Internal Solutions Engineering tool

Sophos Central

Run a live security review in minutes

Connect with a customer's read-only Service Principal and pull their Account Health Check, endpoint and server estate, network appliances, detections and cases into one report you can export as a branded PDF.

Nothing is stored

Credentials and API responses stay in browser memory for this session only. No database, no local storage, no saved reviews.

Read-only by design

Every call is a GET (plus the detections query) against Sophos Central. The app never changes customer configuration.

Creating the API credential

  1. In Sophos Central go to Global Settings → API Credentials.
  2. Add a credential and assign the role Service Principal ReadOnly.
  3. Copy the Client ID and Client Secret. The secret is shown only once in Central — if it is lost, regenerate it.
  4. Partner and organization credentials work too; you will pick the tenant next.

Connect to Sophos Central

Enter the customer's Service Principal credentials.

No credentials?