Skip to content

Multi-factor Authentication

You can require MFA for managed users when they sign in to Sophos Fusion applications and add an extra verification step for administrators before they perform high-risk operations in a customer tenant.

MFA Coverage

You must be a Super Admin to use this feature.

Note

You can't turn off this feature after you turn it on.

Expand MFA Coverage enables an MFA prompt for managed users when they sign in to Sophos Fusion applications that didn't previously require MFA. Managed users who haven't previously set up MFA will be prompted to do so when they sign in to portals such as the Self Service Portal or Sophos Support Portal.

If a user has access to multiple Sophos portals, then any portal that opts in to expanded MFA coverage results in additional MFA requirements for that user.

To turn on this setting, do as follows:

  1. Click the Global Settings icon Global Settings icon..
  2. Click Access Control > Sign-in and Identity and click Multi-factor Authentication.
  3. Under MFA Coverage, turn on Expand MFA Coverage.

Transaction Authentication using MFA

You must be a Super Admin to use this feature.

Note

Your browser must allow pop-ups. You may need to disable pop-up blockers or add an exception for sophos.com.

Transaction Authentication using MFA adds an extra verification step before administrators can perform sensitive operations in a customer tenant. This helps protect against unauthorized actions if an administrator's Sophos Fusion session or device is compromised.

When turned on, administrators must re-authenticate every time they start a Live Response session. They must also re-authenticate when they attempt a Response Action if they haven't re-authenticated within the last 15 minutes.

Note

This setting isn't available for administrators whose sign-in is allowed only through a federated identity provider (IdP) and if MFA is provided exclusively by the federated IdP.

To turn on this setting, do as follows:

  1. Click the Global Settings icon Global Settings icon..
  2. Click Access Control > Sign-in and Identity and click Multi-factor Authentication.
  3. Under Transaction Authentication using MFA, turn on Require re-authentication before executing high risk operations.

When turned on, administrators must sign out and sign back in for the change to take effect.