How to enable 2FA on Sophos Central
Protect your Sophos Central account with two-factor authentication (2FA). Once enabled, signing in also requires a one-time code from your authenticator app — not just your password.
Step-by-step setup
- 1
Sign in to Sophos Central and open your Sophos Central account security settings.
- 2
Turn on two-factor authentication and choose the authenticator-app option.
Look for "Authenticator app", "Authentication app", or "TOTP" rather than SMS.
- 3
Scan the QR code with MS Authenticator App.
Open MS Authenticator App, tap add, and point your camera at the QR code Sophos Central displays. Can't scan? Enter the setup key manually instead.
- 4
Enter the 6-digit code to confirm.
Type the code MS Authenticator App generates to verify and link your Sophos Central account.
- 5
Save your backup codes.
Store the recovery codes Sophos Central gives you somewhere safe — you'll need them if you lose your phone.
Menu names on Sophos Central can change — the official Sophos Central 2FA documentation ↗ always has the exact, current path.
Frequently asked questions
- Does Sophos Central work with authenticator apps like MS Authenticator App?
- Yes. Sophos Central supports TOTP authenticator apps, so you can generate its two-factor codes in MS Authenticator App.
- Is Sophos Central two-factor authentication free?
- Yes. Enabling authenticator-app 2FA on Sophos Central is free — you only need the free MS Authenticator App.
- What if I lose access to my Sophos Central 2FA codes?
- Use the backup or recovery codes you saved during setup. If you didn't save them, contact Sophos Central support to regain access, then re-add the account to MS Authenticator App.
Generate your Sophos Central codes in MS Authenticator App
Free, offline, and encrypted. One tap for every 6-digit code.
Get the appMore Security guides
Novaz is not affiliated with, endorsed by, or sponsored by Sophos Central. Sophos Central and its logo are trademarks of their respective owner and are used here for identification only.

