Skip to content

Set up Sophos EMS

Use Sophos EMS (Email Monitoring System) to connect Sophos Central with third-party email services, such as Microsoft Defender or Google Workspace Security. EMS only monitors email traffic and reporting data. It doesn't apply protection or enforce any policies on the messages.

Instead, EMS gives you observation-only verdicts, showing what Sophos Email would have done if it handled those messages. EMS scans both inbound and outbound email, logs what it sees, and updates reports without taking any action. These verdicts help you see how Sophos Email policies work without changing how your current email service handles things.

When used with Microsoft 365, EMS also supports manual email clawback through API integration.

Sophos EMS also complements Sophos MDR and Sophos XDR by sending email-related data to the Sophos Data Lake. For MDR and XDR customers, this adds valuable context for threat detection and enhances incident response capabilities.

Before you start

It's important to understand the following points before you set up Sophos EMS.

  • Sophos EMS license


    Sophos EMS is a separate product and an alternative to Sophos Email. You can't use both at the same time.

    EMS is for monitoring only. It scans and logs emails but doesn't take action.

  • Sophos EMS mode


    When EMS mode is turned on, you'll see a warning banner on some pages in Sophos Central stating that emails are only being monitored and no actions are applied.

  • Non-configurable settings and policies


    When EMS mode is turned on, some settings and features are disabled, including SMTP Routing, Time of Click, Self Service Portal, and so on. EMS works on a journal copy of emails, so it doesn't support encryption.

    The Secure Message policies are also not available. You can configure Email Security and Data Control policies, but the actions configured are only for reporting purposes and won't be applied to the emails.

Complete the EMS setup

To set up Sophos EMS, do as follows:

Check that EMS mode is on

When you add your Sophos EMS license to your account, EMS mode is turned on by default. To use Sophos EMS, you need to make sure that the EMS mode is turned on.

To do this, do as follows:

  1. Sign in to Sophos Central.
  2. Click your Profile icon Profile icon., then click Account preferences.
  3. In Sophos Email Monitoring System (EMS), make sure Monitor Only mode (EMS) is turned on. If EMS mode is turned off, turn it on.

    For information about EMS mode, see Sophos Email Monitoring System (EMS).

  4. Click Save.

EMS mode is now active for Sophos Central.

Add mailboxes

You can add mailboxes to Sophos Central when you're in EMS mode.

You can add mailboxes in the following ways:

  • Automatically, using a directory service. You can use either AD sync or Microsoft Entra ID sync. For instructions on how to set up a directory service, see Directory service.
  • Manually in the user interface.
  • Manually by importing data from a CSV file.

Add a domain

You can add your domain and integrate it with Sophos EMS as follows:

  1. In Sophos Central, go to My Products > Email Security > Settings.
  2. In the left navigation menu, go to Products and Services > Email > EMS Domains.
  3. Click Add Domain.

    Note

    If you haven't added any domains yet, click Setup domains for EMS.

  4. Select your mail service and configure the required settings for your environment.

    Note

    If you're using another email security solution, select the appropriate option and configure any required delivery IP addresses.

  5. Configure journaling for your mail service:

  6. Complete the journaling configuration and return to the EMS Domains page.

Your domain is now onboarded to Sophos EMS.

Configure policies and settings

To manage your policies, go to My Products > Email Security > Policies.

In EMS mode, only Email Security and Data Control policies are available for configuration. These policies don't enforce actions but are used to generate reporting verdicts. To ensure accurate results, configure them to align with the policies in your current email environment.

To manage your email security settings, click the Global Settings icon Global Settings icon.. Then go to Products and Services > Email.

Test and confirm mail flow

After you've onboarded your domain, created your journal rules, and configured policies and settings, verify that journaling is working correctly.

Run a Quick Test

To run a quick test, do as follows:

  1. In Sophos Central, go to My Products > Email Security > Settings.
  2. In the left navigation menu, go to Products and Services > Email > EMS Domains.
  3. Locate your domain and click the Quick Test icon.
  4. Enter a mailbox address in the domain and run the test.

The test sends a sample email and verifies that the journal rule is configured correctly and that email is being journaled according to your policies.

If the test succeeds, the journal mailbox and the mailbox address you specified should receive copies of the test email according to your journaling configuration.

If the test doesn't complete within the expected time, wait a few minutes and run the test again.

Optionally, you can further validate your configuration by sending inbound and outbound test emails to users covered by the journal rule.

Check Message History

To confirm that email has flowed through Sophos EMS, check the Message History report.

  1. Sign in to Sophos Central.
  2. Go to My Products > Email Security > Reports > Message History.

If mail is flowing through the system, you'll see entries in this report.

Troubleshooting

If mail isn't flowing as expected or you don't receive the test email, take the following steps:

  1. Verify that you configured the Sophos Delivery IPs correctly.
  2. Verify that the mailbox you're testing with exists in Sophos Email Security.
  3. Verify that the journal rule is active and correctly configured.

If mail still isn't flowing after completing these checks, contact Sophos Support.

Manage domains

You must be a Super Admin to use this feature.

If you've added domains, you can do the following actions:

  • Connect or disconnect your domain to or from post-delivery protection.
  • Configure the post-delivery protection feature for your users.

    Note

    Sophos EMS only supports the on-demand clawback feature in post-delivery protection. The auto search and remediate feature doesn't work in EMS. Configure post-delivery protection before using on-demand clawback. See Post-Delivery Protection.

  • Edit your domain.

  • Delete your domain.

Edit a domain

To edit a domain, click the domain name in the list, make your changes, and click Save.

Delete a domain

If you no longer want Sophos EMS to monitor a domain, you can delete the domain.

Warning

Deleting a domain stops EMS scanning and logging for that domain immediately.

To delete a domain, click the Delete icon Delete icon. next to the domain you want to delete. In the confirmation dialog, click Delete to confirm the deletion.

What happens when you delete a domain?

When you delete a domain that was configured automatically, Sophos removes the link between the journal rules and the deleted domain. If the deleted domain is the last domain for the Microsoft 365 tenant, Sophos removes the journal rules and the Microsoft 365 application it created.

Microsoft 365 doesn't allow Sophos to reset the Journal NDR fallback mailbox. If you need to change the NDR mailbox address, you must do so manually in Microsoft Purview.

Note

Background cleanup of Microsoft 365 resources might take a few minutes to complete after you delete a domain. Avoid performing other EMS domain operations until the cleanup finishes.

If you created the journal rules manually during EMS onboarding, or if you're using another journaling source, you must manually remove the journal rules and any dependent configurations.

You must also undo any related changes to your domain settings and email configuration.