > Computers & Servers and filter Agent mode status for Product unassigned and Upgrade available. First identify obsolete or unneeded computers and remove them from Central in a controlled manner. The warning remains until cleanup or software assignment occurs.
For active computers, select the entries and open Manage Software. Under Manage Device Software > Agent mode, Central shows variants available with the license. Select the intended mode and save with Save. The Agent mode column initially shows the pending change. Installation occurs during the computer’s next online update cycle, usually within about an hour. Completion requires not only a cleared warning but the installed mode, a healthy agent, and the expected components on the device.
Correct Server Agent Mode manually
The same basic workflow applies to servers, but assess scope separately. The affected-server count opens the list. Alternatively, under My Environment > Computers & Servers, filter Agent mode status for Product unassigned and Upgrade available. Remove servers that no longer exist in a controlled manner; otherwise, the warning remains.
Select active servers and assign the licensed mode through Manage Software > Manage Device Software > Agent mode. After Save, the Agent Mode column initially shows the planned installation. Central installs components during the next online update cycle, usually within about an hour. For production servers, also review the maintenance window, restart requirement, business application, and resource usage.
With Fix automatically, Central installs the full licensed software set on every affected server after confirmation. Review scope before confirmation, then verify the change in the Audit Log and on representative servers.
Enable Tamper Protection on affected devices
If Tamper Protection is globally disabled, correct Global Settings > Tamper protection first. Only then can it be enabled effectively on individual computers or servers.
The affected-computer count in the Health warning opens the appropriate list. Alternatively, filter the computer or server list for Computers with tamper protection turned off. Select affected devices and choose Turn on tamper protection. The workflow is the same for computers and servers. Then reopen My Environment > Account Health Check and also verify on the device that Tamper Protection is active.
With Fix automatically, Central enables protection on every affected device. Before confirmation, determine whether any systems were deliberately and temporarily unlocked for an authorized support or recovery operation. Verify the change in the Audit Log.
Correct automatic firewall backups
Only licensed firewalls that are connected to and managed by Central count toward the Health Score. Fix automatically > Turn on changes a Never schedule to monthly on the first day by default and adds missing relevant firewalls to the schedule.
For manual control, open My Products > Firewall Management > Backup. Under Schedule Backup, select frequency and weekday, or date for monthly backups. The run starts at 08:00 in the Central data region’s time zone; this time cannot be changed. Every licensed firewall must be assigned to the schedule. After saving, reopen Health Check, wait for the next run, and also test a restore procedure because 100 points confirms the schedule, not recoverability.
Add an MDR Authorized Contact
This check appears only with an MDR license. Under My Products > MDR > Settings > Managed Detection and Response > Authorized Contacts, enter the primary authorized contact and optionally additional contacts, then save with Save.
At least one person must be reachable by the MDR Operations Team and organizationally authorized to make incident decisions. Test the shared address, phone number, time zone, deputy, and escalation authority. The green check confirms only a stored record, not actual reachability.
Correct Protection Improvement deliberately
The check assesses Send Threat Graph data to Sophos, Send Intercept X data to Sophos, and Malware sample submission. If one or two switches are off, the warning names the affected settings. Selecting a name opens the responsible page; enable it after privacy approval, save with Save, and repeat for other named settings. If all three are off, the card does not name individual settings; review the MDR telemetry and Account Preferences completely.
Fix automatically enables all Sophos-recommended sharing after confirmation. Do not do this merely to achieve 100 points; approve data types, purpose, region, and responsibility first. Then verify My Environment > Account Health Check, the Audit Log, and all three actual switches.
Remove unsafe global exclusions manually
In the Health Check warning, first open the arrow beside every flagged exclusion. Central explains why it identifies the pattern as risky. The displayed exclusion count then links to Global Exclusions. Select every truly unsafe entry, remove it with the cross on the right, and save the change with Save at the top.
Reopen My Environment > Account Health Check. A green check means only that Central found none of the particularly unsafe patterns it knows. It confirms neither the business necessity nor the safety of all remaining exclusions. Keep global exclusions to a minimum and use a more narrowly scoped policy exclusion where possible.
Remove unsafe policy exclusions manually
For Policy Exclusions, the arrow in the warning also shows the reason for each exclusion. Because one policy or several policies may contain multiple exclusions, assign each warning individually. Selecting the policy name opens its Exclusions area. Delete flagged entries with the cross on the right and save the policy with Save.
The workflow applies to Endpoint and Server Threat Protection policies. Then review the check again under My Environment > Account Health Check. Green again describes only the especially risky patterns assessed by Sophos. Broad paths, process exclusions, or whole-drive exclusions additionally require recurring review of scope, owner, and expiration date.
Correct global Tamper Protection manually
When Global Tamper Protection is off, no device has this protection even if its individual switch was previously enabled. Open Tamper Protection from the Health Check warning, enable it under Global Settings > Tamper protection, and save at the top right with Save. Reopen My Environment > Account Health Check; the global check must show the enabled state.
The global switch only makes the function available tenant-wide. Individual endpoints or servers can still lack Tamper Protection. Open any additional warning for those devices and remediate each one. The measure is complete only when both the global state and device check are clean.
Document Snooze deliberately
Snooze temporarily defers a deviation. It does not fix the cause or improve the score. A snoozed check appears gray.
Snooze closes Health Check alerts for six months. If Snooze is ended earlier while the score remains below 100, Central reopens the alert.
Central continues updating the check during Snooze. If all underlying deviations are corrected, Central cancels Snooze automatically. The reason and comment can be edited during the period.
Every Snooze needs a reason, owner, and internal due date. Sophos’s six months are not a sensible default for every organization. Reassess critical deviations much sooner.
Alerts and notifications
When a Health Check score falls below 100, Central creates a separate medium-priority alert after a delay of at least about ten minutes. When the score returns to 100, Central closes the alert automatically.
Alerts appear under My Environment > Alerts as Device and Platform Health. Email notifications require separate configuration. A practical recipient and escalation model is covered in Configure Sophos Central alert emails and notifications.
Understand Firewall and Endpoint checks
Account Health is a Central-wide interface that combines several products. Remediation remains product-specific.
For Endpoint checks, inspect Agent Mode, policies, exclusions, and Tamper Protection in the Endpoint context. Operational alert and health handling is described in Handle Sophos Endpoint alerts and Account Health.
For firewall backups, only licensed, Central-connected, centrally managed firewalls count. A schedule of Never produces zero points. With daily, weekly, or monthly backups, the score depends on whether every relevant firewall is included. Health Check does not confirm that a backup can be restored successfully.
With an MDR license, Central also checks for at least one MDR Authorized Contact. That person must actually be reachable by the MDR Operations Team and internally authorized to make incident decisions. A former employee or shared address may formally satisfy the check but is not a reliable incident contact. Test the contact, deputy, and escalation number regularly.
Compare with other organizations
Under each Health summary chart, Other organizations shows the average for similarly sized organizations in the same Central data region. A dash appears when no reliable comparison is available. Bar charts for individual Security Features also compare the tenant’s score with this average.
The trend arrow and number show how the Overall Health Score changed over the last four weeks. A dash here means Central cannot yet calculate a trend, not that the score remained unchanged.
Show scores for organizations with a similar number of devices lets administrators select another size range. This is useful when many inventoried devices are currently unused or comparison with larger environments is desired. The selection changes the benchmark, not the tenant’s Health Score.
This comparison is a rough benchmark, not a target. An organization with stricter requirements may remain inadequately protected despite scoring better than peers.
Many unused or incorrectly inventoried devices also distort the size comparison. Clean up device inventory, license usage, and inactive systems first.
Retain a Health Check report
The download icon at the top right creates a PDF snapshot. It includes Health Summary, feature scores, individual checks, and recorded comments. If co-branding is configured, company or partner details appear in the report.
The PDF is suitable for a review or change approval but proves only the state at export time. Record the tenant, date, responsible administrator, and open actions in the filename or accompanying log for the next review. A report without ownership is not closed security evidence.
Monthly operational workflow
A traceable review includes:
- Record the overall score and four-week trend.
- Identify new and deteriorated individual checks.
- Determine affected devices, policies, and products.
- Accept the deviation, correct it manually, or remediate it with controlled Auto-Fix.
- Verify the Audit Log and technical function.
- Review Snoozes with an owner and internal due date.
- Document open alerts and recurring causes.
A recorded or exported monthly value is more useful than a score brought to 100 once without change evidence.
Common problems
Score does not change immediately
Central processes changes with a delay. First verify that the affected policy was saved, assigned to the correct object, and received by the device. Only then assume a platform delay.
Auto-Fix changes more devices than expected
Auto-Fix follows the check’s scope rather than a freely selected pilot group. Review the affected set before confirmation. Manual staged correction is often safer for sensitive environments.
Firewall backup remains yellow
Every licensed and Central-connected firewall must be in the backup schedule. Also check the Central connection, license state, and schedule.
Snooze is reported as resolved
Snooze defers remediation and temporarily closes the associated alert. The technical deficiency remains and the score turns gray, not healthy.