Security Review
Internal Solutions Engineering toolSophos Central
Run a live security review in minutes
Connect with a customer's read-only Service Principal and pull their Account Health Check, endpoint and server estate, network appliances, detections and cases into one report you can export as a branded PDF.
Nothing is stored
Credentials and API responses stay in browser memory for this session only. No database, no local storage, no saved reviews.
Read-only by design
Every call is a GET (plus the detections query) against Sophos Central. The app never changes customer configuration.
Creating the API credential
- In Sophos Central go to Global Settings → API Credentials.
- Add a credential and assign the role Service Principal ReadOnly.
- Copy the Client ID and Client Secret. The secret is shown only once in Central — if it is lost, regenerate it.
- Partner and organization credentials work too; you will pick the tenant next.
Connect to Sophos Central
Enter the customer's Service Principal credentials.
No credentials?