Synchronized user ID authentication
Synchronized user ID authentication uses Security Heartbeat to provide user authentication for endpoint users.
Synchronized user ID supports users authenticated through Active Directory (AD) and Microsoft Entra ID. The Sophos Endpoint agent installed on an endpoint device shares the user's identity information with the firewall through Security Heartbeat. The firewall then verifies the user against the configured authentication server and activates the user account.
For Microsoft Entra ID users, the firewall uses the User Principal Name (UPN) to identify the user and retrieve the user's group memberships. This information is used to apply user-based and group-based policies, synchronized security policies, and user authentication on the firewall.
Process
Synchronized user ID authentication uses different user identification methods depending on the configured authentication server.
Active Directory users
The synchronized user ID authentication process for Active Directory (AD) users is as follows:
- Users sign in to a device protected by Sophos Endpoint using their Active Directory credentials.
- The firewall's heartbeat daemon receives the device's heartbeat status along with the domain name and username. The domain is taken from the user's UPN, and the username is taken from the user's sAMAccountName.
- The firewall checks the correct AD server to serve this sign-in request based on the domain and looks for the correct username in the firewall user database.
- The heartbeat daemon forwards the user sign-in request to the Active Directory server.
- The signed-in user is displayed on the Live users page.
Microsoft Entra ID users
The synchronized user ID authentication process for Microsoft Entra ID users is as follows:
- Users sign in to a device protected by Sophos Endpoint using their Microsoft Entra ID account.
- Sophos Endpoint sends user identity information to the firewall through Security Heartbeat.
- The firewall uses the user's UPN to identify the Microsoft Entra ID user.
- The firewall retrieves the user's Microsoft Entra ID group memberships.
- The firewall activates the user and applies the appropriate user and group policies.
- The signed-in user is displayed on the Live users page.
If an endpoint heartbeat is lost or missing, such as when an endpoint goes to sleep, the heartbeat daemon signs out the user from the firewall as a synchronized ID user. However, other endpoint authentication mechanisms may still apply. Traffic from the endpoint may be dropped until the user signs in again.
Requirements
For synchronized user ID authentication to work, the following requirements must be met:
- A Sophos Central account must be linked to the firewall.
- The user account in Sophos Central must use the same email address as the corresponding user account on the firewall and in the configured authentication server.
- Sophos Endpoint is installed on domain-joined endpoint devices.
Active Directory requirements
For AD, the following requirements must be met:
- The firewall must be connected to the domain controller for AD authentication.
- In AD, the domain part of the UPN must exactly match the domain configured for your AD server in the firewall.
Microsoft Entra ID requirements
For Microsoft Entra ID, the following requirements must be met:
- The firewall is configured to use Microsoft Entra ID authentication. See Integrate Microsoft Entra ID with Sophos Firewall.
-
Sophos Endpoint 2025.1 or later is installed on managed endpoints.
Endpoints running Sophos Endpoint 2025.1 and later versions send the following user identity attributes:
- Login name
- Domain name
- UPN
Note
Earlier endpoint versions don't send the UPN attribute.
-
Sophos Endpoint must send the user's UPN through Security Heartbeat.
Note
- Sophos Firewall doesn't share or use passwords.
- Synchronized user ID doesn't support local users.
- Synchronized user ID authentication doesn't support devices protected by Server Protection.
Turn off synchronized user ID authentication
Synchronized user ID authentication is turned on by default. To turn it off, do as follows:
- Access the Advanced Shell.
-
Run one of the following commands:
- To keep it turned off even after the firewall restarts:
touch /content/no_userid - To only keep it turned off until the firewall restarts:
touch /tmp/no_userid
- To keep it turned off even after the firewall restarts:
-
To restart the access server service, run the following command:
service access_server:restart -ds nosync
Warning
The change in status isn't included in backups. You must turn it off again if you restore a backup.
Turn on synchronized user ID authentication
To turn on synchronized user ID authentication, do as follows:
- Access the Advanced Shell.
- To turn the feature on, run the following command:
rm /content/no_userid - To restart the access server service, run the following command:
service access_server:restart -ds nosync
Note
If HA cluster is configured, you must turn synchronized user ID authentication on or off from both the devices of the HA cluster.