Skip to content
Avanet

Use Sophos Central Global Settings and policies correctly

Many Sophos Central misconfigurations are caused not by a wrong value but by an incorrectly assessed scope. Global Settings can affect the whole tenant or several products. Policies, by contrast, are assigned to specific users, devices, or groups.

Find Global Settings

Open Global Settings using the gear icon in the top taskbar. The page has four areas:

  • Platform for Directory Service, Notifications, EAP, and other platform functions,
  • Access Control for administrators, roles, sign-in, and API credentials,
  • Protection and Remediation for shared allow, block, exclusion, and response functions,
  • Products and Services for product-specific global settings.

Frequently used entries also appear under Popular settings. After first use, Recently visited shows the last opened settings. Both shortcuts save navigation but do not replace checking the product and scope.

Use the filter icon beside the search field to select one or more products or services, then select Apply. Reset removes filters. Opening My Products > Product > Settings makes Central set the relevant product filter automatically; change or reset that filter to reach settings for other products.

The search box automatically filters the left menu while typing. Hover over a page or group name for a short purpose description. Product tags show which products a setting affects by default. The three-dot menu above the left navigation can turn Show product tags off and on. Tags remain particularly useful for Shared Settings because a familiar name alone does not show the real product boundary.

Distinguish global settings from policies

TypeExampleScope
Platform settingDirectory Service or federated sign-inTenant or identity source
Global protection listAllowed application or global exclusionAll affected products and devices unless narrower logic applies
Product settingEndpoint Proxy or Firewall BackupEntire product or all enrolled devices
PolicyThreat Protection for a pilot groupAssigned users, devices, or groups

A policy is the preferred place when different groups require different values. Global Settings is suitable for shared platform functions and deliberately tenant-wide standards.

Sophos describes Global Settings as settings that apply to all users and devices unless you define exclusions. This is the key question to answer before saving: should the change really reach such a broad audience? If only one department, a pilot group, or selected devices need different settings, an assigned policy is usually the more controlled layer.

Create or edit a policy

Policies are managed from the relevant product page, not directly in Global Settings:

  1. Go to My Products > Product > Policies.
  2. To create a policy, select Add Policy in the upper right.
  3. If the Add Policy dialog appears, select the required feature. For Endpoint Protection, also select the policy type.
  4. On the policy details page, assign the target users or devices, configure the selected feature, and enable or disable the policy.

To edit a policy, go to My Products > Product > Policies, open the policy type, and then select the policy. A policy contains the settings for a feature as a unit. You cannot, for example, distribute Threat Protection settings across several matching policies and expect Central to combine them for each device.

Additional policies are only needed when you want to deviate from the shared standard. Sophos supplies the Base Policy for some features with best-practice settings already configured. Network-specific features such as Application Control or Peripheral Control must instead be configured for your environment. Alongside settings and assignments, a policy can specify whether it is enforced and whether it expires; an expiry is useful for a time-limited pilot, for example.

Understand policy priority

Every function has a Base Policy. It cannot be deleted or disabled and applies when no more specific policy matches.

Additional policies are evaluated from top to bottom. The first matching policy wins. Place specific policies above general rules. A user or device does not automatically combine individual settings from multiple policies for the same function.

User policies follow the person across their devices. Device policies apply independently of the signed-in person. When both types are supported for the same function, order still decides.

Do not infer the effective policy only from its position in the list; verify it at the target. On a computer’s details page, the Policies tab shows the policies that apply. For a user group, go to My Environment > Users & Groups > Groups > Group > Policies. You can open a policy there, but remember that editing it affects every group to which that policy is assigned.

Check role permissions before editing

The assigned administrator role determines which products and policy actions are available. For a Custom Role, check product access separately from policy permissions: Enable policy assignment allows an administrator to turn existing policies on or off and assign targets; Enable policy management also allows them to add, edit, and delete policies. Sophos only allows one of these two policy options to be active in a Custom Role.

If a button is missing or a page is read-only, check the role first. A permanently broader role is not an appropriate workaround; have a Super Admin grant the required capability and product access specifically.

Perform a safe change

Determine scope and dependencies before a global change:

  1. Identify affected products, devices, and users.
  2. Preserve the current setting and an export or screenshot.
  3. Document the business need and expiration date.
  4. Where possible, use a narrower policy for a pilot group first.
  5. Perform functional, security, and performance tests.
  6. Verify the Audit Log, the policy actually applied, and the device effect.
  7. Test or schedule rollback.

Assess automatic recommendations critically

Account Health can flag global or policy settings and sometimes offer Fix automatically. Such a correction follows the Sophos recommendation but does not know every local application and operating requirement.

Treat Auto-Fix like a normal change. Afterward, verify the Audit Log, policy assignment, device health, and business application. Review evidence with Analyze and retain Sophos Central Audit Logs; Use Sophos Central Account Health Check correctly explains the boundaries of automatic recommendations.

Common problems

Change affects more devices than expected

The setting was global or in a broadly matching policy with high priority. Check scope, product filters, and assignments. Roll back in a controlled way rather than adding a second, even broader exclusion.

Expected policy does not apply

The policy is disabled, assigned incorrectly, or below a more general matching policy. For a computer, use the Policies tab on its details page to verify which policy actually applies. For a group, also check that the expected policy appears under My Environment > Users & Groups > Groups > Group > Policies.

Custom administrator can see but not change a policy

The role may only have Enable policy assignment, or it may lack access to the affected product. Changes require Enable policy management; a Super Admin must grant that permission deliberately.

Global Settings appears empty

A product filter is active or the role cannot access the products concerned. Reset filters and inspect the role details.

Frequently asked questions

When does a setting belong in a policy?

When different users, devices, or groups require different values, or when a pilot is needed. Tenant-wide platform and shared list functions remain in Global Settings.

Are multiple matching policies combined?

For the same function, Central uses the first matching policy from the top. Settings are not arbitrarily combined from several policies.

Is a global exclusion easier?

It is faster but usually riskier because of its broader scope. Prefer the narrowest possible exclusion with an owner and expiration date.