Use Sophos Central Global Settings and policies correctly
Many Sophos Central misconfigurations are caused not by a wrong value but by an incorrectly assessed scope. Global Settings can affect the whole tenant or several products. Policies, by contrast, are assigned to specific users, devices, or groups.
Find Global Settings
Open Global Settings using the gear icon in the top taskbar. The page has four areas:
- Platform for Directory Service, Notifications, EAP, and other platform functions,
- Access Control for administrators, roles, sign-in, and API credentials,
- Protection and Remediation for shared allow, block, exclusion, and response functions,
- Products and Services for product-specific global settings.
Frequently used entries also appear under Popular settings. After first use, Recently visited shows the last opened settings. Both shortcuts save navigation but do not replace checking the product and scope.
Use the filter icon beside the search field to select one or more products or services, then select Apply. Reset removes filters. Opening My Products > Product > Settings makes Central set the relevant product filter automatically; change or reset that filter to reach settings for other products.
The search box automatically filters the left menu while typing. Hover over a page or group name for a short purpose description. Product tags show which products a setting affects by default. The three-dot menu above the left navigation can turn Show product tags off and on. Tags remain particularly useful for Shared Settings because a familiar name alone does not show the real product boundary.
Distinguish global settings from policies
| Type | Example | Scope |
|---|---|---|
| Platform setting | Directory Service or federated sign-in | Tenant or identity source |
| Global protection list | Allowed application or global exclusion | All affected products and devices unless narrower logic applies |
| Product setting | Endpoint Proxy or Firewall Backup | Entire product or all enrolled devices |
| Policy | Threat Protection for a pilot group | Assigned users, devices, or groups |
A policy is the preferred place when different groups require different values. Global Settings is suitable for shared platform functions and deliberately tenant-wide standards.
Sophos describes Global Settings as settings that apply to all users and devices unless you define exclusions. This is the key question to answer before saving: should the change really reach such a broad audience? If only one department, a pilot group, or selected devices need different settings, an assigned policy is usually the more controlled layer.
Create or edit a policy
Policies are managed from the relevant product page, not directly in Global Settings:
- Go to My Products > Product > Policies.
- To create a policy, select Add Policy in the upper right.
- If the Add Policy dialog appears, select the required feature. For Endpoint Protection, also select the policy type.
- On the policy details page, assign the target users or devices, configure the selected feature, and enable or disable the policy.
To edit a policy, go to My Products > Product > Policies, open the policy type, and then select the policy. A policy contains the settings for a feature as a unit. You cannot, for example, distribute Threat Protection settings across several matching policies and expect Central to combine them for each device.
Additional policies are only needed when you want to deviate from the shared standard. Sophos supplies the Base Policy for some features with best-practice settings already configured. Network-specific features such as Application Control or Peripheral Control must instead be configured for your environment. Alongside settings and assignments, a policy can specify whether it is enforced and whether it expires; an expiry is useful for a time-limited pilot, for example.
Understand policy priority
Every function has a Base Policy. It cannot be deleted or disabled and applies when no more specific policy matches.
Additional policies are evaluated from top to bottom. The first matching policy wins. Place specific policies above general rules. A user or device does not automatically combine individual settings from multiple policies for the same function.
User policies follow the person across their devices. Device policies apply independently of the signed-in person. When both types are supported for the same function, order still decides.
Do not infer the effective policy only from its position in the list; verify it at the target. On a computer’s details page, the Policies tab shows the policies that apply. For a user group, go to My Environment > Users & Groups > Groups > Group > Policies. You can open a policy there, but remember that editing it affects every group to which that policy is assigned.
Check role permissions before editing
The assigned administrator role determines which products and policy actions are available. For a Custom Role, check product access separately from policy permissions: Enable policy assignment allows an administrator to turn existing policies on or off and assign targets; Enable policy management also allows them to add, edit, and delete policies. Sophos only allows one of these two policy options to be active in a Custom Role.
If a button is missing or a page is read-only, check the role first. A permanently broader role is not an appropriate workaround; have a Super Admin grant the required capability and product access specifically.
Perform a safe change
Determine scope and dependencies before a global change:
- Identify affected products, devices, and users.
- Preserve the current setting and an export or screenshot.
- Document the business need and expiration date.
- Where possible, use a narrower policy for a pilot group first.
- Perform functional, security, and performance tests.
- Verify the Audit Log, the policy actually applied, and the device effect.
- Test or schedule rollback.
Assess automatic recommendations critically
Account Health can flag global or policy settings and sometimes offer Fix automatically. Such a correction follows the Sophos recommendation but does not know every local application and operating requirement.
Treat Auto-Fix like a normal change. Afterward, verify the Audit Log, policy assignment, device health, and business application. Review evidence with Analyze and retain Sophos Central Audit Logs; Use Sophos Central Account Health Check correctly explains the boundaries of automatic recommendations.
Common problems
Change affects more devices than expected
The setting was global or in a broadly matching policy with high priority. Check scope, product filters, and assignments. Roll back in a controlled way rather than adding a second, even broader exclusion.
Expected policy does not apply
The policy is disabled, assigned incorrectly, or below a more general matching policy. For a computer, use the Policies tab on its details page to verify which policy actually applies. For a group, also check that the expected policy appears under My Environment > Users & Groups > Groups > Group > Policies.
Custom administrator can see but not change a policy
The role may only have Enable policy assignment, or it may lack access to the affected product. Changes require Enable policy management; a Super Admin must grant that permission deliberately.
Global Settings appears empty
A product filter is active or the role cannot access the products concerned. Reset filters and inspect the role details.