Sophos Central - SSO Configuration

Sophos Central - SSO Configuration

Alert
This application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk.
Quote
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Sophos Central using Multi-Pass. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization.
Warning
To set up Multi-Pass with Sophos Central, ensure you meet the following requirements:
- Sophos Central admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Sophos Central are registered in your IdP and have the necessary permissions to access Sophos Central.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.





Sophos Central - SSO Configuration




Step 1 - Configure Sophos Central as the Service Provider (SP)

  • Log into Sophos Central as a Super Admin.
  • Navigate to General Settings > Verify Domains.
  • In Federated Domains, click Add domain.

  • Enter the correct domain and click Save.

  • On the Verify Domain Ownership screen, select Copy beside the TXT Record.
  • Log into your DNS Manager for the appropriate domain and create a TXT Record.
  • Return to General Settings > Verify Domains.
  • Under Verification Status, select Verify domain ownership.
  • If successful, the domain will display as verified along with the last date of verification.
  • Navigate back to General Settings > Federated Identity Providers.
  • Select Add Identity Provider and complete the fields below:

FieldValue
NameMulti-Pass
TypeOpenID Connect
VendorOther
Vendor NameMulti-Pass
Client IDsophos-central
Issuerhttps://ca.auth.kzero.com/realms/<TENANT_NAME>
Authz endpointhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/openid-connect/auth
JWKS URLhttps://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/openid-connect/certs

  1. Select your verified domain under Configure Domains.
  2. Check IDP enforced MFA under Confirm Identity provider MFA enforcement.

  1. Click Save

Step 2 - Configure Multi-Pass as the Identity Provider (IdP)

  • Open Multi-Pass Dashboard
  • Select the correct tenant and go to Integrations, then click on Applications.
  • Under the custom integration section, select OIDC.

  • Complete the fields below:
FieldValue
Client ID (=SP Entity ID)sophos-central
NameSophos Central
DescriptionSophos Central OIDC Integration
Client AuthenticationON
Home URLhttps://central.sophos.com
Valid Redirect URIshttps://login.sophos.com/login/callback
  • Click Add Integration.
  • Go to the Advanced Console by clicking on the right side of your screen.

  • Click on Client and search for Sophos Central.
  • Ensure all fields are populated as shown below:
General settings (Multi-Pass)
FieldValue
Client IDsophos-central
NameSophos Central
DescriptionSophos Central SSO Integration
Always display in UION
Access settings (Multi-Pass)
FieldValue
Root URLhttps://central.sophos.com
Valid Redirect URIs (ACS)https://central.sophos.com/*
Admin URLhttps://central.sophos.com/
Capability Config
SettingValue
Client AuthenticationON
Authentication FlowStandard & Implicit Flow